Privacy Notice
Last updated: July 29, 2026
1. Introduction
This notice explains what Chess Labs collects, why, and what you can do about it. Chess Labs is a chess study tool: you enter moves on a board, save them as studies, and share them with people you choose. The data we hold reflects that and very little else.
2. What We Collect
We collect three kinds of data, and nothing is bought from third parties.
Account data
Your email address, a display name, and a profile picture if your sign-in provider supplies one. When you sign in with Google or Apple we receive only what that provider releases for sign-in — we never see your provider password.
Content you create
Your studies: moves, variations, comments, NAGs, titles, player names, events, dates, results, openings, the collections you file them under, and the sharing settings and share links you set.
Operational records
Sign-in times, view counts on shared studies, error reports, and an audit log of administrative actions. These exist to keep the service working and to investigate abuse.
3. How We Use It
Account data identifies you so your studies come back to you and so we can reach you about your account. Content is stored so you can open, edit, export and share it. Operational records let us fix faults, prevent abuse, and answer support requests.
We do not sell your data, we do not use your studies to advertise to you, and we do not profile you.
4. Who Can See Your Studies
Visibility is yours to set, and it is per study.
Private
Visible to you alone. This is the default.
Unlisted or public
Reachable by anyone holding the share link. The public viewer shows the moves, comments and metadata plus the owner's display name — never an email address. Set the study back to private and the link stops resolving.
Shared with a person
Someone you invite by email sees that study as a viewer (read-only) or a collaborator (may add variations and comments). Nothing else.
Administrators
Chess Labs administrators can view account records and studies for moderation, abuse handling and support, and may sign in as a user to reproduce a fault. Those actions are recorded in the audit log.
5. Services We Rely On
Chess Labs runs on third-party infrastructure. Authentication is handled by Google Firebase Authentication, which stores your sign-in identity. Studies and account records are stored in a PostgreSQL database on servers we operate. Error reports go to Sentry. Contact-form messages are delivered over email. Importing a game sends the game id you supply to the public Lichess API; nothing about your account goes with it.
These providers process data on our behalf and may store it outside your country.
7. How Long We Keep It
Studies are kept until you delete them or close your account. Archived studies stay recoverable until you remove them for good. Audit and error records are kept for a limited period for security and debugging, then discarded. Closing your account removes the studies attached to it, so export anything you want to keep first.
8. Security
Traffic is encrypted in transit. Sign-in is delegated to Firebase, so Chess Labs never stores your password. Every request to a study is authorised against its owner, its collaborators and its visibility before any move is returned. Share links use an unguessable random slug.
No system is perfectly secure. Keep your sign-in credentials to yourself and tell us if you think your account has been reached by someone else.
9. Your Rights
Depending on where you live you may have some or all of the following rights over your personal data.
Access
Ask what we hold about you.
Portability
Export your studies as PGN at any time, from inside the app, without asking us.
Correction
Fix your display name or email.
Deletion
Ask for your account and its studies to be deleted.
Objection
Object to a particular use of your data, or withdraw consent where consent is what we relied on.
10. Children
Chess Labs is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will remove it.
11. Contact and Complaints
Questions about this notice, or a request to exercise any of the rights above, go to support@codememory.com. We will respond within a reasonable period. If you are not satisfied with our answer, you may complain to the data protection authority in your country.
12. Changes to This Notice
We update this notice when the way we handle data changes. The date at the top of the page shows the current version, and material changes will be announced in the app.
