Security and subprocessors

What protects the game, who processes what, and how to tell us about a weakness before telling anyone else.

Last updated October 5, 2026

How the game is built

  • Everything travels over HTTPS, and sign-in is handled by our platform rather than by code in the game.
  • Scores are written by our servers, not by the device at the table, so a score cannot be edited from a browser.
  • Records are protected so that each player can only read their own private data, and support tickets are readable only by their author and the support team.
  • Right now there are no advertising scripts, no ad networks and no advertising trackers in the game. Two services count visits, and only after you accept analytics: Google Analytics 4 and our app platform Base44. Neither one receives your name or email address.
  • The only outside content the game loads is its own typefaces from Google Fonts, which sets no cookies.

Service providers (subprocessors)

  • Base44 (Wix.com Ltd.) — hosts the app, its database, sign-in, realtime game rooms and server-side logs, and provides the AI model service used by the help assistant and the Coach helpers. Servers in the United States.
  • Google LLC — Google Sign-In, only if you choose to sign in with Google. Google Fonts serves the game's typefaces.
  • Apple Inc. — Sign in with Apple, only if you choose to sign in with Apple.
  • Twilio SendGrid — delivers our emails: account codes and password resets, game emails, and support ticket confirmations and replies.

Data is processed and stored in the United States. The Privacy Policy at https://nertz.app/privacy lists what each provider does and what we send them.

Your account, kept safe

  • Use a password you do not use anywhere else, and keep your email account secure, because a password reset goes there.
  • We never ask for your password or a sign-in code, so nobody legitimate ever will.
  • If you think somebody got into your account, reset your password straight away and open a ticket under "Security vulnerability", then "I think my account was accessed".
  • If you signed in with Google, review the apps with access to your account and remove anything you do not recognise.

Reporting a vulnerability

  1. 1Open a ticket from the help centre and choose "Security vulnerability".
  2. 2Describe the issue, how you found it, what it affects, and what an attacker could do with it.
  3. 3Attach a proof of concept in the ticket instead of sending it around.
  4. 4Give us a reasonable chance to fix it before saying anything publicly.

Please work only against your own account and your own table, never against other players' data. We do not run a paid bug bounty, so we cannot promise a payment, but we read every report, fix what needs fixing, and credit researchers who want to be named.