Privacy Policy
This Privacy Policy describes how Chess DNA ("we", "us", or "our") collects, uses, discloses, and protects your information when you use our web application and iOS/Android apps (together, the "Service"). By using the Service you agree to the terms described below.
1. Information We Collect
1.1 Information you provide directly
- Account information. When you sign up we store your email address (or OAuth identity from Google / Apple / chess.com), a display name, and any preferences you configure.
- Chess identifiers. Your chess.com or Lichess username, provided voluntarily to enable game imports.
- Feedback & support correspondence. Bug reports, support emails, or content you submit through in-app forms.
1.2 Information imported from third-party chess services
- Chess games. When you connect a chess.com or Lichess username, we fetch your public game history (PGNs, timestamps, opponents, ratings, outcomes) via their official public APIs. We never receive passwords for those services.
- Public profile data. Public avatar URL and country from chess.com's public player endpoint, displayed in share cards.
1.3 Information collected automatically
- Usage analytics. Aggregate usage counters (e.g. how many analyses or AI generations you've run) tied to your account. These are never shared with third parties for advertising.
- Technical logs. Standard server logs (IP address, user-agent, timestamps) retained for a maximum of 30 days for debugging and abuse prevention, then deleted.
- No mobile advertising IDs. Our iOS/Android apps do not use IDFA, AAID, or a mobile ad-tracking SDK. On the web we use a limited set of analytics and ad-measurement tools (described in section 9) which load only after you opt in via our consent banner.
- Push-notification token (mobile apps only). When you install the iOS or Android app and grant notification permission, our push provider OneSignal generates an anonymous device push token so we can send you transactional notifications. The token is not linked to advertising IDs and you can revoke it any time in your device settings.
2. How We Use Your Information
- To provide the core Service: run engine analysis on your games, compute your skill profile, detect weakness patterns, generate training plans.
- To send AI prompts to our AI provider (Anthropic Claude, OpenAI, or Google Gemini) when you use AI features like commentary or exercise generation.
- To respond to support requests.
- To improve the Service (aggregate, de-identified usage metrics only).
We do not sell your personal data for money. We use a limited set of advertising-measurement pixels (see section 9) to understand which campaigns bring people to Chess DNA. Where this counts as “sharing” for cross-context advertising under laws such as the California CCPA/CPRA, you can opt out at any time via “Your Privacy Choices” in the footer, and these tools load only after you opt in via our consent banner.
3. When We Share Information
Your data is shared only with the following categories of service providers, and only to the extent necessary to deliver the feature you're using:
- Database & storage. Supabase (our database provider) stores your account data, games, analyses, and preferences.
- Authentication. Base44 powers account sign-up and login.
- Cloud analysis. On paid plans, your game positions are sent to our analysis server hosted on Fly.io to run the Stockfish engine. On the free plan, analysis runs on-device in your browser.
- AI providers. When you use AI features, the relevant prompt is sent to the AI provider we route it to (Anthropic Claude, OpenAI, or Google Gemini). Their data-retention and training terms apply to those requests.
- Chess game APIs. chess.com and Lichess public APIs receive only the username you entered.
- Flag CDN. Your country flag (if shown on a share card) is fetched from flagcdn.com as a static PNG; no personal data is sent.
- Analytics & ad measurement. To measure usage and the performance of our ads we use Contentsquare (product analytics, including session replay and heatmaps), the TikTok pixel, and the Reddit pixel. These may receive a hashed identifier (such as your hashed email) and your interactions with the site. They load only after you opt in via our consent banner; you can withdraw at any time via “Your Privacy Choices” in the footer. We also keep our own first-party usage analytics on our backend.
- Legal compliance. We may disclose information if required by valid legal process (subpoena, court order) and only the minimum necessary.
4. Data Retention
- Account and game data are retained as long as your account is active.
- If you delete your account (in-app: Settings → Danger Zone, or via the Data Access Request form), all game, analysis, pattern, preference, and AI-generated records are permanently removed from our database.
- Server logs are rotated and deleted after 30 days.
- Backups are retained for up to 60 days before being overwritten.
5. Your Rights
Depending on your jurisdiction (EU/UK GDPR, California CCPA/CPRA, UK DPA, Brazil LGPD, and similar), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated data.
- Export (portability) a copy of your data in a machine-readable format.
- Restrict or object to certain processing.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your supervisory authority (e.g. your national data protection regulator).
To exercise any of these rights, submit the Data Access Request form or email us at yuval@chessdna.app. We respond within 30 days.
6. Children's Privacy
Chess DNA is not directed at children under 13, and you confirm that you are 13 or older when you create an account. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
7. Security
- All data in transit is protected by TLS 1.2+ (HTTPS).
- Data at rest is encrypted by our database provider (Supabase).
- We use role-based access controls; only the operator has admin access, and only for debugging or support.
- No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you within 72 hours where required by law.
8. International Data Transfers
Our infrastructure, hosting (Supabase, Fly.io), and AI providers operate in the United States and other jurisdictions. When you use the Service from outside those regions, your data is transferred under Standard Contractual Clauses (SCCs) or equivalent safeguards provided by the relevant provider.
9. Cookies & Local Storage
Strictly necessary storage. Chess DNA uses localStorage and IndexedDB to keep you signed in, remember your preferences, and cache app data so it survives a page reload. These are essential to run the Service and are always on.
Analytics & advertising measurement. We also use a limited set of third-party tools that set cookies or similar identifiers: Contentsquare (product analytics, including session replay and heatmaps), the TikTok pixel, and the Reddit pixel (to measure the performance of ads that bring people to Chess DNA). These load only after you opt in via our consent banner — we do not run them until you accept, in any region. You can change your choice at any time through “Your Privacy Choices” in the site footer, which also serves as your opt-out of “sale”/“sharing” under U.S. state privacy laws.
10. Third-Party Links & Content
The Service may link to third-party websites (chess.com, Lichess, provider docs). We are not responsible for their privacy practices; please review their policies separately.
11. Changes to This Policy
We may update this Privacy Policy occasionally. When we make material changes, we'll update the "Last updated" date above and, where required, notify active users by email or in-app banner before changes take effect.
12. Contact
Questions or requests about this policy?
Email: yuval@chessdna.app
Data request form: /data-access-request.html