Last updated: 12 August 2026
1. Who controls your data
The data controller is ChessInspect, France. For any privacy question or request, contact [email protected].
2. What we collect
You do not create an account, and we never ask you for an email address or a password. We collect:
- What you type in the form: your chess platform (chess.com or Lichess), your username there, and anything you choose to add to personalize the report (goals, favourite openings, time available).
- Your games: the public games we fetch for that username, and the report we produce from them.
- Technical data: basic rate-limiting metadata such as your IP address, and a session cookie that links your browser to your report.
- Payment data: handled by Stripe. We do not see or store your card details; we keep only the references needed to reconcile your purchase. Any email address you give Stripe stays with Stripe.
3. How we use it
We use your data to provide the Service (analyze your games and generate your report), to reconcile your payment, to prevent abuse, and to comply with legal obligations. We do not send you marketing email — we have no address to send it to.
4. Who we share it with
We share data with processors strictly to run the Service:
- OpenRouter — receives an anonymized summary of your game statistics to generate the written report.
- Stripe — processes payments.
- chess.com / Lichess — public game data is fetched using the platform and username you provide.
- Resend — delivers email if you write to us through the feedback form.
We do not sell your personal data.
5. Legal bases (GDPR)
Where the GDPR applies, we process data to perform our contract with you (producing and hosting the report you paid for), for our legitimate interests (security and abuse prevention), and to meet legal obligations (e.g. tax records).
6. Retention
We keep your report and the data behind it so that your link keeps working. Payment records may be retained longer where required by law. You can ask us to delete your report at any time (see our GDPR notice).
7. Security
Session cookies are signed and, in production, served over HTTPS with secure flags. No system is perfectly secure, but we take reasonable measures to protect your data.
8. Your rights
Depending on your location you may have rights to access, correct, delete, or export your data, and to object to certain processing. See the GDPR notice or email [email protected].