Privacy and data storage
This page explains the information used by ChessStep at chessstep.com. Contact support@chessstep.com with questions about your records.
Guest practice and local storage
Guest notebook positions, attempts, and endgame practice records are stored in your browser. New guest bot games remain only in the open page and are not saved to history until you sign in. Review analysis runs in your browser with Stockfish. Maia and Stockfish bot moves also run on your device; model files are downloaded from our domain, and positions are not sent to a third-party AI service for inference. Opening a PGN is not the same as saving all its moves to your account. If you explicitly save a position or play a recorded practice game, it can become part of your learning records.
Clearing site data can remove local records. Signing out is not a device wipe. On a shared device, sign out and clear the browser’s site data after you finish, keeping any exports you need first.
Accounts, sessions, and synchronization
For accounts we store a username, an associated email address when provided, password verification data using a salted password hash, and session records. An HttpOnly session cookie keeps you signed in. Verification emails support registration and password recovery.
Signing in merges eligible guest learning records into your account and synchronizes saved exercises, attempts, and recorded endgame and bot games. Friend games are stored on the server for play and replay. The other player can see the game and your username. Do not put sensitive information in usernames or game metadata.
Infrastructure and external services
Cloudflare hosts the site and database and handles transactional email delivery. Requests include network information such as an IP address; the service uses request information for delivery, abuse prevention, and diagnosing errors. Verification attempts and rate limits are used to protect accounts.
When you look up a public Chess.com username, ChessStep’s import service requests public game information from Chess.com. This does not require your Chess.com password and does not access its private review reports. External links take you to services with their own privacy practices.
Retention, exports, and deletion
Learning and account records are kept to provide account access, synchronization, and replays; the current product does not provide an automatic expiry schedule for these records. Expiring sessions and verification challenges have their own operational lifetimes.
You can remove individual saved exercises through My notebook and download PGN where the game interface offers it. Removing a saved exercise does not necessarily remove past attempts or game records. For account-wide access or deletion, email support from your associated address. We may need to verify ownership before acting. A self-service account deletion button is not currently available.
When asking for deletion, specify whether you also want help clearing local copies. Deleting server records does not remotely erase browser storage or files you downloaded. We will explain any limitations relevant to the request.
Changes and contact
We update this page when the product’s data handling changes. The date above identifies this version. Use the contact page for support and avoid sending passwords or verification codes.