Skip to main content

Legal

Privacy Policy

Last updated: June 10, 2026

ChessCore provides management software for chess academies. Because academies serve families and most students are minors, this policy is written to be read by academy owners and parents alike. It describes what we collect, why, and the protections that apply, in the same plain language we use everywhere else.

1. What we collect

We process the data an academy enters or connects in order to run its operations:

  • Account data: names, email addresses, and roles of academy staff
  • Student and guardian data entered by the academy: profiles, enrollment, attendance, notes, and contact details
  • Chess data: linked Lichess or Chess.com identifiers, imported games, ratings, and engine analysis results
  • Billing data: invoices, payment status, and receipts (card and bank details are handled by Razorpay or Stripe, not stored by ChessCore)
  • Usage data: logs needed to operate, secure, and improve the service

2. How we use it

Data is used to provide the service the academy signed up for: scheduling, attendance, billing, game analysis, reports, and communication. We do not sell personal data, and we do not use your academy's data to train AI models.

3. AI processing

ChessCore's AI copilot drafts game reviews, progress reports, and messages from the academy's own records. Before any text reaches an AI model, personally identifying details are redacted by a policy layer we own and operate. Chess evaluations come from the Stockfish engine, and numbers in reports come from the database, not from a model. Every AI draft waits for human approval before it is sent to a family, unless the academy has explicitly enabled auto-send for a specific routine template.

4. Minors' data

Most students on ChessCore are children, and the platform is built around that fact. Academies capture guardian consent, which is recorded, versioned, and renewable. A minor's data is never used in any AI workflow that has not been specifically approved, is never used for advertising or profiling, and is visible only to the academy roles that need it. Guardians can ask their academy to access, export, correct, or delete their child's data at any time.

5. Data isolation and security

Every academy's data is isolated from every other academy's, enforced at the database layer. Access is role-based, actions are audit-logged, data is encrypted in transit, and rating history is append-only so records cannot be silently rewritten.

6. Retention and deletion

We keep data for as long as the academy's account is active or as needed to provide the service. Notification records are purged automatically after a retention window. When an academy closes its account, its data is deleted on request, subject to legal retention obligations such as tax records.

7. Third-party processors

We rely on a small set of processors to operate: payment providers (Razorpay, Stripe), communication channels (WhatsApp Business, email), chess platforms the academy connects (Lichess, Chess.com), and hosting infrastructure. Each receives only the data needed for its function.

8. Your rights

Depending on where you live, including under India's DPDP Act and the EU's GDPR, you may have rights to access, correct, export, restrict, or delete your personal data. Requests can be made through your academy or directly to us, and we respond within the timelines the applicable law requires.

9. Changes

If this policy changes in a way that matters, we will notify academy owners by email and note the new date at the top of this page.

Questions about this document? Write to [email protected].