Arcanum Chess · play free
Arcanum Chess — Fair-Play & Anti-Cheat Policy
Operator: in legal review ("we", "us", "our"), a company registered in England and Wales (company number in legal review), registered office in legal review.
Service: Arcanum Chess (arcanumchess.com) and its progressive web app (the "Service").
Contact: in legal review · Data protection / ICO registration: in legal review.
Version: in legal review · Last updated: in legal review
This Policy forms part of, and should be read together with, our Terms of Service and Privacy Policy. Where this Policy describes features that are planned but not yet live (paid prize tournaments, identity verification, and webcam/screen proctoring for money finals), those provisions take effect only when and where the relevant feature is introduced, and are marked "[where applicable / when introduced]". Until then, only the free-play and reporting measures in Tier 0 are in force.
1. Our commitment to fair play
Chess is a game of skill. The entire value of a rating, a leaderboard position, a tournament result, or a prize depends on every result having been earned by a human playing their own moves, unaided. We are committed to protecting that integrity for everyone who plays on Arcanum Chess.
We make the following promises:
- We will be proportionate. The strength of our checks scales with the stakes. Free and ranked play is monitored with statistical tools used as a tripwire only; paid play adds identity checks; money finals add recorded proctoring. We do not subject casual players to intrusive monitoring.
- We will be evidence-led. We do not void results, strip ratings, or withhold prizes on the basis of a statistical anomaly in a short sample alone. Statistics flag; identity and proctoring evidence decide (see Section 4).
- We will give you a fair process. Save for the most clear-cut automated abuse, you will receive notice of a concern, an opportunity to respond, and a route of appeal before a serious or permanent sanction takes effect (see Section 5).
- We will be transparent about your data. Everything we collect to detect cheating is described in this Policy and in our Privacy Policy, with the lawful basis for processing it (see Section 7).
- We will not publicly shame players on weak evidence. We do not name suspected cheats publicly (see Section 8).
This Policy is both our public commitment to the community and the contractual basis on which we investigate and enforce fair play. By using the Service you agree to it.
2. What counts as cheating
For the purposes of this Policy, "cheating" means any conduct intended to gain, or which has the effect of gaining, an unfair advantage, or which corrupts the integrity of ratings, leaderboards, tournaments, the reporting system, or any prize. It includes, without limitation:
2.1 Outside engine or assistance. Using, consulting, or receiving help from any chess engine, computer evaluation, opening/endgame tablebase, bot, automation, "assist" tool, or any other software, hardware, or service that suggests, evaluates, or selects moves during a game where such help is not part of the game. It also includes a human consulting another person (a "coach") about moves during a rated or competitive game.
2.2 Multi-accounting and smurfing. Operating more than one account to manipulate ratings or matchmaking; creating a new account to play below your true strength ("smurfing"); evading a suspension, ban, or rating with an alternate account.
2.3 Sandbagging. Deliberately losing, drawing, or under-performing — including intentional resignation, timeout, or weak play — to lower your rating, manipulate matchmaking, mislead an opponent or the seeding of a tournament, or qualify for a lower bracket.
2.4 Collusion and result-fixing. Pre-arranging a result with an opponent; "feeding" rating, points, prizes, or tournament progression to another account; coordinating with others to manipulate standings, leaderboards, or payouts.
2.5 Account sharing. Allowing another person to play any rated or competitive game on your account, or playing on an account that is not your own. [Where applicable / when introduced:] for any account eligible to receive a money payout, one verified human = one payout account (see Section 3, Tier 1).
2.6 Abuse of the rating or reporting systems. Exploiting bugs in rating calculation or matchmaking; filing knowingly false, malicious, or mass fair-play reports to harass another player or game the moderation queue; coordinating reports to trigger action against an innocent player.
2.7 Other integrity abuse. Manipulating connection, clock, or disconnection mechanics to gain an advantage; interfering with the Service's anti-cheat or telemetry; misusing chat/presence to coerce, intimidate, or arrange any of the above.
This list is illustrative, not exhaustive. Conduct that defeats the spirit of fair competition may be treated as cheating even if not specifically listed.
3. How we detect it — a tiered model scaled to the stakes
Our detection effort is proportionate to what is at risk. The higher the stakes, the stronger the verification.
Tier 0 — Free and ranked play (no money) — live now
Applies to: all casual and ranked games on the Service.
- Statistical engine-detection (FLAG ONLY). For ranked games we maintain a per-move record of timing and moves played. Server-side analysis compares a player's games against their own rating baseline using signals such as:
- average centipawn loss (how far moves deviate from optimal),
- engine move-match (how often moves coincide with an engine's top choice(s)),
- move-time analysis (suspiciously uniform thinking times, or hard moves played as fast as easy ones).
These signals are evaluated relative to the player's own established strength and history, not an absolute threshold. A flag is only a flag — it routes a case for human review or further verification. No Tier 0 flag, on its own, automatically voids a game or bans an account (see Section 4).
- Ranked-eligibility gating (live). To play ranked you must meet a server-computed eligibility test — currently a confirmed email address and a minimum account age/tenure — which raises the cost of throwaway and engine accounts. Eligibility is enforced server-side.
- Player reporting (live). Any player can file an in-game fair-play report against an opponent, choosing a reason (engine assistance, sandbagging, stalling, chat abuse, or other) with an optional note. Reports are stored in a moderation queue, server-side rate-limited and de-duplicated to resist abuse, and reviewed by us. Reports are a signal that contributes to a case; they are not themselves a verdict.
- Server-authoritative state. Ratings and game results are calculated and stored server-side and are not writable by the client; presence, chat, and challenge traffic from other players is treated as untrusted and validated/sanitised on receipt. This removes whole classes of client-side tampering.
Tier 1 — Paid play (entry-fee or prize-eligible games and tournaments) — **
Applies to: any game, tournament, or competition that charges an entry fee or can pay out money/prizes. Restricted to eligible users (e.g. 18+ where money is involved; see Terms).
In addition to all Tier 0 measures:
- Identity verification — one verified human per payout account. Before a payout can be made, the account holder must verify their identity so that we can ensure a single real person is not operating multiple prize-eligible accounts. Verification is handled to the minimum extent necessary and is described, with its lawful basis and retention, in our Privacy Policy.
- Device and network (IP) fingerprinting. We use device and network signals to detect multiple prize-eligible accounts operated from one person/device, ban evasion, and collusion rings. (Note: the hosting layer already logs IP addresses and user-agents for security; Tier 1 uses such signals specifically for integrity.)
- Account-tenure and eligibility gating. Stricter tenure, verification, and standing requirements than Tier 0 before an account may enter paid play or receive a payout.
Tier 2 — Money finals — **
Applies to: the latter stages / finals of competitions where a meaningful cash prize is decided.
In addition to all Tier 0 and Tier 1 measures:
- Mandatory webcam and screen proctoring, recorded and reviewed before any payout is released, to confirm the player is unaided.
- This is conditioned on explicit, informed, freely given consent obtained before the relevant final, given the heightened sensitivity of webcam/screen-recording data (which may be special-category or biometric-adjacent). Consent is a precondition of entering a proctored final; a player who does not consent does not enter that final but is not otherwise penalised.
- A prize-holding window during which results are provisional, the recordings are reviewed, and any flags or reports are resolved before prizes are paid.
- Proctoring is governed by a Data Protection Impact Assessment (DPIA) completed before the feature goes live, and by the Privacy Policy. See Section 7.
4. Why we never auto-void on statistics alone (for a short sample)
Statistical engine-detection is powerful but probabilistic. Over a small number of games, a strong human can legitimately produce a low centipawn loss or a high engine-match — and a cheat can deliberately add noise to look human. Treating a short-sample statistical anomaly as proof would punish innocent strong players and would not, by itself, be a fair or evidentially sound basis for stripping ratings, voiding results, or withholding money.
Accordingly:
- In Tier 0, statistics are a tripwire. A flag routes a case for human review and may, over a sustained pattern across an adequate sample, support action — but a single flagged game does not auto-void or auto-ban.
- In Tiers 1 and 2, the evidentiary gate is identity verification and (for money finals) recorded proctoring, corroborated by — not replaced by — statistical and reporting signals. Money is not paid out, withheld, or clawed back on statistics alone; the identity/proctoring evidence is the deciding record.
The only exceptions to human-in-the-loop are unambiguous, mechanically-verifiable abuses (for example, a confirmed automation/bot signature, or technical ban-evasion), which may be actioned automatically and are subject to the same right of appeal in Section 5.
5. Investigations and due process
5.1 Opening a case. A case may be opened by a statistical flag, one or more player reports, an identity/device signal, proctoring review, or our own observation.
5.2 Review. Cases are reviewed by a human, save for the unambiguous automated abuses described in Section 4. We consider the full picture — sample size, the player's history and rating baseline, corroborating evidence, and any pattern across accounts — rather than a single number.
5.3 Notice and the right to respond. Except where (a) the abuse is clear-cut and automatically verifiable, (b) prior notice would let the player destroy evidence or continue causing harm, or (c) we are required to act immediately to protect other players or a prize pool, we will give the player notice of the concern and a reasonable opportunity to respond before a serious or permanent sanction takes effect. We may apply a provisional measure (e.g. pausing payouts or ranked access, or holding a result during the prize-holding window) while we investigate.
5.4 Appeal. A player subject to a sanction may appeal in writing to in legal review within in legal review days. Appeals are considered by someone not solely responsible for the original decision where reasonably practicable. We will tell you the outcome and, so far as we can without compromising our detection methods or other players' privacy, the basis for it.
5.5 Records. We keep a record of investigations and decisions for audit, consistency, and to defend against, or pursue, claims, in line with the retention periods in our Privacy Policy.
Nothing in this Policy affects your statutory rights, including (where the Consumer Rights Act 2015 and related consumer law apply to any paid product or subscription) your rights in respect of paid services, or your data-protection rights under UK GDPR and the Data Protection Act 2018.
6. Consequences
Where we conclude, on the appropriate standard for the stakes involved, that this Policy has been breached, we may apply one or more of the following, proportionate to the seriousness, history, and stakes:
- Warning and/or required acknowledgement of this Policy;
- Rating correction or reset, and removal of affected accounts from leaderboards;
- Voiding of affected game results and reversal of associated rating changes;
- Removal from, or disqualification within, a tournament;
- Temporary suspension of some or all features (e.g. ranked or paid play);
- Permanent ban of the account, and refusal of future accounts, for serious or repeated breaches or ban evasion;
- [Where applicable / when introduced] Prize forfeiture, withholding, or clawback, including reversal or recovery of any payout obtained in breach of this Policy, and forfeiture of entry fees as permitted by the relevant competition terms and applicable law.
Where money is involved we operate within the legal framework applicable to skill-based prize competitions (including the Gambling Act 2005 context), and competition-specific terms will govern entry, eligibility, payout, forfeiture, and clawback. Refunds of any paid product or subscription are handled under our Terms and applicable consumer law.
We may also report conduct to law-enforcement or other authorities where we believe an offence (for example, fraud) may have been committed.
7. Data and privacy of anti-cheat data
Anti-cheat is a form of processing of personal data and is governed by the UK GDPR, the Data Protection Act 2018, and our Privacy Policy.
7.1 What we process for fair play. Depending on tier: account identifiers and username; email-confirmation and account-age status (eligibility); game records including moves, results, and per-move timing; statistical detection scores; fair-play reports and notes; chat and presence signals; server logs including IP address and user-agent (held at the hosting layer); identity-verification data, device/network fingerprints, and — for money finals — recorded webcam and screen-proctoring footage**.
7.2 Lawful basis.
- Tier 0 statistical detection, reporting, eligibility gating, and security logging rely on our legitimate interests (and, for paid services, performance of a contract) in protecting the integrity of the Service and our users — balanced against your rights, which is why these measures are flag-only and proportionate.
- identity verification and device/IP integrity checks for paid play rely on contract and legitimate interests, and where required legal obligation** (e.g. anti-fraud).
- webcam/screen proctoring for money finals, to the extent it involves special-category or biometric-adjacent data, relies on your explicit consent**, obtained before the relevant final; you may decline (and simply not enter that proctored final).
7.3 DPIA for proctoring. Because webcam/screen proctoring is high-risk processing, we will complete a Data Protection Impact Assessment before it goes live, covering necessity, proportionality, retention, access controls, security, and your rights. Proctoring will not be enabled until that DPIA is in place.
7.4 Retention, access, and your rights. Anti-cheat data is retained only as long as necessary for the purposes above and the periods set out in our Privacy Policy; proctoring recordings are kept only for the prize-holding/review window and any dispute/appeal period, then deleted. Access is restricted to those who need it for review. You retain your UK GDPR rights (access, rectification, erasure, objection, restriction, and complaint to the ICO), subject to our need to retain certain records to investigate abuse, defend or bring claims, and ensure fairness across accounts.
Third-party processors involved in these flows (including our authentication/database provider, payments provider, bot/captcha provider, hosting provider, and — when introduced — any identity-verification and proctoring providers) are listed in our Privacy Policy.
8. No public shaming on weak evidence
We will not publicly name, label, or accuse a player of cheating on the basis of weak, statistical-only, or unconfirmed evidence. Specifically:
- We do not publish "cheater" lists, call-outs, or accusations identifying individuals.
- Where we sanction an account, we communicate the decision and its basis privately to the affected player, not to the community.
- We may publish aggregate, anonymised integrity information (e.g. how many accounts were actioned in a period) that does not identify individuals.
- We will take reasonable steps to discourage and moderate public accusations between players made through our chat or community features, which can be defamatory and unfair.
This protects players from reputational harm based on probabilistic signals and reflects our awareness of the law of defamation. It does not prevent us from acting privately and firmly on the evidence, nor from disclosing information where required by law or to the affected player as part of due process.