Privacy Policy

Last updated: 4 October 2026

1. Who we are

EloCoach.ai is operated by Benjamin Marsili, established in the Netherlands. References to “we”, “us”, or “EloCoach” in this policy refer to that entity.

We are the controller of your personal data within the meaning of the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679). Our supervisory authority is the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority.

Contact: [email protected]

2. Data we collect and why

Account data. Your Chess.com or Lichess username, fetched at your request, plus the email address and account identifier Google or Lichess shares with us when you sign in through them. Legal basis: contract (Art. 6(1)(b) GDPR) — we cannot provide the service without it.

Game data. PGN game records retrieved from the Chess.com or Lichess public APIs on your behalf. We store only recent games needed for coaching. Legal basis: contract.

Conversation history.Your messages and the coach's responses within a session, stored so the coach can maintain context across turns. Legal basis: contract.

Coaching memory (facts). Structured insights extracted from your sessions — opening tendencies, recurring weaknesses, stated goals — stored to make future sessions meaningful. Legal basis: contract; legitimate interest in delivering a coherent long-term coaching experience.

Website analytics. Aggregated, pseudonymous usage data via PostHog and Google Analytics on elocoach.ai. Legal basis: consent (you control this via the cookie banner). You may withdraw consent at any time.

App analytics and diagnostics. In the mobile app, PostHog records pseudonymous usage data — the screens and features you use, crash and error reports, and session recordings of the app screen, with every text field and image masked so their contents are never captured. We use this to find bugs and understand which parts of EloCoach actually help players. Legal basis: legitimate interest in operating and improving a product in early development. You can object at any time by emailing [email protected].

Device and log data. IP address, device type, OS version, and error logs, retained for up to 30 days for security and debugging. Legal basis: legitimate interest.

3. How we use AI to process your data

Your game data and conversation history are sent through OpenRouter, our AI inference routing layer, which forwards each request to a foundation-model provider selected from EloCoach's own model configuration. We use a range of underlying AI models, and which provider or model handles a given request can change over time — including per coach persona — as we tune and test the product; we don't name specific models here since that configuration changes frequently. We do not restrict routing to Zero Data Retention-only endpoints. Depending on the provider handling a given request, your data may be retained for a period set by that provider's own terms, and may be used by that provider to train or improve its models. Where a provider processes your data for its own purposes in this way, it is acting independently for that portion of processing rather than solely as our processor. Legal basis: your acceptance of this policy when you create your account.

We do not make solely automated decisions that produce legal or similarly significant effects about you.

4. Third-party services

We share data with the following third parties. Most act solely as our processor; where one also processes your data for its own purposes (see OpenRouter below), that is noted. Services marked planned are not yet active; we list them in advance so you are informed before processing begins.

  • OpenRouter— AI inference routing; your game data and conversation history are forwarded to a foundation-model provider selected from EloCoach's model configuration, which may change over time — including per coach persona — as we route requests to different underlying providers. We do not restrict routing to Zero Data Retention-only endpoints: depending on the provider, your data may be retained per that provider's own terms and may be used by that provider to train or improve its models. A minimal account identifier may be retained after account deletion solely to prevent abuse — see Section 6.
  • Google Analytics (GA4) — pseudonymous usage analytics. Activated only with your consent. IP anonymisation enabled. EU SCCs in place.
  • Google Sign-In— identity verification when you sign in with Google. Google's native Sign-In SDK issues a signed identity token that we verify to confirm your email address and account identifier. Google does not receive your chess data or coaching conversations through this integration.
  • Lichess Sign-In — identity verification when you sign in with Lichess. Works the same way as Google Sign-In above: we verify your identity with Lichess to confirm your account. Chess.com is never used for sign-in.
  • Chess.com & Lichess (game data)— beyond sign-in, we rely on data that's publicly available on these platforms, such as your games and public profile, and may process it to power your coaching.
  • Hugging Face — hosting for the peer-analysis model your device downloads during setup. Your device requests the file directly, so Hugging Face sees your IP address and the fact that a download occurred. No account details, chess data or coaching conversations are shared with them, and the model runs entirely on your device once downloaded.
  • Stockfish (stockfishchess.org)— hosting for the chess engine's neural network, which your device downloads during setup on the same basis as above: your IP address is visible to them for the duration of the download, and nothing else is shared. The engine then runs entirely on your device; no position or game is ever sent to them for analysis.
  • Neon / PostgreSQL — primary database hosting for account data, game records, and coaching memory. EU region.
  • Koyeb — application server hosting. Your requests are processed on Koyeb infrastructure.
  • PostHog — product analytics, error tracking and masked session recordings. On the website, activated only with your consent; in the mobile app, on the basis described in Section 2. Data is stored in the EU.
  • LangWatch — LLM call tracing and observability. Coaching prompts and responses (stripped of sensitive identifiers) may be logged for quality monitoring.
  • Upstash Redis — in-memory cache for active session state and API rate limiting. No personal data is persisted beyond session TTL.
  • Inngest — durable background job execution for game fetching, retry logic, coaching-memory processing, and scheduled tasks. Game identifiers, player handles, and session data pass through job payloads.
  • Resend — transactional email delivery for your welcome email and weekly coaching digest. Your email address (if provided) is shared with Resend solely to deliver these emails.
  • GIPHY— animated reactions on the game review screen. When you open a game review, the app asks GIPHY for a GIF matching the game's result (for example "victory dance"). GIPHY receives that search phrase and your device's IP address, never your name, account, chess handle or game data.
  • Expo Push Notification Service (planned) — push notifications for proactive coaching alerts (e.g., tilt detection, critical moment reviews). Your device push token will be stored and shared with Expo solely to deliver notifications.
  • Adapty— in-app subscription and purchase management. The Adapty SDK runs on every app launch and creates a subscription profile identified by your internal EloCoach account ID, independent of whether you make a purchase. We've disabled advertising-identifier (IDFA / GAID) and IP-address collection, since EloCoach doesn't use them for ads. We also share your PostHog analytics ID with Adapty so purchase events can be linked to the same analytics profile described above. Once you make a purchase, billing-related data (purchase history, entitlements) is also processed by Adapty. Payment card details are handled directly by Apple / Google and are never stored by EloCoach or Adapty.

We do not sell your personal data to third parties.

5. Cookies and tracking

On our website, we use strictly necessary cookies to operate the service and, with your consent, analytics cookies (_ga, _gid, PostHog) to understand how people use EloCoach. You can manage or withdraw consent at any time using the cookie preferences link in the footer. The mobile app does not use cookies; its analytics are described in Section 2.

6. Data retention

We retain your account and coaching data for as long as you have an active account. If you request deletion, we will remove your personal data within 30 days, except where we are required by law to retain it longer.

When you delete your account, we remove your coaching data, game history, and conversation records immediately. A minimal set of account records is retained for a longer period solely to prevent abuse of the service — for example, creating a new account to circumvent usage limits. This retained data is limited to what that purpose requires and is not used for anything else. Legal basis: legitimate interest in preventing service abuse.

You can delete your account in the app (Settings → Delete account) or, without the app, by email — see how to delete your account.

7. Your rights (GDPR)

You have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Erase your data (“right to be forgotten”)
  • Restrict or object to certain processing
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent at any time, without affecting prior processing
  • Lodge a complaint with the Autoriteit Persoonsgegevens

To exercise any right, email [email protected]. We will respond within one month.

8. Children

EloCoach is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it promptly.

9. Security

We apply appropriate technical and organisational measures to protect your data, including encrypted transport (TLS), access controls, and regular security reviews. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

10. International transfers

Some processors operate outside the European Economic Area. All such transfers are protected by EU Standard Contractual Clauses or an equivalent adequacy mechanism.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified via in-app notice or email at least 14 days before they take effect. Continued use after that date constitutes acceptance.