Privacy Policy
Last updated: 2025-01-01
🔒
Your Privacy Matters to Us

We are committed to protecting your personal data and being fully transparent about how it is used.

1 Introduction

This document ("Privacy Policy") describes the practices of Chess Dream AI ("we", "us") regarding how we collect, use, and protect information you provide when using our website.

By using the website, you agree to the practices described in this policy. If you do not agree, please discontinue use of the website.

2 Data We Collect

[Replace this placeholder with your real policy.] We collect the following types of information:

  • Account Data: Name, email address, and hashed password provided during registration.
  • Usage Data: Pages you visit, session duration, browser type, and IP address.
  • Chess Data: PGN files and board positions you upload for analysis.
  • Feedback: Name, email, and messages submitted through the feedback form.

3 Third-Party APIs (Google Gemini, Stockfish)

Google Gemini API

We use the Google Gemini API via a local PHP proxy to generate coaching commentary after Stockfish analysis completes. No personal account data is sent to Google. Submitted data is subject to Google's Privacy Policy.

Google Analytics 4

We use Google Analytics 4 to measure visitor counts and usage patterns. This service collects information about your visit such as IP address, device type, and browser. You can opt out via the Google Analytics opt-out add-on.

Stockfish 18 (WebAssembly)

The Stockfish engine runs entirely inside your browser (WebAssembly). It is never sent to any external server and collects no personal data whatsoever.

4 Account Security

We apply the following technical measures to protect your data:

  • Password Hashing: Passwords are stored using argon2id hashing — no one, including administrators, can see your plain-text password.
  • CSRF Protection: All forms use CSRF tokens to prevent cross-site request forgery attacks.
  • Prepared SQL Statements: All database queries use PDO Prepared Statements to prevent SQL injection.
  • HTTPS Encryption: [Ensure SSL is enabled on your hosting] All traffic is transmitted over an encrypted TLS connection.

5 Cookies

[Replace this placeholder.] We use limited cookies for functional purposes (session management, language preferences) and analytics (Google Analytics). You can disable cookies in your browser settings, though this may affect site functionality.

6 Data Retention

[Replace this placeholder.] We retain your data as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us at contact@chessdreamai.com.

7 Your Rights

[Replace this placeholder.] You have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Opt out of marketing emails.

To exercise any of these rights, contact us at: contact@chessdreamai.com

8 Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be indicated by updating the "Last updated" date at the top. We recommend reviewing this page periodically.

9 Contact Us

If you have any questions about this Privacy Policy, we are happy to answer them: