Arcanum Chess · play free
Arcanum Chess — Privacy Policy
Effective date: in legal review
Last updated: in legal review
This Privacy Policy explains how we collect, use, share and protect your personal data when you use Arcanum Chess at arcanumchess.com and our related Progressive Web App (together, the "Service"). It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Please read it together with our Terms of Service and Cookie information.
1. Who we are and how to contact us
Arcanum Chess is operated by , a company registered in England and Wales under company number , with its registered office at (referred to in this policy as "we", "us" or "our"**).
For the purposes of UK data protection law, we are the data controller of the personal data described in this policy.
- Privacy / data protection contact: **
- Postal address: **
We are registered with the UK Information Commissioner's Office (ICO) under registration reference **.
If you have any questions about this policy or how we handle your data, please contact us using the details above.
2. What personal data we collect
We only collect data that we actually need to run the Service. The table below ties each category to the part of our technology stack that handles it.
2.1 Account and identity data
- Email address and password (passwords are never stored by us in plain text — authentication is handled by our managed auth provider, Supabase Auth, which stores a salted hash, not the password itself).
- Username (3–16 characters; stored lowercase and shown publicly on leaderboards, in the lobby, in chat and on your profile).
- Account identifier (a system-generated user ID).
- We do not offer anonymous or guest accounts for online play; an email and password are required to register.
2.2 Gameplay, ratings and competition data
- Game history: moves, results (win/loss/draw), opponents, time controls and related game metadata, stored in our database (Supabase Postgres).
- Rating data: your Elo/rating and win/loss/draw counts, which feed public leaderboards and league standings.
- Puzzle data: puzzle points, daily-solve streaks, best streaks, total solved, and Puzzle Rush / Gauntlet run scores.
- Achievements: unlocked achievement keys and unlock timestamps.
- Tournament data: tournament registrations, entrant records, qualifier and knockout standings (currently free "Founders" events; see section 9 regarding planned paid prize tournaments).
2.3 Chat and presence data
- Lobby chat messages (broadcast to other players present in the live lobby).
- In-game chat messages for ranked games and spectators (these are transmitted in real time and are ephemeral — they are broadcast over a realtime channel rather than stored on the authoritative game record; however, messages may be visible to other participants and may be captured in reports).
- Casual friend-game chat sent peer-to-peer over WebRTC (see section 2.7).
- Presence / online status (e.g. "idle" or "playing"), broadcast to other players so they can see who is online and challenge or spectate you.
2.4 Fair-play / moderation data
- Fair-play reports you submit about other players (the reported player, the related game, a reason such as "engine"/"sandbagging"/"stalling"/"chat"/"other", and an optional free-text note up to 500 characters).
- Reports filed by other players that name you, together with associated game data, used for cheat detection and moderation.
2.5 Payment data (via Stripe)
- If you buy a cosmetic item or subscribe to "Arcanum Plus", payment is processed by Stripe. Stripe collects and holds your card and billing details; we never receive or store your full card number.
- We store, in our own database, entitlement records (which items/SKUs you own) and your subscription status / expiry (e.g. "plus until" date). These are written by Stripe's webhook to our backend and are read-only from your device.
2.6 Anti-bot / captcha data (Cloudflare Turnstile)
- At sign-up and certain auth steps, we may use Cloudflare Turnstile to check that you are a human and not an automated bot. When enabled, Turnstile issues a short-lived, single-use token that is verified during authentication. Cloudflare may process limited technical signals from your browser to make this assessment. (Note: this captcha can be toggled on or off in our configuration; when it is off, no Turnstile token is collected.)
2.7 Technical, device and connection data
- Server logs from our hosting provider (Vercel) may include your IP address, user-agent / device and browser information, request paths and timestamps.
- Peer-to-peer connection data: when you play a casual friend game over WebRTC (PeerJS), a direct connection is established between you and your opponent. This means your IP address may be exposed to the other player (and to the signalling/relay infrastructure that brokers the connection), which is inherent to how real-time peer-to-peer connections work.
- Push subscription data (if and when you enable push notifications): the push endpoint, the browser-generated keys (
p256dh,auth) needed to deliver a notification, and a truncated user-agent string. (Push notifications are currently dormant and inactive — see section 4.)
2.8 Cookies, local storage and on-device data
- We use browser localStorage to keep you signed in (your authentication session), to remember your preferences and settings, and to hold short-lived hints (e.g. a pending username during sign-up).
- Our Progressive Web App service worker stores a cache of app files on your device so the app can load quickly and work offline.
- See section 4 for the cookies/PECR detail.
We do not knowingly collect special-category data (such as health, biometric or racial/ethnic data) today. The planned proctoring feature described in section 9 would involve special-category-adjacent data and is not yet active.
3. How and why we use your data, and our lawful basis
Under the UK GDPR we must have a lawful basis for each use of your personal data. Our uses and bases are:
| # | What we do (purpose) | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|---|
| a | Create and manage your account; authenticate you and keep you signed in | Email, password (hashed), username, user ID, session in localStorage | Contract (Art. 6(1)(b)) — necessary to provide the Service you sign up for |
| b | Run online play: matchmaking, the live lobby, presence, challenges and games | Username, rating, presence/status, game data, IDs | Contract (Art. 6(1)(b)) |
| c | Maintain ratings, leaderboards, puzzle stats, achievements, league standings and tournaments | Rating, win/loss/draw, puzzle/achievement/tournament data, username | Contract (Art. 6(1)(b)); and Legitimate interests (Art. 6(1)(f)) in providing competitive, public leaderboard features |
| d | Enable lobby chat, in-game chat and spectating | Chat messages, username, presence | Contract (Art. 6(1)(b)) |
| e | Detect and act on cheating, abuse and breaches of our rules; handle fair-play reports | Fair-play reports, game data, account and technical data | Legitimate interests (Art. 6(1)(f)) — protecting the integrity of competition and the safety of our community |
| f | Process payments for cosmetics and Arcanum Plus, and grant entitlements/subscriptions | Stripe payment data, entitlement and subscription records | Contract (Art. 6(1)(b)); and Legal obligation (Art. 6(1)(c)) for tax/accounting record-keeping |
| g | Protect the Service against bots, fraud and abuse at sign-up (captcha) | Turnstile token and related browser signals | Legitimate interests (Art. 6(1)(f)) — securing the Service against automated abuse |
| h | Keep the Service secure, reliable and debuggable; maintain server logs | IP address, user-agent, log data | Legitimate interests (Art. 6(1)(f)) — security, fraud prevention and operating a reliable service |
| i | Send essential service emails (e.g. email confirmation, password reset) | Email address | Contract (Art. 6(1)(b)) |
| j | Send push notifications (e.g. "your move", "you've been challenged") if you opt in | Push subscription data | Consent (Art. 6(1)(a)) — via your browser notification permission; you can withdraw at any time |
| k | Comply with legal obligations and respond to lawful requests | Relevant account/transaction data | Legal obligation (Art. 6(1)(c)) |
| l | Notify you of material changes, or send optional marketing (only if you have opted in) | Email address | Consent (Art. 6(1)(a)) for marketing; Legitimate interests for service-change notices |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You have the right to object to this processing (see section 7).
4. Cookies and local storage (PECR)
We aim to use as little client-side storage as possible, and we currently do not use third-party advertising or tracking cookies.
Strictly necessary / essential storage (no consent required under PECR because it is essential to provide a service you have requested):
- Authentication session held in localStorage (under the key
arcanum-authand related keys) to keep you signed in across visits. - Preferences and settings stored in localStorage so the app remembers your choices.
- Short-lived sign-up hints (e.g. a pending username) in localStorage.
- Service-worker cache that stores app files for offline/PWA functionality.
Third-party functional storage:
- Cloudflare Turnstile, when enabled, may set storage/cookies needed to run the anti-bot challenge. This is functional/security-related rather than advertising.
Non-essential storage:
- We do not currently set non-essential marketing or analytics cookies. If we introduce any in future, we will request your consent first through a cookie banner or settings control, and update this policy.
You can clear localStorage and the service-worker cache, and block or delete cookies, through your browser settings. Doing so may sign you out and reset your preferences, and may affect offline functionality.
5. Who we share your data with (processors and third parties), and international transfers
We do not sell your personal data. We share it only with the service providers ("processors") and recipients needed to run the Service:
| Provider | Role | Data involved | Notes / location |
|---|---|---|---|
| Supabase | Database, authentication and realtime backend (our core processor) | Account, gameplay, chat, fair-play, puzzle/tournament, entitlement and push-subscription data | Hosting region/location to be confirmed and documented in our processor records; international transfers safeguarded as below |
| Vercel | Application hosting and content delivery | Technical/log data including IP address and user-agent | May process data in the US and other regions |
| Stripe | Payment processing for cosmetics and Arcanum Plus | Card/billing details (held by Stripe), transaction data | Global payment processor; PCI-DSS compliant |
| Cloudflare | Anti-bot/captcha (Turnstile) when enabled | Browser signals and challenge token | Global edge network |
| PeerJS / WebRTC signalling and relay infrastructure | Brokering peer-to-peer casual friend games | Connection data, including IP addresses exchanged between peers | Inherent to peer-to-peer play; see section 2.7 |
| Other players | Multiplayer interaction | Public profile (username, rating), chat you send, presence, and — in peer-to-peer casual games — your IP address | Only data you make visible through play |
| Push delivery services (when push goes live) | Delivering web-push notifications | Push endpoint and keys | Provided by your browser/OS push service (e.g. Google/Apple/Mozilla) |
We may also disclose data to professional advisers, auditors, or to law enforcement and regulators where required by law, and to a buyer or successor in the event of a business sale or reorganisation.
International transfers. Some of these providers process data outside the UK. Where personal data is transferred outside the UK, we rely on appropriate safeguards under UK GDPR — such as the UK's "adequacy" recognition for certain countries, the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required. You can ask us for more detail using the contact details in section 1.
6. How long we keep your data (retention)
We keep personal data only for as long as we need it for the purposes set out in this policy:
- Account data (email, username, profile): for the life of your account. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain certain records (see below).
- Gameplay, ratings, puzzle, achievement and tournament data: kept while your account is active to provide competitive features. After account deletion, we may retain results in an anonymised / de-identified form (e.g. detached from your identity) for leaderboard and statistical integrity.
- Chat messages: in-game and lobby chat are ephemeral/transient by design; copies captured in fair-play reports are retained as part of the moderation record.
- Fair-play / moderation records: retained for as long as needed to protect competitive integrity and for a reasonable period afterwards to detect repeat behaviour.
- Payment and transaction records: retained for the period required by UK tax and accounting law (generally 6 years).
- Server logs (IP, user-agent): retained for a short period for security and debugging, then deleted or aggregated.
- Push subscription data: retained until you disable notifications or the subscription expires.
We will finalise specific retention periods in a retention schedule reviewed by our solicitor.
7. Your rights
Under the UK GDPR you have the following rights, which you can exercise free of charge by contacting us at **:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten") — have your data deleted in certain circumstances.
- Restriction — ask us to limit how we use your data in certain circumstances.
- Data portability — receive certain data in a structured, commonly used, machine-readable format, or have it transferred to another controller, where technically feasible.
- Object — object to processing based on our legitimate interests, and to any direct marketing (which we will always stop on request).
- Withdraw consent — where we rely on consent (e.g. push notifications or any optional marketing), you can withdraw it at any time, without affecting processing already carried out.
- Rights relating to automated decision-making — we do not currently make decisions producing legal or similarly significant effects about you by solely automated means. If automated fair-play or proctoring decisions are introduced (see section 9), we will provide appropriate safeguards, including the ability to seek human review.
We will respond within one month (extendable where permitted). We may need to verify your identity before acting on a request.
Complaints. You have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk, by calling 0303 123 1113, or by writing to: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would, however, appreciate the chance to address your concerns first.
8. Children and age requirements
The Service is a general-audience chess game, but it is not directed at young children, and online accounts require a valid email address.
- You must be at least ** years old to create an account.
- Any feature that involves money — including paid prize tournaments and paid entry, when introduced — is strictly limited to users aged 18 or over.
If you believe a child has provided us with personal data without appropriate consent, please contact us and we will take steps to delete it.
9. Anti-cheat and proctoring data (planned — when introduced)
We are planning future features that are not yet live:
- Paid prize tournaments with real-money entry and prizes; and
- Enhanced anti-cheat for money finals, which may use webcam and/or screen recording (remote proctoring) during high-stakes, money-prize matches to verify fair play.
Webcam and screen-proctoring data can include images of your face and surroundings and may be considered special-category data (or special-category-adjacent, e.g. biometric-adjacent). When and if these features go live, we will:
- Process proctoring data only on the basis of your explicit, freely-given consent (UK GDPR Art. 9 condition), obtained separately before any recording begins, and only for players who choose to enter money finals;
- Complete and act on a Data Protection Impact Assessment (DPIA) before launch;
- Apply strict purpose limitation (cheat-detection for the relevant event only), data minimisation, tight, short retention, and robust security;
- Provide a meaningful route to human review of any decision that affects you, and a way to withdraw consent (recognising that withdrawal may mean you cannot take part in money finals); and
- Update this Privacy Policy with full detail (what is recorded, who can access it, how long it is kept, and the legal bases) before the feature is enabled.
Until that detailed update is published, no webcam or screen-recording proctoring data is collected.
These money/prize features are also intended to operate as skill-based prize competitions. We will structure and review them with our legal advisers in light of the Gambling Act 2005 and related UK guidance before launch, and they will be restricted to users aged 18+.
10. How we protect your data (security)
We take appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (HTTPS/TLS) across the Service.
- Managed authentication via Supabase Auth, with passwords stored only as salted hashes; we never see or store full card numbers (handled by Stripe).
- Server-authoritative design for sensitive values: ratings, entitlements and subscription status are write-locked against client devices and can only be changed by trusted server-side processes (e.g. validated game results and Stripe webhooks).
- Row-level access controls in our database so users can only access data they are permitted to.
- Input validation and sanitisation of untrusted, peer-supplied data (chat, presence, challenges) to reduce abuse and injection risks.
- Rate-limiting and anti-abuse controls (including optional captcha) on sensitive actions such as sign-up and reporting.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO (and, where required, you) in line with our legal obligations.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our processors, or the law. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you (for example by email or an in-app notice). The version in force is the one published at arcanumchess.com as of its stated effective date.
Effective date: in legal review