Home
Resources
Privacy

Privacy Policy

How RepertoireLab processes personal data for accounts, cloud sync, training features, billing, support and optional chess account integrations.
Last Updated
6 September 2026
Controller
The controller for RepertoireLab is Ben Zeller. Contact: repertoirelabinfo@gmail.com.
Im Oberried 28
87665 Mauerstetten
Germany
These details are limited to the provider and privacy contact information needed for transparency and legal notices.
No data protection officer is stated for RepertoireLab. Privacy requests can be sent to the contact email above.
Scope
This policy covers the RepertoireLab web app and supported mobile app experiences. It does not replace the privacy notices of third-party services such as Paddle, Apple, Google, RevenueCat, Supabase, Lichess or Chess.com when those services process data under their own terms.
Data We Process
-
Account data: email address, authentication identifiers, account settings, session data and a dated record of the Terms/Privacy versions acknowledged at signup.
-
Cloud data: repertoire folders, opening lines, moves, PGN/FEN content, side selections, order data and timestamps.
-
Training data: progress, statistics, spaced repetition state, daily tasks, completed games, local practice history and cached analysis results.
-
Product analytics: a random installation ID, app version, platform, coarse usage events such as onboarding or training completion, session counts and durations. Product analytics does not include chess moves, repertoire names or advertising identifiers.
-
Billing data: plan status, entitlement status, price/product IDs, Paddle customer IDs, subscription IDs, transaction IDs and renewal/period information.
-
Mobile purchase data: app-store receipt or purchase-token information and entitlement state processed through RevenueCat, Apple App Store or Google Play where applicable.
-
Chess account data: optional Lichess OAuth token/account ID/username, optional Chess.com username and public games fetched for analysis.
-
Technical data: device, browser, operating system, platform, IP address in provider logs, error details and security/audit information needed to run the service.
-
Support data: messages, email metadata, receipts, order IDs and other information you send when asking for help.
Local Storage
RepertoireLab can store app state in browser localStorage on web and AsyncStorage on mobile. This includes onboarding state, settings, local repertoire data, notification settings, cached analysis results and training progress. Local data stays on the device unless you sign in, enable cloud sync or use a feature that sends data to a provider.
Cookies and Similar Storage
RepertoireLab does not use advertising cookies. On the web, it uses browser localStorage and similar device storage for settings, authentication sessions, security, consent choices, local repertoire data and other functions you request. This necessary storage cannot be switched off through the privacy banner because the relevant feature would not work without it.
Optional product analytics is off until you select “Allow analytics.” If you select “Necessary only,” no product analytics events are sent. Your dated choice and the policy version are stored on the device. You can reopen Privacy choices from the website footer or change Product analytics in Settings at any time.
Paddle.js is loaded on the pricing or checkout flow to retrieve localized offer prices and provide secure payment. Paddle may use cookies or similar technologies needed for checkout, fraud prevention and service security and provides its own notice and controls for any optional tracking it operates.
Cloud Sync
Supabase is used for authentication, database storage, row-level access controls and cloud sync. When you create an account or use cloud-backed features, your account, repertoire and training data may be stored in the Supabase project so the service can authenticate you and keep your data available across supported devices.
Product Analytics
RepertoireLab uses first-party, pseudonymous product analytics to understand whether onboarding succeeds, training sessions are completed and users return on later days. Events are stored in the RepertoireLab Supabase project and are visible only through a protected aggregate admin dashboard. Signed-in events may be linked to the account identifier so account-level support and retention can be understood.
Product analytics is disabled unless you affirmatively allow it. You can disable it at any time in Settings. Disabling it stops future collection on that device and clears unsent events. Previously collected data may remain for the limited retention period or until a valid deletion or objection request is processed.
Payments
Web checkout is handled by Paddle. Paddle may act as reseller or merchant of record and processes payment details, invoices, tax information, fraud checks, refunds and subscription management. RepertoireLab stores only the billing identifiers and entitlement status needed to activate and verify Pro access.
Mobile purchases may be handled by Apple App Store or Google Play and entitlement verification may use RevenueCat. RepertoireLab does not store full card numbers or full app-store payment credentials.
Chess Integrations
Lichess connection is optional. If you connect Lichess, RepertoireLab stores an OAuth access token locally and may request your Lichess account username, public games, opening explorer data and cloud evaluations from Lichess APIs.
Chess.com connection is optional and uses a public Chess.com username. RepertoireLab may fetch public game archives and PGNs from Chess.com to compare recent games against your repertoire.
Opening explorer, game analysis and evaluation features may send board positions, move strings or FEN values to external chess data providers. Do not enter private personal information into repertoire names, imported PGNs or notes unless you want it processed with the feature.
Notifications
Mobile notifications are local reminders for daily tasks, streaks and inactivity. The app stores notification settings, permission state, scheduled reminder data and local statistics. RepertoireLab does not currently register push tokens with its own server for these reminders.
Legal Bases
-
Contract performance, GDPR Article 6(1)(b): account access, cloud sync, paid features, support and requested training functionality.
-
Legal obligations, GDPR Article 6(1)(c): tax, accounting, refund, chargeback, fraud-prevention and compliance records.
-
Legitimate interests, GDPR Article 6(1)(f): service security, abuse prevention, reliability, debugging and strictly necessary local caching.
-
Consent, GDPR Article 6(1)(a): optional product analytics, Lichess connection, notifications and any other non-essential device access or permissions where requested.
Processors and Recipients
-
Supabase: authentication, database hosting, cloud sync and backend functions.
-
Paddle: web checkout, billing, invoices, taxes, fraud checks, refunds and subscription management.
-
RevenueCat: mobile entitlement verification and app-store purchase state.
-
Apple and Google: app-store distribution, in-app purchase handling and refund workflows where applicable.
-
Lichess and Chess.com: optional chess account integration, public game data and opening analysis.
-
Lichess Opening Explorer and chess-api.com: board-position statistics and optional engine evaluation requested by analysis features.
-
Email and support providers, if used: user support, legal notices and account communications.
International Transfers
Some providers may process data outside the European Economic Area. Where required, transfers should rely on an adequacy decision, standard contractual clauses or another lawful transfer mechanism. The operator must keep the required data processing agreements and transfer safeguards with processors before public launch.
Retention
-
Account and cloud data are kept while your account exists or until you request deletion, unless legal retention duties require longer storage.
-
Billing, invoice, tax, refund and chargeback records may be retained for statutory limitation, tax and accounting periods, which can be up to ten years under German rules.
-
Local device data remains until you clear app/browser storage, uninstall the app or use an in-app reset/delete function.
-
Pseudonymous product events should be kept only as long as needed for cohort comparison and product improvement, normally no longer than 13 months, then deleted or aggregated.
-
Lichess tokens and connected account usernames are kept until you disconnect the account or clear local storage.
-
Support messages are kept as long as needed to answer the request and handle legal or security follow-up.
Your Rights
If the GDPR applies, you may request access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interests and withdrawal of consent for future processing. You may also lodge a complaint with a competent data protection supervisory authority in the EU.
Send requests to repertoirelabinfo@gmail.com from the email address associated with your account. RepertoireLab may need reasonable information to verify that the request comes from the account holder.
Deletion
You can permanently delete your account and cloud-stored chess data in Settings, or request help at repertoirelabinfo@gmail.com. Account deletion also removes analytics events linked to that account and pseudonymizes the email in RepertoireLab's retained billing-link record. Deleting the app alone does not delete cloud data. Billing, tax, fraud, refund and app-store records may remain where law or a payment provider requires them.
Data Minimization
RepertoireLab does not request a real name for a standard account and does not collect advertising identifiers, contacts, precise location, microphone, camera or full payment-card data for its core service. Optional integrations are activated only when you choose to use them.
Automated Decisions
RepertoireLab does not use automated decision-making that produces legal effects for users. Entitlement checks may automatically decide whether Pro features are active based on billing status.
Children
RepertoireLab is not directed to children. Users under the age required to create an account or consent to online services in their country should use the service only with permission from a parent or legal guardian.
Provider Policies
Provider privacy information is available from the respective providers, including Supabase, Paddle, RevenueCat, Apple, Google, Lichess and Chess.com.