Information stored on your device
Current game settings, player names, spotted plates, camera-verified state markers, scoring locations, and live-location preference are saved in your browser's local storage. This lets the current board continue after you close or refresh the page. In guest mode, that browser copy is the only saved game. If you sign in and start a cloud game, the current Player 1 board is also saved to your account through the authenticated cloud service.
Accounts and cloud games
If you create an account, our authentication provider stores your email address, password credential, account identifier, and any display name you provide. Spot the States does not receive or store your readable password.
Signed-in games store the game name, start and end times, optional start and end location labels, game settings, spotted plates, scoring state, points, verification markers, and the account identifier that owns the game. These records provide cloud resume, game history, and total statistics across signed-in devices.
Cloud game requests pass through authenticated server endpoints. The browser does not receive database credentials and cannot choose another account's ownership identifier.
Live location
Live location is optional and only appears when you play with points. If you turn it on, your browser asks for permission and provides your coordinates directly to this page. The page compares those coordinates with a U.S. state boundary map downloaded from this site, then fills in your current state.
The state-boundary comparison happens in your browser. While live location remains on, the page checks again every 5 minutes. You can turn it off at any time or revoke permission in your browser settings.
When you spot a plate while live location is on, the app records that spotting point at five decimal places so it can place a pin on your live road map. Guest-game pins remain in this browser. For a signed-in cloud game, spotting pins are sent through the authenticated game endpoint and stored with that game. The app does not save a continuous route or background-location history.
Opening the live road map requests standard map tiles from OpenStreetMap. That service may receive technical request details such as your IP address and the map area being viewed under its own privacy terms. The findings-poster view does not need those map tiles.
Optional start and end locations for cloud games are text labels that you enter yourself. They are separate from live location and do not require location permission.
When a signed-in cloud game ends, the app creates a findings-map image from the state-level locations already recorded with your spotted plates. That souvenir image is stored with the completed game in Netlify object storage. Deleting the game or all cloud data also deletes its saved map and live-location spotting pins.
Camera plate verification
Plate verification is optional and requires a live camera capture; gallery uploads are not offered. The captured image is sent to a temporary recognition endpoint and processed in memory to identify only the issuing U.S. state or District of Columbia. The image and plate number are not saved to disk, object storage, logs, or the game database, and the image data is discarded after processing.
Verification records contain only the detected or confirmed state, processing time, confidence score, verification status, and an approximate location rounded to two decimal places when location permission is available. Camera verification uses an AI recognition provider to process the temporary image. Low-confidence results require you to confirm or correct the state before it is awarded.
Emailing results
Emailing results is optional. When you request an email, the email address and game summary are used only to deliver that message to the recipient you choose. Depending on site configuration, the message is sent through our email delivery provider or opened in your device's mail app. We do not sell this information or share it for advertising.
Analytics and advertising
We do not use your live location for analytics, advertising, or profiling. We do not sell personal information.
Your choices
You can play without live location by selecting a state manually. You can clear guest data with the Clear game control, remove this site's local storage in your browser settings, delete individual cloud games, or delete all cloud game and statistics data from Account settings. You can also request password recovery, change your password, sign out, and manage location permission through your browser or device.
Deleting cloud game data does not delete the Identity login itself. Account access remains available so you can start over securely.