Privacy Policy

What CommuniChess collects, why, who it goes to, and how long we keep it.

Last updated: 22 August 2026

Who we are

CommuniChess is a chess app that pairs players for games, live video and a shared community feed. Contact us at support@communichess.com with any question about this policy or about the data we hold on you.

What we collect

Every item below is data we actually store or transmit. Nothing else is collected.

Account identity — email address, username, profile picture
Why: To create and sign you in to your account, and to show you to other players. Handled by our authentication provider, Clerk; we store the username and the avatar URL, and read the email address from Clerk when needed.
Shared with: Clerk (authentication provider)
Kept for: Until you delete your account
Account identifiers — your Clerk user ID and an internal CommuniChess user ID
Why: To link your games, posts, friendships and settings to your account.
Shared with: Clerk (the Clerk ID originates there); not shared otherwise
Kept for: Until you delete your account
Precise location — latitude, longitude and city
Why: To match you with chess players near you and to show nearby events on the map. Your coordinates are only read when you allow the location prompt. Other players see your city and approximate distance, never your exact coordinates.
Shared with: Not shared with third parties. Addresses you type when submitting an event are sent to a geocoding service to turn them into coordinates.
Kept for: Until you change or clear it, or delete your account
Community posts — text you write and photos you upload
Why: To publish your posts in the community feed. Photos are stored on Cloudflare R2 and served from a public URL, so anyone who has the URL can view them.
Shared with: Cloudflare (R2 object storage)
Kept for: Until you delete the post or your account
Shared games — Lichess game ID, the two players, the result and a PGN excerpt
Why: To render a game you chose to share as a card in the feed.
Shared with: Lichess (the game data originates there)
Kept for: Until you delete the post or your account
Chat messages
Why: To deliver your messages to the person you are playing. Messages in CommuniChess games are relayed through our server in memory and are never written to our database. Messages you send in a Lichess game are delivered by Lichess and stored under Lichess's own policy.
Shared with: Lichess (for Lichess game chat only)
Kept for: Not stored by CommuniChess
Live video and audio during games
Why: To let you see and hear your opponent. The call is peer-to-peer (WebRTC) and encrypted by the browser. We never record, store or listen to it. When a direct connection is not possible, the encrypted stream is relayed through Cloudflare's TURN service, which passes it through without being able to read it.
Shared with: Cloudflare (TURN relay, encrypted pass-through only)
Kept for: Not recorded — the stream exists only for the length of the call
Lichess connection — OAuth access token, Lichess ID, Lichess username, granted scopes and your Lichess ratings
Why: To play games on your Lichess account from inside CommuniChess and to show your rating. The access token is stored so we can act on your behalf while you are connected.
Shared with: Lichess
Kept for: Until you disconnect Lichess or delete your account; on deletion the token is revoked at Lichess
Reports and blocks
Why: To review abuse reports, enforce blocks, and suspend accounts that are repeatedly reported. A report records who reported whom, the reason, and any comment you add.
Shared with: Not shared with third parties; visible to our moderators
Kept for: Up to 12 months after review, then deleted. A report filed about you outlives your account — it is detached from it and keeps only your username, so deleting an account cannot erase its abuse record. Reports you filed about others are deleted with your account.
Friendships, language preference, rating-range preference and moderation status
Why: To run the friends list, show the app in your language, filter matchmaking, and enforce suspensions.
Shared with: Not shared
Kept for: Until you delete your account
Server logs
Why: To keep the service running and diagnose faults. Logs contain request paths, usernames and error details.
Shared with: Railway (our hosting provider)
Kept for: Rolling — replaced automatically by the hosting platform, typically within days

What we do not do

  • We do not sell your personal data.
  • We do not use it for advertising or share it with advertisers.
  • We do not record video or audio calls.
  • We do not track you across other apps or websites.

Third parties we use

  • Clerk — authentication. Holds your email address, username and profile picture.
  • Lichess — the chess engine behind every game. Receives your moves, your Lichess game chat, and acts on your OAuth token.
  • Cloudflare — R2 object storage for post photos, and the TURN service that relays encrypted video when a direct connection fails.
  • Railway — hosting for our server and database.

Each of these processes data on our behalf under their own privacy policy. We do not send them anything beyond what is listed above.

Location, specifically

CommuniChess asks for your precise location because proximity matchmaking is a core feature: it is how the app finds players near you and shows nearby events. Location is only read after you allow your device's permission prompt, and you can revoke that permission at any time in your device settings — the rest of the app keeps working without it.

Your rights

You can access, correct, export or delete your data. The fastest route is in the app: Delete your account removes it permanently. For anything else, email support@communichess.com and we will respond within 30 days.

If you are in the EU or UK, you have rights under the GDPR including access, rectification, erasure, restriction, portability and objection, and the right to complain to your national data-protection authority.

Children

CommuniChess is for adults. You must be 18 or older to create an account. The app pairs adults for live video, so we do not knowingly allow accounts for anyone under 18. If we learn that an account belongs to a minor, we delete it. Contact support@communichess.com if you believe a minor has an account.

Security and where data is held

Data is stored in a PostgreSQL database and on Cloudflare R2, both accessed over encrypted connections. Our servers and database are hosted in the EU and the United States by Railway and Cloudflare; using the app involves transferring your data to those regions.

Changes to this policy

If this policy changes materially we will update the date at the top of this page and, where the change affects how we use your data, notify you in the app.