C4ChessC4ChessBack to C4Chess

Privacy Policy

Version 3.0 — effective August 6, 2026

1. In short

C4Chess is a chess coaching academy and most of our learners are children. That single fact shapes everything below, so here is the summary before the detail.

We collect what we need to teach: an account, an age band, what you do on the platform, and — for enrolled students — attendance, homework, coach feedback and progress. We ask for an age band rather than a date of birth, because that is less data about a child and it answers every question we need answered.

We use Google Analytics 4 to measure how the site is used. It loads only if you accept optional cookies, we do not send it your name, email or account ID, and you can switch it off at any time in the portal under Settings → Account → Analytics cookies. Advertising is not running today; if it ever does, it will be non-personalised, with Google's Tag for Age Treatment configured as "child", for everyone except a user who has declared 18 or over. Declining optional cookies does not switch advertising off — it switches it to Google's limited mode, which picks the advertisement from the page rather than from you and stores nothing about you.

We do not sell personal data. We do not build advertising profiles of children. We do not record live classes. We do not use students' work or games to train artificial-intelligence models.

Our primary database, authentication system and stored learning records are hosted in Mumbai, India. Some limited data is processed internationally by the service providers described in sections 13 and 15. To ask a question, exercise a right, or complain: privacy@c4chess.com.

2. Who we are and how to reach us

C4Chess Education Private Limited is the data fiduciary — the organisation that decides why and how your personal data is processed — for everything described in this policy. It is a private limited company incorporated in India under Corporate Identity Number U85410WB2025PTC280318, with its registered office at 4th Floor FL-4C, 83 S.P. Mukherjee Road, Kalighat, Kolkata - 700026, West Bengal, India.

Our Grievance Officer under section 13(3) of the Digital Personal Data Protection Act, 2023 is Surya Tribedy. For any privacy question, to exercise a right, or to raise a grievance, write to privacy@c4chess.com, or by post to the Grievance Officer at the registered office above. For anything else, support@c4chess.com.

If you are a parent or guardian writing about your child, say so and tell us the child's account email; section 10 explains how we handle those requests.

3. Who this policy covers

Visitors to our public pages, including anyone reading ChessDaily or browsing without an account.

Guest users who play or solve puzzles without registering. A guest is given a random token stored in their own browser so their game can work; that token is not linked to a name or an email address.

Registered users, whether or not they are enrolled for coaching.

Enrolled students, and the parents and guardians linked to a student's account.

Coaches and staff, in respect of their use of the platform. Employment records are handled separately and are outside this policy.

4. What personal data we collect

Account and identity: email address, password (stored only as a cryptographic hash, never in readable form), a public user ID you choose, first and last name where you give them, an avatar image if you upload one, country, time zone, a short profile bio if you write one, and preferred language.

Age information: an age band — under 13, 13 to 15, 16 or 17, or 18 and over — together with the date you declared it. A full date of birth is optional; you can add it in your profile and remove it again at any time. Enrolled students may be asked for a date of birth separately where an age-group class or a tournament entry needs it.

Consent records: which version of the Terms, Privacy Policy and Cookie Policy you accepted and when, whether the account was set up with guardian consent, and your answer to the cookie banner.

Sign-in provider data: if you sign in with Google, the basic identifiers Google shares with us, which is your email address and basic profile information. We do not receive your Google password.

Learning and coaching data, for enrolled students: batch and schedule, attendance, homework assignments and submissions, assessments, coach feedback and notes, progress reports and certificates, and feedback a parent gives about coaching.

Gameplay and practice data: games you play and their moves, opponents, ratings and rating history, puzzle attempts and results, opening repertoire and course progress, missions and XP, and analysis produced from your games.

Communications: messages you send through the platform, notifications, support tickets, reports you file about another user, demo-class and enquiry forms, and email we exchange with you.

Live classes: the fact and timing of joining and leaving a session, and the display name shown to other participants. We do not record the audio or video (see section 12).

Payment records: the fact and amount of a payment, the enrolment it relates to, and any proof of payment you upload. We do not collect or hold card numbers, bank credentials or UPI credentials — there is no payment gateway in the platform.

Contact details for reminders: an email address and, where you give one, a phone number used for class reminders.

Technical data: IP address, device and browser information, and pages and features used. Where you have accepted optional cookies this is also seen by Google Analytics, in the limited form described in section 9.

What we deliberately do not collect: we do not ask for a government identity document, an Aadhaar number, a school address, a home address, precise location, biometric data, or any special-category data about health, religion, caste or community. Do not send us these; if you do, we will delete them.

5. Why we use it, and on what legal basis — category by category

This is the table regulators and reviewers look for: for each category of personal data, what we use it for and what makes that lawful. Under the Digital Personal Data Protection Act, 2023 the lawful bases available to us are consent (section 6) and certain legitimate uses (section 7); where a person is a child, consent must come from a verifiable parent or guardian (section 9). Where the GDPR applies to a user in the EU or UK, the corresponding basis is given in brackets.

Account and identity data — to create and secure your account, sign you in, let others recognise you in games and classes, and contact you about the service. Basis: performance of the agreement with you or your guardian, and consent given at sign-up (GDPR equivalent: contract).

Age band and date of declaration — to decide which terms apply, whether guardian consent is needed, whether the account may see advertising at all, and to pitch material at the right level. Basis: consent, and compliance with our obligations towards children under the DPDP Act (GDPR equivalent: legal obligation and contract).

Consent and acceptance records — to show what a user or guardian was shown and agreed to, and when. Basis: compliance with a legal obligation, and our legitimate interest in being able to demonstrate consent (GDPR equivalent: legal obligation, legitimate interests).

Learning and coaching data — to deliver classes, set and mark homework, record attendance, write feedback and progress reports, issue certificates, and let a linked parent see how their child is doing. Basis: performance of the coaching agreement with the guardian or adult student (GDPR equivalent: contract).

Gameplay and practice data — to run games and puzzles, match you with suitable opponents and material, calculate ratings, produce analysis, and show your own progress back to you. Basis: performance of the agreement (GDPR equivalent: contract).

Communications — to deliver messages and notifications, answer support requests, investigate reports, and keep the community safe. Basis: performance of the agreement, and our legitimate interest in a safe platform, which for a service used by children we treat as a duty rather than a preference (GDPR equivalent: contract, legitimate interests).

Live-class attendance events — to record who attended which class, for attendance reporting to guardians and for our own records. Basis: performance of the coaching agreement (GDPR equivalent: contract).

Payment records and proof of payment — to verify that a fee has been paid, activate enrolment, keep accounts, and meet tax and company-law obligations. Basis: performance of the agreement and compliance with a legal obligation (GDPR equivalent: contract, legal obligation).

Contact details for class reminders — to remind a student or guardian that a class is due. Reminders currently go by email only. The platform can also send them over WhatsApp, but that is switched off, and it would be used only where a phone number has been given for that purpose. Basis: performance of the agreement; for WhatsApp, were it switched on, your consent, which you could withdraw by telling us to stop (GDPR equivalent: contract, consent).

Technical and security data — to keep the service working, detect and investigate abuse, fair-play violations and security incidents, and diagnose faults. Basis: our legitimate interest in the security and integrity of a platform used by children, and compliance with law (GDPR equivalent: legitimate interests, legal obligation).

Analytics data — to understand which pages and features are used so we know what to build and fix. Basis: your consent, given through the cookie banner and withdrawable at any time (GDPR equivalent: consent).

Advertising data, if and when advertising launches — to show contextual advertising on the platform, non-personalised for everyone except a user who has declared 18 or over. Basis: your consent, given through the cookie banner and withdrawable at any time (GDPR equivalent: consent).

Safety and abuse records — to act on reports, moderate content, restrict accounts, and where necessary report a matter concerning a child to the authorities. Basis: compliance with a legal obligation and the protection of vital interests, particularly of a child (GDPR equivalent: legal obligation, vital interests, legitimate interests).

6. What we do not do with your data

We do not sell personal data, and we do not share it for anyone else's marketing.

We do not build behavioural profiles of users for advertising, and we do not track anyone across other websites.

We do not use a student's homework, games, messages or coach feedback to train artificial-intelligence models, ours or anyone else's.

We do not publish a student's games, rating or progress outside the platform, and we do not make a user's friend list visible to anyone but the user.

We do not make decisions about a student purely by automated means that produce a legal or similarly significant effect on them. Automated tools suggest material and produce analysis; a coach makes the judgements that matter.

7. Cookies and similar technologies

We use a small number of strictly necessary storage items to keep you signed in and to remember your settings, and — only if you accept them — optional items for analytics and, in future, advertising.

Nothing optional loads before you accept it. The analytics and advertising tags are injected by our own code only after consent is recorded; they are not present in the page beforehand.

You can change your answer at any time, in the portal under Settings → Account, towards the end of that section, under "Analytics cookies". Turning analytics off stops reporting immediately, in the same page view, without a reload or a sign-out.

The full list of what we store, what each item is for, and how long it lasts is in our Cookie Policy at /legal/cookies.

8. A note on where we are being precise

This policy names the specific services we use rather than saying "trusted partners", because a general statement would not let you check anything. Where something is not live yet, we say so rather than describing it in the present tense.

As at the last-updated date: Google Analytics 4 is live and consent-gated. Google AdSense is not live — no publisher account is configured and no advertisement is placed anywhere on the platform. Sign-in with Apple is built but switched off. Reminders over WhatsApp are built but switched off, so no reminder is being sent over WhatsApp and no phone number is reaching Meta today. Class reminders currently go by email.

One thing we used to do and have stopped: the typefaces on this site were previously fetched from Google Fonts as each page loaded, which told Google the address of every visitor to every page, before anyone had consented to anything. They are now served from our own domain.

What that does and does not buy you, stated carefully. Ordinary C4Chess pages do not intentionally load Google Analytics or advertising resources before you accept optional cookies. But certain features you choose to use may contact Google when you activate them — playing a video in the video library, which is embedded through YouTube's privacy-enhanced player, or signing in with Google. Those are user-initiated, and the section below lists them.

9. Analytics — Google Analytics 4

We use Google Analytics 4, property G-V8S30EV4MN, operated by Google, to understand how the site is used in aggregate.

It loads only if you accept optional cookies. Until you do, nothing is sent to Google Analytics at all — the tag is not on the page. If you decline, or later switch it off, nothing is sent from that moment.

What it receives: the pages you view, a small set of named events (for example that a game was started, a lesson was opened, or an article was read), a randomly generated analytics identifier, your approximate location derived from your IP address, and basic device and browser information.

What it does not receive: your name, your email address, your account ID, whether you are a student, your messages, your homework, your games, or the text of anything you search for. Where an event relates to something you searched for, we send only the length of the query, never the query. Where an event relates to an article, lesson or video, we send its title but not your identity.

Advertising storage, advertising user data and advertising personalisation start denied and stay denied for everyone except a user who has declared 18 or over and accepted optional cookies — the only case where we grant them, because personalised advertising is not possible without them. These are a single browser-wide setting shared by Analytics and advertising, so for that one group the setting is granted for both, and we would rather say so than describe a separation that does not exist. For everyone else — every minor, every unplaceable age, and everyone who declined — they are never granted, and analytics data is not used to build an advertising profile. What Analytics receives never includes your name, email or account ID in either case. Analytics is also suppressed entirely on pages that could carry a sign-in or password-reset token in the address, so no credential can reach Google in a URL.

To withdraw: portal → Settings → Account → Analytics cookies. Google publishes its own terms and privacy information for Analytics, and offers a browser add-on that opts you out of Google Analytics across all sites.

10. Advertising

No advertising is being served on C4Chess as at the last-updated date. This section describes what will apply if and when it launches, so that the position is disclosed before anything changes rather than after.

Advertising, if it launches, will be Google AdSense, and what kind you see depends on one thing: the age band you declared at the check-in. If you have told us you are 18 or over, your advertisements may be personalised. If you have told us anything else, if your answer is old enough that we can no longer rely on it, or if you have not answered at all, every request is made with personalised advertising disabled and with Google's Tag for Age Treatment configured as "child", which also switches off remarketing and third-party ad vendor calls.

We want to be exact about what non-personalised does and does not mean, because the difference matters. It stops advertisements being chosen using a profile of you. It does not make an advertisement contentless: a non-personalised advertisement may still be selected using contextual information, such as the content of the page you are reading and a coarse location derived from your IP address, as permitted by Google's documentation and applicable law. Some limited data is still processed to serve and measure it, and to detect invalid traffic.

Personalised advertising means the opposite: Google may use information it holds about you, including activity on other sites, to choose what you are shown. That is why it is offered to adults only, and why declining optional cookies switches it off for everyone regardless of age.

The line we draw is the line the Act draws. Section 9(3) of the Digital Personal Data Protection Act, 2023 prohibits tracking, behavioural monitoring and targeted advertising directed at children, and the Act treats everyone under 18 as a child. It does not say the same about adults. Asking for an age band is what makes it possible to tell the two apart, and this is what that answer is used for. Your declared band is the only thing we go on, so it is worth answering accurately; if the rules made under the Act prescribe a verification mechanism, we will adopt it and say so here.

Cookie consent is the only thing that withholds advertising, and it withholds it completely. Everything else decides what KIND of advertisement you see, never whether you see one: your declared age band chooses between personalised and non-personalised, and nothing else is consulted. Enrolment makes no difference — an enrolled student whose family pays for coaching sees advertising on the same terms as anyone else of their age.

If you decline optional cookies, or have not answered the banner, you still see advertising — but in Google's "limited ads" mode. A limited advertisement is chosen from the content of the page you are on and nothing else. No personal data is used to select it, no advertising profile is built or consulted, and nothing is stored on your device or read from it except Google's own invalid-traffic detection, which exists to stop click fraud rather than to learn anything about you. This is the mode we would rather you understood clearly than be surprised by: your refusal is honoured in full, and what it buys you is that the advertisement knows about the page and not about you.

We have made that choice deliberately and will say why plainly. C4Chess is given away — the whole portal, free, including things that are sold elsewhere — and advertising is what pays to keep it that way. An arrangement where declining a cookie banner removed all advertising would mean the people who use the service most pay for it least, and it would not survive contact with the bills. Limited advertising asks nothing of you and still keeps the lights on.

To opt out: portal → Settings → Account → Analytics cookies, and turn optional cookies off. That one switch governs advertising as well as analytics.

11. Children and young people — the longest section here, on purpose

Most services write one line about children because they never ask anyone's age and prefer not to know. We are not in that position. C4Chess enrols children into age-graded classes, links parent accounts to child accounts, and asks every user for an age band. We have actual knowledge that children use this service, and a one-line children's section would be inadequate to the point of dishonesty. So this section is the longest one in the policy.

WHO IS A CHILD. Under section 2(f) of the Digital Personal Data Protection Act, 2023, a child is anyone who has not completed 18 years. That is the line we use throughout, and it is a higher bar than the 13-year line many international services use.

PARENTAL CONSENT. Personal data of a child is processed on the basis of the consent of a parent or legal guardian, as section 9(1) of the Act requires. Every account whose declared band is under 18 — including under 13 — is created with that consent recorded as outstanding, and a guardian must consent to these documents and to the child's use. The account is not closed while that is outstanding. When we link a parent account to a child account, we verify the link with a one-time code sent to the parent rather than accepting a claimed relationship, because a parent view exposes the child's progress, attendance and feedback.

IF YOU ARE UNDER 18, DO NOT DO THIS ALONE. Users are hereby requested to read this Privacy Policy, our Terms & Conditions and our Cookie Policy before agreeing to them, and a user under 18 is advised to seek their parent's or guardian's guidance before proceeding any further — including before ticking the three boxes at the check-in.

HOW WE ASK, AND WHAT WE RECORD. Signing up has a compulsory second step. Before the portal opens, we ask for an age band — under 13, 13 to 15, 16 or 17, or 18 and over — and we ask you to acknowledge each of these three documents separately rather than as one bundle. What is stored is the band, the date you declared it, and one row per document naming which document, which version of it, and when. That is what makes it possible to reconstruct, later, exactly what a particular person was shown on a particular day.

AND WHAT WE DO WHEN AN ANSWER AGES. A date of birth stays true; an age band does not. So a band is never stored on its own — it is stored with the date it was given, and a person's status is worked out from the pair. Someone who told us they were 13 to 15 is certainly still a child for the next two years and certainly an adult after five, and in between we ask again rather than guess. Where there is no usable answer, the person is treated as a child. On a platform used mostly by children, not knowing is not the same as being told they are an adult, and we do not let it resolve that way.

VERIFYING THAT CONSENT. The Act requires consent to be verifiable. What we have today is: a recorded acknowledgement per document, tied to a version and a timestamp; an age band recorded with its declaration date; a parent-child link verified by a one-time code before any parent view is granted; and, for enrolled students, direct contact with the paying guardian during enrolment. For a child who signed up on their own, the guardian's consent stays recorded as outstanding until a guardian gives it. The rules prescribing a verification mechanism under the Act were still awaited when this policy was written; we will adopt what they require, update this policy, and seek fresh consent where the change calls for it.

WHAT WE COLLECT ABOUT A CHILD. The same categories set out in section 4, and no more: account and contact details, an age band rather than a date of birth, learning and coaching records, gameplay and practice records, messages within the platform, and attendance. We do not ask a child for a home address, a school name, a phone number, a government identity document, or a photograph beyond an optional avatar. We do not require a child to disclose more than is needed to take part, and no feature is gated behind giving us extra personal data about a child.

NO TARGETED ADVERTISING TO A CHILD, NO CROSS-SITE TRACKING OF A CHILD, NO PROFILES. Section 9(3) of the Act prohibits tracking, behavioural monitoring and targeted advertising directed at children. No user whose declared age band is under 18 is shown personalised advertising, nor is anyone whose declared band has aged past the point where we can rely on it, nor anyone who has not answered — on a platform used mostly by children, not knowing is treated as a child, never as an adult. That covers children under 13, who see contextual advertising only, on the same footing as every other child here. We do not follow a child across other websites, we do not build advertising profiles of children, and we do not sell or share a child's data for anyone else's marketing. A user who has declared 18 or over is outside section 9(3) and may see personalised advertising; section 10 sets out what that means.

ANALYTICS, STATED PRECISELY, BECAUSE THIS IS THE HARD CASE. Where you have accepted optional cookies, Google Analytics 4 runs. We report it here rather than filing it under a general reassurance, because it is the one thing on this platform that sits closest to the section 9(3) line and we would rather you judged it than took our word. What it does: it assigns your browser a randomly generated identifier that persists between visits, and it records the pages you view and a set of named events describing what was used — a puzzle attempted, a lesson opened, homework submitted. What we do not send it: your name, your email address, your account ID, whether you are a student, your messages, your homework, your games, or the text of anything you search for. For a child — anyone whose declared band is under 18, and anyone whose age we cannot place — every advertising signal is denied, so for a child this cannot feed an advertising profile at all. It is switched off entirely for anyone who declines. Section 9 explains the one case where those signals are granted, which is a user who has declared 18 or over.

We are not going to tell you that this is beyond argument. A persistent identifier plus a sequence of activity is not the same thing as a headcount, whatever it is called, and whether consented analytics inside a portal used by children falls within "tracking or behavioural monitoring" in section 9(3) is not a question we should decide in our own favour in our own privacy policy. It is one for our legal advisers and ultimately for the Data Protection Board. We are separately reviewing whether analytics should run on signed-in pages at all, as against public pages only, with first-party aggregate counting behind the sign-in. If that review moves the line, we will move with it and say so here. In the meantime the control is yours: Settings → Account → Analytics cookies, and declining costs you nothing on this platform.

NO HARM. Section 9(2) of the Act prohibits processing that is likely to cause any detrimental effect on the wellbeing of a child. This is why classes are not recorded, why a child's friend list is never shown to anyone else, why messaging is confined to the platform and moderated, why grooming and any attempt to move a child to a private off-platform channel are absolute grounds for removal, and why we treat a safety report about a child as an escalation rather than a ticket.

WHAT A CHILD'S DATA IS NEVER USED FOR. It is never sold. It is never shared for anyone else's marketing. It is never used to train an artificial-intelligence model. It is never used to advertise to the child. It is never published outside the platform.

HOW A GUARDIAN EXERCISES RIGHTS FOR A CHILD. A parent or legal guardian may, on the child's behalf: ask what personal data we hold about the child and why; ask for a copy; ask us to correct or complete it; ask us to erase it; ask us to stop a particular use; withdraw consent; and complain. Write to privacy@c4chess.com from the email address on the account or the linked parent account, tell us the child's account email, and say what you want. If we cannot tell that the request comes from the guardian, we will ask for enough to establish that, and no more — we will not ask you to send an identity document.

OUR RESPONSE. We acknowledge within 48 hours and respond within 30 days. There is no charge. If we cannot do what you have asked — for example where we must keep a financial record to comply with tax law — we will tell you exactly which part we cannot do and why.

WITHDRAWING CONSENT. A guardian may withdraw consent at any time, and it is as easy to withdraw as it was to give. Because a child's data is processed on the basis of that consent, withdrawing it means we can no longer lawfully provide the service to that child, and the account will be closed and the data deleted or anonymised on the schedule in section 16. We will explain that consequence and confirm before we act, never afterwards.

IF A CHILD UNDER 13 HAS REGISTERED WITHOUT A GUARDIAN. Tell us at privacy@c4chess.com and we will suspend the account and delete the data unless a guardian confirms consent. We would rather hear about it than not.

IF YOU ARE A YOUNG PERSON READING THIS. You have rights too, and you can write to us at privacy@c4chess.com yourself. If we need to involve your parent or guardian before we act, we will tell you that we are doing it. If someone on C4Chess makes you uncomfortable, or asks to talk to you somewhere else, use the report button or tell a coach. You will not be in trouble.

12. Live online classes

Live classes run over infrastructure provided by LiveKit. While you are connected, your audio, video and any screen you share pass through that infrastructure to the other participants in your class in real time.

We do not record classes. The platform has no recording function and stores no video or audio of a session. What is stored from a class is the fact and timing of joining and leaving, and any notes a coach writes afterwards.

Participants are not permitted to record either. This rule exists because these rooms contain children.

Some meetings can be joined by a guest through a link and a code, with the host admitting them. A guest's display name is visible to the other participants for the duration of the session.

13. Who we share personal data with

We do not sell personal data. We share it only with the providers that make the service work, and only with what they need, under contracts requiring them to protect it and to use it only on our instructions.

Supabase — the database, sign-in, file storage and server functions behind the platform. Effectively all of the data described in section 4 is stored here. Hosted in the ap-south-1 (Mumbai) region.

Cloudflare — hosting and content delivery for the website. Receives request metadata such as IP address and browser information in the course of serving pages.

LiveKit — real-time audio and video for live classes. Receives the media stream while a class is in progress and a participant identity and display name. No recording.

Resend — delivery of transactional and notification email, such as welcome messages, class reminders, one-time codes, and staff notifications. Receives the recipient's email address, name, and the content of the message.

Meta Platforms (WhatsApp Business Cloud API) — class reminders by WhatsApp. Built, but switched off: no reminder is being sent this way and no phone number is reaching Meta as at the last-updated date. If it is switched on, it would receive the phone number and the reminder details, and only where a number has been given for that purpose.

Google — Analytics as described in section 9, only after you accept optional cookies; sign-in with Google if you choose to use it; the YouTube privacy-enhanced player for the video library, which sets no cookie until you press play; and AdSense if and when advertising launches, as described in section 10. Note what is not on that list: the typefaces used across the site are served from our own domain rather than from Google Fonts, so an ordinary page load no longer fetches anything from Google to render itself. The YouTube player and Google sign-in are different — they contact Google when you use them, and the privacy-enhanced player changes what is stored and personalised rather than preventing the request.

Apple — sign-in with Apple is built into the platform but is currently switched off. If it is enabled, Apple will receive the fact of a sign-in and will share the identifiers you permit.

Translation providers — where you read the portal in a language other than English, the text being translated is sent to a translation service. By default that is MyMemory; a self-hosted service is used where one is configured, and an AI provider only if that option is deliberately switched on. What is sent is stored content — articles, lesson and opening text, and these legal documents — and each distinct string is translated once and then cached, so it is not re-sent for every reader. Your own messages, homework submissions and personal details are not sent for translation.

Anthropic — used to generate ChessDaily articles from public chess news, which involves no user data. The optional in-app coaching explanations feature can also use it; it is switched off by default, and when it is switched on it is sent a summary of a game (result, opening, moves, accuracy figures, key moments and the opponent's username) and any question you type, but not your name, your email or your account ID.

Chess.com and Lichess — where you ask us to prepare for an opponent or analyse a player, we fetch that player's publicly available games from those services using the username you enter. Nothing about you is sent beyond the request itself.

Content delivery networks — chess piece artwork and country flag images are loaded from public CDNs, which receive your IP address and browser information as part of serving the image.

Others, where necessary: professional advisers under a duty of confidence; a purchaser or successor if the business is transferred, with your rights preserved; law-enforcement, a court, or a regulator where we are legally required to disclose or where it is necessary to protect a person, particularly a child, from harm.

14. Artificial intelligence on the platform

ChessDaily articles are generated by an AI model from public chess news and tournament data, and are passed through an automated child-safety and accuracy review before publication, with anything that does not clear the review held for a human. No user data is involved in producing them.

Translation of stored content into other portal languages may use an automated translation service. Machine translations are reading aids; the English text of these legal documents is the version that governs.

Game analysis, ratings, puzzle selection and mission recommendations are produced by our own software running on our own infrastructure. They are calculations, not AI models trained on your data.

An AI-assisted coaching explanation feature exists and is switched off by default. It is never enabled without a deliberate decision, and section 13 sets out exactly what it would send.

We do not use your personal data, your games, your homework or your messages to train any AI model.

15. Where your data is stored, and international transfers

The database, files and sign-in system that hold the substance of your personal data are hosted in India, in the ap-south-1 (Mumbai) region.

Some of the providers listed in section 13 operate globally, so certain data is processed outside India: website hosting and content delivery, live-class media routing, email delivery, analytics, translation, and any advertising, along with the image CDNs that serve chess piece artwork and flags to your browser.

Where personal data leaves India, we rely on the transfer being permitted under section 16 of the Digital Personal Data Protection Act, 2023, and on contractual protections with the provider — including, where the provider offers them, standard contractual clauses and a data processing agreement restricting use to our instructions.

We do not transfer personal data to any country that the Central Government has restricted.

16. How long we keep personal data

We keep personal data only as long as the purpose it was collected for requires, and then delete it or reduce it so that it no longer identifies you. The periods below are our policy rather than a description of an automated schedule, and we say that plainly: building the jobs that enforce them is work in progress.

Active accounts — for as long as the account is open.

After an account is closed or consent is withdrawn — deletion from the active user-facing database begins immediately when you close the account yourself from Settings, and within 90 days where we close it for you. One of two things results. Usually the profile is deleted outright, and everything attached to it goes with it: your games, ratings and rating history, experience points, friendships, notifications, analysis, homework and any reports you filed. Where a record must legitimately survive — a payment, a support ticket, a certificate, an attendance row — the profile cannot simply be removed, so it is instead reduced to a shell: name, email address, phone number, avatar, bio and date of birth are destroyed and the public identifier is replaced with a meaningless one. Your sign-in is deleted either way, so nobody can sign in as you again.

Two honest qualifications on that. First, residual copies may remain temporarily in encrypted backups, security logs or a service provider's systems until they are overwritten or expire under the applicable retention schedule; "deleted immediately" describes the live system you use, not every copy in existence. Second, a shell record that still points at a payment or an attendance row is pseudonymised rather than anonymous — it no longer names you, but it has not been severed from a record that relates to you, and we would rather say so than claim a standard we cannot meet.

Inactive accounts — where an account has not been signed into for 3 years, we will notify the account holder and, absent a response, close and delete it.

Learning and coaching records for an enrolled student — for the duration of enrolment and 3 years afterwards, so that a former student or their guardian can obtain a progress record, a certificate reissue, or a reference.

Payment and accounting records — 8 years from the end of the relevant financial year, as required of an Indian company by the Companies Act, 2013 and tax law. These records are kept even after an account is deleted, and are reduced to what the law requires.

Consent and acceptance records — for as long as the account exists and 3 years afterwards, because they are the evidence of what was agreed.

Safety reports, moderation records and abuse investigations — 3 years, or longer where a matter has been reported to an authority or is the subject of proceedings.

Security and access logs — 12 months.

Support correspondence — 2 years from the ticket being closed.

Class attendance events — for the duration of enrolment and 3 years afterwards, alongside the coaching records they belong to.

Guest data — a guest's browser token and locally stored progress live only in that browser and are removed when the browser's storage is cleared.

Analytics data — retained by Google for the period set on the Analytics property, which we keep at the shortest option available.

You can ask us to erase your data sooner. Section 17 explains how, and what we cannot delete.

17. Your rights, and how to exercise them

Under the Digital Personal Data Protection Act, 2023 you have the right to obtain a summary of the personal data we hold about you and how it is processed, and the identities of those we have shared it with; the right to have inaccurate or incomplete data corrected, completed or updated; the right to have your data erased where we no longer need it for the purpose it was collected for or where you withdraw consent; the right to withdraw consent at any time, as easily as you gave it; the right to nominate another person to exercise these rights if you die or become incapacitated; and the right to a grievance procedure, described in section 18.

A parent or legal guardian exercises these rights on behalf of a child, as set out in section 11.

You can erase your account yourself, without asking us. Portal → Settings → Account, at the bottom, under "Close your account". You confirm by typing a phrase and by proving it is you — your password, or a code emailed to you if you sign in with Google — and the account is then destroyed straight away rather than queued for someone to action. A right you have to request is a right somebody can be slow about; this one you exercise directly.

Four kinds of account cannot use that button, and are routed to us instead. A staff account, because it is an employment record. An enrolled student whose fees are paid, because closing mid-enrolment has billing and safeguarding consequences that need a person. A child, because a child's own click is not a valid erasure request — a linked parent or guardian has to make it. And an account whose age we cannot currently place on either side of 18, for the same reason: we cannot rule out that it belongs to a child. In each case write to privacy@c4chess.com and we will deal with it.

To exercise any other right, write to privacy@c4chess.com from the address on your account, saying what you want. There is no fee. We acknowledge within 48 hours and respond within 30 days. We will ask only for what we need to be sure it is really you, and we will not ask you to send an identity document.

What we may not be able to delete: records we are legally required to keep, principally payment and accounting records for 8 years; records needed to establish, exercise or defend a legal claim; and safety and moderation records where deleting them would put another user at risk. We will tell you specifically which of these applies and delete everything else.

Where deleting a child's account is requested, we delete the child's personal data and reduce any retained financial record to what the law requires, with the child's identifying details removed where that is possible.

Withdrawing consent does not make anything we did beforehand unlawful, but it stops the processing that depended on it from that point.

If you are in the EU or UK, you may additionally have rights of access, rectification, erasure, restriction, objection and portability under the GDPR, and a right to complain to your local supervisory authority. Write to the same address.

18. Grievances, and how to escalate

If you are unhappy with how we have handled your personal data, or with our response to a request, contact our Grievance Officer, Surya Tribedy, at privacy@c4chess.com, or by post at C4Chess Education Private Limited, 4th Floor FL-4C, 83 S.P. Mukherjee Road, Kalighat, Kolkata - 700026, West Bengal, India. Please describe the problem, the account it concerns, and what you would like us to do. We acknowledge within 48 hours and respond within 30 days.

Before approaching the Data Protection Board of India under the Digital Personal Data Protection Act, 2023, a Data Principal is required to exhaust the grievance-redressal opportunity provided by C4Chess. This does not restrict any other remedy that may independently be available under applicable law. So please raise it with us first — not as a courtesy, but because the Act asks you to — and if you remain dissatisfied afterwards, you may complain to the Board.

Complaints about the service rather than about data can go to support@c4chess.com, and consumers retain the right to approach a Consumer Disputes Redressal Commission under the Consumer Protection Act, 2019.

19. Security

Passwords are stored only as cryptographic hashes. Traffic is encrypted in transit. Access to data in our database is restricted by row-level security rules so that a user can reach their own records and a member of staff can reach only what their role requires.

The storage buckets holding certificates, portal content, student profile files and student avatars are private: their objects are not served from public URLs and are opened through short-lived signed links instead. Sensitive staff actions, including administrative access to and deletion of member accounts, are written to an audit record.

Analytics and any advertising tag are suppressed on pages whose address could carry a sign-in or password-reset token, so a credential cannot leak to a third party in a URL.

We update third-party libraries and review our access rules periodically, and we treat a reported security issue as a priority. We are describing a practice here, not a guarantee that every dependency is on its newest release at any given moment.

No system is perfectly secure. If a breach occurs that affects your personal data, we will notify you and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires.

Please help: use a password you do not use elsewhere, do not share your account, and tell us at support@c4chess.com if something looks wrong.

20. Users outside India

C4Chess is operated from India and is aimed at families in India, but the platform is reachable elsewhere. If you use it from outside India, your personal data will be processed in India and in the other locations described in section 15.

Where a law of your own country gives you rights that this policy does not describe, those rights are not taken away by this policy. Write to privacy@c4chess.com and we will deal with your request under the law that applies to you.

21. Changes to this policy

We may update this Privacy Policy. Each version carries a version identifier and a last-updated date, and we record which version you accepted and when.

Where a change is material — a new category of data, a new purpose, a new recipient, or anything affecting children — we will give notice in the portal or by email before it takes effect, and seek fresh consent where consent is the basis for the change.

The current version is always at /legal/privacy. Questions: privacy@c4chess.com.

Questions? Contact support@c4chess.com — for privacy or data requests, privacy@c4chess.com.