Privacy policy

This page says exactly what Chess Buddy stores about you, where it goes, and how to get rid of it. It is short because the site collects very little: reading the opening guides needs no account at all, and the trainer needs a free account with nothing but an email address.

Who is responsible

The controller for the processing described here is the person named in the Impressum. Contact for any data question: [email protected]. There is no statutory obligation to appoint a data protection officer for an operation of this size, and none has been appointed.

Using the site without an account

Reading the opening guides needs no account and no email address. The trainer itself is opened with a free account. Your drill progress, your streaks and the two onboarding answers (your rating and what you find hardest) are written to local storage in your browser under keys starting with cb. They stay on that device and clearing your browser data deletes them.

We do count how many people reach each step of the site, and how many picked each answer, per day and per traffic source. Those are plain counters: a number per day, per step, per answer. They carry no identifier, no cookie and no IP address, nothing in them points back to a person, and no profile of you is built from them. This is how we know whether an advert brings people who actually drill a line.

The server the site is hosted on writes ordinary access logs (IP address, time, requested page, user agent) for security and troubleshooting. Legal basis: legitimate interest, Art. 6 (1) (f) GDPR.

Buying full access

Payment runs through Stripe. The card form is served by Stripe itself and only displayed inside our checkout page, so your card details go straight to Stripe: we never see them and never store them. Stripe acts as a controller in its own right for payment data; see stripe.com/privacy. Provider: Stripe Payments Europe, Ltd., Ireland. Opening the checkout page loads a script from js.stripe.com, which is necessary for the payment to work at all.

After a successful payment we store, in our own database, your email address, the state of your access (trialing, active, cancelled, refunded), the date your access runs until, the Stripe customer and subscription identifiers, and the two onboarding answers if you gave them. That is the whole record. Legal basis: performance of the contract, Art. 6 (1) (b) GDPR.

The database is Cloudflare D1, provisioned in the Western Europe region, and the API runs on Cloudflare Workers. Provider: Cloudflare, Inc., with an EU data processing addendum and standard contractual clauses in place.

Signing in

There is no password. You get a six-digit code by email; the code is stored only as a hash and expires after 15 minutes. A successful sign-in sets one cookie, cb_session, on chess-buddy.com. It holds no personal data, only a random token, and it is strictly necessary for the paid area to work, so no consent is required for it.

Sign-in emails are sent through Brevo (Sendinblue SAS, France), which processes the recipient address on our behalf as a processor.

The sign-in form is protected by Cloudflare Turnstile. It checks that the request comes from a browser rather than a script and processes technical data about that request. Legal basis: legitimate interest in preventing abuse, Art. 6 (1) (f) GDPR.

Progress sync

If you are signed in, your drill progress can be stored server side as one JSON record tied to your user id, so that it follows you to another device. Without an account nothing is synced and the local copy in your browser is the only one.

Meta pixel, only with your consent

When advertising is running, this site can load the Meta pixel to measure which advert brought a visitor and whether they reached a lesson or a purchase. It loads only after you press Accept in the consent banner. Press Decline and no third-party script is loaded at all; events that happened before your answer are discarded rather than sent. On the puzzle pages under /puzzle the banner is not shown and the pixel is never loaded, whatever you answered elsewhere: those pages talk to Meta only in the one case described in the next section.

If you consent, Meta Platforms Ireland Limited receives your IP address, information about the pages you opened on this site and the events described above, and may match them to your Meta account. Meta and we are joint controllers for the collection and transmission of that data; Meta's own use of it is covered by its policy at facebook.com/privacy/policy. Data may be transferred to the United States on the basis of the EU-US Data Privacy Framework.

Legal basis: your consent, Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. You can withdraw it at any time by clearing the cb.consent.marketing entry in your browser storage, which brings the banner back on your next visit.

Telling Meta that an advert worked

If you create a free account from a puzzle page, we send one event to Meta from our own server, not from your browser: the fact that an account was requested, and again later the fact that you confirmed it by clicking the link in the email. This is how we can tell whether the advert you clicked brings people who actually sign up, which is the only reason we run the advert at all.

What goes with that event: your email address hashed with SHA-256, so that Meta receives a fingerprint it can match against its own records but cannot read back; the click identifier Meta itself put on the link you arrived through (fbclid), if you arrived through an advert; and the IP address and browser user agent of the request that created the account. Nothing else about you is sent: not your rating, not your answers, not what you drilled, not which pages you opened.

Nothing is sent for visitors who do not leave an email address. Looking at the puzzle, answering it and watching the line to the end are invisible to Meta.

Legal basis: your consent under Art. 6 (1) (a) GDPR, given by creating the account with that transfer described directly above the button. Meta Platforms Ireland Limited and we are joint controllers for this transfer; Meta's own use of the data is covered by its policy at facebook.com/privacy/policy, and data may reach the United States on the basis of the EU-US Data Privacy Framework. To withdraw it, or to have the event deleted on Meta's side, write to [email protected] and we will pass the deletion request on.

How long anything is kept

Login codes: 15 minutes. Sessions: until they expire or you sign out. Account and access records: as long as your access is valid, and afterwards for as long as commercial and tax law requires records of the transaction to be kept, which in Germany means up to ten years for invoicing data. Local storage in your browser: until you clear it.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time without affecting processing already carried out. One email to [email protected] is enough, and it is answered within a few working days.

You also have the right to complain to a supervisory authority, in particular the data protection authority of the German state in which the controller is established, or the authority where you live.

Anything unclear here, or a request to delete your data: write to [email protected]. Company details are in the Impressum.

Last updated