Last updated August 13, 2026
chessdesk is a chess workspace and a set of free chess tools. The free tools (game review, analysis board, best-move finder) run the engine in your browser. We do not sell your data, we do not run advertising, and we limit collection to what is described below. You can use every free tool without an account.
Drafted By (JD Michael Casanova), the operator of chessdesk, is responsible for the personal data described in this policy. Contact the operator at [email protected].
The public tools are designed to keep your data on your device. The chess engine that powers game review, the analysis board, and the best-move finder runs locally in your browser; the positions you analyze are not sent to us. When you fetch games by username, those games are requested directly from the public Chess.com and Lichess APIs and analyzed on the fly; we do not store them on our servers. When you upload a screenshot to the best-move finder, the image is sent only to our position recognition service so it can read the board, used to return the detected position, and not retained afterwards.
You can create an account to save your work. When you do, we store:
We use Umami and PostHog to measure use of chessdesk and improve the product. For signed-in users, analytics events can be associated with an internal account identifier and account role. PostHog is configured for automatic interaction capture and may record product sessions. Visible interface text and form inputs are masked in recordings, and element attributes are masked from automatic interaction capture. Interaction timing and types, page URLs, usage events, and browser or device technical context can still be processed. Umami receives the connection IP address through our same-origin analytics proxy as part of processing a visit. We do not use this information for advertising profiles and do not sell it.
We use Sentry to diagnose errors and crashes. A report can include the page, browser, connection data, account or request context, error message, and local application variables available when the error occurred. These diagnostics can contain personal data even though we configure masking and filters to reduce unnecessary capture.
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Payments & subscriptions | Email, name, payment data |
| Cloudflare | Traffic delivery, security & transactional email | Technical connection data (IP, request metadata), email address |
| Lichess / Chess.com | Importing your games (only when you connect or import) | Your public username; for a connected Lichess account, an access token |
| Optional Google sign-in for student accounts | Email address, name, and sign-in identifiers | |
| Cal.com | Coach booking pages and appointment management | Connection data and booking details you submit |
| Sentry | Error diagnostics | Error, request, account, connection, and application context |
| PostHog / Umami | EU-hosted product and usage analytics | Account identifier and role when signed in, usage events, session context, IP and device data |
Cal.com may connect a booking to a meeting provider chosen by the coach; that provider handles the call under its own terms. We may change providers to improve or secure the service. Our own application and database run on self-hosted infrastructure.
We keep account and saved-work data while your account is active. The free tools are built to avoid retention: fetched games and uploaded screenshots are processed and not stored. When an account is deleted, we remove application data under our control unless it must be kept for security, dispute, tax, accounting, or other legal obligations. Limited backup copies expire through the normal backup lifecycle. Billing, analytics, and diagnostic providers retain data according to their configured retention periods and legal duties; deletion from chessdesk does not require a provider to erase records it must keep by law.
You can use every free tool without an account and without signing in. If you have an account, you can edit or remove saved work, disconnect Lichess, or delete your chessdesk account from Settings. Before deleting an account with a paid subscription, manage or cancel that subscription from the Billing section.
Depending on applicable law, you may ask to access, correct, erase, restrict, or receive a portable copy of your personal data, and may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it without affecting earlier processing. You may also complain to your local data-protection authority; in France, this is the CNIL. Contact us to exercise a right.
Some providers may process data outside the European Economic Area. Where that happens, the transfer must use a lawful safeguard made available by the provider, such as an adequacy decision or approved standard contractual clauses. You can contact us for information about the safeguard relevant to your data.
We may update this policy as the service evolves. When we make material changes, we will update the date at the top of this page.
Questions about privacy, or want your data deleted? Email [email protected].