Privacy Policy
Last updated: 16 August 2026 · Effective: 16 August 2026
In short: playing Chessllenge requires no name, email, phone number or any other identifying information; your account is an anonymous guest account. We run no ad networks, use no analytics or tracking SDK, and sell no data. The one exception: on Android we receive a report if the app crashes — section 4.
Contents
1. Who this policy covers
This policy applies to the Chessllenge mobile app for Android and iOS, to this website, and to the servers that run them. The data controller is the app's developer, reachable at muhammedariforhan@gmail.com. See also the contact page.
2. What our server stores
When you first open the app, our server creates an anonymous account for you. This is everything we keep on our own server:
| Data | Why | Personal? |
|---|---|---|
| Random player ID (UUID) | To recognise your account | No — cannot be linked to your real identity |
| Username | Your display name and player search | Only if you choose to make it so — see below |
| Rating, rank, games played | Matchmaking and leaderboard | No |
| Game history (opponent ID, moves, result, date) | Game history, replay, fair-play analysis | No |
| Daily quest, achievement and puzzle progress | Progression system | No |
| Coin balance, cosmetic ownership, selected avatar | Shop and appearance | No |
| Follow and friend relationships | Social features | No |
| Cryptographic digest of your recovery code (SHA-256) | To protect your account and restore it on a new device | No — the code itself is never stored |
| IP address (transient) | Abuse and rate limiting | Held in memory only, briefly |
About your username
Your account starts with an automatically generated username. You may change it at any time. We recommend not using your real name, email address or anything that identifies you — usernames are public and appear in player search. What you type is entirely your choice; we do not verify it and do not link it to a real identity.
3. What we don't collect
- Your real name, email address or phone number (unless you write to us)
- Your location, contacts, photos or microphone — the app never requests these permissions
- Payment details — there are no in-app purchases
The app contains no ad network and shows no advertising to anyone. This website sets no cookies and loads no content from any third-party server.
4. Crash reporting
The app contains no analytics or usage-tracking SDK. Nothing measures which screens you open, how long you play or what you tap.
The one exception is crash reporting: the Android build sends a report to Google's Firebase Crashlytics when the app closes with an unexpected error. The reason is simple — a crash on your phone leaves no trace on our server; without the report we would not even know the bug exists.
This service is not configured in the iOS build; on iPhone and iPad no crash data is sent at all.
What a crash report contains
- The error message and stack trace — which line of code broke
- Device model, OS version, app version
- Technical context at the moment of the crash (such as which screen you were on)
- Your player ID (UUID) — to tell whether a bug hits one user or everyone
- A Firebase installation identifier assigned by Google
The advertising ID is not collected. This data is used only to find and fix the bug; never for advertising, targeting or profiling, and it is shared with no ad network.
If you'd rather not
To object to crash reporting, write to us and we will request deletion of the reports tied to your player ID. On iOS no reports are sent in the first place.
5. Your recovery code
The app gives you a recovery code. It is stored on your device and is the only key to your account. Our server keeps only an irreversible digest (SHA-256 hash) of it — not even we can read the code itself.
- If you lose the code and change devices, we cannot restore your account.
- Anyone you share the code with can access your account. Don't share it.
6. Visible to other players
Your username, avatar, rating, rank and game results are visible on the leaderboard, in player search and in other players' game history. The app has no player-to-player messaging; nobody can send you anything.
7. Sharing and third parties
We do not sell, rent or share your data for marketing. The only parties with any access are:
| Party | Purpose | What they get |
|---|---|---|
| Our hosting provider | Running the server | The server data in section 2 physically resides there |
| Google (Firebase Crashlytics) — Android only | Crash reporting | Only when the app crashes: the technical data in section 4 |
| Google Play / Apple App Store | Distributing the app | Install and crash statistics they collect independently of us |
Crash reports are processed on Google's servers and may be transferred outside Türkiye. We disclose data to no one else except where legally required.
8. Retention
- Account and progression data: kept until you delete your account.
- IP addresses: held briefly for rate limiting only; never written to a permanent record.
- Crash reports: Crashlytics keeps these for up to 90 days, then deletes them automatically.
- Game result records: these remain in your opponents' history even after you delete your account, but your identity is removed and you appear as “Deleted player”. This keeps their game history and rating calculations intact.
9. Deletion and your rights
You can delete your account and data instantly from inside the app: Profile → Danger zone → Delete account. The action is irreversible. Full steps: Account deletion.
Your rights of access, rectification, erasure, objection and portability under the GDPR and the Turkish data protection law (KVKK, Law No. 6698) are reserved. Write to muhammedariforhan@gmail.com and we will complete the request within 30 days. To verify a request we have to ask for your player ID or recovery code — we hold nothing else that identifies you.
10. Legal basis
- Performance of a contract: account, rating, matchmaking, game history — the service cannot work without these.
- Legitimate interest: rate limiting, fair-play enforcement, and finding and fixing the bugs that crash the app.
We do no processing for marketing purposes.
11. Children
The app is not directed at children under 13 and does not knowingly collect data from them. If we learn that we hold a child's data, we delete the account.
12. Security
All traffic between the app and the server is encrypted with TLS. Recovery codes are stored only as hashes. Administrative endpoints are protected by a separate secret and are fully disabled when no secret is set. No system is 100% secure, so keeping your recovery code safe is your responsibility.
13. Changes
If we update this policy we will change the “Last updated” date above and announce significant changes inside the app.
14. Contact
For any privacy question, and for GDPR/KVKK requests: muhammedariforhan@gmail.com (contact page)
