Most free game sites are not, in a meaningful sense, free. They are paid for in data. A typical casual gaming portal — even the ones that look clean — quietly runs half a dozen third-party trackers, requires an account to play past the first level, gates content behind an email wall, and resells aggregate behavioral profiles to ad networks. That is the business model the category has settled into. We did not want to settle into it. This article explains, in concrete terms, what we do instead and why.
If you want the legally complete version, our Privacy Policy is the authoritative document. This piece is the philosophy behind it, and the practical answers to the questions players ask us most.
How Free Game Sites Usually Monetize
It is worth being specific about the norm we are deviating from, because “everyone does it” has a way of becoming invisible. A standard free-to-play portal monetizes through three layers stacked on top of each other.
- Display advertising. This is the layer we share — ads pay for the servers and the games.
- Account data capture. Many portals require sign-up to play beyond a trial, harvesting emails that are then used for retargeting email campaigns and, in some cases, sold or shared with partners.
- Behavioral tracking. Multiple third-party scripts follow you across the site and across the web, building a profile that is more valuable to advertisers than the ad inventory itself. The player is, in effect, a product sold twice: once as ad impressions, once as a profile — a pattern the Electronic Frontier Foundation (EFF) has documented across years of tracker audits.
The second and third layers are where the category’s privacy reputation collapses. They are also, in our experience, not actually necessary to run a sustainable free puzzle site. They make more money than advertising alone — that part is true — but the trade is a worse product and a worse relationship with the people playing it.
What We Do Differently
Our privacy stance can be stated in a single sentence: we collect the minimum needed to operate and improve the site, we never collect identity, and the only third parties we allow on the page are the ad networks that pay for it. The implications of that stance are concrete and worth listing.
This stance is not just an internal preference; it tracks the direction of the privacy laws we operate under. The EU's General Data Protection Regulation (GDPR) established the global baseline for data minimization and consent, and Indonesia's Personal Data Protection Act (UU No. 27 Tahun 2022, "UU PDP") — the law that governs our operating entity, PT Sunton Sun Indonesia — enforces the same principles domestically. Designing for "collect nothing you do not need" is the cheapest way to comply with both at once.
Under both GDPR and Indonesia's UU PDP, the default is not "collect first, ask later." The default is that personal data may only be processed for a specified, legitimate purpose, and nothing more. A site that never collects identity in the first place has nothing to leak, nothing to honor a deletion request for, and nothing to breach.— Summarized from the GDPR official text and UU No. 27 Tahun 2022 (UU PDP)
No sign-up. Ever.
There is no account on Suntongames. There is no login form. There is no “create an account to save your progress” flow that converts into a marketing database. Your game progress, where relevant, is stored in your browser’s local storage and stays on your device. If you clear your browser data, the progress is gone — and that is the correct trade-off, because the alternative is us holding a profile about you that we would then have to protect and that you would have to trust us with.
No email wall.
We do not ask for your email to play, to save progress, to “unlock” levels, or to receive rewards. If you want to contact us, you can email us directly — that address is in the Privacy Policy — but the direction of that communication is yours, not ours. We do not maintain a mailing list and we do not run email campaigns.
No third-party trackers beyond ad networks.
This is the line we are most explicit about, because it is the line that defines whether a site is privacy-respecting in practice rather than in policy. We do not run cross-site tracking scripts, behavioral profiling SDKs, or “analytics” services that build user graphs. The only third parties that load code on our pages are the advertising networks that actually pay us — and we keep that set as small as we can. When an ad partner asks to add a tracking SDK that does not directly serve ads, the answer is no.
Anonymous, aggregate analytics only.
We do need to know, in broad strokes, which games are played and how the site performs. So we run lightweight, privacy-respecting analytics that tell us aggregate numbers: how many sessions, roughly where from (country level), which games get opened, how long sessions last. None of this is tied to a name, an email, or a persistent identifier across visits. We cannot, even if asked, produce a list of “what Alice played on Tuesday,” because we never built the system that would let us know who Alice is.
If we cannot answer a data request about a specific person, it is not because we are refusing. It is because we engineered the system so that we would not have the data to answer.
What We Specifically Collect, and Why
Transparency only counts if it is specific. Here is the actual list of what our analytics and infrastructure touch.
- Aggregate session counts. How many sessions happened on each game. We use this to decide which games to keep and which to retire. See how we pick games to ship for why this matters.
- Rough geography, country level. We need this to ensure our CDN routes serve the right regions and to understand, in broad strokes, which languages to consider for future localization. We do not store city-level or IP-level granularity.
- Device class and browser. Phone, tablet, laptop; major browser. This drives our compatibility and performance work — see how we hit sub-3-second loads.
- Performance metrics. Core Web Vitals and our own load-time samples, collected from a small subset of sessions so we can detect regressions without monitoring everyone.
- Local storage on your device. Game preferences and progress. This never leaves your device; it is not transmitted to our servers.
What we deliberately do not collect: names, emails, precise locations, cross-site identifiers, persistent device fingerprints, behavioral profiles tied to a single user over time. The absence of these is not a feature we advertise and then quietly undermine. It is a structural property of how the site is built.
The Advertising Trade-Off, Stated Honestly
We are not going to pretend the site is funded by good intentions. It is funded by advertising. Google AdSense and similar partners serve ads on our pages, and those partners use cookies and similar technologies to measure and personalize ads. This is the one place where third-party code runs on our pages, and it is the one place where the privacy story is not fully ours to tell — Google’s ad privacy controls, including opt-out of personalized advertising, are described in our Privacy Policy.
We accept this trade because the realistic alternative — no ads, no sign-ups, no tracking — is a site that cannot pay its server bill. What we refuse is the layering that turns ad-supported into data-surveillance-supported. Ads pay for the games. That is the entire monetization model. There is no second business hiding behind it.
Why Privacy-First Is Also Product-First
It would be possible to write all of the above as pure principle. In practice, the privacy stance is also the product stance, and the two reinforce each other in ways that surprise people who assume privacy and good UX are in conflict.
No sign-up means no friction before the first game. That is not just a privacy win; it is the single biggest reason players stay. No email wall means no broken reset-password flow interrupting a session. No third-party trackers means fewer scripts competing for main-thread time, which is a measurable contribution to our sub-3-second load target. The design choice that respects the player is, almost without exception, the design choice that produces the better product.
The privacy stance is therefore not a cost we pay for being ethical. It is the architecture that lets the rest of the site be what it is: fast, frictionless, and focused on the game you came to play.
What This Means for You, Practically
If you have read this far, here is the practical takeaway. You can open Suntongames, play any puzzle on the catalog, close the tab, and return a week later — and there is no profile of you that grew during that process. Your browser may remember your progress locally; our servers did not learn anything about you that we could turn into a marketing email, because we never built the machinery to. If that ever changes, this article and our Privacy Policy will say so before the change ships.
Privacy is not a feature you toggle on. It is a property of the system you build. We built it that way on purpose, and we intend to keep it that way.