Privacy
Last updated 16 August 2026
You can use the whole app without an account and without giving us anything. We record five product events — how many games a scan read, how many puzzles it found, how long it took — and none of them contain your moves, your games, your username, or your IP address. If you make an account, your puzzles and settings are stored so they follow you between devices; delete the account and they go with it. Nothing is sold, and there is no advertising or third-party tracking anywhere on this site.
1. Who this is
Opening Punisher is a chess training site operated by one person at openingpunisher.com. Questions about anything on this page go to support@openingpunisher.com.
2. Using the app without an account
Signing in is optional and is not a gate. You can download games, run a scan, solve puzzles and browse the opening explorer as a guest.
As a guest, your work lives in your own browser and nowhere else. Downloaded
games, the puzzles a scan produced, and your settings are held in that
browser's localStorage and sessionStorage. They
are never uploaded. An account is what buys you saving — guest work is
session-only by design, and clearing your browser storage erases it
permanently, including for us, because we never had a copy.
3. If you create an account
Accounts are handled by Firebase Authentication (Google LLC). Signing in with Google or with an email and password gives us:
- your email address, and the display name and avatar on the Google account if you used that route;
- a Firebase user id, which is the key everything else hangs off.
We never see or store your password. If you use email sign-in, Firebase handles the credential; if you use Google, we never touch it at all.
Once you have an account, these are stored against your user id:
- the Lichess and Chess.com usernames you save, so the load form remembers them;
- your puzzle collection and its folders;
- your saved repertoires and report snapshots;
- your settings — theme, board colours, engine depth, scan preferences.
That data is private to your account. The database rules grant read and write on your records to your signed-in user id and to nobody else; there is no shared or public area, and every other path is denied by default.
One exception worth naming: if you paste a personal Lichess API token into Settings, it stays on that device only and is deliberately excluded from account sync. It is never sent to us.
4. Analytics — exactly five events
There is no analytics product on this site. No Google Analytics, no Segment, no Meta pixel, no session recorder, no heatmaps, no advertising network, no third-party tracker of any kind. What exists instead is five events, recorded by our own server, to answer one question: does a real scan find enough for the app to be worth using?
| Event | What is recorded with it |
|---|---|
scan_started |
which site the games came from, how many were requested, the time control filter, and which kind of scan it was |
scan_completed |
the same, plus how many games were read, how many puzzles and missed chances were found, and how many seconds it took |
puzzle_solved |
whether it was solved first try, how many attempts it took, and whether the puzzle came from your own games or from prep against an opponent |
pgn_exported |
that a saved set was downloaded as a PGN file, how many games and marked positions were in it, and whether the set was your own record or prep against an opponent. The file itself, the games in it, and who they were against are not sent to us — the whole export is built in your browser |
signin_completed |
which method was used (Google, email, or a restored session) |
Every event also carries these four fields and nothing else:
- A session id. A random string generated in your
browser that groups one visit's events together. It is kept in
sessionStorage, which means it is destroyed when you close the tab — it does not follow you between visits and no attempt is made to turn it into an identifier for a person. - Your account id, only if you are signed in. A guest has none and one is not invented.
- A device class: the literal word
mobile,tablet,desktop, orunknown. This is derived from your browser's user-agent string and then that string is thrown away — it is not stored. - A timestamp.
What analytics deliberately does not include
The list of fields above is enforced on the server as an allowlist: the recorder can only produce a record whose every field it already names, with a value inside a fixed range or a fixed set of words. There is no free-text field anywhere in it. This means the following cannot be recorded, even by accident:
- your IP address — it is not stored with any event;
- your chess usernames, or any name of a player you scouted;
- any game, position, move, or puzzle — the actual chess never leaves your browser during a scan;
- your full user-agent, screen size, language, timezone, or fonts — no device fingerprint is taken;
- your location, beyond nothing at all;
- referrer or campaign data.
Turning it off
The site honours Global Privacy Control and Do Not Track. If your browser or an extension sends either signal, no event is sent at all — the check runs before anything is built, not on the server after the fact. Setting GPC in your browser is the whole opt-out; there is nothing else to click, and the app is not degraded in any way by it.
5. Cookies
This site sets no tracking cookies, and there is no cookie banner because there is nothing to consent to. What the site does use is browser storage on your own device, for the app to work at all:
localStorage— your settings, downloaded games, puzzles and repertoires;sessionStorage— the per-visit session id described above;- the Cache API — a copy of the chess engine (about 7 MB) so it does not download again on every scan;
- Firebase Authentication keeps its own sign-in token in browser storage if you have an account, so you stay signed in.
Clearing site data in your browser removes all of it. If you are a guest, that erases your work; if you have an account, your saved data is on the server and comes back when you sign in again.
6. Other people's servers
Some things the app does necessarily involve a request to somebody else, and any server you make a request to can see your IP address. That is how the web works and it is not something this site can prevent, so it is listed plainly instead:
| Who | When, and what they see |
|---|---|
| Netlify | Hosts the site. Sees requests for pages and serves them. |
| Google — Firebase | Authentication and the database, if you have an account. |
| Lichess | When you download games, use the opening explorer, read a game inside the app, or export a saved set as a PGN. Requests your browser makes directly identify themselves only by origin. Explorer queries that go through our server are relayed, so Lichess sees our server rather than you. |
| Chess.com | When you download games from a Chess.com account, and when reading or exporting a single game from one — all through their public archive interface. |
| Cloudflare (cdnjs), unpkg, Google Fonts | Serve the code libraries and the two typefaces the page is built from. Loading a page fetches these. |
We do not send any of these your personal information, and none of them is an advertising or analytics relationship. Each has its own privacy policy governing what it does with a request it receives.
One thing worth knowing about downloading games: the games you pull from Lichess or Chess.com are the ones already published on those platforms. The app reads what is public there. Scouting an opponent shows you nothing they have not already made visible on their own account.
7. How long anything is kept
- Account data — until you delete it or ask us to. It is not kept on a timer.
- Analytics events — kept while they are still answering the product question they were recorded for. They contain nothing that identifies you, so there is nothing in them to expire, but they are not collected forever either; the five events exist to settle specific questions and will be retired when those are settled.
- Guest data — we never have it. It lives and dies in your browser.
8. Getting rid of your data
You can do all of this yourself, without asking:
- Delete puzzles, folders, repertoires or reports from inside the app.
- Clear everything on this device by clearing site data in your browser.
- Stop analytics by enabling Global Privacy Control.
To delete your account and everything stored against it, email support@openingpunisher.com from the address on the account. It gets removed, along with the puzzles, repertoires and settings held under it. You can also ask for a copy of what is stored, or for a correction.
Depending on where you live you may have further rights over your personal data — to access it, correct it, delete it, take it elsewhere, or object to how it is used. The same address handles all of them, and there is no charge.
9. Children
This site is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has made an account, write to the address above and it will be removed.
10. Where data is held
The site and its database run on infrastructure operated by Netlify and Google in the United States. Using the app means your data is processed there.
11. Changes
If this policy changes in a way that affects what is collected or why, the date at the top changes with it.
This section deliberately does not promise a fixed number of events. An
earlier draft did, and the number moved the first time the app grew a
feature — pgn_exported was added when PGN export shipped, and
section 4 was updated to match. Counting is not the commitment worth making,
because the count changes whenever the app does.
The commitment that does hold is about kind, not number. Every field in every event is either a whole number inside a fixed range or a single value from a fixed list, and which fields are allowed is decided on our server before anything is written. There is no free-text field anywhere in it. That is why section 4 can state flatly that your username, your moves, your games and your email address are not recorded — not as a rule we promise to follow, but as something the format cannot express in the first place. The material change to watch for is that structure changing: a field that could carry free text, or an event that records something about you rather than about how the app performed. If either ever happens it will be said here in plain terms, and the date above will change.
Contact
support@openingpunisher.com — privacy questions, data requests, account deletion.