Privacy
The board is local by default. Network processing begins only when a user chooses functionality that requires it.
Published by DeviantData, 4123 Monterey Street, Los Angeles, CA 90065, United States. Effective July 19, 2026.
Local-Only Use
- No account is required for local chess play.
- No Rookies sends no product telemetry or advertising identifiers.
- Cached matches, replays, and PNGs remain in browser storage.
- Files are written only after the user selects a folder or export.
Position Bridge
The extension reads selected text after a context-menu action, or temporarily inspects the active tab after a toolbar click. It has no broad host or extension-storage permission. Recognized FEN or PGN text is placed in a URL fragment and decoded locally. Browsers may retain that URL fragment in local history.
Optional Relay
When a model-relay player is selected, the app sends a PNG of the current board, the responsible color, and the fixed move instruction. The relay may process account identity, request metadata, provider and model identity, token counts, cost, abuse signals, and payment-credit balance. Provider credentials are never placed in the public web bundle.
Authentication And Security
A self-service provider key is entered into a password field, sent only over HTTPS, omitted from browser storage, and held only in relay process memory until disconnect, timeout, or relay restart. Operator-configured provider secrets may instead be encrypted at rest. Authentication tokens and session cookies authorize relay operations. Security logs should exclude board images, prompts, credentials, and full tokens. Operational records are retained only for documented security, billing, legal, and recovery periods.
Payments
When paid relay access is offered, Stripe hosts card checkout and the DeviantData payment rail records settlement and issues signed, account-bound credits or licenses. No Rookies receives transaction and invoice identifiers, product, amount, currency, tax, refund, dispute, and account-link information. Card details remain with Stripe.
Age
Local-only use is available to all ages. An account, model relay, bring-your-own-key connection, or commerce feature requires age 13 or older. A user under the age of legal majority must have permission from a parent or legal guardian. DeviantData does not knowingly permit a child under 13 to use network or commerce features.
Retention
- Temporary provider keys remain only in relay memory until disconnect, 30 minutes of inactivity, eight hours total, or restart.
- Board PNGs and prompts are not placed in service logs or backups.
- Routine request and security metadata is retained for up to 90 days, unless an incident or legal obligation requires longer retention.
- Support and deletion records are retained for up to three years after closure.
- Payment, credit, refund, dispute, and tax records are retained for seven years after the transaction or account closure.
- Active service data is deleted within 30 days of an authenticated request. Any encrypted backup copy expires within 35 additional days. Required financial or legal records are restricted instead of erased.
Deletion
Deleting a cached match removes it from the current browser. Deleting a relay account revokes relay access and deletes account secrets and service data, except records that must be retained for payment, tax, fraud prevention, security, backup expiry, or legal claims. Exported files remain under the user's control. DeviantData sends necessary deletion instructions to applicable processors within the same 30-day period.
Disclosure And Requests
DeviantData does not sell personal information or share it for cross-context behavioral advertising. Information is disclosed only to a model provider selected by the user, Stripe and necessary service processors, authorities when legally required, or a successor that accepts this notice. Users may request access, correction, export, or deletion without discrimination.
Contact
Privacy requests: support@deviantdata.net.