1. Data Controller
The controller responsible for the processing described in this Policy is Chessmis, operating the Service under the name Chessmis (the “Controller” or “Chessmis”).
- Privacy contact: chessmis.support@gmail.com.
- Website: https://chessmis.com.
2. Children and Minimum Age
2.1. Minimum Age
Chessmis is available to persons aged 6 or older.
2.3. Parental Consent
Where applicable law requires verifiable parental or guardian consent before a child’s personal data may be collected or otherwise processed, that consent must be obtained before the relevant processing begins. The Controller may request reasonable evidence that the person providing the authorisation is entitled to act for the child.
2.4. Requests Concerning a Child’s Data
A parent or legal guardian may contact chessmis.support@gmail.com to exercise applicable rights in relation to a child’s personal data. If the Controller becomes aware that personal data were processed without an authorisation required by law, the Controller will take reasonable steps to restrict the processing and delete the data, unless continued retention is required or permitted by law.
3. Personal Data Processed
3.1. Account and Authentication Data
When an account is created or used, Chessmis processes an account identifier, email address, chosen display name or username, authentication and session information, account creation date and related account-security records. Where Google sign-in is selected, Chessmis may receive the Google account identifier, email address, name, profile image and other information made available through the sign-in flow.
3.2. Chess Platform, Game and PGN Data
When a user connects or identifies an account on Chess.com or Lichess, requests the import of public games or ratings, or submits a PGN, Chessmis processes the relevant platform username, public identifier, ratings, selected rating category, game moves, positions, player and opponent names or usernames, result, timestamps, event and opening information, and other metadata contained in the game record or PGN.
3.3. Analysis and AI Coaching Data
For chess analysis and coaching, Chessmis processes positions, moves, variations, evaluations, move classifications, identified key moments, recurring error categories and related chess context. Where an AI-assisted feature is requested, selected game and analysis data, which may include player and opponent names or usernames, may be transmitted to an artificial intelligence service provider for the generation of explanations and training recommendations.
Chessmis does not use automated chess analysis to make decisions producing legal effects or similarly significant effects concerning a user.
3.4. Profile, Preferences and Training Data
Chessmis processes profile ratings and preferences, connected chess-platform details, recurring error statistics, assigned exercises, the relationship between an exercise and a source analysis, training reasons, exercise status, attempts, submitted moves and completion timestamps. Interface preferences, favourite games, a locally selected avatar and local personalisation information may also be stored on the user’s device.
3.5. Technical, Security and Communication Data
Chessmis and its service providers may process IP addresses, device and browser information, request and session metadata, authentication events, error records and security signals to operate and protect the Service. If a person contacts Chessmis, the Controller processes the contact details, correspondence and any information supplied with the request.
4. Purposes and Legal Bases
| Purpose | Categories of personal data | Legal basis where the GDPR applies |
|---|---|---|
| Account registration, authentication and account administration | Account, profile, authentication, session and necessary technical data | Performance of a contract or steps taken at the user’s request; legitimate interests in account administration and security |
| Importing games and ratings and providing chess analysis | Chess-platform identifiers, public ratings, game and PGN data, positions and analysis results | Performance of a contract or steps taken at the user’s request; legitimate interests in processing public game data necessary to provide the requested analysis |
| Providing AI-assisted explanations and personalised training | Selected game and analysis context, recurring error information, preferences, exercises and training progress | Performance of a contract or steps taken at the user’s request; where required for a child, valid consent of a parent or legal guardian |
| Maintaining security, preventing misuse and resolving technical failures | Technical, authentication, error and security data | Legitimate interests in the security, integrity and availability of the Service; compliance with legal obligations where applicable |
| Responding to privacy, legal and support requests | Contact details, correspondence, account data and records relevant to the request | Compliance with legal obligations; performance of a contract; or legitimate interests in handling and documenting requests |
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal. Where processing is based on legitimate interests, Chessmis considers the necessity of the processing and its effect on the rights and interests of the individuals concerned.
Account and authentication data are required to maintain a registered account. Game, PGN and chess-platform data are optional; however, the corresponding import, analysis or personalisation function cannot be provided without the data required for that function.
5. Sources of Personal Data
- the user, including information submitted during registration, game import, PGN submission, profile configuration and communications;
- Google, where the user selects Google sign-in;
- Chess.com and Lichess, where the user requests the import or synchronisation of public game or rating data;
- automated chess-analysis processes, which produce evaluations, classifications and training context; and
- the user’s browser, device and the technical systems used to deliver and protect the Service.
6. Recipients and Disclosures
Personal data may be disclosed, to the extent necessary for the relevant purpose, to the following categories of recipients:
- cloud hosting, database and authentication service providers;
- external identity providers selected by the user;
- third-party chess platforms from which the user requests game or rating data;
- artificial intelligence service providers engaged to generate requested chess explanations or recommendations;
- technical, security and professional service providers acting on behalf of Chessmis; and
- public authorities, courts, regulators and professional advisers where disclosure is required by law or necessary for the establishment, exercise or defence of legal claims.
Chessmis does not sell personal data and does not use personal data for behavioural advertising under the current operation of the Service.
7. International Transfers
Certain service providers may process personal data in countries other than the country in which the user is located, including countries outside the European Economic Area. Where the GDPR applies and a recipient is located in a country that has not been recognised as providing an adequate level of protection, the Controller will use an applicable safeguard under Chapter V of the GDPR. Where required, transfers are based on an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where appropriate. Information concerning the applicable safeguard may be requested through the contact details in section 14.
8. Retention of Personal Data
Personal data are retained only for as long as necessary for the purposes set out in this Policy, subject to any longer period required or permitted by law. The applicable periods or criteria are as follows:
| Data category | Retention period or criterion |
|---|---|
| Account, authentication, profile and connected-account data | Kept while the account is active and deleted when the user completes account deletion, except for limited records that must be retained by law or for the establishment, exercise or defence of legal claims. |
| Imported games, submitted PGN and server-side analysis context | Complete imported games are not intentionally maintained as a server-side game archive. A manually submitted PGN remains in browser session storage for the browser session. Request context is processed transiently and is not intentionally retained as a complete server-side game archive after the requested response; derived mistake and training records follow the training-data period below. |
| Recurring error information, assigned exercises and training progress | Kept while the account is active and deleted when the user completes account deletion. |
| Inputs and outputs of AI-assisted features | Chessmis does not maintain a complete server-side chat history. Derived training records may be retained with the relevant training data. Chessmis does not retain a complete server-side history of AI requests and responses. Google may retain Gemini API prompts and responses for a limited abuse-monitoring period under its applicable terms; where optional API logging is enabled, the configured retention is no more than 55 days. |
| Device-side preferences and locally stored data | Until removed by the user, cleared by the browser, or no longer required by the relevant browser session |
| Operational and security logs | Chessmis does not maintain a separate permanent user-activity log archive. Necessary infrastructure and security logs are retained only for the period configured by the relevant hosting or infrastructure provider and for as long as needed to investigate security or service incidents. |
| Privacy and support correspondence | Kept for up to three years after the request is closed, unless a longer period is required for an unresolved dispute or by law. |
| Backup copies | up to 30 days after deletion, according to the active database backup cycle |
Deletion may be deferred to the extent that retention is necessary to comply with a legal obligation, establish, exercise or defend legal claims, investigate misuse or protect the rights of Chessmis or another person. Data retained solely in a backup will not be restored to ordinary use except where necessary for recovery or legal compliance.
9. Rights of Data Subjects
9.1. Available Rights
Subject to applicable law, a data subject may have the right to obtain access to personal data, request rectification or erasure, restrict processing, receive data in a portable format, object to processing based on legitimate interests, and withdraw consent where processing is based on consent. The exercise of a right may be subject to statutory conditions and exceptions.
9.2. Exercise of Rights
Requests may be submitted to chessmis.support@gmail.com. The Controller may request information reasonably necessary to verify the identity and authority of the requester. Requests will be handled within the period prescribed by applicable law.
9.3. Self-Service Account Deletion
Users may initiate account deletion through the Chessmis account settings. To prevent unauthorised deletion, a user who has a password must re-authenticate, and every request must be confirmed through a one-time link sent to the verified email address associated with the account. For an account used through Google, the link is sent to the verified email associated with the corresponding Google account; Chessmis does not request the user’s Google password.
Following the user’s separate final confirmation, Chessmis deletes the authentication account and the associated active user data: the Chessmis profile, connected chess-platform account details, recurring-mistake statistics, assigned training tasks and progress, and pending deletion requests. Shared system data that is not owned by the user is not deleted.
Data stored only in the browser are cleared on the device that opens the deletion-completion page; browser data on another device remain subject to removal by the user or browser. Residual copies may remain in backups for up to 30 days after deletion, according to the active database backup cycle, and limited data may be retained where required by law. A user who cannot use self-service deletion may submit a request to chessmis.support@gmail.com.
9.4. Complaints
Where the GDPR applies, a data subject has the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate or with another competent supervisory authority, in particular in the Member State of habitual residence, place of work or place of the alleged infringement.
10. Automated Processing
Chessmis uses automated processes to analyse chess positions, identify patterns and generate educational explanations and recommendations. These processes support chess training and may produce inaccurate results. They are not used to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning a user within the meaning of Article 22 of the GDPR.
12. Security
The Controller applies technical and organisational measures intended to provide a level of security appropriate to the nature of the personal data and the risks of the processing. Access to personal data is limited to persons and service providers requiring access for an authorised purpose. No method of transmission or storage can guarantee absolute security.
13. Changes to this Policy
This Policy may be amended to reflect changes in the Service, processing activities or applicable law. The revised version will be published with an updated effective or revision date. Where required by law, material changes will be notified by an appropriate additional means before they take effect.
14. Contact
Questions, objections and requests concerning personal data may be addressed to chessmis.support@gmail.com.