Effective August 19, 2026
You do not need a ChessIQ account. ChessIQ does not sell personal information or run an advertising profile. Public-game imports, optional site measurement, hosting, and abuse protection still involve the limited processing described below.
Data stored in your browser
Pasted or imported games, PGNs, positions, Stockfish results, saved review history, practice progress, public usernames, preferences, and offline assets can be stored on this device in localStorage, sessionStorage, IndexedDB, and Cache Storage.
This browser data remains until you remove it, the app replaces it, or the browser or operating system evicts it. It is not synced to a ChessIQ account or ChessIQ cloud profile. Stockfish analysis runs in your browser after the engine files have been delivered and, when available, cached on this device.
Imports, servers, hosting, and logs
When you look up a Chess.com or Lichess username, import a shared game URL, or request public rating data, the username, game identifier, or URL is sent to a ChessIQ server route. That route validates the request and contacts the selected public provider. These requests pass through our hosting and network/CDN infrastructure before reaching Chess.com or Lichess.
ChessIQ marks username, game, and PGN API responses as private and not for shared caching. Normal hosting, CDN, security, and error logs can still process request metadata such as time, route, network address, user agent, and—depending on provider configuration—the requested URL. Application warning logs do not intentionally record raw public usernames, PGNs, or submitted game URLs.
Chess.com public game responses can be held temporarily in memory by a warm ChessIQ server process to reduce repeat provider work. This is not a durable account store; the data disappears when that process is recycled. Chess.com and Lichess handle the requests they receive under their own policies.
Optional analytics and performance measurement
On a production deployment, Vercel Web Analytics and Vercel Speed Insights run only when their separate environment flags are enabled. Web Analytics can receive page views and coarse product events. Speed Insights can receive real-user performance metrics. Before either integration sends an event, ChessIQ removes the search query and hash fragment from its URL.
ChessIQ's custom event filter excludes usernames, player and opponent names, PGNs, FENs, game URLs, move text, and variations. Allowed event data is limited to coarse labels, counts, buckets, and boolean state used to understand whether product flows work. Vercel states that Web Analytics is cookie-free and that its anonymous visitor hash is discarded within 24 hours. Aggregated reports can remain available to the site operator.
Rate limiting and abuse protection
Our host and network providers necessarily receive your network address when serving a request. Before ChessIQ uses an address as an application rate-limit key, it applies a namespaced SHA-256 hash and keeps only the first 24 hexadecimal characters.
By default, that identifier is held in the active server process. If Upstash Redis credentials are configured, the derived identifier and request-window state are sent to Upstash instead. Upstash rate-limit analytics are disabled. Upstash remains an independent processor subject to its own retention and privacy terms.
Cookies
ChessIQ application code does not set account, advertising, or analytics cookies. Browser storage and Cache Storage used for local features are not cookies. Vercel Web Analytics is cookie-free. If you follow a link to Chess.com, Lichess, Vercel, Upstash, or another external site, that provider can use cookies under its own policy.
Retention and policy updates
Browser data remains until you delete it, ChessIQ replaces it, or your browser or operating system evicts it. Temporary Chess.com response data in server memory remains only until the warm process is recycled. The application rate-limit window is one minute, although an in-memory identifier can remain until its server process is recycled. Provider operational records can remain longer under the configured service and provider terms.
Hosting, CDN, security, and error-log retention—and retention of aggregated analytics or performance reports—depends on the active deployment and provider settings. This repository does not establish a fixed retention period for those systems, so this notice does not promise one. If ChessIQ's processing practices materially change, this page and its effective date will be updated before the revised notice applies.
Your controls and deletion limits
The Your Data page can inspect, export, and remove the browser data ChessIQ knows how to manage. You can also clear this site's storage in your browser. Clearing data can fail when another tab keeps a database open, and browsers may retain items outside ChessIQ's managed list; the page reports failures so you can retry.
Browser deletion does not delete public data held by Chess.com or Lichess, provider or hosting logs, rate-limit records that have not yet expired, or previously aggregated analytics reports. ChessIQ has no account record or cloud library to delete. For a privacy question about processing controlled by ChessIQ, email support@chessiq.ca.
Provider policies and contact
- Chess.com privacy policy
- Lichess privacy policy
- Vercel Web Analytics privacy
- Vercel privacy notice
- Upstash privacy policy
Plain-language questions are welcome at support@chessiq.ca.