Plain-language summary
Local and direct AI games stay on your device unless you save. Online play needs compact game and account data. We use service providers—not data brokers—and do not sell personal information.
Effective and last updated: July 21, 2026
Scope and our role
This policy explains how Busted Minds Chess (“we”, “us”, or “the service”) handles personal information when you use the website, installed web app, games, learning tools, community features, or support channels. It does not govern third-party sites you choose to visit.
The service is in public beta. Features and data flows may change; we will update this notice when a material change affects how information is handled.
Information we collect
- Account data: email address, display name, avatar, authentication provider identifiers, account status, and server-controlled roles.
- Chess data: moves, positions, clocks, results, ratings, pairings, tournament entries, saved analysis summaries, achievements, and fair-play or integrity metadata.
- Social content: profiles, club membership, friend and block relationships, messages, reactions, reports, and moderation history.
- Technical data: IP address, timestamps, browser and device characteristics, request identifiers, security events, error details, and limited usage metrics.
- What you send us: feedback, support messages, and any contact details or links you choose to include.
Google sign-in requests only OpenID, email, and basic profile information. We do not request access to contacts, Drive, Calendar, or other unrelated Google data.
Local play and browser analysis
Local Hotseat and direct Vs AI play run primarily on your device. They do not use Supabase resources or become part of your cloud game history unless you explicitly save eligible game or progress data.
Stockfish analysis runs in a browser Web Worker. Large engine lines and search output are not persisted by default. If you save an analysis, the service may keep a compact summary and your annotations rather than the full engine computation.
Offline preferences and unsaved games may be stored in browser storage on your device. Clearing site data can remove them.
How and why we use information
- Provide authentication, games, clocks, matchmaking, ratings, tournaments, learning, social features, and account recovery.
- Validate legal moves, prevent duplicate mutations, enforce permissions, investigate abuse, and protect competitive integrity.
- Operate, debug, measure, and improve the service, including free-tier capacity planning.
- Respond to support, feedback, privacy, and safety requests.
- Meet legal obligations and establish, exercise, or defend legal claims where necessary.
Legal bases
Depending on where you live, we rely on performance of our agreement to provide requested features, legitimate interests in security and service improvement, consent where the interface asks for it, and compliance with legal obligations. You may withdraw consent for future processing where consent is the basis; this does not undo lawful earlier processing.
Public and social information
Your display name, avatar, ratings, public games, achievements, and profile details may be visible to others. Tournament standings, club activity, and shared annotations may also be public according to their settings. Direct messages, blocks, reports, email addresses, and moderation notes are not public. Review visibility controls before posting or sharing a game link.
Retention
We keep account and persistent game data while your account is active and as needed to provide features you requested. Temporary, abandoned, or anonymous records may be removed sooner through request-driven or scheduled cleanup. Security, moderation, transaction-integrity, and legal records may be retained longer where reasonably necessary.
Deletion from live systems does not always remove data immediately from encrypted backups; backup copies age out on provider schedules and are not used to restore an individual deleted record except during disaster recovery.
Security
We use encrypted transport, restrictive database access policies, server-side authorization, protected secrets, rate limits, audit-oriented identifiers, and authoritative move validation. No internet service can guarantee absolute security. Use a unique password, protect your sign-in method, and report suspected account compromise promptly.
Your choices and rights
You can edit eligible profile fields, change display preferences, avoid cloud saving for local modes, block or mute users, and disconnect by signing out. Depending on local law, you may request access, correction, deletion, restriction, portability, or objection, and may complain to your data-protection authority.
Send a request through the contact form using the email associated with your account. We may need to verify identity without asking for your password. Some records must be retained for security, legal, or rating-integrity reasons.
Children
The service is not directed to children under 13, or a higher minimum age required by local law without appropriate guardian authorization. If you believe a child provided personal information contrary to this rule, contact us so we can investigate and delete it where required.
International processing
Our providers may process information in countries other than your own. Where required, we use provider commitments and legally recognized transfer safeguards. Provider locations and subprocessors can change; their current documentation contains the most precise infrastructure information.
Contact and changes
Questions or privacy requests can be submitted through the Contact page. Choose “Privacy request” so it can be routed correctly.
Material changes will be reflected by a new effective date and, when appropriate, an in-product notice. Continuing to use the service after an effective update means the new policy applies to future use, subject to rights provided by law.
