Check what surrounds the game
The most visible risk is not always inside the game. Look for advertisements styled like play or download buttons, automatic redirects, chat boxes, public usernames, and links that leave the original site. A child should be able to identify the real Play, Restart, and Full Screen controls without passing an advertisement.
coolmath launches its original games without an account and keeps favorites in the browser. That reduces data collection, but it also means favorites can disappear when browser storage is cleared.
A two-minute inspection
Open the game once before handing over the device. Confirm that sound can be controlled, full screen can be exited, and the page does not request notifications, location, contacts, a camera, or a microphone without a clear reason. Refresh the page and check whether an unexpected sign-in prompt appears.
On a shared Chromebook, avoid entering a child’s full name into a score field. If a service requires an account, read what is public, what a teacher or parent can delete, and whether the account is genuinely needed for the intended activity.
Privacy labels need to match behavior
A privacy page should describe analytics, advertising, cookies, local storage, forms, and third-party embeds actually used by the site. A broad promise such as safe for kids is not enough. For our own pages, we inventory browser storage and third-party requests before changing that description.
Inspect the browser, not only the page copy
In Chrome or Edge, the site-information panel can show permissions and stored site data. A parent does not need to understand every developer tool entry, but unexpected camera, microphone, location, notification, or download prompts are reasons to stop and investigate. Open one game, interact with it, refresh, and check whether an unfamiliar tab, extension prompt, or sign-in screen appears.
The current coolmath build uses local storage for optional favorites and recently played items. That information stays in the browser profile and can be cleared through browser settings. The launch build has no account, public profile, comment field, chat, advertising code, or third-party game embed. Hosting logs may still receive ordinary request information, which is why the privacy notice describes server records separately from browser storage.
A worked family-device scenario
Suppose two children share a family laptop. Use a separate supervised browser profile when practical, keep saved passwords unavailable, and open the intended game from a bookmark rather than a search advertisement. Play one round together, identify the actual game controls, and agree on a stopping point. When the session ends, close full screen and check that no additional tab or download opened.
On a school-managed Chromebook, the school’s filtering and logging rules may add behavior that the game site does not control. Ask the school which account, extension, and browsing records apply. Do not infer that an account-free game creates an anonymous school session.
When not to continue
Leave the page if a control is disguised as a download, a child is pushed into public chat, sensitive information is requested without a clear necessity, or closing an advertisement repeatedly opens another page. Capture the exact URL and a screenshot for an adult or administrator rather than asking a child to troubleshoot.
Our checklist reduces avoidable surprises; it cannot certify a site as universally safe or replace age-appropriate supervision. Recheck services after material changes because advertising, analytics, account requirements, and external links can change independently of the game itself.
Our judgment
Prefer games that work without an account, have clear controls, collect little data, and let an adult understand the learning purpose after one round. No checklist can replace supervision for a younger child, and a privacy policy does not prove that every advertisement or external page is appropriate.
