Privacy Policy
Last updated: August 2, 2026
This Privacy Policy explains how MY NOVELTY LABS LLC, which operates MyNovelty (“MyNovelty,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you use mynovelty.io, our applications, the MyNovelty UCI bridge, and related services (collectively, the “Service”).
MyNovelty provides chess analysis, cloud chess engines, repertoire storage, game databases, broadcasts, and related tools. This policy applies to information handled by MyNovelty. Third-party services have their own privacy practices.
To change in-product privacy controls, open Settings > Privacy.
Information We Collect
Account and authentication information
We collect your email address, optional display name, password hash, account settings, plan, token balance, and account-security status. If you use a supported social sign-in, we receive a stable provider identifier and available profile information such as your email and name. We store security information such as active sessions, API-key labels and hashes, two-factor-authentication records, and recovery-code hashes. We do not store your plain-text password, API keys, or recovery codes.
Chess content and analysis data
We process PGN files, repertoire files and folders, annotations, game metadata, positions in FEN format, engine settings, and other chess content you submit. When you choose a cloud engine, the current position and analysis parameters are transmitted to cloud compute so the engine can return analysis. Position data is held in memory for the active engine session and is not written to engine logs by default. We retain session and usage metadata needed to operate the Service and account for compute usage.
The Service also includes professional and public chess-game data from public sources. Those records may contain player names, ratings, event details, and game scores, whether or not a player has a MyNovelty account.
Payments and purchases
Stripe collects and processes payment-card details. We receive and store Stripe customer and transaction identifiers, subscription status, billing term, purchased token amounts, payment status, and records of automatic top-up attempts. We do not receive or store complete payment card numbers.
Usage, device, and security information
We collect request timestamps, IP address or a coarsened IP prefix, approximate city and country, browser or device information, app and bridge version, routes used, session activity, engine type and duration, tokens charged, error information, and security events. This information helps us authenticate users, prevent abuse, diagnose failures, measure capacity, and account for usage.
Feedback and support
If you send feedback or request support, we collect your message and contact information. A feedback report may include screenshots, audio clips, the page URL, app version, browser information, plan, and other context shown to you in the feedback flow. If audio transcription is enabled for internal feedback review, an authorized administrator may request that the clip be sent to our transcription provider.
Information stored on your device
The web application stores authentication tokens, a limited account profile, a browser-scoped privacy-choice record, open chess-workspace content, and interface or engine preferences in browser storage. The functional preference portion of that storage stays off until you allow it on the device you are using. The UCI bridge stores its configuration and authentication credential on your device. See our Cookie Policy for details and controls.
Private chess content controls
- Local engine analysis stays on your device.
- Cloud engine analysis processes only the current position and engine parameters needed for the live session.
- Raw board text is not intentionally retained in ordinary logs or Sentry payloads.
- Public Lichess fallback is off by default for private workspaces. If you explicitly enable it, the FEN for a position our local tablebase cannot answer is sent through MyNovelty's tablebase proxy to the public Lichess tablebase service. When functional preferences are rejected, that choice is session-only for the current tab.
- Account deletion erases the active MyNovelty server/account systems tied to the account. Local or offline copies already on your device are not remotely wiped, and version history is capped at the newest 50 versions and nothing older than 30 days.
Sources of Information
We receive information directly from you, automatically from your use of the Service, from payment and sign-in providers you choose, and from public chess sources. If another person submits a public chess game or a support report that refers to you, we may receive information from that person.
How We Use Information
- Provide, personalize, maintain, and secure the Service, including accounts, sync, cloud analysis, privacy choices, data export, and customer support.
- Process purchases, administer subscriptions and promotions, account for token usage, and prevent payment fraud.
- Send transactional messages such as verification, security, billing, service, and data-export notices.
- Monitor reliability, troubleshoot errors, enforce our Terms of Service, prevent abuse, and protect users and the Service.
- Analyze aggregate usage, improve product features, plan capacity, and develop new features.
- Comply with law, enforce legal rights, and respond to lawful requests.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use third-party advertising trackers.
No optional analytics or advertising technologies are active in the current product experience. If that changes, we will update this policy, the Cookie Policy, and the available privacy controls before enabling the new processing where required.
Legal Bases for Processing
Where the law requires a legal basis, we process information as needed to perform our contract with you, comply with legal obligations, and pursue legitimate interests such as securing and improving the Service, preventing fraud, and supporting users. We rely on consent where required, including for optional features or communications. You may withdraw consent at any time, but withdrawal does not affect processing already completed and may prevent an optional feature from working.
How We Disclose Information
We disclose information only as reasonably necessary for the following purposes:
- Infrastructure and storage: Railway hosts application services, databases, and object storage. Oracle Cloud Infrastructure and RunPod may provide cloud engine compute. A cloud position and engine parameters are sent to the compute provider selected by the Service.
- Payments: Stripe processes checkout, subscriptions, saved payment methods, fraud checks, token purchases, and optional automatic top-ups.
- Security and reliability: Cloudflare provides network security and Turnstile bot detection. Sentry receives error and diagnostic events; our configuration disables default collection of personally identifying information and redacts secret-like values.
- Email: Resend or SendGrid delivers transactional email.
- Sign-in and connected features: Google, Facebook, or Chess.com processes information when you choose its sign-in or connection flow. We do not receive the password you use with those providers.
- Chess data services: when a position cannot be served by our local tablebase and you explicitly enable public Lichess fallback for a private workspace, the position in FEN format may be sent through MyNovelty's tablebase proxy to the public Lichess tablebase service. We also retrieve public games and broadcasts from chess-data sources.
- Optional transcription: OpenAI may process audio from a feedback report only if transcription is configured and an authorized administrator requests it.
- Legal and safety: we may disclose information when we reasonably believe it is necessary to comply with law, protect rights or safety, investigate fraud or abuse, or respond to lawful process.
- Business transfers: information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
Service providers may process information only to perform services for us or as otherwise permitted by their agreements and applicable law.
Retention
- Account and user content are generally retained while your account is active or until you delete particular content.
- Access tokens expire after a short period; active refresh sessions expire after up to 30 days and are rotated or revoked when you sign out, revoke a session, or delete your account.
- Cloud positions are processed for the live engine session and are not intentionally retained in engine logs by default. Usage records do not include the full analyzed position by default.
- Version history for private repertoire content is capped at the newest 50 versions and nothing older than 30 days.
- Data-export archives are available for seven days and are scheduled for removal from object storage shortly afterward.
- Feedback reports are ordinarily retained for up to 365 days while open and up to 180 days after they are resolved or dismissed.
- Billing, fraud-prevention, security, tax, dispute, and legal records may be retained for the period reasonably necessary for those purposes or required by law.
When you delete your account, we erase the active MyNovelty server/account systems tied to it, including direct account identifiers, credentials, active login sessions, connected identities, API keys, private repertoire content, version history, and generated export files. Local or offline copies already on your device are not remotely wiped. We may retain de-identified or pseudonymous service records, public chess records, billing records held by us or Stripe, security records, and backup copies where needed for the purposes above. We take reasonable steps not to use retained records to re-identify you except for security, fraud, legal, or compliance purposes.
Your Rights and Choices
Depending on where you live, you may have the right to know, access, correct, delete, restrict, object to, or obtain a portable copy of personal information, and to withdraw consent or appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
- Open Settings > Privacy to review privacy choices, export your data, open session and security controls, or reach the account-deletion flow.
- Control browser storage through your browser, use supported “Privacy choices” entry points to revisit your browser preference record, and sign out to remove account-scoped data from that browser.
- Email privacy@mynovelty.io for another privacy request or to appeal a decision.
We may need to verify your identity before fulfilling a request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct verification with you. You may complain to your local data-protection authority where that right applies.
International Transfers
MyNovelty and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use contractual or other lawful safeguards for international transfers.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, hashed credentials, access controls, session revocation, and secret redaction. No system is completely secure, so we cannot guarantee absolute security. Keep your credentials private and contact us if you believe your account has been compromised.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information in violation of this policy, contact us so we can investigate and delete it as appropriate.
Changes to This Policy
We may update this policy as the Service or law changes. We will post the updated policy here and change the “Last updated” date. If a change materially reduces your rights, we will provide additional notice when required by law.
Contact
MY NOVELTY LABS LLC is the controller of personal information covered by this policy. For questions or privacy requests, contact privacy@mynovelty.io. For general support, contact support@mynovelty.io.