Privacy Policy
Last updated: March 28, 2026
1. Overview
This Privacy Policy describes how Deep Red ("we," "us," or "our"), operated at deepredchess.com, collects, uses, and protects your information when you use our Service.
2. Information We Collect
Information you provide
- Account information: Email address, username, and password (stored as a secure hash) when you register
- OAuth data: Name, email, and profile picture from Google or GitHub if you use social login
- Chess data: PGN files you upload and games you import from Chess.com or Lichess
- API keys: If you use the Bring Your Own Key (BYOK) feature, your API key is stored encrypted and used only to process your requests
- Preferences: Theme, board style, piece set, and other display settings
Information collected automatically
- Usage data: Pages visited, features used, review history, and session duration
- Device information: Browser type, operating system, and screen size
- Network information: IP address (used for rate limiting and security)
- Cookies: Authentication session cookies and Google Analytics cookies
3. How We Use Your Information
- Provide, operate, and improve the Service
- Generate AI-powered game reviews and coaching commentary
- Authenticate your identity and secure your account
- Enforce rate limits and prevent abuse
- Analyze usage patterns to improve the Service (via Google Analytics)
- Communicate with you about your account or changes to the Service
4. Data Shared with Third Parties
To provide AI-powered analysis, we send chess game data (positions, moves, and game metadata) to the following providers based on your selection:
- Anthropic (Claude) — Privacy Policy
- OpenAI — Privacy Policy
- Google (Gemini) — Privacy Policy
Data sent to these providers via their APIs is generally not used for model training. Please refer to each provider's privacy policy and API terms for details.
We also share data with:
- Google Analytics: Anonymized usage and browsing data for understanding how the Service is used
- Google / GitHub: Authentication tokens when you use OAuth login
We do not sell your personal information to any third party.
5. Data Storage and Security
Your data is stored on secured servers. We implement appropriate technical and organizational measures to protect your information, including:
- HTTPS encryption for all data in transit
- Secure password hashing (passwords are never stored in plaintext)
- Encrypted storage for BYOK API keys
- Access controls limiting who can access production systems
While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Cookies
We use the following types of cookies:
- Essential cookies: Authentication session tokens required for the Service to function
- Preference cookies: Your theme, board style, and display settings (stored in localStorage)
- Analytics cookies: Google Analytics cookies to understand usage patterns
You can manage or disable cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and associated data
- Export: Download your reviews and game data
- Objection: Object to certain types of data processing
To exercise any of these rights, contact us at vxvware@gmail.com.
8. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it by law.
Server logs containing IP addresses are retained for up to 90 days for security and debugging purposes.
9. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it promptly.
10. International Data Transfers
Your data may be processed in countries other than your own, including the United States, where our servers and third-party providers are located. By using the Service, you consent to the transfer of your data to these locations.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact
For questions or concerns about this Privacy Policy, contact us at vxvware@gmail.com.