Scope and controller
This policy applies to chesstier.com and the ChessTier web app. The operator of ChessTier is responsible for the processing described here. For privacy questions or a request concerning your account, contact privacy@chesstier.com.
ChessTier is a local-first chess analysis workspace. It is independent and is not affiliated with Chess.com, Lichess, Google, Firebase, or Stockfish.
Information you provide and we receive
If you use Google Sign-In, Firebase Authentication may provide ChessTier with your Google account display name, email address, profile image URL if available, a Firebase user identifier, and authentication tokens needed to maintain your session. ChessTier uses Google Sign-In for identity and session access only; it does not request access to Gmail, Drive, Calendar, contacts, or any other Google data.
If you use an email sign-in link, Firebase Authentication processes the email address you enter and the authentication information required to send and complete the one-time link. Firebase may also process technical information such as IP address and user-agent to secure authentication and prevent abuse.
If you import public games, you enter a Chess.com or Lichess username. ChessTier sends that username to its import endpoint and then to the relevant public game API solely to retrieve the public games you requested.
Local chess data
PGN text you paste or upload, board positions, engine analysis, classifications, and saved reports are stored locally in your browser using IndexedDB and local storage. In the current version, ChessTier does not upload those local reports to a ChessTier cloud database.
Your browser may also store your selected color theme, recently used public-game usernames, and Firebase session state. You can delete local reports inside the workspace; clearing browser site data removes local preferences and locally saved reports.
Why we process information
We process authentication data to sign you in, keep your session secure, display your account state, and allow sign-out. We process imported usernames and public-game responses to show games you explicitly request. We process local chess data to run the features you initiate in your browser.
We do not sell personal information, use Google account data for advertising, create advertising profiles, or use it for credit, employment, insurance, or similar eligibility decisions.
Service providers and sharing
Firebase Authentication is provided by Google and processes authentication information on ChessTier’s behalf. Firebase documentation explains that the service may process email addresses, IP addresses, user agents, and related account data to provide authentication and account management.
Chess.com and Lichess receive the public username you choose to import because their public APIs are needed to retrieve the requested games. We do not share your locally stored PGN reports with those services.
Google Analytics
ChessTier uses Google Analytics to measure aggregate site use and improve reliability. This service may process online identifiers, browser and device details, IP-derived technical information, and page-use events under Google's policies.
We use Google Analytics for measurement rather than advertising. Google signals and ad-personalisation signals are disabled, and we do not use the service for retargeting or personalised advertising.
Google OAuth disclosures
Google Sign-In is optional: the core local analysis workspace can be used without a Google account. When you choose Google Sign-In, ChessTier requests only the basic identity information necessary for authentication. We use that information only for the sign-in feature prominently presented in the app.
If ChessTier changes the Google user data it accesses, uses, stores, or shares, we will update this policy and obtain any required consent before using the data for a new purpose.
Retention, security, and your choices
Local analysis data remains on your device until you delete it or clear browser data. Firebase Authentication retains account and security data according to Firebase’s service operation and retention practices; account-deletion requests can be sent to privacy@chesstier.com.
ChessTier uses HTTPS in production. No internet service can guarantee absolute security, but we limit the current app to the data needed for the requested feature and use Firebase Authentication rather than storing passwords in ChessTier code.
Children and changes
ChessTier is not directed to children under 13. Do not use Google Sign-In for a child-directed experience. If you believe a child has provided personal information, contact privacy@chesstier.com.
We may update this policy when the app or applicable requirements change. The effective date at the top will change when we publish a material revision.