Privacy Policy

LAST UPDATED: August 23, 2026

This Privacy Policy explains what information Depthly ("we," "us," or "our") collects from you when you use our chess training platform, how we use it, and your rights regarding that data. By using this platform, you agree to the practices described below.

SECTION 1: What We Collect

1.1 Account Information

Authentication is provided by Clerk. Depthly receives your verified primary email and Clerk user identifier, and uses them to link your Clerk account to your Depthly profile. Depthly stores your display name, linked chess usernames, avatar reference, puzzle rating data, and account timestamps in Supabase. Depthly does not store your raw password.

1.2 Chess Data

We store the games you import, including PGN content and selected game metadata, analysis results generated by the Stockfish engine, puzzle attempt history, accuracy scores, and performance statistics. Imported PGNs can contain player names, usernames, event names, locations, dates, and annotations supplied in the source file. This data powers your private training and review experience.

1.3 Linked Third-Party Accounts

If you provide a Chess.com or Lichess username, Depthly sends that username to the corresponding public API to validate the account or retrieve public game data. Depthly stores the linked username and any imported games you choose to save. Depthly does not receive or store credentials for those platforms.

1.4 Usage Data

Depthly uses consent-controlled product analytics through PostHog Cloud US to understand aggregate use of puzzles, imports, analysis, and core application flows. Analytics is disabled until you allow it, and you can withdraw that choice at any time from Settings. We do not use analytics for advertising or sell analytics data. The application also uses short-lived rate-limit records containing an endpoint, a user or address key, a counter, and an expiry time. Hosting and infrastructure providers may process ordinary request metadata in order to deliver and operate the service; their retention practices require separate provider review.

1.5 Shared public chess data

Depthly caches public Lichess puzzle and opening data, such as positions, moves, ratings, themes, game identifiers, and player names, so the service can respond efficiently. This shared cache is not part of an individual account and is not removed when one account is deleted. Third-party terms and attribution requirements are reviewed separately.

1.6 Cookies and Local Storage

Clerk manages authentication session cookies. Depthly stores a theme preference, a consent preference, and limited puzzle-history and interface preferences in browser storage, and caches public opening data in IndexedDB. These values do not contain passwords, authentication tokens, imported PGNs, or game-analysis results. When product analytics is enabled, PostHog may store an analytics identifier and consent-related state according to its service documentation. Depthly does not use analytics for advertising and does not enable session recording, heatmaps, surveys, or browser console-log capture in the initial analytics configuration.

SECTION 2: How We Use Your Data

We use your data to:

  • Authenticate your account and maintain your session
  • Run game analysis and store your results
  • Track puzzle and training performance over time
  • Retrieve public chess data from Chess.com or Lichess when you provide a username
  • Maintain short-lived operational rate limits and service reliability
  • Provide account export and account deletion controls

We do not use your data to:

  • Sell it to any third party
  • Serve you behavioral advertising
  • Build advertising profiles
  • Train third-party AI models without your explicit consent

SECTION 3: Data Sharing

We share your data only in these narrow circumstances:

3.1 Service Providers

We use Clerk for authentication, Supabase for application data, database, and private avatar storage, PostHog Cloud US for consent-controlled product analytics, and hosting/CDN providers to deliver the service. When you use chess import or puzzle features, Depthly requests public data from Chess.com or Lichess. Product analytics receives only bounded event names and approved aggregate properties. Depthly does not send imported PGNs, FENs, move lists, profile details, authentication tokens, or free-form form values to PostHog. The application does not use advertising pixels or behavioral advertising.

3.2 Public chess services

The current application does not send imported PGNs or saved game analysis to an AI or LLM provider.

3.3 Legal Requirements

We may disclose data if required by law, court order, or to protect against fraud or security threats. We will notify you where legally permitted.

3.4 Business Transfer

If the platform is acquired or merged, user data may transfer to the new owner. You will be notified in advance.

SECTION 4: Data Retention

Account-owned profile, game, review, puzzle-history, identity-mapping, and avatar data is retained while your account is active. When you use the account-deletion control, Depthly removes account-owned application rows and avatar objects during the deletion process, then removes the linked authentication accounts where available. Shared public chess caches and provider-managed operational logs are not account-owned and follow their own lifecycle. Any longer retention requirement must be confirmed with the relevant provider or policy reviewer.

SECTION 5: Your Rights

The account controls provide the following self-serve controls:

  • Export: Download a machine-readable JSON copy of your supported profile, game, review, and puzzle-history data.
  • Correction: Edit your display name, linked usernames, and avatar from Settings.
  • Deletion: Permanently delete your account and account-owned data from Settings.

Additional rights may apply depending on where you live. Questions about the scope of a request can be sent to the contact below.

For a privacy question or request that is not covered by the account controls, email us at: privacy@depthly.app.

SECTION 6: Security

Authentication is handled by Clerk, application data is stored in Supabase, and private avatar objects are served through an authenticated server route. Depthly uses HTTPS and security headers, bounds upstream responses, and avoids logging account payloads in the inspected application paths. No system is perfectly secure.

SECTION 7: Children's Privacy

This platform is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has registered, contact us and we will delete the account promptly.

SECTION 8: Third-Party Links

The platform may link to Chess.com, Lichess, or other external sites. We are not responsible for their privacy practices. Review their policies separately.

SECTION 9: Changes to This Policy

We may update this policy as the platform evolves. The "Last Updated" date at the top reflects the most recent revision. Material changes will be handled through the notice process selected by the policy owner.

SECTION 10: Contact

For any privacy questions or requests:
Email: privacy@depthly.app