1. Controller and contact
The controller responsible for Chessiax is:
Simon Ribrant, operating Chessiax, Sweden
Privacy and data-protection contact: privacy@chessiax.com
2. Scope
This policy applies to personal data processed through the Chessiax Service. It does not govern independent third-party services such as Chess.com, Google, Supabase or external links. Those services have their own privacy information and responsibilities.
Public chess data can still be personal data. For example, a public Chess.com username, profile, rating history or game record may relate to an identifiable person even though the source is public.
Chessiax does not currently sell personal data or use personal data for third-party behavioral advertising. Chessiax does not currently implement third-party advertising.
3. Personal data we process
What Chessiax processes depends on the features you use, whether you are signed in and whether you choose to save or synchronize data.
A. Account and authentication data
- Chessiax account ID and email address;
- account creation, update and sign-in information provided by Supabase Auth;
- authentication session information, including access/refresh or equivalent session material managed by Supabase; and
- local onboarding status associated with the Chessiax account ID.
The password you enter is submitted to Supabase Auth. The current Chessiax application code does not write plaintext passwords to a Chessiax database table.
Purposes: create and secure an account, authenticate you, restore sessions, associate synchronized data with the correct user and prevent unauthorized access.
B. Public chess-platform data
- a public Chess.com username that you enter or that is stored with an analysis;
- public profile details such as avatar URL, profile URL, country, join date, status, title and follower count;
- public rapid, blitz and bullet ratings and public game records;
- public game identifiers/URLs, participants, results, timestamps, time controls, archive references and PGNs; and
- opening information and other metadata available in a public PGN.
Purposes: retrieve the requested public profile or games, identify the player's color/results, analyze performance, build a Coach Report, compare reports and prepare relevant training.
Chessiax may process a public username that is not the signed-in user's username. The current Service does not verify ownership of a Chess.com account.
C. User-submitted chess and content data
- PGNs pasted into the game-review tool;
- an optional username used to identify the player in a PGN;
- coach notes and optional session-feedback notes;
- training goals and choices; and
- free-text product feedback and contact permission.
Purposes: provide the requested review, save user-selected content, remember goals, personalize training, troubleshoot issues, evaluate feedback and respond where contact permission or another lawful basis permits.
Please do not place unrelated sensitive personal information in PGNs, notes or feedback.
D. Analysis, Coach Reports and player intelligence
- win/draw/loss, color, opening and opening-family statistics;
- estimated game phases and loss patterns;
- engine-derived moves, FEN positions, evaluation changes, critical moments and classifications;
- confidence information, weaknesses, summaries, recommended study and training plans;
- previous/current report comparisons and public-profile snapshots;
- Coach Reports, report history, deep analysis and player-intelligence state; and
- current or previous public Chess.com username attached to this state.
Purposes: deliver chess analysis, explain findings, preserve report history and create more relevant training.
E. Training, mastery and Adaptive Coach state
- training plans, weekly programs, active tasks and active training sessions;
- completed tasks/days, study-plan progress and training history;
- opening mastery, practice attempts, accuracy, correct/mistake counts, difficulty and timestamps;
- tactics/endgame/opening session progress and saved review evidence;
- session difficulty, helpfulness, optional note and next-step suggestion; and
- Adaptive Coach inputs, decisions and personalization state.
Purposes: restore progress, synchronize devices for signed-in users, adapt the next chess-training recommendation and show history.
F. Product feedback
- current page, including its query string and fragment where present;
- feedback type, rating and usefulness/accuracy/clarity choices;
- free-text message and whether follow-up is permitted;
- public Chess.com username, analysis ID, current focus, confidence and number of games analyzed where attached as context;
- Chessiax account ID if signed in, local feedback ID, source prompt and app version; and
- local delivery status and sent time.
Purposes: receive beta feedback, understand the relevant product context, diagnose issues, improve Chessiax and follow up where permitted.
G. Usage metering
- authenticated Chessiax account ID or an opaque guest UUID;
- analysis/refresh completion, logical operation UUID and duplicate-attempt status;
- plan label, monthly period, requested/analyzed game counts and source page; and
- usage totals and reset date returned to the user.
Purposes: maintain idempotent usage records, understand operation volumes and support current or future feature limits. The current beta is configured in an observe-only mode and does not include payment processing.
H. First-party product analytics
- event name, opaque guest UUID, per-tab session UUID and client-event UUID;
- Chessiax account ID derived by Supabase when signed in;
- source page, event/receipt timestamps and app version; and
- bounded categorical, Boolean or numeric properties such as games analyzed, focus category, confidence, training category/source/difficulty, session duration, helpfulness and counts.
The server strips properties outside an allow-list. The current first-party product analytics excludes email, password, session tokens, IP-based identity, browser fingerprints, Chess.com usernames, PGNs, Coach Report text, coach state, private notes and product-feedback message content from its event properties.
Purposes: understand key product actions, funnels, identity continuity, duplicate events and retention, and improve limited product operation.
I. Google Analytics information
When analytics is accepted, Chessiax can send GA4 a page label and allowed event parameters such as games requested/analyzed, training focus, difficulty, completed/total count and category. Google also receives ordinary request, browser, device and network information under its own service operation.
Purposes: understand traffic sources, campaigns and broad website/product behavior.
J. Technical and security information
Hosting and service providers may process IP address, request time, path, referrer, browser/User-Agent, response status and similar network or diagnostic information. Application logs contain bounded error/operation metadata, and some legacy backend statements log OpenAI-generated output. The current engine parser is designed not to log raw PGNs or FENs on parsing errors.
Purposes: deliver the Service, diagnose failures, prevent abuse and maintain security.
The exact fields and retention settings for provider logs depend on the production configurations used by Chessiax and its providers.
4. Where data comes from
We receive data:
- directly from you when you create an account, enter a username, paste a PGN, train, save a note or send feedback;
- from public Chess.com APIs at your request;
- from your browser and device through local/session storage and network requests;
- from Supabase when it authenticates your Chessiax account or returns your synchronized records;
- from Chessiax's own analysis, Stockfish engine processing and personalization logic; and
- from service providers that provide analytics, hosting, authentication or error information.
5. Purposes and lawful bases
The lawful basis depends on the processing and the circumstances.
| Purpose | Typical lawful basis under GDPR/EEA law |
|---|---|
| Create an account, authenticate, provide a requested public-profile/game/PGN analysis, save requested content, restore progress and provide training | Performance of a contract or steps at your request before entering a contract, where the processing is necessary to provide the Service |
| Process public chess data to offer requested analysis and relevant training, including data relating to a public username that may not belong to the user | Performance of the requested Service where applicable; otherwise legitimate interests in providing a public-data chess analysis tool, balanced against the public nature of the data, limited purposes and affected person's rights |
| Secure the Service, prevent abuse, diagnose errors and maintain limited technical logs | Legitimate interests in security, reliability and protection of users and systems; legal obligation where a specific law requires processing |
| Store limited usage records and first-party product events for idempotency, operation, measurement and improvement | Legitimate interests where the processing is necessary, proportionate and permitted; consent must be obtained first where applicable ePrivacy or data-protection law requires it |
| Use GA4 or other non-essential analytics storage/technology | Consent where legally required. You can reject or later withdraw the analytics choice |
| Receive and respond to product feedback | Performance of the Service or legitimate interests in support and product improvement; consent where we specifically rely on an optional permission, such as an optional follow-up choice |
| Establish, exercise or defend legal claims; comply with binding requests | Legitimate interests or legal obligation, as applicable |
We do not rely on consent for processing that is genuinely necessary to provide a feature you request merely because you agreed to use the Service. Where we rely on legitimate interests, you may object as described below.
6. Chess.com and public chess data
Chess.com is an independent third-party platform and public data source. Chessiax sends the public username in a request to Chess.com's public profile, statistics and game/archive endpoints and receives the public data returned by those endpoints.
Users may request analysis of a public Chess.com profile, including a profile belonging to someone who does not use Chessiax. To provide that requested analysis, Chessiax may process the publicly available profile, rating, game and PGN data described in this policy. Public availability does not remove any data-protection rights that may apply.
Chess.com remains an independent third-party source and handles its platform and Public API data under its own terms and privacy practices. If you have a question, objection or removal request concerning public Chess.com data processed by Chessiax, contact privacy@chessiax.com. Chessiax will assess the request under applicable law and may need enough information to identify the relevant profile or data.
Chessiax does not currently:
- use Chess.com OAuth;
- verify that you own the analyzed Chess.com username;
- access private Chess.com account information; or
- act on behalf of, or with endorsement from, Chess.com.
7. Cookies, local storage and session storage
The current Chessiax application code does not directly set a first-party cookie. It does use browser storage extensively.
Necessary account and product storage
- Supabase Auth uses its default browser-client configuration and browser-managed session persistence. The exact storage behavior depends on the deployed Supabase library and configuration.
localStoragepreserves account onboarding state, Chessiax analysis and Coach Reports, review/PGN data, coach notes, training plans, active/completed sessions, feedback, opening mastery, progress and user preferences.- A persistent opaque guest UUID in
localStoragesupports usage metering and first-party product-event continuity. - Pending usage-operation and analytics-deduplication records are stored locally to avoid duplicate events.
- Cached opening details and legacy ELO/recommendation results are also stored locally.
Session storage
First-party product analytics stores a random per-tab session UUID and session-level deduplication receipts in sessionStorage. This normally ends with the browser-tab session, subject to browser behavior.
Google Analytics choice and technology
The analytics banner stores accepted or rejected in localStorage under chessiax_analytics_consent. The code defaults Google analytics and advertising storage to denied. Advertising storage, ad user data and ad personalization are kept denied by Chessiax's consent calls.
The Google tag is nevertheless downloaded and configured on current product pages before the stored choice is read. With storage denied, Google Consent Mode may still send limited cookieless requests. The current beta also records the limited first-party product events described above independently of the Google Analytics choice.
Non-essential analytics and similar technologies should be activated only in accordance with applicable consent requirements. Chessiax's deployed consent behavior, including whether the first-party guest analytics identifier requires consent, is under manual compliance review. No third-party consent-management platform is present in the current beta.
You can clear Chessiax browser data using the account-page local-data tool or your browser controls. Clearing browser storage may sign you out, remove local progress and create a new guest identifier.
8. Who receives data
We disclose data only as needed for the Service, the purposes above, legal compliance or protection of rights. Chessiax currently uses these recipients or external services:
| Recipient/service | Current use and data involved |
|---|---|
| Supabase | Email/password authentication, browser-session management, account-linked database storage, feedback, usage metering and first-party product analytics. Depending on use, this can include account/email, synchronized Coach Reports/training state, PGNs and feedback |
| Render | Hosts the Flask backend identified for the current beta and can process backend requests, request metadata and application logs, including a username or PGN sent to Chessiax endpoints |
| Google Analytics / Google tag | Consent-related GA4 traffic and event measurement, plus ordinary request/device/network information as described above |
| Chess.com Public API | Receives the public username in API request paths and returns public profile, rating, archive and game/PGN data as an independent third-party source |
| OpenAI API | Current Chessiax calls send an ELO value for a short tip, an opening name for opening details, or public rapid/blitz/bullet ratings for a profile summary. These calls do not send the Chess.com username or PGN |
| Browser asset providers | Current product pages load code or assets from jsDelivr, code.jquery.com, cdnjs/Cloudflare, unpkg and chessboardjs.com. These hosts receive ordinary browser request metadata |
| Authorities or claim participants | Data may be disclosed where required by law or reasonably necessary to establish, exercise or defend legal claims |
Stockfish runs as software in the Chessiax backend environment and is not a remote data recipient in the current architecture. Chessiax also uses static Lichess-derived datasets/imports; the current code does not make runtime requests to a Lichess API.
9. International transfers
Chessiax is operated from Sweden, but service providers may process personal data in countries outside your country or outside the EEA. Specific processing locations depend on the providers and production configurations used.
Where GDPR requires safeguards for an international transfer, Chessiax will use an applicable lawful mechanism, such as an adequacy decision or approved contractual safeguards, and supplementary measures where required. The safeguards that apply depend on the provider arrangements in effect.
You may contact privacy@chessiax.com for information about safeguards relevant to your data.
10. Retention
Chessiax does not apply one fixed retention period to every category. Retention is based on the criteria below, and some categories do not currently have an automated deletion schedule:
- Account and synchronized product data: retained while the account and data are needed to provide the requested features, until the user clears supported cloud categories or requests deletion, and longer where needed for security, backups, legal obligations or claims.
- Local browser data: retained until it is replaced, removed through Chessiax/browser controls, or cleared by the browser. Some local histories are count-limited rather than time-limited—for example, coach notes (50), review history (10), Coach Report/history lists (generally 20), critical moments (20), session feedback (50), feedback queue (100) and analytics receipts (200).
- Usage and first-party product analytics: database events do not currently have an automated deletion window. A retention schedule remains to be approved and implemented. Monthly usage periods are accounting groupings, not automatic deletion dates.
- Product feedback: local copies are count-limited to 100, but no database deletion window is defined.
- GA4 and provider logs: retention depends on the applicable production property and provider settings; no fixed period is stated here.
- Engine cache: bounded derived position/evaluation records are held in a process-local cache for at most 30 days, up to 128 entries, and can disappear sooner through eviction or process restart. The cache can contain game IDs and PGN-derived positions/moves, not a separate persistent database of full archive responses.
- Legal/security records: retained only as long as reasonably necessary for a binding legal obligation, security incident, abuse investigation or legal claim.
The account-page cloud-clear tool currently deletes selected coach/training tables but not the login account, feedback, usage events, product analytics, private backups or provider logs. Contact us for a complete deletion request.
11. Data security
Chessiax uses reasonable technical and organizational measures appropriate to the beta service, including access controls, scoped credentials, limits on analytics fields and payload sizes, and safeguards intended to reduce unnecessary logging of raw chess data.
No system is completely secure. Security depends on the deployed configuration, providers and user devices. Keep your credentials confidential, use a secure device and contact privacy@chessiax.com if you suspect unauthorized access or a data incident.
12. Your rights
Subject to applicable law, including exceptions and identity verification, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests;
- receive personal data you provided in a structured, commonly used and machine-readable format and have it transmitted where the portability right applies;
- withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing; and
- complain to a supervisory authority.
The Chessiax account page provides some controls for downloading selected local and synchronized coach/training data and for clearing selected local or cloud data. These controls are not comprehensive and do not provide an automated full account-deletion mechanism. They omit the Auth account, product feedback, usage/product-event data, private backups and provider logs.
For access, correction, deletion, restriction, objection, portability or consent-related requests where applicable—including requests not fully covered by the in-app controls—email privacy@chessiax.com. Describe your request and the email or identifiers associated with your account. We may ask for proportionate information to verify identity and protect other users. We will respond within the time required by applicable law.
You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or to the competent supervisory authority where you live or work. IMY information is available at imy.se.
13. Automated personalization and decision-making
Chessiax automatically analyzes chess activity and can rank or change training recommendations based on public games, engine/statistical findings, user goals, mastery, completed sessions and feedback. Adaptive Coach can recommend repeating, simplifying, advancing, reinforcing or replanning a chess-training item.
This is personalized training advice. It does not appear to make decisions about legal rights or similarly significant matters such as employment, credit, insurance, education admission or access to public services. You can ignore a recommendation, choose another training activity or stop using the feature.
On the current design, Chessiax does not consider this solely automated decision-making with legal or similarly significant effects under GDPR Article 22. We will reassess this if the feature's purpose or consequences materially change.
14. Children
Chessiax does not currently implement an age gate, collect a date of birth, define a verified minimum age or provide a parental-consent system. Chessiax is a general chess-training beta.
If you cannot lawfully consent to relevant data processing or agree to the Terms on your own, do not create an account or submit personal data without any authorization required from a parent or guardian. If you are a parent or guardian and believe a child has provided personal data unlawfully, contact privacy@chessiax.com so the situation can be reviewed.
Chessiax must adopt and document a specific child/age/guardian policy before intentionally directing the Service to children or relying on a particular age threshold.
15. Changes to this policy
We may update this policy when the Service, providers, law or data practices change. The updated version will state a new last-updated date. We will provide additional notice where a change is material and notice is required.
This policy will be reviewed and updated before any Chess.com OAuth feature, payment processing, third-party advertising, materially different analytics, or new category of data processor is activated.
16. Contact
Privacy questions and requests:
Simon Ribrant, operating Chessiax
Sweden
Email: privacy@chessiax.com
General support: support@chessiax.com