← chessperiment

Privacy Policy

Last updated: July 2026

1. Controller

Responsible for data processing on this website: Lasse Thoroe — Chessperiment Ahlerfeld 29 38527 Meine Germany Email: [email protected] Website: https://chessperiment.app No data protection officer has been appointed as this is not legally required.

2. General Information

We take the protection of your personal data very seriously. We process personal data only to the extent necessary to provide a functional website and our services. All processing is carried out in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the Telecommunications and Digital Services Data Protection Act (TDDDG). This privacy policy explains what data we collect, how we use it, and what rights you have regarding your data.

3. SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the "https://" prefix and the lock icon in your browser's address bar. When SSL/TLS encryption is active, data you transmit to us cannot be read by third parties.

4. Cookies & Local Storage

a) Technically Necessary Session Cookie (JWT)

When you log in, a technically necessary session cookie (JSON Web Token) is set to maintain your authenticated session. This cookie is essential for the website's core functionality and does not require consent under § 25(2) TDDDG. It is deleted when you log out or close your browser. No tracking or advertising cookies are used. Legal basis: Art. 6(1)(b) GDPR (contract performance).

b) Local Storage & Session Storage

Our website stores certain data in your browser's localStorage and sessionStorage for functional purposes. This includes: — Anonymous player identifiers for multiplayer games — Guest project data (unsaved chess boards, pieces, and rules created without an account) — Board editor state and game engine settings — AI chat history per project (sessionStorage, cleared when you close the browser) These storage mechanisms are technically necessary for the features you actively use. No personal data is stored in localStorage or sessionStorage.

5. User Accounts & Authentication

a) Email/Password Registration

When you create an account with your email address, we store your display name, email address, and your password (hashed by Firebase). Optionally, you may provide a profile picture URL. This data is not public and is used exclusively to provide your account and platform features. Legal basis: Art. 6(1)(b) GDPR (contract performance).

b) Google OAuth Sign-In

You may also sign in using your Google account. In this case, Google transmits your name, email address, and profile picture to us. Google's own privacy policy applies to the authentication process. We do not receive your Google password. Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (contract performance).

c) Email Verification & Password Reset

Firebase sends automated emails for email verification (upon signup) and password reset (upon request). These emails are sent directly by Google's Firebase infrastructure. Your email address is transmitted to Firebase for this purpose only. Legal basis: Art. 6(1)(b) GDPR.

6. Firebase Cloud Services

a) Cloud Firestore (Database)

We use Google Firebase Cloud Firestore as our primary database. The following categories of your data are stored there: — Account data (display name, email, profile picture, auth provider, creation date) — User-created content (chess boards, piece sets, game logic) — Game history and player statistics (games played, wins, losses, draws, rating) — Marketplace items you publish (title, description, previews, ratings, reviews) — Creator profiles (handle, display name, bio, photo) — Community feedback and feature requests — Anonymous usage counters (feature button clicks) No payment data is stored or processed by us. Legal basis: Art. 6(1)(b) GDPR.

b) Cloud Storage

When you upload custom piece images in the creator tools, these files are stored in Google Firebase Cloud Storage. Only images you explicitly upload are stored. Legal basis: Art. 6(1)(b) GDPR.

c) EU-US Data Privacy Framework

Google LLC is certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection for transfers to the USA. Additionally, standard contractual clauses and supplementary technical and organizational measures are in place. You may request a copy of these safeguards by contacting us.

7. AI Services

We offer an AI-powered assistant that can help you design chess variants. When you interact with the AI, your chat messages, your current project state (board layout, pieces, and game rules), and system instructions are sent to a third-party AI provider for processing. Depending on configuration, this may be: — DeepSeek (based in China, API endpoint: api.deepseek.com) — OpenRouter (OpenRouter Inc., based in the USA, API endpoint: openrouter.ai) The AI provider processes the transmitted data solely to generate responses and does not use it to train models. Chat history is temporarily stored in your browser's sessionStorage (per project, cleared when you close the browser) and may be persisted server-side for job recovery. We do not send personal identifiers to the AI provider — only your chat messages and anonymized project data from the current conversation are transmitted. Legal basis: Art. 6(1)(a) GDPR (consent, implied by your use of the AI feature).

8. Multiplayer & Real-Time Communication

a) Socket.io

Our real-time multiplayer feature uses Socket.io, an open-source WebSocket library. When you join or create a multiplayer game, an anonymous player identifier is generated and stored in your browser's localStorage. This ID is not linked to your account and is only used to maintain your connection during the game session. Connection data (IP address) is processed transiently to establish and maintain the WebSocket connection. Legal basis: Art. 6(1)(b) GDPR.

b) Stockfish Engine

During multiplayer games, a server-side instance of the Stockfish chess engine may analyze board positions upon your request. Best-move suggestions are transmitted via the Socket.io connection to your browser. No personal data is sent to the engine — only the current board position. Legal basis: Art. 6(1)(b) GDPR.

9. Email Services

a) Resend (Transactional Emails)

We use Resend (Resend Inc., USA) to send transactional emails. These are limited to: — Marketplace item report notifications (sent to our admin email) — Referral survey responses (sent to our admin email) Your email address is not transmitted to Resend for end-user communication. Admin notifications contain only the content of your report or survey response. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in platform safety and improvement).

b) Firebase Email Services

Automated emails (email verification and password reset) are sent via Google's Firebase infrastructure. See Section 5c above. Legal basis: Art. 6(1)(b) GDPR.

10. User-Generated Content & Public Features

Chessperiment includes public-facing features where content you create may be visible to other users: — Marketplace: Boards, piece sets, and designs you publish are publicly visible along with their title, description, and preview image. Other users can rate, review, and fork your published items. — Creator Profiles: If you register as a creator, your public profile (handle, display name, bio, photo) is visible to other users. — Reviews & Ratings: Reviews and ratings you leave are publicly visible along with your display name. You control what you publish. Unpublished content remains private. Published content that has been forked by other users may persist after you delete your account, as it becomes part of the forked project's history. Legal basis: Art. 6(1)(a) GDPR (consent, given by publishing) and Art. 6(1)(b) GDPR.

11. Feedback & Surveys

a) Community Feedback Form

Our feedback form on the Features page allows you to submit bug reports, feature requests, and general feedback. Submissions are stored in Firestore. You may optionally provide your email address for follow-up. Your IP address is processed in-memory only for rate limiting (maximum 5 submissions per hour) and is not stored. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our service).

b) Referral Survey

A voluntary survey asks how you discovered Chessperiment. Your response is sent to our admin email via Resend (see Section 9a). No personal data is transmitted with your answer. Your dismissal of the survey is stored in localStorage to avoid showing it again. Legal basis: Art. 6(1)(a) GDPR (consent, given by choosing to respond).

12. Third-Party Services & External Links

a) BotID

We use BotID, a bot detection service, on authentication-related endpoints to protect against automated abuse. BotID evaluates request patterns to distinguish between human users and bots. No personal data is transmitted to BotID — the service operates based on request metadata. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in securing our service against automated attacks).

b) Buy Me a Coffee

Our website includes a link to our Buy Me a Coffee page (buymeacoffee.com/chessperiment), an external donation platform. Clicking this link takes you to Buy Me a Coffee's website, where their own privacy policy applies. We do not transmit any personal data to Buy Me a Coffee through this link.

c) Google Profile Images

If you sign in with Google, your profile picture is loaded from Google's servers (lh3.googleusercontent.com). This image request is made directly by your browser. Google's privacy policy applies to this data transfer.

13. Data Retention & Deletion

We store your personal data only as long as necessary for the purposes for which it was collected: — Account data: Stored until you delete your account. You may request deletion at any time by contacting us. — User-created content: Retained while your account exists. On account deletion, your personal content is removed. Content forked by other users may persist in their projects. — Game history & statistics: Retained for the lifetime of your account to maintain your player profile. — Marketplace items: On account deletion, published items are removed from the marketplace. — Chat messages: Retained while your account exists. — Community feedback: Retained as long as relevant for product improvement. To request deletion of your account and associated data, email us at [email protected].

14. Your Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data: — Right of access (Art. 15 GDPR): You may request confirmation of whether we process your data and obtain a copy. — Right to rectification (Art. 16 GDPR): You may request correction of inaccurate personal data. — Right to erasure (Art. 17 GDPR): You may request deletion of your data, subject to legal retention obligations. — Right to restriction of processing (Art. 18 GDPR): You may request restricted processing under certain conditions. — Right to data portability (Art. 20 GDPR): You may receive your data in a structured, commonly used format. — Right to withdraw consent (Art. 7(3) GDPR): You may withdraw consent at any time without affecting the lawfulness of prior processing. To exercise any of these rights, please contact us at [email protected]. We will respond within the statutory period of one month.

15. Right to Object

You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data which is based on Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims. To exercise your right to object, simply send an email to [email protected]. No special form is required.

16. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you believe that the processing of your personal data infringes the GDPR. The competent supervisory authority for Chessperiment is: Der Landesbeauftragte für den Datenschutz Niedersachsen Prinzenstraße 5 30159 Hannover Germany Phone: +49 (0)511 120-4500 Email: [email protected] Website: https://www.lfd.niedersachsen.de

17. Minors

Our services are not directed at persons under the age of 16. We do not knowingly collect personal data from minors without verifiable parental consent. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us and we will delete it.

18. Changes to this Privacy Policy

We may update this privacy policy from time to time to reflect changes in our data processing practices or legal requirements. The current version is always available on this page. We encourage you to review it periodically.