Privacy Policy
Effective date: 12 August 2026
1. Controller
Felix HierstetterOrtrudstr. 4
81925 München, Germany
support@opening-lab.org
2. Data we process
- Account data: username, email address, password hash, account status, verification timestamps, latest login and authenticated-use timestamps, any inactivity-warning and planned-deletion timestamps, and the Terms version and time you accepted.
- Beta waitlist data: email address, confirmation and invitation status, and related timestamps. We do not collect a password when you join the waitlist.
- Chess and usage data: repertoires, PGNs, training progress, annotations, reports, review state, preferences, and linked chess-service usernames you choose to use.
- Technical data: IP address, request time, requested resource, response status, user agent, session identifier, and security/rate-limit events.
- Communications and feedback: email address, subject, message, account username if signed in, and related correspondence when you contact support; category and message when you submit in-app feedback. Opening Lab does not attach your username, email address, or IP address to in-app feedback, although the message may contain information you choose to provide.
We do not require your real name, postal address, public profile, or payment details for an Opening Lab account. Passwords are stored as one-way hashes, not readable text.
3. Purposes and legal bases
We process account, session, and chess data to provide the service and requested features (Article 6(1)(b) GDPR). We process security, limited server-log, abuse-prevention, service-stability, and support data based on our legitimate interests in operating and protecting Opening Lab and responding to users (Article 6(1)(f) GDPR). We process data where necessary to comply with legal obligations (Article 6(1)(c) GDPR).
Providing account and chess data is necessary if you want those features. You may use the public landing and legal pages without an account.
4. Hosting, email, and recipients
Opening Lab runs on a STRATO VPS in Germany. STRATO processes hosting infrastructure and server-log data on our behalf. We use an email service configured for opening-lab.org to deliver verification, recovery, beta-waitlist, inactivity-warning, and support messages. Access is limited to service providers and persons who need it to operate the service, or authorities where disclosure is legally required.
5. Sessions and browser storage
After sign-in, we set one essential, HTTP-only session cookie named sid. It is required for authentication, uses SameSite=Lax, and expires after up to 30 days of inactivity. No advertising or analytics cookies are used.
The application uses browser local storage for local preferences, cached chess data, training state, and resilience while synchronizing. Local data remains on your device until the application or you remove it; browser controls can clear it at any time. Signing out does not automatically erase all local training data because it supports later continuation. Account deletion clears the known local data for that account in the current browser.
6. Optional external services
When you choose a feature that requests data from Lichess or Chess.com, Opening Lab sends the necessary username, position, or game query to that service. Lichess sign-in uses OAuth; an access token may be held in your server session to access the permissions shown by Lichess. These providers process technical request data under their own privacy notices.
The “Support Opening Lab” link opens our external Buy Me a Coffee page. Opening Lab does not embed Buy Me a Coffee and receives no payment-card data. Buy Me a Coffee and its payment provider, Stripe, independently process payments and may provide us with supporter account details or messages through the creator dashboard. We do not publish those details or use them for marketing. Their processing may involve the United States and their stated transfer safeguards.
7. Retention
- During the limited beta, non-administrator accounts are considered inactive after two months without a login or other authenticated use. We then email a warning and schedule deletion 14 days later. Any login, authenticated use, or use of the retention link cancels the planned deletion. If it is not cancelled, we apply the same complete deletion process used for a user-requested account deletion.
- Confirmed beta-waitlist entries are retained until an account place is accepted or the entry is no longer needed. Invitation links expire after 7 days; expired reservations return to the waitlist. Waitlist data linked to a completed registration is removed after email verification.
- Unverified registrations are removed after 25 hours. Email-verification links expire after 24 hours and password-reset links after 30 minutes; expired or used tokens are routinely deleted.
- Application sessions expire after up to 30 days of inactivity.
- STRATO states that provider-side IP log files are retained for no more than 7 days. Opening Lab application logs should normally be rotated within 14 days. Aggregate operational counters and runtime summaries are retained for up to 45 days, and security-incident extracts may be retained for up to 90 days where needed.
- In-app feedback is held in the operational database until it is included in the next successful daily report, and for no more than 45 days if reporting remains unavailable. The resulting report email is treated as support correspondence.
- Support correspondence is normally deleted within 12 months after the matter is resolved, unless it is needed longer for legal claims or obligations.
- Where rolling backups are enabled, deleted data may remain inaccessible in backups until overwritten, normally within 30 days. Backups are used only for disaster recovery.
8. Account export and deletion
You can download an account-data export and permanently delete your Opening Lab account through Account. The export includes the recorded account-activity and any planned-deletion timestamps. User-requested deletion requires your password and username. Both user-requested and completed inactivity deletion remove the account, synchronized chess data, opponent-preparation reports, and active sessions. The inactivity-warning email also reminds you to export first and includes a link that retains the account. Data held independently by Lichess, Chess.com, Buy Me a Coffee, Stripe, or your email provider must be managed with those providers.
9. Your rights
Subject to the GDPR’s conditions, you may request access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interests. You may also complain to a supervisory authority. Contact us at support@opening-lab.org.
Our competent supervisory authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
10. Security, age, and changes
We use measures appropriate to the service, including encrypted transport, hashed passwords, restricted database permissions, essential-only cookies, access controls, and rate limits. No online service can guarantee absolute security. Opening Lab accounts are intended only for adults aged 18 or older.
We may update this Policy when the service, providers, or law changes. Material changes will be communicated in the application, and the effective date above will be updated.