Privacy Policy
Last updated: July 19, 2026
GoudaChess ("we," "us," or "our") operates Learn Chess. This Privacy Policy explains how we collect, use, store, and protect information when you use our Learn Chess mobile apps for iOS and Android (from the Apple App Store and Google Play), and when you visit learnchess.app.
We are based in Alphen aan den Rijn, Netherlands, and comply with the General Data Protection Regulation (GDPR) where it applies. Our main app database is hosted with Supabase in the European Union.
1. Information We Collect
1.1. Information You Provide
• Identity & Account Data: Your unique User ID (UUID), username, full name, and email address. Sign-in is managed via our authentication provider (Supabase). You may also sign in with optional third-party providers we enable (for example Discord), and optional multi-factor authentication (MFA).
• Profile Data: Preferred language; board and piece theme choices where you customize them; subscription tier (for example free or pro); and flags we use for account state (such as whether your profile is hidden from others).
• Communications: Any information you provide when contacting us for support or when you submit in-app feedback.
1.2. Learning Progress & Usage Data
To provide core functionality and track your learning progress, we collect:
• Curriculum progress: Your placement in the course, per-lesson status (locked, available, in progress, completed), section and test cursors, mid-lesson checkpoints, completion times, and structured performance summaries (for example wrong attempts, hints, reveals, and star/mastery scores).
• Coach Play: Completed practice games against the in-app coach (result, color, estimated strength, time control, hints, takebacks, move counts, and finish times), plus aggregate win/loss/draw stats. For history replay we may also store moves and replay-style data (including keys used to rebuild in-game coach commentary and hints).
• Achievements: Badges and tiers you unlock through lessons and mastery (for example lessons completed, stars earned, or perfect scores).
• Guest progress & notifications: Before you create an account, lesson progress may be stored locally on your device and later merged into your account after you sign up. We also store in-app notification payloads (title, message, type, read state).
• Subscription state: We store your subscription tier on your profile so premium features (for example Pro piece themes) stay accurate. If you purchase through the app stores, payment cards are processed by Apple or Google; we do not receive your full card number.
1.3. Information Collected Automatically
• Device & app signals: When you submit in-app feedback, we may store device OS version and app version with your message. Product analytics events (section 1.4), when enabled, include your platform (iOS or Android) and app version.
• Identifiers: A random id on your device for first-party analytics when that pipeline is active (section 1.4); and ids synchronized with subscription tooling when purchases are linked to your account.
1.4. Product analytics & in-app events
We may collect first-party product analytics when you use the App. These are discrete events (for example when a screen is shown, a lesson completes, or you move through sign-in). They are sent to our own backend (Supabase, hosted in the EU; see section 3) over encrypted connections. This pipeline is separate from third-party advertising networks.
• Typical contents: An event name, optional properties you trigger in context (such as the active screen or lesson, scores, or timing fields where relevant), your platform, app version, a per-session identifier, and a client-generated id used to avoid duplicate rows. Events may also include coarse device signals (for example device model).
• Guests vs signed-in users: Before you authenticate, events may be tied to a random anonymous id stored on your device. After you create an account or sign in, we may link prior anonymous events to your profile so product analytics stay in one timeline. Guest curriculum progress on the device may similarly be merged after signup.
• Why we use events: To understand feature usage, measure funnels and stability, improve lessons and Coach Play, and support product decisions, in support of our legitimate interests in running and improving the App.
• Retention: When raw analytics event rows are stored, they are deleted on a rolling basis after about 14 days. Aggregated or derived metrics used internally may be kept longer where permitted and in line with data minimisation.
• Marketing website: learnchess.app is a marketing and information site. It does not require an account. We do not use personalised advertising cookies on the marketing site by default.
2. How We Use Your Information
We use your information to:
• Operate the App: Authenticate your session, load your profile and themes, and keep your curriculum progress in sync across devices.
• Deliver learning features: Serve lessons, checkpoints, mastery scores, achievements, and Coach Play practice games.
• Profiles: Basic profile fields for accounts that are not deleted may be readable under our database rules. Other players may view your public profile and learning stats when your profile is not hidden. Treat your username as public.
• Subscriptions: Apply free or Pro entitlements on your account, including longer Coach Play history for paying players. Purchases, when offered, go through the app stores; we store subscription tier on your profile.
• Communication: Send in-app notifications regarding progress, achievements, and other app-related events.
• Product analytics: Use the first-party event data described in section 1.4 to measure usage, improve features, and guide product decisions.
3. Third-Party Service Providers
We share information with the following providers solely to operate the App:
• Supabase (Backend & Database): Stores user account data, curriculum progress, Coach Play records, achievements, and notifications. Data is hosted in the European Union. Sign-in secrets stay inside Supabase’s auth service.
• Apple & Google: App stores and payment processors for installs and in-app purchases when you buy through them. We store subscription information on your profile but we do not receive your full card number.
• Discord (optional): If you choose to sign in or link Discord, Discord’s policies apply to the identity data they share with us for authentication.
• Expo: Provides infrastructure for app updates and related mobile app tooling.
4. Data Retention & Deletion
We apply data minimization: we keep data only as long as needed for the purposes described in this policy:
• Usage analytics: When detailed event rows are stored, automated cleanup typically removes them after about 14 days.
• Account deletion: Start it from the App settings or from our website account deletion page (linked in the site footer). On the web, enter your username and confirm via the email link we send you. We soft delete your profile immediately; after 30 days a maintenance job permanently removes your authentication user (which cascades to related personal progress data) unless the law requires longer retention; see section 5. Guest progress stored only on your device is pruned locally after about 30 days if unused.
• Read notifications: Read in-app notifications may be purged after about 14 days; other items may be kept until you act on them or a later retention pass applies.
• Coach Play history: free accounts may only see a shorter history in the app (for example about seven days in lists). Pro accounts can browse a longer history window in the app.
5. Your Rights (GDPR)
• Access & Rectification: You can request a copy of your data or correct inaccurate information (username and full name can be changed directly in the App, subject to rate limits).
• Erasure: You may request the full deletion of your account and data. After 30 days, all profile data and authentication records are permanently removed unless legal obligations require longer retention.
• Object or limit: You may object to some processing based on legitimate interests, within legal limits. Contact us using the details in section 8.
6. Children’s Privacy
The App is not designed specifically for children under 13, but it is a general chess learning app. Account creation requires you to be at least 13. We do not ask for or store your date of birth and we do not knowingly collect personal data from children. If a parent or legal guardian contacts us and tells us that a child under 13 is using the App and has provided personal data, we will take reasonable steps to delete that account and associated personal data.
7. Security
We use technical measures, including Row Level Security (RLS) on our database and encrypted HTTPS/TLS connections, to protect your data. No system is 100% secure, and we cannot guarantee absolute security.
8. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
• Email: [email protected]
• Operator: GoudaChess. Location: Alphen aan den Rijn, Netherlands.