← WeChessUp

Privacy Policy

Last updated 16 August 2026

WeChessUp is operated by CoreSync Technology Inc., a Massachusetts corporation, at 148 Concord Road, Wayland, MA 01778, United States. “We” and “us” below mean that company. You can reach us at admin@wechessup.com.

This policy explains what WeChessUp collects, why, who else processes it, how long it is kept, and how to get it removed. It covers both this website and the WeChessUp app for iPhone and iPad, which offers the player-facing half of the product — following a rated player (§5) and reading a live event page (§4). Everything below applies to both unless it says otherwise; §10 covers what is specific to running on a phone.

WeChessUp serves several quite different groups of people, and what we hold about you depends on which you are:

  • Tournament directors — adults who hold accounts and run events (§1).
  • Players and parents — adults who hold accounts to follow rated players they have a right to follow (§2, §5).
  • Players entered by a director — people, often children, whose details an organiser types into a roster (§3).
  • Followers — people who subscribe to updates about a live event (§6).
  • Visitors — people who read a public page (§4, §10).

1. Account data

  • Your name and email address, so we can identify you and send account email.
  • A password hash, or an identifier from Google, Microsoft, GitHub or Apple if you sign in with one of those. We receive your address and basic profile from the provider; we never receive your password for that provider. If you use Sign in with Apple and choose Hide My Email, the address we hold is Apple’s relay address rather than your own — that is fine, and our mail still reaches you.
  • Optional profile details you add yourself: a profile photo, an organisation or club, a phone number, your preferred language and time zone, and your own federation IDs (US Chess, FIDE, CFC, DWZ). The photo is stored in a private bucket, is shown only in your own account, and is never published on a live page or included in an export. The phone number is for our support desk only — it is never shown to a player and never appears in an export.
  • Security questions, if you set them. We store the two questions you chose and a hash of each answer, never the answer itself. They exist so our support desk can check it is you when you write to us about a lost authenticator; they cannot sign you in and they cannot reset your password.
  • Messages you send us from inside the product. When you use the support form we store your message, its subject and topic, and a small technical context — the app or web version, the operating system version and your language — because they answer most questions without us having to ask. We do not attach your location, your device identifier or any advertising ID. A copy is emailed back to you when your address is confirmed.
  • Your subscription tier and, if you subscribe, a Stripe customer reference. We never receive or store your card number (§7).
  • Operational records: sign-in timestamps, rate-limit counters and abuse-prevention events, kept to run the service safely.

2. Player & family accounts (“Play”)

An account can be used in a player/family view instead of (or as well as) the director console. For those accounts we additionally store which players you have chosen to follow — see §5, which describes that feature in full, because it is the part of the product where the data is most personal.

3. Tournament data entered by directors

To pair a tournament and file a rated report, WeChessUp stores what the federations require: player names, ratings, federation IDs and expiry dates, sections, team assignments, results and, where a section is age- or grade-restricted, a date of birth, age or grade. A director may also record contact details for players or guardians to operate their own event.

For this data the tournament director is the controller and WeChessUp is the processor: the director decides what to collect, and we hold and process it on their instructions. If you are a player or a parent and want to know what is held about you, contact the organiser of your event first — they can see, correct and delete it directly. We will help them, and we will act on a request sent to us where the law requires it.

4. Public event pages

A director can publish an event to a public live page — pairings, results, standings, a schedule — reachable by an event code or QR without any sign-in, in a browser or in the app. What appears there is controlled per event, and the app shows exactly what the web page shows. Three protections are built in and always on:

  • No public page ever shows a date of birth, an age or a grade. Ages are used only to pick privacy defaults, and reach the director as counts, never per player.
  • Where the field appears to include minors, or where ages are unknown, defaults reduce displayed names and restrict who can be followed.
  • Live pages under /e/ are marked not-for-indexing to search engines, and revoking an event code stops future access. Federation IDs are hidden on public pages unless the director explicitly turns them on.

5. Adding a rated player (cached US Chess records)

A signed-in account can add a small number of rated players to its dashboard. Because the record is the federation’s public one, you do not have to be the player or their guardian: players, parents, coaches and directors all have lawful reasons to read it. What you agree to is how you will use it (Terms §5). This is the feature with the most personal data in the product, so here is exactly how it works:

  • It starts with an explicit step. You search our copy of the published US Chess rating list, pick the player, and confirm — on a screen that lists precisely what will be fetched — that you are asking us to fetch that player’s public record and will use it lawfully. We record the wording you were shown, so we can always tell what a given person actually agreed to.
  • Adding is limited, and that limit is a privacy measure. An account may hold only a few players and may add only a few distinct players in a rolling period; removing one does not reset the period. It exists so no account can walk the federation’s member list through us a few players at a time.
  • A photo is a separate decision. Uploading a picture of a player asks its own question — that you are that player, their parent or legal guardian, or have their permission (or their guardian’s, if they are under 18). Adding a player does not by itself give you that right.
  • What we then fetch, from the official US Chess Ratings API: the member’s public tournament record — ratings per rating system, rated sections with before/after ratings, game results with opponent names and states, monthly published ratings, awards and milestones, norms, appearances on official top-player lists, the list of events played (city, state, field size, organiser), and — for events you open — the official crosstable of those events, which is the same public record US Chess publishes. Nothing else: the member payload’s gender field is stripped before storage, and we never fetch anything about a player nobody has claimed.
  • Where it comes from. US Chess ratings and tournament results are public records published by the United States Chess Federation. We fetch them through the federation’s official API, identify ourselves honestly on every request, pace and cap our traffic, and stop on request. WeChessUp is independent — not affiliated with or endorsed by US Chess.
  • When we fetch, and how often. The step above says the record is kept up to date automatically, so here is precisely what that means. We ask for a player’s record when you sign in, and we skip any player whose record was already refreshed in the previous 24 hours. The Refresh button on a player’s profile overrides that, within a short cooldown. There is no background job that fetches on a schedule of its own: the work only happens for a player somebody is about to look at — which keeps our traffic to US Chess small, and means an account that stops using WeChessUp stops generating requests about the players it added.
  • Who can see it. Only accounts that claimed that player. There are no public player profiles. Two parents (or a parent and a coach, with the family’s consent) may claim the same player, in which case they see the same record.
  • Opponents appear in a claimed record because they appear in the public crosstable — their name, state and rating, exactly as US Chess publishes them. We add nothing about an opponent from any other source, and an opponent’s presence in someone’s claimed record creates no profile of the opponent here.
  • Removing the player deletes the record. When the last account following a player removes them, everything WeChessUp cached about that member — record, statistics, photo — is deleted in the same transaction. The claim itself (who consented, when, to what wording) is kept as our record of consent.
  • Live-page recognition. When you are signed in and open a live event page, we check — at that moment, server-side — whether any player on that event’s roster matches a player you follow, so yours can be highlighted without clicking. The result is computed per visit and not stored, and nothing about your follows is revealed to the page’s other visitors or to the director.

6. Followers and notifications

  • If you follow a live event, we store your email address or phone number, which channels you chose, and a record of your confirmation — the time, the IP address and the version of the disclosure you were shown.
  • Follows are double opt-in: an address is not used until it is confirmed. SMS additionally requires you to tick a separate consent box that names the sender, purpose, frequency and rates, and texts honour STOP and HELP.
  • Every message includes a way to stop that needs no login: a link in the message, and the one-click unsubscribe your mail app can show as a button. Unsubscribing from one event does not stop you following another.
  • Follower records do not outlive the event. They are deleted automatically 90 days after the event ends, by a job that runs daily — not on request, and not when someone remembers to.
  • Addresses that hard-bounce, complain, or reply STOP go on a permanent suppression list. That list is kept indefinitely and deliberately — it exists so we never message those addresses again, and deleting it would defeat its purpose.
  • Anti-abuse limits cap how often any address can be sent a verification message, so the follow form cannot be used to bombard someone else’s inbox or phone.

7. Payments

Subscriptions are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we hold your subscription tier, a Stripe customer reference, and the invoice/receipt records Stripe returns to us. Refund handling and cancellation are described in the Terms and in the app’s billing settings.

8. Player photos

An account that follows a player may upload one photo of that player — chosen from the photo library, or taken with the camera in the app. Photos are stored in a private bucket, capped in size, and served only through short-lived signed links to the accounts that follow that player — a player photo never appears on any public page. The photo is deleted together with the player’s record when the last follower removes them, and either follower can replace or remove it at any time. Upload rules and our right to remove images are in the Terms of Service.

Before anything leaves your device, the picture is cropped square and re-encoded there. That is a privacy measure as much as a size one: re-encoding discards the file’s embedded metadata, including the location the photo was taken at. Most of these photos are of children, and where a child was on a Saturday morning is not something we want to be holding.

9. Processors we use

  • Supabase — database, authentication, file storage and background functions.
  • Google Cloud (Cloud Run, Cloud Scheduler) — serves the web application, runs the pairing engine, and drives scheduled jobs. The engine receives tournament data to compute pairings and standings and does not retain it.
  • Cloudflare — DNS, and the Turnstile human-verification widget on our sign-in, sign-up and password-reset forms.
  • Stripe — subscription payments.
  • Amazon Web Services — account and notification email (SES), and SMS delivery (AWS End User Messaging), where enabled.
  • Twilio — alternative SMS delivery, where enabled.
  • Apple — distributes the iOS app, and operates Sign in with Apple for accounts that use it. Apple does not receive your WeChessUp data. If you have iOS’s “Share with App Developers” setting turned on, Apple may pass us anonymous crash reports about the app; we run no other crash or analytics reporting, in the app or on the web.

Human verification on the sign-in, sign-up and password-reset forms uses Cloudflare Turnstile. It loads a script from Cloudflare and sends signals about the browser and the request — not the contents of the form — so Cloudflare can judge whether the request came from a person. It does not use cookies to profile you across sites, and we do not receive anything about you from it beyond a pass or fail. The rest of our sign-up abuse prevention — rate limiting and blocking disposable email domains — runs inside our own database.

These providers process data on our instructions under their own data-processing terms. Some operate outside your country, so your data may be transferred internationally, principally to the United States, where we are based.

10. On your device: the app, its permissions, and local storage

This section is about what stays on your own hardware rather than on ours — the two permissions the app asks for, what each surface remembers locally, and what we deliberately do not do. If you only use the website, skip to In a browser below.

What the app asks your phone for. Two permissions. Both are optional, both are asked for at the moment they are used rather than at launch, and refusing either leaves the rest of the app working:

  • Camera — to scan the QR code on a table tent or a wall poster and open that event. The scan happens entirely on your device: no image is captured, stored or uploaded, and the app reads nothing from the frame except the code. You can type the event code by hand instead, and the app says so if you decline.
  • Photo library — read-only, and only when you are choosing a photo: either of a player you added (§8) or for your own account (§1). Uploading a player’s photo asks its own question first — see §5. The app never writes to your library and never reads it other than the one photo you pick, which it crops to a square and shrinks on the device before anything is uploaded.

It asks for nothing else. The app does not request your location, your contacts, your calendar, your microphone or your health data, and it does not ask to send you push notifications — event updates arrive by email or text, exactly as they do on the web (§6).

What the app keeps on your device. Your sign-in session, and any per-event visitor tokens, are held in the iOS keychain — encrypted by the operating system, not included in an iCloud backup, and gone when you delete the app. Your theme, the list of tournaments you have opened, and an offline copy of the last live page you looked at sit in ordinary app storage. That offline copy is deliberate: it is what lets a page you opened on venue wifi still show real pairings when the signal drops, and it is stamped with its own age on screen so it never passes itself off as current. Settings → Clear saved tournaments removes all of it.

The app contains no third-party SDKs, no analytics, and no advertising identifier. It does not track you across other companies’ apps or websites, which is why iOS never shows you an app-tracking permission prompt for it — there is nothing for us to ask permission for.

In a browser, we use local storage for your session and your interface preferences — theme, the screen you were last on, the tournament you had open, which players this browser follows on a live page, and the postcode you last searched the directory with. Live pages keep a random per-event device token in your browser so your check-in and “who I’m here for” choices survive a reload; the server stores only a hash of it.

That token works the same way in both places, and its shape is the point: it is one token per event, generated on your device. A phone at two tournaments holds two unrelated tokens, and nothing in our database can join one event’s visitors to another’s — that is a fact about how the data is stored, not a promise about how we behave. Clearing your browser data, or deleting the app, ends the relationship completely. We do not use advertising cookies or third-party analytics trackers.

11. How long we keep things

  • Tournament data: until the director deletes it or closes their account. Events can be archived rather than deleted so historic results stay available.
  • Claimed player records (§5): while at least one account follows the player; deleted transactionally when the last follower removes them. The consent record itself is retained.
  • Player photos: same lifetime as the claimed record, or until a follower removes the photo.
  • Follower records: 90 days after the event ends, then deleted automatically.
  • Suppression list: indefinitely, as described in §6.
  • Account data: deleted when you close your account, except records we must keep for tax, accounting or legal reasons.
  • Directory listings: while the event is upcoming and for a period afterwards as a record of what took place. A submitter’s contact details are removed on request at any time.
  • Cached federation reference data (the published rating list, national rank counts): refreshed on the federation’s publication cycle; superseded copies are not kept.

12. Children

WeChessUp accounts are for people 16 and older; we do not knowingly let a child create an account or give us information directly. Junior chess, however, means the product necessarily handles information about children, and it does so in three tightly scoped ways:

  • Rosters — a director enters players, often minors, to run an event. The director is the controller (§3); our publication defaults (§4) reduce what is shown publicly when the field appears to include minors, and no public page shows a birth date, age or grade.
  • Following a live event — an adult subscriber must confirm their own age and, where a director requires it, hold the code from the player’s badge before following one named player.
  • Claimed records (§5) — an adult affirms they are the player or the player’s parent/legal guardian before anything is fetched, the record is visible only to accounts that made that affirmation, and it is deleted when the last of them removes the player.

The app adds no child-facing surface. There is no screen in it a child would open by themselves: no game to play, no player login, nothing to do but follow a rated player or read an event page — both of which are things the adult holding the phone does. It is used for adult tournaments as much as scholastic ones. So information about a child reaches us in one of two ways only: an adult who has affirmed their relationship to that player gives us the player’s member number, or it comes from the public record US Chess itself publishes. Nothing is collected from a child.

If you believe a child has given us information directly, or that someone has claimed or is following a child without the right to, email admin@wechessup.com — we will investigate and remove data and access as appropriate. We will act on such a request whether or not the person asking holds an account with us.

13. The tournament directory

We publish a directory of upcoming chess tournaments. A directory listing describes an event — its name, dates, venue, sections, entry fee and organiser — and never describes a player. No entrant, and no child, appears in it. Most listings are sent to us by the organiser; some are built by reading tournament calendars organisers have already published publicly, always with the source named and linked, and any site can have itself excluded in one email (wechessup.com/bot). If you submit a listing we store your name and email to confirm it is yours; that address is not published unless you ask. Searching by distance keeps your postcode in your own browser; “use my location” asks your browser’s permission, runs one search, and stores nothing. Directory pages are indexable because being found is their point; live pages carrying player names are not (§4).

14. Your rights

Depending on where you live — including under the GDPR if you are in the EEA or UK, and under state privacy laws such as the CCPA/CPRA if you are in California — you may have the right to access, correct, export or delete your data, to object to or restrict processing, to withdraw consent, and to complain to a data-protection authority. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

  • Account holders can export tournament data, and can remove individual tournaments and claimed players at any time from within the product.
  • You can delete your whole account yourself, and it happens immediately. On this website it is Settings → Security → Delete my account; in the app it is Settings → Delete account. Both ask you to type the word DELETE, because it is the one thing here that cannot be undone. No email, no waiting period, and nobody has to approve it.
  • What deleting removes: your sign-in details and email address; every player you follow — including the cached US Chess record and photo of any player no other account follows; and any tournaments and live pages you own, which takes their public pages down with them. Before you confirm, the screen tells you how many of each there are, counted at that moment.
  • If you have a paid subscription, it has to stop before the account can go — an account that vanished while its subscription kept billing would leave you with nothing to cancel from. On this website, deleting does both in one step: it cancels first, you keep the access you have already paid for until the period ends, and Stripe does not charge you again. The app does not carry any billing screens, so there it asks you to cancel on the website first and then delete. Either way, if you would rather have a refund than a cancellation, ask on the Subscription tab before you delete — the refund window is described in the Terms.
  • Three things outlast the account, and each is deliberate. The suppression list keeps addresses that bounced, complained or replied STOP (§6) — removing an entry would silently re-subscribe someone who opted out. An SMS follow survives, because it is keyed to a phone number you never gave the account and nothing links the two; reply STOP to any message, or use the link in it, and it ends at once. And we keep a dated note that a deletion happened, holding nothing that identifies who — no name, no address, no account reference — so that we can answer “was this account deleted, and when” without keeping the very thing the deletion removed.
  • For anything else, email admin@wechessup.com. We will verify the request is really yours, answer within 30 days, and never discriminate against you for exercising a right.
  • If your request concerns data a director entered about you, we will point you to the organiser (the controller) and help them comply (§3).

15. Security

Data is encrypted in transit. Every tournament table is protected by row-level security so one account cannot read another’s data; claimed-player reads are checked against the claim on every call; file storage is private, path-scoped and served by signed URLs; the app keeps your session in the device keychain rather than in ordinary app storage, and marked so it is never carried into an iCloud backup; and service credentials are held outside the codebase. No system is perfectly secure; if a breach affects you we will notify you as the law requires.

16. Changes

We will update this policy as the service changes. The date above tells you when it last changed, and material changes will be announced on the website and in the app before they take effect.


Questions about this document? Email admin@wechessup.com.