Chessr ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our chess analysis extension and related services.
2. How We Use Your Information
We use your information to:
- Provide the Service: Enable chess analysis and move suggestions
- Manage your account: Authentication and user settings
- Process payments: Handle subscriptions and billing
- Improve the Service: Fix bugs, analyze usage patterns, develop new features
- Communicate with you: Service updates, billing notifications, support responses
- Ensure security: Detect and prevent fraud or abuse, including detecting temporary email addresses and suspicious account activity via IP address analysis
- Discord integration: Verify free trial eligibility and assign roles on our Discord server based on your subscription status
3. Data Storage and Security
3.1 Where We Store Data
Your data is stored using Supabase (PostgreSQL database) with servers located in the United States. Supabase complies with GDPR requirements for international data transfers.
3.2 Security Measures
- Encrypted data transmission (HTTPS/WSS)
- Password hashing with industry-standard algorithms
- JWT token-based authentication
- Row-level security policies in our database
- Regular security updates and monitoring
While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security of your data.
4. Third-Party Services
We use the following third-party services:
Paddle.com (Payment Processing)
- Purpose: Process payments and manage subscriptions
- Data shared: Email, billing information, transaction details
- Privacy policy: paddle.com/legal/privacy
Supabase (Database & Authentication)
- Purpose: Store user data, settings, and manage authentication
- Data shared: Email, encrypted password, user preferences
- Privacy policy: supabase.com/privacy
Discord (Account Linking & Roles)
- Purpose: Verify free trial eligibility and automatically assign subscription-based roles on our Discord server
- Data shared: Discord user ID and username (received via OAuth when you link your account)
- Data received: Discord user ID, username
- Privacy policy: discord.com/privacy
5. Your Rights (GDPR)
If you are in the European Union, you have the following rights under GDPR:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing of your data
- Right to Withdraw Consent: Withdraw consent at any time
To exercise any of these rights, contact us at contact@chessr.io
6. Cookies and Tracking
The Chessr browser extension uses minimal cookies and local storage:
- Authentication tokens: To keep you logged in (stored in browser local storage)
- User preferences: Your extension settings (stored in Chrome sync storage)
Our website may use cookies for analytics and functionality. You can disable cookies in your browser settings, though this may affect functionality.
7. Data Retention
- Account data: Retained while your account is active
- Chess analysis data: Not permanently stored; processed in real-time only
- IP addresses: Retained for security purposes while your account is active, and deleted within 30 days of account deletion
- Discord data: Discord user ID and username retained while your account is linked; removed upon unlinking or account deletion
- Payment records: Retained for 7 years for tax and legal compliance
- Deleted accounts: Personal data deleted within 30 days, except where legally required
8. Children's Privacy
Chessr is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Email notification to your registered address
- Notice within the extension
- Updating the "Last updated" date at the top of this page