Legal / 01
Privacy
policy.
Effective date: 4 September 2026 · Last updated: 4 September 2026
Short version. Chess Mutator uses Supabase for accounts and cloud game state, Google services for optional sign-in and mobile advertising, Cloudflare Turnstile for abuse protection, Cloudflare Pages for website hosting and delivery, Cloudflare Web Analytics for browser performance metrics, and email for support. Cloudflare describes Web Analytics as cookie-free and separate from mobile advertising and consent services. The mobile app may show explicit rewarded ads, subject to Google consent controls and your choices.
1. Who is responsible
Data Controller / Veri Sorumlusu: Buğra Kaan Sağlam. Chess Mutator is operated by an independent individual developer in Türkiye, based in Ankara, Türkiye. For privacy and support correspondence, contact [email protected]. A postal/service address is not established for this notice; we do not publish a residential or street address.
This notice covers chessmutator.com, its account and support pages, the Chess Mutator mobile app, and services that link to it. App stores, Google, Supabase, Cloudflare, email providers, and other third parties may publish separate notices.
2. Information we process
Accounts may include an email address, Supabase user identifier, confirmation state, session metadata, and a password-derived authentication record held by Supabase. Google sign-in may process identity and basic profile information. A guest is a real authenticated Supabase anonymous account, not offline play or a device identity; its cloud profile, progression, attempts, matches, entitlements, and rewarded-ad state remain server-controlled.
The service may process username, progression, achievements, statistics, attempt and match state, level and mode, player colour, match seed and starting position, terminal results, Undo Move state, and rewarded-ad totals to provide the game and enforce integrity rules.
The mobile app contains the Google Mobile Ads SDK and User Messaging Platform (UMP). Those services may process device or advertising identifiers, IP address, app interactions, diagnostics, ad request and delivery data, consent choices, and fraud-prevention signals. Rewarded flows use short-lived server verification data; the database stores the token hash, not the raw token.
For anonymous-account abuse prevention, the app uses an opaque random installation signal in secure storage where supported. It is not account, gameplay, advertising, or device-tracking identity. Support, feedback, deletion, and diagnostics requests may contain the contact, request, device, browser, operating-system, app-version, and safe technical details that you choose to provide. Do not send passwords, tokens, reset links, private keys, payment data, or arbitrary secrets.
Your username is a public game display name. It may be shown to other players only on the global leaderboard, together with your leaderboard rank and total-star score. Email addresses, Supabase user IDs, and private account information are not publicly shown.
3. Sources and purposes
Information comes from you, your selected identity provider, the app or browser, security and advertising services, Turnstile, and website requests. We use it to authenticate and secure accounts, deliver cloud progress and matches, grant verified rewards, prevent abuse, operate support and deletion channels, diagnose failures, maintain compatibility, and comply with law.
Depending on the jurisdiction, the legal bases may be service performance, consent, legal obligation, and legitimate interests in security, fraud prevention, operation, and support. Consent can be withdrawn through the available control or by contacting us; withdrawal does not undo earlier lawful processing.
4. Cookies, local storage, and permissions
The checked-in app requests no camera, microphone, contacts, location, health, notification, or OS-level advertising permission. Mobile advertising is provided by Google Mobile Ads only through explicit rewarded flows, subject to UMP consent choices and platform/provider rules.
5. Providers and disclosures
Chess Mutator uses Supabase for Auth, database, Edge Functions, and game infrastructure; Google Sign-In/OAuth, Google Mobile Ads, UMP, and Google Fonts; Cloudflare Turnstile for bot protection; Cloudflare Pages for website hosting and delivery; Cloudflare Web Analytics for browser performance metrics; and Apple and Google app platforms. Support is available through the email address listed on this site. No separate website analytics beyond Cloudflare Web Analytics, crash-reporting, payment, social, location, or upload service is used by the checked-in application.
6. International processing
Providers may process information outside your country. Provider region, subprocessors, and transfer safeguards are controlled by provider accounts and contracts. Where the law requires a transfer mechanism or additional safeguard, the operator must make it available through the relevant provider or request channel.
7. Retention
Information is kept only as long as needed, unless law, security, disputes, or backups require longer. Account state remains until deletion or a lawful exception. Finalized matches, rewarded-ad requests and events, and Undo Move events are normally removed after 60 days; inactive matches enter that window after seven days. User-error aggregates expire after 60 days without recurrence, diagnostic rate-limit rows after two days, and eligible anonymous guests may be deleted after 365 full days without server activity. Ordinary support, feedback, privacy, and deletion request rows that are resolved or rejected are scheduled for deletion 14 days after the request/case is resolved, where technically and legally reasonable; active requests remain until resolved. Security, abuse, legal, dispute, provider, mailbox, and backup records may have separate or longer retention.
8. Account deletion and data control
The public deletion request page remains available after uninstall. Submission starts a verified review; it does not delete an account immediately. Completed deletion removes the Auth user and current account-owned state through the existing boundary. The support request remains as an operational record and its user link is detached. Security, abuse, legal, dispute, storage, and backup records may remain where a lawful exception applies. Signing out, clearing browser storage, or uninstalling is not account deletion.
9. Your rights and choices
Subject to applicable conditions, you may have rights to information, access, correction, deletion, restriction, objection, portability, consent withdrawal, and review of certain automated outcomes. Türkiye KVKK Article 11, EEA and UK GDPR, and California CCPA/CPRA rights may apply. We do not use solely automated processing for legal or similarly significant decisions, although security controls may delay an account action.
Send privacy requests to [email protected] or use the deletion form. Provide only the minimum information needed for verification; we may request reasonable proof of identity.
10. Security
We use TLS/HTTPS, Supabase Auth and RLS/RPC boundaries, server-only secrets, secure storage, rate limits, redacted diagnostics, bounded request bodies, and signed server-side ad verification. No system is completely secure. Report suspected compromise promptly without credentials.
11. Children
The services are not directed to children under 13. If a parent or guardian believes a child has provided information unlawfully, contact [email protected]; we will review it under applicable law.
12. Changes, links, and complaints
We may update this notice when the service, providers, practices, security measures, or law changes. The effective and last-updated dates will change for a new version. Third-party links and providers have their own terms. For privacy, legal, security, or data requests, contact [email protected] or the competent authority where you live.