Privacy & security

What we store, and why

DataStorage

Username

Your name on the site

Plain text

Password

Signing in, if you chose a password

Hashed

Recovery email (optional)

Recovering your password. We can't read it back: emails go out only when you type it again

Hashed

Email, name and photo

Google sign-in keeps only Google's number for your account, never your address, name or picture

Not stored

Lichess and Chess.com usernames

Importing your games, only if you give them

Plain text

Lichess link in Openings (optional)

Reading what players at your rating play. The token stays in your browser and never reaches us

Not stored

Puzzles and activity

Training, schedules and progress. Only you see them, unless you share your profile

Plain text

Language

Showing the site in your language on every device

Plain text

Your password can't be read, not even by us

We store only a one-way hash of it, so no one, including us, can get your password back. Even with the whole database, an attacker would only see scrambled data.

Hashing uses bcrypt (10 rounds), with a unique salt for each password and a server-side pepper.

We ask for no real names or personal information, and we never sell or share your data.

Cookies

Only the ones the site needs: one that keeps you signed in, a few short-lived ones while you sign in or connect an account, one for your language and one for light or dark. No analytics and no advertising.

A few good habits

  • Never share your password with anyone
  • Use a different password for every site
  • Consider a password manager to create and keep strong passwords