ChessMentor Privacy Policy
ChessMentor (“the app”) is developed by Vaara Mobile, Oulu, Finland (“we”, “us”). We are the data controller for the personal data described in this policy. Contact: hei@vaaramobile.com.
ChessMentor is built local-first: your games, training progress, and coach data live on your device. Nothing personal is sent anywhere without either your explicit action or your explicit consent — the one thing that travels on its own is a bare chess position sent to Lichess’s free endgame database when you open one of three analysis screens, which is described in section 4. This policy explains every case where data leaves your device, and your rights over it.
- Your chess data stays on your phone. Games, puzzles, progress, coach memory — stored locally. We run no game server and cannot see them. The few cases where a position or a summary reaches a provider are listed below — each is your action, your consent, or (for the endgame-database lookup) opening one of three analysis screens.
- An account is optional. Guest mode is fully local. If you create an account, we process your email address and chosen username for sign-in and verification.
- The online coach is opt-in. Only with your one-time consent does chess data go to Anthropic — and in this beta, only if you supply your own Anthropic API key.
- Telemetry is opt-in. Usage counts, app performance timings and crash reports are sent only if you say yes, and you can turn them off any time. They are not linked to your account, but they do carry a random per-install identifier (see section 5).
- No ads. No advertising ID. No sale of data. No tracking across apps.
What we process, and why
1. Account data (optional)
If you create an account, your email address, password and the username you choose are processed by Google Firebase Authentication to provide sign-in and email verification. Google runs that service for us as our processor; the account record (your email and username) is visible to us in the Firebase console. We never see or store your password. Guest mode requires no account and keeps everything local.
We hold no other cloud copy of anything: there is no game server, no database and no cloud sync — Firebase Authentication is the only place any first-party account data lives.
- Purpose / legal basis: providing the account you request (GDPR Art. 6(1)(b), contract).
- Retention: until you delete your account. You can delete it directly in the app (Profile → Delete account, effective immediately) or by emailing hei@vaaramobile.com from the account’s address (removed within 30 days). Deleting the account also clears that device’s local data, and signing out clears it too — export a backup first if you want to keep it. Uninstalling the app removes all local data from your device.
2. Game and training data (local)
Your games, moves, analysis, puzzles, ratings, streaks, onboarding answers, and the coach’s memory of your play are stored only on your device. They are not transmitted to us. Backup files you export are created at your request and remain in your control; treat them as containing your training history. A backup deliberately leaves out your sign-in credentials, any API key, and your consent choices, so sharing or restoring one cannot hand over a credential or silently turn a data-sharing option back on.
3. Online AI coach (optional, consent-gated)
The built-in coach works fully offline. In this closed beta, online mode only works if you supply your own Anthropic API key — the app ships with no key of its own, so nothing reaches Anthropic unless you enter one.
Turning online mode on is a mode-level consent, not a per-question one. Once you accept it, the following goes to Anthropic PBC (the AI provider) over an encrypted connection:
- when you ask something: your typed question and your recent chat turns with that coach;
- a compact chess profile summary (rating, strengths and weaknesses, recent results, training goals, study milestones);
- while you read a finished game’s Lesson or your Coach’s Corner: the coach’s own short written summary of that game — which can name individual moves from it — so that it can be re-voiced in the coach’s style. This happens as the page renders, without you asking;
- for your weekly coach letter: your recent activity highlights (games, courses and milestones).
This is chess data, not identity data: your email address and account details are never included, no game is ever uploaded as a position or a move list, and nothing at all is sent about a game you are still playing. Your API key is stored in your device’s secure storage (Android Keystore), used only to call Anthropic directly from your device, and never sent to us.
- Purpose / legal basis: your consent (GDPR Art. 6(1)(a)). You can decline and keep the offline coach. Turning online mode off in Settings (Profile → AI Coach Online Mode) withdraws it and stops every flow above, including the two that run as a page renders.
- Anthropic’s processing is described in the Anthropic Privacy Policy.
4. Lichess connection (optional)
If you connect a Lichess account (OAuth — you approve on lichess.org, we never see your Lichess password), the app receives your Lichess username, ratings, and the games you play or import, and can perform the actions you authorise (playing board moves, joining tournaments, challenges, messages the app sends on your behalf). The access token is stored in your device’s secure storage and can be revoked in the app or from your Lichess account settings at any time. Of the profile Lichess returns, the app keeps only your username, id, title, ratings and game counts on the device; anything else in your Lichess profile (real name, location, bio, links) is discarded rather than stored.
- Purpose / legal basis: providing the connection you request (Art. 6(1)(b)).
- Lichess’s processing is described in the Lichess Privacy Policy.
Position lookups (no account needed). Separately from any connection, some analysis features ask Lichess’s free public databases about the position on the board:
- the endgame tablebase (
tablebase.lichess.ovh) is asked for the perfect verdict on a position of seven pieces or fewer. This happens when you open the Lab in the Analysis Room for one of your own games, when you practise in the Endgame Trainer, or on the Lichess analysis board; - the opening explorer and cloud evaluation are asked about the position on the Lichess analysis board only.
What is sent is the position itself (a FEN) and nothing else — no account, no game id, no name, and, for the tablebase and explorer, no access token even if you are connected. Each position is asked once and the answer is cached. This works whether or not you have a Lichess account, so if you would rather send nothing to Lichess, avoid those three screens.
5. Beta telemetry (optional, opt-in)
To measure the beta’s stability and which features get used, the app can send three kinds of data through Google Firebase. One switch turns on all three, so all three are listed here:
- usage events via Firebase Analytics — screen and feature names (e.g.
onboarding_completed), plus how each game was set up and how it ended: mode, coach, difficulty, coach style, time-control bucket, result, the reason it ended, and rounded figures for its length in moves, its duration and how many hints you took; - crash reports via Firebase Crashlytics — technical stack traces with a short trail of recent screen and feature names;
- app performance timings via Firebase Performance Monitoring — how long the app takes to start and how long screens take to draw, plus the device model, OS version, connection type and carrier those timings came from. (Network-request tracing is not active in this app, so no addresses the app contacts are collected.)
This is off by default; the app asks once, and a Settings toggle (“Share usage & crash data”) controls it thereafter. Never included: your account details, your moves or positions, the text you type, and no advertising ID (the app removes the AD_ID permission entirely).
Not anonymous, but not linked to your account. We never attach your email, username or user id to any of this. Firebase does attach a random per-install identifier (an “app instance ID”, reset if you reinstall or clear the app’s data) so that events from one device group together, and it infers an approximate country from your IP address. That makes this pseudonymous rather than anonymous data under the GDPR: your rights in the section below apply to it, and you can ask us to delete it at any time using the contact address above.
- Purpose / legal basis: your consent (Art. 6(1)(a)), withdrawable any time in Settings.
- Retention: crash data up to 90 days; performance data up to 90 days; analytics data up to 14 months (Google Firebase defaults).
- Google acts as our processor for all three; nothing here is used for advertising or shared onward.
6. Bug reports (user-initiated)
The in-app “Report a problem” tool composes a diagnostic report — app version, device model and OS version, recent in-app activity (screen and feature names), and any captured errors. You see the report content and nothing is sent until you choose to send it (by email or share sheet), and it travels through whichever app you pick, to us. A report you share as a file is written to the app’s temporary folder; the app deletes those files again on its next launch, and “Clear captured diagnostics” on that same screen deletes them immediately.
7. Coach voices (on-device)
Coach speech is produced by your device’s own built-in text-to-speech engine. No voice model is downloaded and nothing you hear needs a network connection — the app sends no text, audio or request off the device in order to speak. (Earlier beta builds bundled their own neural voice engine, which fetched voice files on first use; that engine was removed in July 2026 in favour of the system voice, and with it the download.)
8. Notifications
The daily training reminder is a local, on-device notification you enable in Settings. There is no push-notification infrastructure and no device token is sent anywhere.
What we don’t do
No advertising or ad SDKs. No advertising ID. No sale or sharing of personal data for marketing. No tracking across other apps or websites. No payments are processed in the beta (store prices are display-only).
Processors and recipients
| Recipient | What | When |
|---|---|---|
| Google (Firebase Authentication) | account email, username, password (we never see the password) | account creation |
| Google (Firebase Analytics, Crashlytics, Performance Monitoring) | opt-in usage events, crash reports, performance timings + a per-install app instance ID and IP-derived country | telemetry opt-in |
| Anthropic PBC | coaching questions, chess profile summary, per-game coach summaries, weekly activity highlights | online-coach consent (your own API key) |
| Lichess.org | your Lichess account interactions | Lichess connection |
Lichess.org (tablebase.lichess.ovh, explorer.lichess.ovh, cloud eval) | the position on the board, as a FEN — no account, no token | opening the Lab, the Endgame Trainer, or the Lichess analysis board (no Lichess account needed) |
These providers act as processors or independent services under their own policies (linked above). We share nothing beyond the table above, and nothing at all for advertising or marketing.
International transfers
Google and Anthropic may process data in the United States. Transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable to those providers.
Your rights (GDPR)
You have the right to access, rectify, and erase your personal data, to restrict or object to processing, to data portability, and to withdraw any consent at any time (Settings, or by email). Contact hei@vaaramobile.com to exercise these rights. You also have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi).
Children
ChessMentor is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Security
Data in transit is encrypted (TLS). Tokens and API keys are stored in the device’s secure storage (Android Keystore). Release builds are obfuscated. Your chess data never leaves the device except as described above.
Changes
We may update this policy as the beta evolves; material changes will be announced in the app or by email to account holders, with the effective date above updated. Earlier versions are available on request.
What changed in version 1.1 (30 July 2026). Nothing new was collected — these are corrections. We now name Firebase Performance Monitoring, which the telemetry switch also turns on; we describe the telemetry as pseudonymous rather than “anonymous” and disclose the per-install identifier and IP-derived country behind it; we list the Lichess position lookups, which were not described before; we describe the online coach’s two render-time senders in full; and we removed a description of a coach-voice download the app no longer performs.