LAST UPDATED AUGUST 4, 2026
PRIVACY
ChessRiot stores the information needed to run your account and games: your chosen permanent username, display name, game and move history, and limited operational events used to keep the service reliable.
What we collect
- Display names, game settings, moves, results, reactions, and feedback you submit.
- Hashed identifiers for private game access, rate limiting, and operational diagnostics.
- Push-notification subscription data only when you explicitly enable notifications on a device. It is used for friend requests, turn alerts, and occasional service or test messages, never marketing.
- A pseudonymous account ID, Google profile display name, and the unique username you choose.
- Personal invite codes, referral attribution, friend connections, and your non-cash credit ledger, including starter, referral, Magic use, and World creator entries. Creator analytics are exported only as per-World totals; another player’s private game identifiers and timestamps are not disclosed.
- Magic World codes, canonical rules, lineage, game counts, and creator attribution. Raw Magic descriptions are not published with Worlds.
Google sign-in
Google sign-in is required to play and lets your full game history follow you across devices. ChessRiot requests only OpenID, email, and profile access. We verify your Google account identifier, verified-email status, and profile name during sign-in. ChessRiot stores a one-way pseudonymous account ID and your display name. It does not store your raw Google account identifier, Google access token, refresh token, or email address.
A secure, HTTP-only session cookie keeps you signed in for up to one year. Successful activity extends that one-year window, unless you sign out, delete the account, or the cookie is removed. A separate short-lived cookie protects the sign-in transaction. Google processes the sign-in under its own privacy terms.
How we use it
We use this data to run ChessRiot, synchronize authorized games, deliver requested alerts, prevent abuse, answer feedback, and diagnose failures. We do not sell personal information or use it for targeted advertising.
Privacy-safe product and reliability metrics may include a one-way account hash. These operational events exclude usernames, emails, game secrets, and raw account IDs. Events stop contributing to metrics after 30 days and are physically removed during the next service request after that cutoff.
When you open a personal player-invite link, ChessRiot uses that signed sign-in path to connect you with the inviter. A referral reward is recorded only for a newly created account that completes username onboarding. Existing accounts can connect through the same link but do not generate another reward.
Sharing and AI
Service providers may process data only to host and operate ChessRiot. Optional owner-triggered demo narration can send prepared narration text to OpenAI. Private seat tokens and raw game secrets are not sent for narration. Operational LLM health checks send only a fixed test marker and no player or game data.
Your choices
You can disable music, effects, coaching, celebrations, or push alerts. Signed-in players can use the Privacy & Data center to download their account data, manage blocked players, or permanently delete their account after recent Google verification.
Account deletion removes the profile, social connections, active access, referrals, credit balance, and game membership. Creator attribution is removed from Worlds, while immutable World rules and finished game boards may remain as anonymized records so results cannot be rewritten. A minimal tombstone reserves the deleted username and prevents the same Google identity from silently recreating the account.
If an account is part of an abuse report, a restricted moderation copy may make the involved usernames, category, and submitted note available to administrators for no more than 90 days. Expired copies are hidden at the cutoff and physically removed during the next service request.
For a private data question, use the in-app feedback form. Never post an invitation token or other game credential in a public GitHub issue.
See also the ChessRiot Terms.