Skip to content
Imposter
How to playAboutContact

Privacy

Privacy policy

Last updated 6 October 2026.

This policy explains how the Imposter Game Generator handles information. The short version: the game runs on your device, the cookie banner defaults to off, and we do not sell personal data. The site is run by an independent operator and does not publish a contact email address at the moment.

Who is responsible

The publisher of this website is the controller for any personal data that actually reaches us, which in practice means an email you choose to send. The game itself does not transmit player names, word lists or rounds to us. Hosting is provided by Cloudflare, which processes connection data such as IP address as part of delivering the pages. Their privacy notice is at cloudflare.com/privacypolicy.

What stays in your browser

If you use the optional features, the site stores these in local storage on the device:

  • Game settings: player count, imposter count, category, hint mode, timer and reveal style.
  • Optional player names and any custom word list you type.
  • Your colour theme.
  • Your cookie choice, so we do not ask on every page.

The last word dealt is kept in session storage for that visit so Play again can avoid an immediate repeat. Close the tab and that memory goes. None of this is a server account. Clear the site data in your browser settings and it is gone.

Cookies, local storage and PECR

Under the Privacy and Electronic Communications Regulations (PECR), storing or reading information on your device needs your consent unless it is strictly necessary for a service you asked for. Remembering the game you just set up, and remembering the consent choice itself, is treated as necessary for the game and for this banner. Advertising and analytics storage are not necessary. They stay off unless you opt in.

The banner offers Accept all, Reject all and Manage with the same prominence. Rejecting is as easy as accepting. You can reopen the banner from Cookie settings in the footer and change your mind. The choice is stored in local storage, not in a tracking cookie.

Google Consent Mode v2 defaults are set to denied before any optional tag could run: ad storage, ad user data, ad personalisation, analytics storage, functionality storage and personalisation storage. Security storage is granted because it is not used for advertising. No analytics product is installed. No advertising script is loaded.

Advertising that is not switched on yet

Empty spaces are reserved for adverts so that, if advertising is added later, the page does not jump. Those spaces stay empty until an advert is actually switched on, and they are hidden during the card reveal so a tap cannot hit an advert by mistake.

If Google AdSense is added, it will load only after you grant advertising consent, from the single hook described in the site’s code. AdSense may then store or access information on your device and use it to measure or personalise ads, under Google’s advertising policies. In the UK and EEA, AdSense approval will likely require a Google-certified consent management platform, such as Google’s free Privacy & messaging tool, to replace or sit in front of this banner. Until that exists, the banner is the control, and the default remains denied.

If Amazon Associates links are added later, some outbound links may be affiliate links, which means the publisher may earn a commission. Amazon may set its own cookies when you follow those links. Those links will not be enabled ahead of a proper disclosure on the page, and any non-essential storage they need will follow the same consent rule. Nothing on the site is an affiliate link today.

If you email us

If you write to the contact address, we receive your email address, anything in the message, and routine delivery data. We use that to read the message and reply. The lawful basis under UK GDPR is our legitimate interests in answering you, or steps towards a request you made. We do not add you to a marketing list. We keep the correspondence until the question is dealt with and for a short period afterwards in case you write again, then delete it unless we need it for a legal claim.

Children

The game is suitable for families, and a child may use it with an adult. Do not type a child’s full name if you would rather not; the pass screen works with “Player 4”. Names never leave the device as part of the game. We do not knowingly collect personal data from children on a server. If you believe an email includes a child’s data and you want it removed, write to the contact address.

Your rights

Where UK GDPR applies, you can ask for access, correction, erasure, restriction, or a copy of personal data we hold, and you can object to processing based on legitimate interests. Because the game data stays on your device, the practical way to erase it is to clear site data in the browser. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.

Transfers

Cloudflare may process connection data outside the UK in order to serve the site. Cloudflare describes its safeguards in its own privacy notice. We do not run a separate database of players to transfer.

Changes

If this policy changes, the date at the top will change with it. If we start using AdSense, analytics or affiliate links, the policy and the banner will be updated first, and non-essential tags will still wait for consent.

Advertisement

AboutContactPrivacyTerms

Free pass-the-phone word game. Settings stay on this device. Works offline after the first visit.