ChessSmith
  • Features
  • Pricing
  • Blog
  • Log in
  • Start Free
Legal

Privacy Policy

Governing law: Victoria, Australia Last updated: April 2026 Effective: at launch
Plain English Summary

ChessSmith collects your email, chess game data from Lichess and Chess.com, and your training history so the product works. We don't sell your data, don't use it to train AI models, and don't show you ads. When you choose to publish a shared repertoire, your username and move tree become publicly visible — everything else stays private. You can export or delete everything from Settings at any time.

Contents

  1. Who we are
  2. What we collect
  3. How we use your data
  4. Lawful basis (GDPR)
  5. Third-party processors
  6. Public sharing
  7. Data retention
  8. Your rights
  9. Cookies & analytics
  10. AI features
  11. Mobile app
  12. Security
  13. Minimum age
  14. International transfers
  15. Changes
  16. Contact
Section 1

Who we are

ChessSmith is operated by Nathan Belton, trading as ChessSmith, a sole trader registered in Victoria, Australia (ABN 42 817 706 877). We are the data controller for personal data collected through chesssmith.com and, once launched, the ChessSmith mobile applications.

Privacy inquiries: support@chesssmith.com

Section 2

What we collect

The table below covers every category of personal data ChessSmith collects, based on our current database schema.

CategorySpecific dataHow collected
IdentityEmail address, username, Google account ID (if Google sign-in used), Lichess user ID, Chess.com username (pending)Provided at registration or via OAuth
AuthenticationBcrypt-hashed password (never plaintext), refresh token hash, JWT access tokens (httpOnly cookies only)Created automatically on registration or login
OAuth tokensLichess access token — encrypted at rest with Fernet encryptionProvided when you connect Lichess via OAuth
Training & usageEvery card review (move, rating given, time), training session records, FSRS scheduling state per move, training streaksRecorded automatically as you train
Game historyImported games (PGN text), move-by-move analysis results, deviation records, mistake classifications. Pro feature only.Imported when you connect Lichess, Chess.com, or upload a PGN file
PaymentStripe customer ID, Stripe subscription ID, subscription status. Card details are handled directly by Stripe — ChessSmith never receives or stores them.Created when you start a trial, subscription, or lifetime purchase
PreferencesTheme, FSRS retention target, coverage threshold, timezone, self-reported ratingSet by you in Settings
AnalyticsCountry, city (approximate), session counts, feature usage events. EU users: only after consent.PostHog — gated on cookie consent for EU users

We do not collect demographic data, sensitive personal information as defined by the Australian Privacy Principles, or any data unrelated to providing the ChessSmith service.

Section 3

How we use your data

To provide the service

  • Authenticating your account and maintaining your session
  • Storing and displaying your opening repertoire
  • Scheduling FSRS training reviews based on your performance history
  • Importing and analysing your chess games from Lichess and Chess.com
  • Detecting opening deviations and coverage gaps
  • Managing your Pro subscription or Lifetime Access via Stripe
  • Calculating training streaks using your stored timezone
  • Hosting any repertoire you choose to share publicly

To operate the business

  • Sending transactional emails — subscription confirmations, renewal reminders, password reset, and account deletion confirmation
  • Sending marketing emails — product updates and tips, only with your consent (opt-in at registration or via Settings → Notifications)
  • Responding to support and privacy inquiries
  • Detecting and preventing fraudulent or abusive account activity
  • Monitoring application errors via Sentry

What we do not do

We do not sell your personal data. We do not use your data to train machine learning models. We do not serve advertising. We do not engage in automated profiling that produces decisions with legal or similarly significant effects on you.

Section 4

Lawful basis for processing (GDPR)

For users in the EU and EEA, our lawful basis for each processing activity is:

Processing activityLawful basis
Account creation and authenticationContract — necessary to provide the service
Training history, FSRS scheduling, streak trackingContract — core product functionality
Game import and deviation detection (Pro)Contract — Pro feature you have subscribed to
Stripe subscription and payment managementContract — necessary to manage your paid plan
Transactional emailsLegitimate interest — service communication required to operate the account
Error monitoring (Sentry)Legitimate interest — maintaining security and reliability
Analytics (PostHog)Consent — opt-in via cookie consent banner
AI position explanations (Pro)Legitimate interest with clear disclosure — see Section 10
Public repertoire sharingConsent — activated by you when you enable a public link
Marketing emailsConsent — opt-in at registration or via Settings → Notifications
Section 5

Third-party data processors

ChessSmith uses the following third-party services that process personal data on our behalf. We have executed Data Processing Agreements (DPAs) with each processor where required under GDPR Article 28.

ProcessorPurposeData receivedLocation
RailwayBackend hosting and databaseAll personal data stored in PostgreSQLUS (TBC — confirm region)
VercelFrontend hosting and CDNIP addresses, request logsGlobal CDN
StripePayment processingEmail address, billing country, card details (Stripe handles directly)US (Stripe global)
SentryError monitoringApplication error logs, which may include user ID and API request pathsUS
PostHogProduct analyticsCountry, city (approximate), session data, feature events. EU users: only after consent.EU (TBC — confirm EU region selected)
AnthropicAI position explanations (Pro)Chess position data: FEN string, move played, correct repertoire move, engine evaluation. No identifying information.US

We do not share your personal data with any other third parties, except where required by law.

Section 6

Public sharing

When you publish a shared repertoire, the following data becomes publicly accessible to anyone with the link and to search engines if the link is indexed:

  • Your ChessSmith username
  • The full move tree of the shared repertoire, including all branches
  • Any text annotations you have added to moves in that repertoire
  • The opening names (ECO classifications) of lines in the repertoire

Your email address and personal training data (FSRS state, review history, game import data) are never included in shared repertoires. You can remove a public link at any time from your repertoire settings, which immediately deactivates public access.

Section 7

Data retention

We retain your personal data for as long as your account is active. When you delete your account, a 30-day soft-delete window begins — your data is retained and recoverable by logging back in. After 30 days, all personal data is permanently and irreversibly deleted, except for:

  • Anonymised aggregate statistics (e.g. total cards reviewed across all users) that cannot be linked back to you
  • Limited account data retained for fraud prevention if your account was terminated for a serious Terms violation — typically no more than 3 years
  • Records required by law (e.g. financial records for tax purposes) for the period required by applicable law

Server request logs (IP address and request path) are retained for up to 30 days for security monitoring, then automatically deleted.

Section 8

Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (available directly via Settings → Data)
  • Portability: Request your data in a machine-readable format (PGN export is available in-app)
  • Objection: Object to processing based on legitimate interest
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw consent: Withdraw consent for any processing based on consent (e.g. marketing emails, analytics)

To exercise any of these rights, email support@chesssmith.com. We will respond within 30 days. Most requests can be fulfilled directly through the app in Settings → Data.

Australian users may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. EU/EEA users may lodge a complaint with their local data protection authority.

Section 9

Cookies & analytics

Strictly necessary cookies

ChessSmith uses httpOnly, SameSite=Strict cookies to maintain your authentication session. These are essential for the Service to function and cannot be disabled. They do not track you across websites.

Analytics (PostHog)

We use PostHog to understand product usage at an aggregate level. PostHog does not receive your name, email, or any directly identifying information. EU and EEA users: PostHog does not load until you click Accept on our cookie consent banner. All other users: PostHog loads by default. You can opt out via the cookie settings link in the footer.

No advertising or tracking cookies

ChessSmith does not use advertising networks, cross-site tracking cookies, social media pixels, or any third-party script that follows you across the web. The only third-party scripts are PostHog (analytics, gated on consent) and Stripe (payment, loaded only on checkout pages).

Global Privacy Control (GPC)

ChessSmith recognises the GPC browser signal. Because ChessSmith does not sell or share personal data for advertising, this signal has no material effect on our current processing — but we acknowledge and honour it.

Section 10

AI features

ChessSmith Pro includes an AI-powered feature that explains in plain English why the correct repertoire move is better than the move you played in a real game (Step 11.5).

What data is sent to Anthropic

When you use this feature, ChessSmith sends the following to Anthropic's API: the FEN position string (board state), the move you played in the game, the correct move from your repertoire, and engine evaluation data for context. This is chess game data, not directly identifying information.

Anthropic's data handling

Anthropic does not use API request data to train their models by default. See Anthropic's current data usage policy at privacy.claude.com.

ChessSmith's handling

ChessSmith does not permanently store AI-generated explanations unless caching is enabled for performance optimisation. The AI feature is rate-limited to 20 requests per hour per Pro account.

Section 11

Mobile app

ChessSmith plans to release native apps on iOS (App Store) and Android (Google Play), built with CapacitorJS. This section describes how those apps will handle your data once available, and this page will be updated at launch. The mobile app will use the same ChessSmith account and data as the web application — no additional personal data will be collected by the mobile app beyond what is described in Section 2.

Device permissions

The ChessSmith mobile app does not request access to your camera, microphone, contacts, location, or photo library. Standard internet access is the only permission required.

Push notifications

The app may send push notifications for training reminders and streak alerts. Push notification permission is optional and can be revoked at any time in your device settings.

App Store and Google Play

Apple and Google may collect diagnostic and usage data when you download or use the app, subject to their own privacy policies. ChessSmith does not control or receive this data.

Section 12

Security

  • All data in transit is encrypted via HTTPS (TLS). All connections to chesssmith.com are HTTPS-only.
  • Passwords are hashed using bcrypt before storage and are never stored in plaintext.
  • Lichess OAuth tokens are encrypted at rest using Fernet symmetric encryption with a 12-month key rotation policy.
  • Authentication uses httpOnly, SameSite=Strict cookies. JWT access tokens are not accessible to JavaScript.
  • Payment data is handled entirely by Stripe. ChessSmith never transmits or stores card numbers, CVCs, or expiry dates.
  • All database queries use parameterised statements (SQLAlchemy ORM). No raw SQL string concatenation is used.
  • Content Security Policy headers are enforced on all responses.

Data breach notification

In the event of a data breach likely to result in serious harm, we will notify affected users and relevant supervisory authorities as required by law — within 72 hours for GDPR-covered incidents, and as soon as practicable under the Australian Notifiable Data Breaches scheme.

Section 13

Minimum age

ChessSmith is not intended for anyone under the age of 16. We do not knowingly collect personal data from anyone under 16. By creating a ChessSmith account, you confirm that you are at least 16 years old. If we become aware that an account has been created by someone under 16, we will promptly delete the account and all associated data. If you believe a child under 16 has created a ChessSmith account, please contact support@chesssmith.com.

Section 14

International data transfers

ProcessorLocation of processing
Railway (database hosting)United States (TBC — confirm Railway region)
Vercel (frontend)Global CDN (US primary)
Stripe (payments)United States
Sentry (error monitoring)United States
PostHog (analytics)European Union (EU-hosted region — TBC confirm)
Anthropic (AI explanations)United States

For transfers of EU/EEA personal data to the United States, we rely on Standard Contractual Clauses (SCCs) incorporated in our Data Processing Agreements with each US-based processor. TBC — confirm SCCs are included in each DPA before launch.

Section 15

Changes to this policy

We may update this policy as the product evolves, as new features ship, or as applicable law changes. When we make material changes, we will update the "Last updated" date at the top of this page and notify registered users by email at least 30 days before the changes take effect. The current version is always at chesssmith.com/privacy.

Section 16

Contact

Privacy inquiries

Email: support@chesssmith.com
Response time: within 30 days

Data controller

Nathan Belton, trading as ChessSmith
Victoria, Australia · ABN: 42 817 706 877

Australian supervisory authority

Office of the Australian Information Commissioner (OAIC) — oaic.gov.au

This document provides general informational guidance only and does not constitute legal advice. Consult a qualified attorney for advice specific to your situation.

Features Pricing Blog Terms of Service Open Source Privacy Policy

© 2026 ChessSmith. Built for players who take preparation seriously.