We collect account, usage, and chess data to run this service. This page
describes what that means, including our use of chess engines and third-party
AI. It is a description of our practices, not legal advice.
1. What we collect
Account: email, password hash (or Google account id if you use Google sign-in), optional display name, linked chess.com and Lichess usernames, plan/billing status.
Chess data you give us: opening reports you run, repertoire lines, imported PGN, pasted FEN/PGN for the board, practice and spaced-repetition cards, shared-report snapshots you create.
Public games: when you analyze a username, we fetch that player’s public games from chess.com and/or Lichess. We do not receive private or unlisted games from those sites.
Usage: login sessions (including user agent and IP), Analyze lookups, and product events. If analytics are enabled, this can include pages visited and (with PostHog) session replay.
Payments: if you subscribe to Pro, Stripe handles card details. We store Stripe customer and subscription ids, not your full card number.
2. Artificial intelligence and chess engines
We use automated analysis tools on chess positions and, if you use AI coach, a third-party large language model.
Stockfish (open-source chess engine) runs on our servers for the eval bar, best-move hints, game review, blunder scan, and repertoire practice. Positions, moves, and related game context you analyze are sent to our backend so Stockfish can score them. This is not a generative AI model and is not sent to Anthropic.
Anthropic Claude powers the in-app AI coach (and optional CLI recommendations) when an Anthropic API key is configured. If you click AI coach, we send aggregated opening statistics from your report (opening names, game counts, scores, and similar summary stats — not your password) to Anthropic so Claude can write coaching notes. Anthropic processes that content under their terms and privacy policy.
We do not use your chess data to train our own foundation model. Third-party providers may process prompts according to their own policies.
3. Third parties who may receive data
Depending on which features are enabled on this deployment:
Google: Google Identity Services if you sign in with Google; Google Analytics (GA4) for traffic/audience when a measurement ID is configured (production may use a default GA4 id).
Stripe: checkout, customer portal, and subscription webhooks for Pro billing.
PostHog: product analytics (people profiles with email when you are logged in, events, and possibly session replay) when a PostHog project key is configured.
Anthropic: AI coach prompts as described above.
chess.com and Lichess: we request public player/game data from their APIs. We do not sell your account to them.
Hosting: the website is typically served via Netlify; the API and database via Render (or the operator’s equivalent). Server logs may include IP addresses and request paths.
Each provider has its own privacy policy. We do not sell your personal information.
4. Cookies and similar storage
We use a session cookie to keep you logged in and a CSRF token for account
actions. The app may also use local storage for board settings and a
logged-out repertoire draft. Google Analytics and PostHog, when enabled, set
their own cookies or local storage as described in their documentation.
5. Where data is stored
Account data lives in a private server-side database (SQLite on the API host),
not in a public cloud storage bucket. Cached chess.com/Lichess month files are
stored on the server disk for performance and are not published as a public
website folder. Uploaded or imported PGN is stored as repertoire rows on your
account, not as world-readable files.
6. Retention and deletion
We keep account and repertoire data until you delete the account or we close
the service. Analyze caches of public games may outlive a single session
because they are shared lookups of public data, not your private uploads.
You can permanently delete your Opening Explorer account from
Profile → Delete account. That removes your user row,
repertoire (including imported PGN), learning cards, habits, shared reports,
sessions, and related jobs we store for you. It also signs you out. If you
had a Stripe subscription, we attempt to cancel it. Copies in backups,
server logs, or third-party systems (Google, Stripe, PostHog, Anthropic)
may persist for a limited time according to those systems.
7. Your choices
Use the site without an account to look up public usernames.
Skip AI coach if you do not want opening stats sent to Anthropic.
Edit linked chess usernames in Profile, or log out to end the session.
Delete your account as described above.
8. Children
Opening Explorer is not directed at children under 13, and we do not
knowingly collect personal information from them.
9. Changes
We may update this policy when the product changes. The “Last updated” date
at the top will change. Continued use after an update means you should review
the new text.
10. Contact
Use Profile → Delete account to erase stored account data.
For other privacy requests, contact us from the email address on your
Opening Explorer account (the operator of opening-explorer.com).