Skip to content

Privacy Policy

Last updated 2026-09-05

Cool Idle Games ("we", "us", "the site") is operated by William Wan, a sole operator based in Australia. This policy explains what information the site collects when you visit, why, and what choices you have about it.

This site is a directory of idle and incremental games, some of which we build from source and host ourselves, and it is intended to carry display advertising in future. That combination means more than one party can end up handling data when you use it. This policy tries to be honest about which parts we control and which we do not, and about which parts are live today as opposed to planned.

1. Who we are

  • Operator: William Wan
  • Country: Australia
  • Contact: [email protected]
  • Postal address: not published; email is the contact channel

We are a small, independent operator, not a company with a dedicated privacy office. If you have a concern, email us and we will do our best to answer personally.

2. What this site collects

2.1 Information we collect directly

None. There are no accounts, no logins, and no sign-up of any kind, either to read the directory or to play a game hosted here. There is no form on this site that asks you for anything. If that ever changes, this section will describe exactly what is stored, where, and for how long, before the change ships.

If you contact us by email, we receive whatever you send us, which is your email address and your message. We use that only to reply to you, and we do not add it to a mailing list unless you ask us to.

2.2 Information collected automatically: analytics

Where traffic measurement is switched on, it is Cloudflare Web Analytics, and nothing else. This is worth describing accurately rather than in vague terms, because it is genuinely different from tools like Google Analytics:

  • Cloudflare Web Analytics does not use cookies and does not use any other persistent client-side identifier.
  • It does not fingerprint your device and does not track you across other websites.
  • It measures aggregate counts, meaning pageviews, approximate visitor counts, referrers, and browser and country-level data, without building an individual profile of you.

The beacon is switched on by a build-time setting, and when it is off the script is not written into the page at all. Because it sets no cookie and stores nothing on your device, it does not trigger the cookie-consent requirement under the EU and UK ePrivacy rules the way tracking cookies do. It still involves processing some request data, such as your IP address briefly, to derive a country and de-duplicate visits, which is why it is disclosed here rather than treated as entirely outside data protection law.

2.3 Information collected automatically: advertising

There is no advertising on this site as of the date at the top of this page, and no advertising or ad-measurement script is loaded on any page.

We intend to run Google AdSense display advertising on directory and guide pages. If and when ads are live on a given page:

  • Google and its advertising partners may set cookies or use similar technology in your browser to serve ads, measure their performance, and, where you have consented, personalise which ads you see based on your browsing activity.
  • Those would be third-party cookies, set by Google and its partners, not by us. We would not have access to the personal data Google collects through them, and we do not control what Google does with it beyond what Google's own policies say.
  • You can see and manage the ad-related choices Google offers at adssettings.google.com and read Google's own explanation of how it uses data at policies.google.com/technologies/ads.

For visitors in the EEA, the UK, and Switzerland, we, or a consent management platform we use, will ask for your consent before any cookie that is not strictly necessary is set, and before your data is used for personalised advertising, in line with Google's EU User Consent Policy. See Section 6. This page will be updated before the first ad is served, not after.

2.4 Games, frames, and local storage

Some game pages carry a playable frame. Today every one of those frames is served from our own domain, from a build we made ourselves out of the game's published source. None of them loads a third party's code, and none of them carries a third party's advertising or analytics.

Two things follow, and both are worth stating plainly:

  • A game we host ourselves stores its save file in your browser's local storage, on our domain. That data stays on your device, is not transmitted to us, and has no account attached to it. It identifies a browser, not a person. Clearing site data for this domain deletes it.
  • Games we have no right to host or embed are not framed at all. Those pages link out to the developer instead, and following that link takes you to a site with its own policy that is not ours.

If we ever embed a game hosted by a third party, whether through a distribution network or by direct arrangement with a developer, that is a separate website loaded inside ours, and it can set its own cookies, use its own local storage, and run its own analytics or advertising, none of which we would control. In that case we would name the provider on the game's page, link its privacy policy where we know it, and update this policy before that game went live. In every case a frame is not loaded until you click to play, so nothing loads from anyone else until you ask for it.

2.5 Server and hosting logs

The site is hosted on Cloudflare Pages. Cloudflare, as our infrastructure provider, processes standard connection information such as IP address, timestamp, and requested URL, in order to serve the site and protect it from abuse, for a limited retention period. This is normal for any website and is separate from the analytics described in Section 2.2. See Cloudflare's privacy policy for how Cloudflare itself handles this.

For visitors covered by the GDPR or the UK GDPR, we rely on the following legal bases:

  • Legitimate interests for aggregate, cookieless analytics, and for basic security and hosting logs.
  • Strict necessity for the save file a game writes on your device after you press play, which exists only because you asked the game to run.
  • Consent for any cookie or local storage that is not strictly necessary, and for personalised advertising, obtained through the mechanism described in Section 6.
  • Consent or legitimate interest, depending on how you reach us, for replying to emails you send us.

Where a third party processes your data under its own legal basis, that is governed by their policy, not this one.

4. Who we share information with

  • Cloudflare, as our hosting provider, and as our analytics provider where analytics is switched on.
  • Google (AdSense) and its advertising partners, for ad serving and, with consent, personalisation, once advertising is live.
  • We do not sell personal information, and we do not share it with anyone for their own independent marketing purposes.

There is no third-party embed on the site today, so there is currently no other recipient of any kind.

Pages that list games hosted elsewhere show a preview picture for each one. Those pictures are copies, stored on our own domain and served from it, so viewing the list sends nothing to the site the game is on and does not disclose your IP address to them. That only happens if you click through, and then it is an ordinary visit to their website, governed by their policy rather than this one.

5. International visitors and international data transfers

This is an Australian-operated site, but because the content is aimed at a general audience found through search, visitors come from anywhere, including the EU and the UK. Two things follow from that, and they are easy to get backwards, so we state them plainly:

  • The GDPR and the UK GDPR apply based on who is visiting, not where we are. If you are in the EU or the UK, those laws protect you when you use this site, regardless of the fact that the operator is in Australia. This is why Sections 2.2, 2.3, and 6 exist.
  • The Australian Privacy Act applies based on where the operator is, and, as described in Section 9, currently applies more lightly to a small sole operator than the GDPR does to anyone. It does not replace GDPR obligations toward EU or UK visitors; the two sit alongside each other.

Where data is transferred outside your own region, for example to Cloudflare's or Google's servers, which may be located in the United States or elsewhere, those companies rely on their own transfer mechanisms, such as the EU-US Data Privacy Framework or standard contractual clauses, to do so lawfully. We do not operate any international data transfer infrastructure of our own beyond choosing providers who publish how they handle this.

6. Your choices and rights

There is nothing on this site today that requires consent, so no consent prompt is shown. If you are in the EEA, the UK, or Switzerland, you will be shown one before any non-essential cookie is set or your data is used for ad personalisation, which in practice means before advertising goes live. No consent platform is installed yet, because there is nothing yet to consent to; this page will name the mechanism and how to change your choice before one is needed.

Wherever you are, including Australia, your browser's cookie and storage controls will limit third-party advertising cookies; Google's own opt-out tools are at adssettings.google.com.

6.2 Rights under the GDPR and the UK GDPR

If the GDPR or the UK GDPR applies to you, you have the right to ask us to confirm what personal data we hold about you, correct it, delete it, restrict or object to its processing, and receive a copy of it in a portable format, subject to the usual exceptions. Because we collect no personal data directly at all, as described in Section 2.1, most of these requests will have a very short answer, but we will still respond properly to any request. Email [email protected]. You also have the right to complain to your local data protection authority.

6.3 Rights under the Australian Privacy Act

See Section 9 for what currently applies to a small operator like this one. Where the Act does apply to us, or to the extent we choose to follow its principles regardless, you can ask what personal information we hold about you and request correction, by emailing [email protected].

7. Children

This site is not directed at children and we do not knowingly collect personal information from children. Some games listed here are suitable for a general audience including younger players; that does not change what data we, as opposed to a game's own provider, collect about any visitor, which today is none.

8. Advertising disclosure

Google requires publishers using AdSense to tell visitors plainly what happens with their data for advertising purposes. Ads are not running yet, and when they are, the plain-terms position will be this:

  • Ads on this site may be personalised based on your prior activity across websites you have visited, unless you are in a region where consent is required and you have not given it, in which case non-personalised ads are shown instead.
  • We do not choose which specific ad you see; Google's systems do, based on signals including any consent you have given.
  • You can control ad personalisation generally, across any site using Google ads, at myadcenter.google.com or adssettings.google.com.

9. Australia: what genuinely does and does not apply here

It is easy to find privacy policy templates written for large US companies and copy obligations onto this site that do not actually apply to a small Australian operator. Here is the honest picture as at 2026-09-05:

  • The Australian Privacy Act 1988 has historically exempted small businesses with annual turnover under AU$3 million from most of its obligations, which would cover a solo site like this one in its early life.
  • That exemption is scheduled to be removed, with commencement reported as around 10 December 2026, after which many more small operators, including sole traders, would need to comply with the Australian Privacy Principles in full. Reform timelines have moved before, so the current position is best confirmed with the Office of the Australian Information Commissioner at oaic.gov.au.
  • Regardless of the exemption's status, some things already apply to any Australian operator: the statutory tort for serious invasions of privacy, and several carve-outs in the Act that the small business exemption never covered in the first place.
  • None of this affects your rights as an EU or UK visitor under the GDPR or the UK GDPR, which apply regardless of the operator's size or location, as described in Section 5.

We intend to follow the Australian Privacy Principles voluntarily as a matter of good practice even while any exemption technically applies, because it is the same standard we are applying to the rest of this policy, and because the exemption is on its way out regardless.

10. Changes to this policy

We will update this page when what we collect or how we use it changes, and update the date at the top. Anything that changes what is collected about you will be in place on this page before the change ships, not after.

11. Contact

Questions about this policy: [email protected]