Privacy
How Chessou collects, uses, and protects your data. Information according to Articles 13 and 14 of the General Data Protection Regulation (GDPR).
Controller
The controller responsible for the processing of personal data on this website is the operator listed in the Imprint. You can reach us via the contact details there.
What we collect
Account data
When you create an account we store your email address, a hashed password (or, if you sign in via Google, a unique identifier from Google), the timestamp of your sign up, and any onboarding preferences you provide such as your selected chess platform and training time budget. We also store activity timestamps such as when you last visited the dashboard and when you were last active, which are used to provide the service and to clean up inactive anonymous accounts.
Linked chess profiles
To analyze your games we store the Lichess or Chess.com username you connect, the time controls you choose to import, and metadata about your import jobs.
Chess data
We fetch your public games from the connected platform and store the PGN of each game, derived analysis results (moves, evaluations, detected patterns), personalized training items (puzzles, reviews, plans), your training history (which puzzles you solved and when), and rating snapshots that let us show your progress over time.
Training and settings
Your daily time budget, spaced repetition intensity, appearance preferences, and your email notification preferences are stored on your account.
Server logs
When you visit Chessou our hosting providers automatically log technical request data such as IP address, user agent, request path, timestamp, and response status. These logs are used for security and debugging and are retained for a short period by the respective provider.
Analytics
We use Umami for usage analytics. Umami is cookieless and does not track you across sites. It records aggregated page views, referrer, browser type, country at country level, and screen size. No personal identifiers and no cross site tracking are involved.
Product analytics
To understand and improve how the app is used, we record first party product events tied to your account under a pseudonymous user identifier (for example: which onboarding steps you completed, which training or feed items you opened or dismissed, how long a report was read, and how long imports and analysis took). These events contain no plaintext personal data, are stored only in our own EU database, are never shared with third parties or used for cross site tracking, and set no tracking cookie. Raw events are deleted after about 180 days; only aggregated, non identifying trends are kept longer.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the account and training service | Art. 6(1)(b) GDPR (contract performance) |
| Importing and analyzing your games | Art. 6(1)(b) GDPR (contract performance) |
| Sending transactional emails (sign in, password reset, account updates) | Art. 6(1)(b) GDPR (contract performance) |
| Sending optional product or marketing emails | Art. 6(1)(a) GDPR (consent), revocable at any time |
| Server logs and security | Art. 6(1)(f) GDPR (legitimate interest in a secure service) |
| Cookieless usage analytics | Art. 6(1)(f) GDPR (legitimate interest in improving the product) |
| Product analytics (pseudonymous, first party, to improve the app) | Art. 6(1)(f) GDPR (legitimate interest in improving the product) |
Our legitimate interests (Art. 6(1)(f))
Some processing relies on our legitimate interests. For each of these we have weighed our interest against your rights and freedoms and concluded that the processing is necessary and proportionate with minimal impact on you:
- Security and abuse protection (server logs, Cloudflare Turnstile during sign up): our interest in operating a secure and available service protected against bots and abuse. Limited to technical data, kept for a short period, no advertising profiling.
- Error and performance monitoring (Sentry, EU region): our interest in detecting and fixing faults. Configured so that no personal payload data is sent (PII scrubbing enabled).
- Cookieless usage analytics (Umami, self hosted in the EU): our interest in understanding aggregate usage to improve the product. Cookieless, aggregated, no cross site tracking, no personal identifiers.
- Product analytics (first party, stored in our own EU database): our interest in improving the app by understanding how it is used. Pseudonymous user identifier only, no plaintext personal data, no cross site tracking, no tracking cookie, raw events deleted after about 180 days.
You can object to processing based on legitimate interests at any time on grounds relating to your particular situation (Art. 21 GDPR). Contact us via the Imprint.
Subprocessors
We use the following service providers to operate Chessou. Where a provider processes personal data on our behalf, it acts as a processor under Art. 28 GDPR and a data processing agreement is in place. Our usage analytics (Umami) is self-hosted on our own server, so no external analytics processor is involved.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, file storage | Frankfurt, Germany |
| Vercel | Frontend hosting and edge delivery | Frankfurt, Germany (parent company in the USA) |
| Railway | Backend worker and import jobs | Amsterdam, Netherlands |
| Netcup | Chess engine server and hosting of our self-hosted analytics | Germany |
| Resend | Transactional and product emails | Ireland (eu-west-1) |
| Paddle | Payment processing and merchant of record (subscription billing, invoices, tax, refunds) | United Kingdom |
| Lichess | Importing your public Lichess games via the public Lichess API | France (Lichess non-profit) |
| Chess.com | Importing your public Chess.com games via the public Chess.com API | USA |
| Cloudflare | Bot and abuse protection (Turnstile CAPTCHA during sign up) | USA (global network) |
| Sentry | Error and performance monitoring | EU (Frankfurt, Germany) |
Sign in with Google
When you choose "Sign in with Google", your browser connects directly to Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), which receives your IP address and the Google account you select in order to authenticate you. For this sign in Google acts as a separate, independent controller and processes your data under its own privacy policy, so it is not one of our processors listed above. Because Google LLC is based in the USA, this involves a transfer to a third country; it is covered by the EU Commission's adequacy decision for the EU US Data Privacy Framework (Art. 45 GDPR), under which Google LLC is certified, with the Standard Contractual Clauses applied as a fallback. We only receive your basic Google profile (identifier, email, name) back from this sign in; none of your chess or training data is sent to Google.
International data transfers
Some of the providers above are headquartered outside the EU or process data there: in the United States (Vercel parent company, Chess.com, Cloudflare, and Google for "Sign in with Google") and in the United Kingdom (Paddle). Where a third country transfer occurs, we rely on the relevant EU Commission adequacy decision (the UK adequacy decision, and the EU US Data Privacy Framework) or on the Standard Contractual Clauses (Art. 46 GDPR) as a safeguard.
How long we keep your data
Account and chess data are kept for as long as your account exists. If you start onboarding but do not convert your anonymous account into a real account, your data is automatically deleted after 1 day by a scheduled cleanup job. When you delete your account, your account data, linked profiles, games, analyses, and derived training items are removed immediately through a cascading database delete. There is no soft delete and no grace period. Server logs are kept by the respective hosting provider for a short period. Pseudonymous product analytics events are automatically deleted after about 180 days. Aggregated analytics events do not allow your identification and are kept for the lifetime of the project.
Your rights
Under the GDPR you have the following rights regarding your personal data:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time, where processing is based on consent
- Right to lodge a complaint with a data protection supervisory authority
You can exercise these rights directly inside the app (Settings, Privacy section) or by contacting us via the email address listed in the Imprint. For data export, the app provides a self service export of all data we hold about you.
Cookies and local storage
Chessou only uses cookies that are strictly necessary to operate the service. We do not use tracking, advertising, or third party marketing cookies, and our analytics provider Umami is cookieless. The cookies we set are:
- The authentication session cookie (and a short lived code verifier used during sign in) provided by Supabase, which keeps you logged in.
- Your appearance preference (light or dark theme), so the correct theme can be rendered immediately when a page loads.
- A short lived flag (up to 24 hours) that tells the server you are in the middle of the onboarding flow.
- During sign up only, our bot protection provider Cloudflare Turnstile may set its own challenge cookie to tell humans from bots.
We also store a number of values in your browser local storage and session storage. These stay on your device, are not sent to external services, and are not used for tracking or profiling:
- Onboarding progress (selected platform, training time budget, and flow state) so we can continue where you left off.
- A temporary password during the email confirmation step of sign up. This value is single use and is removed automatically within 30 minutes.
- Your daily training plan and which items you have completed, so the daily queue stays stable as you navigate.
- One time interface flags (for example which first run hints, celebrations, or report highlights you have already seen) and small interface preferences such as board sounds and your selected chess profile.
- A counter of the free analyses you have used before creating an account, to enforce the free usage limit.
Profiling and automated decision making
To personalize your training, Chessou automatically analyzes your games and builds a profile of your chess strengths and recurring mistakes, for example skill levels per tactical pattern. This constitutes profiling within the meaning of Art. 4(4) GDPR. It is limited to your chess performance and serves only to select and prioritize training content for you.
Chessou does not use automated decision making that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR. The training recommendations are not legal decisions; they are content suggestions based on patterns detected in your own games, and you remain free to ignore them.
Changes to this policy
We may update this policy as the product evolves or as legal requirements change. The current version is always available at this page with the last updated date shown below.
Last updated: July 19, 2026