Privacy Policy
Last updated: July 13, 2026
In short: we collect only what the product needs. Your email and training activity if you create an account; no account and no server-side training data if you train as a guest (guest progress stays in your browser). Payments are handled by Stripe, or by Apple/Google on mobile; we never see your card. We use no advertising trackers and we never sell your data. You can delete your account, and everything with it, from your dashboard at any time.
1. Data controller
The controller of your personal data under the EU General Data Protection Regulation (GDPR) and the French Data Protection Act is:
ANKT SERVICES
SAS (Société par Actions Simplifiée) with a share capital of EUR 100
SIREN: 843902156 · RCS: Angers
EU VAT: FR78843902156
25 Rue Lenepveu, c/o WeForge
49100 Angers, France
President and publication director: Antoine Tamano
Email: support@chessendings.com
2. Data we collect
2.1 Account data
- Email address, for sign-in and service emails. If you sign in with Google, we receive your email and basic profile (name, avatar) from Google.
- Display name, chosen by you, shown on leaderboards only if your profile is public.
- Settings and preferences (language, training options, email preferences).
2.2 Training data
Your training activity: drills played, moves, results, mistakes and their explanations, ratings, XP, streaks, achievements, and journey progress.
2.3 Scan feature
If you use the scan feature, we store the public Lichess or Chess.com username you enter and fetch publicly available games for it from those platforms' public APIs. We never access private data on those platforms.
2.4 Payment data
Purchases on the website are processed by Stripe; we store your Stripe customer ID, plan, and payment status, never your card details. On mobile, purchases are processed by Apple or Google and managed through RevenueCat; we receive only a purchase receipt and subscription status, no payment details.
2.5 Technical data
Standard server logs (IP address, user agent, timestamps) collected by our hosting provider for security and debugging, and, where analytics is enabled, product usage events (see section 5).
2.6 Guests
You can train without an account. Guest training runs entirely in your browser: your progress and the daily drill counter are stored in your browser's local storage on your device and are not sent to our servers. No guest account or server-side profile is created.
3. Legal bases (GDPR)
- Contract (Art. 6(1)(b)): operating your account, tracking your progress, delivering Pro purchases, support.
- Legitimate interests (Art. 6(1)(f)): security, fraud and abuse prevention, service improvement and debugging.
- Consent (Art. 6(1)(a)): optional emails (streak reminders, weekly digest) and any consent-based analytics; withdrawable at any time.
- Legal obligation (Art. 6(1)(c)): tax and accounting records, responding to lawful requests.
4. How we use your data
- Running the product: accounts, progress tracking, mistake explanations, achievements, quotas.
- Leaderboards: your display name and ranking only, and only if your profile is public. You control this in your settings.
- Emails you opt into: streak reminders and the weekly digest, each with an unsubscribe link, plus transactional emails (receipts, account notices).
- Improving the service: aggregate usage analysis and debugging.
- Security and compliance: preventing abuse, meeting legal obligations.
We never sell your personal data and we do not share it with anyone for advertising.
5. Third-party processors
We share data with providers who process it on our behalf, under GDPR-compliant data processing agreements:
- Supabase: authentication and database hosting.
- Stripe: payment processing on the website (PCI-DSS certified); receives your email for receipts and billing.
- Vercel: website hosting and content delivery (server logs).
- Resend: transactional and opt-in email delivery.
- Web3Forms: contact form delivery; your email and message are transmitted to reach our support inbox.
- Google: optional sign-in with Google (OAuth).
- PostHog: product analytics, if enabled; usage events without advertising trackers.
- Apple App Store / Google Play and RevenueCat (mobile apps): purchase processing and subscription status. The store handles your payment data directly; RevenueCat stores an app user identifier and purchase receipts, no email or card data.
- Lichess: our servers query the Lichess tablebase API with chess positions only, which contain no personal data. The scan feature fetches public games from the Lichess and Chess.com public APIs for the username you provide.
6. International transfers
Some providers process data outside the European Economic Area (notably in the United States). Where they do, transfers are protected by the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses. You can request details of these safeguards at support@chessendings.com.
7. Data retention
- Account and training data: kept while your account exists. Deleting your account from the dashboard removes your profile and training data immediately.
- Billing records: kept for 10 years, as French accounting law requires. Purchase records are never edited retroactively; refunds are recorded as reversals.
- Support messages: kept up to 3 years after resolution.
- Server logs: kept for a short rolling window by our hosting provider.
- Guest data: stored only in your browser; clear your browser storage to remove it.
8. Your rights
Under the GDPR you have the right to:
- access your data and get a copy (Art. 15)
- correct inaccurate data (Art. 16)
- have your data erased (Art. 17); account deletion is self-service from the dashboard
- restrict processing (Art. 18)
- receive your data in a portable, machine-readable format (Art. 20)
- object to processing based on legitimate interests, and to any direct marketing (Art. 21)
- withdraw consent at any time, without affecting prior processing
To exercise any of these rights, email support@chessendings.com. We respond within one month. You also have the right to lodge a complaint with a supervisory authority (see section 13).
10. Security
Data is encrypted in transit (TLS), authentication is handled by Supabase with hashed credentials, access to production data is restricted, and database access is enforced by row-level security. No system is perfectly secure, but we design the Service so that the server never trusts unverified client input and holds no more personal data than the product needs.
11. Children
The Service is not directed at children under thirteen (13) and we do not knowingly collect their data. Users under the age of digital consent in their country (fifteen (15) in France) need parental consent to use the Service with an account. If you believe a child provided us personal data, contact us at support@chessendings.com and we will delete it.
12. Changes to this policy
We may update this policy as the product or the law evolves. Material changes are announced by updating the date above and, if you have an account, by email or an in-product notice.
13. Contact and complaints
For any privacy question or to exercise your rights, write to support@chessendings.com or use the contact page.
ANKT SERVICES
SAS (Société par Actions Simplifiée) with a share capital of EUR 100
SIREN: 843902156 · RCS: Angers
EU VAT: FR78843902156
25 Rue Lenepveu, c/o WeForge
49100 Angers, France
President and publication director: Antoine Tamano
Email: support@chessendings.com
If you are not satisfied with our response, you may lodge a complaint with the French supervisory authority: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (www.cnil.fr), or with the authority of your country of residence.