covers your zochess account and zochess play
$ privacy
privacy policy
last updated Sep 30, 2026
This Privacy Policy explains what zochess (operated by Maksym Dolhov) collects, how we use it, and your choices. It covers your zochess account, which works in all our apps, and zochess play. The analysis and vision apps each have a page with what is specific to them.
01 Information we collect
- Account — your email address, username, and a securely hashed password (we never store your password in plain text). If you sign in with Google or Apple, we receive a unique account identifier and your email address from that provider instead of a password. Telegram gives us no email address, so an account created from Telegram is assigned a placeholder address that cannot receive mail.
- Profile — optional country, bio, and an avatar image (photo) if you upload one.
- Gameplay — your games, moves, ratings, and game history; in-game chat and direct messages you send.
- Technical — your IP address and browser user-agent (kept with your login sessions for security), and an approximate country derived from your IP to suggest your profile country.
- Mobile push token — if you use our mobile app and enable notifications, we store the device push token issued by your device's notification service to deliver alerts (such as new messages, challenges, and friend requests). See "Push notifications" below.
- Cookies — a single essential session cookie that keeps you signed in. See our Cookie Policy.
02 How we use your information
- To provide the Service: create your account, authenticate you, match games, maintain ratings and leaderboards.
- To uphold competitive integrity under our Fair Play Policy.
- To send transactional email — email verification and password resets.
- To keep the Service secure, prevent abuse, and comply with legal obligations.
03 Product analytics
We use self-hosted, cookie-free product analytics to understand sessions, screens, acquisition, feature use, and product funnels. Before sign-in, a random installation identifier is used. After sign-in, activity may be associated with your internal account UUID so journeys work across devices. We never include email addresses, usernames, tokens, messages, chess moves, FEN, PGN, or other free text in behavioral events.
Event properties are limited to app/platform versions, locale, bounded product categories, attribution fields, and experiment assignments. Raw behavioral analytics are retained for 13 months. You can disable future collection under Settings → Privacy; account, payment, security, and other operational records remain governed by their existing retention rules. Account deletion removes or anonymizes associated behavioral data except records we must keep for financial, security, or legal obligations.
04 Email
We send account-related email (such as verification and password-reset links) using Google's email service (Gmail SMTP). Your email address is shared with that provider only to deliver those messages. We do not send marketing email.
05 Push notifications
Our mobile app can send push notifications for new direct messages, challenges, and friend requests. To deliver them we use Google Firebase Cloud Messaging and your device's notification service (Apple Push Notification service on iOS). We register a device push token with that service so messages reach your device; the token is not used for tracking or advertising. You can turn notifications off at any time in your device settings, after which we delete the stored token.
06 Sign in with Google and Apple
If you choose "Sign in with Google" or "Sign in with Apple", that provider confirms your identity and shares a unique account identifier and your email address with us so we can create or access your account. We do not receive your provider password. These options are optional alternatives to signing in with an email and password.
07 Telegram Mini App
If you open the Service inside Telegram, Telegram passes us your numeric Telegram id, your first and last name, your @username if you have one, and your language setting, so that we can create or sign you into an account. On account creation only, and only if you have one, we also import your Telegram profile photo as your avatar; you can change it afterwards and we never import it again. Because a Mini App cannot receive push notifications, we deliver notifications as messages from our bot instead and store your chat id in order to send them — blocking the bot stops them. Purchases made inside Telegram are paid in Telegram Stars and processed by Telegram; we receive a payment charge identifier, which we store with the purchase for reconciliation and refunds. What Telegram itself does with your data is governed by Telegram's own privacy policy.
09 Retention
We keep your account information for as long as your account is active. Completed games may be retained as part of public game history and leaderboards. If you delete your account, your profile is removed; past games may be retained in anonymized form.
10 Your rights and choices
- You can view and edit your profile, and change your email or password, in your account settings.
- You can delete your account at any time from settings.
- You can opt out of IP-based country detection by choosing "International" as your country.
- To request access to or deletion of your data, email contact@zochess.com.
11 Security
Passwords are hashed with bcrypt; session and email-link tokens are stored only as hashes; traffic is served over HTTPS. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your information.
12 Changes to this policy
We may update this policy from time to time. We will revise the "last updated" date above when we do.
13 Contact
Questions about your privacy? Email contact@zochess.com.