Chess Sidebar
Plain-language policy

Privacy, without vague promises.

Chess Sidebar needs access to the game you choose to show. This page explains what stays in your browser, what is exchanged with Chess.com or Lichess, what reaches our server, and what is sent only when you choose to contact us.

Effective August 9, 2026 · applies to the Chess Sidebar extension and chessmirror.pages.dev

Scope

This policy covers the Chess Sidebar Chrome extension and the pages and APIs operated at chessmirror.pages.dev. Chess Sidebar is an independent product and is not affiliated with or endorsed by Chess.com, Inc. or Lichess.org.

Your use of Chess.com or Lichess remains subject to that service's own terms and privacy policy.

Data collection

To show an active game, Chess Sidebar collects and processes the board position, move sequence, clocks, game status, player display information, game identifier, and selected platform. Chess.com state is read from the open Chess.com tab. Lichess state is received from Lichess's official Board API after you choose to connect your account.

Connecting Lichess uses OAuth with the board:play permission. The extension receives a Lichess access token and basic account identity so it can locate supported active games, stream their state, and submit only moves and game actions you choose. The token is not your password and can be revoked from Lichess.

Live game state and the Lichess access token stay in your browser. Chess Sidebar does not send your moves, board positions, clocks, player names, ratings, Chess.com credentials, Lichess token, browsing history, or the contents of unrelated tabs to our server.

When a game finishes, Chess Sidebar automatically sends the following information to our game-counter endpoint:

  • the platform and its game identifier, used to prevent the same game from being counted twice; and
  • the installed Chess Sidebar version.

We collect this data to keep track of the number of games that have been played using Chess Sidebar. The counter record also receives a creation timestamp. It does not include the game's moves, result, player names, ratings, or account credentials.

The bug-report page may collect the description of what happened, what you expected, reproduction steps, error text, an optional game URL, optional contact email, and up to four screenshots. The extension version and browser user-agent shown on that form are included when you submit it. Contact information is used only to respond to the report.

The uninstall survey may collect a selected reason, an optional comment, and the extension version. The application does not add an account identifier, cookie, or user-agent value to the stored uninstall response.

Data handling

Live Chess.com and Lichess game data is handled locally by the extension only for board synchronization, clock and status display, premoves, and moves selected by the user. Lichess authorization is handled only to communicate with the official Board API. None of this data is used for chess analysis, advertising, profiling, or decisions unrelated to the extension's single purpose.

Completed-game platform identifiers, game identifiers, and extension versions are handled only to update the aggregate game counter and reject duplicate counts. Bug reports and uninstall feedback are handled only to investigate problems, respond when contact information is supplied, and improve Chess Sidebar.

When Chess Sidebar site pages or APIs are requested, Cloudflare may process standard network information such as an IP address, request headers, and security signals to deliver and protect the service. We do not use cookies or analytics on the Chess Sidebar site.

Data storage

Chrome's local extension storage holds display preferences, the selected platform, the Lichess OAuth access token and account name when connected, and a short list of completed platform-and-game identifiers that have already been counted. This prevents repeated authorization and duplicate counting. Disconnecting Lichess revokes and removes the locally stored token.

Our Cloudflare database stores the completed platform-and-game identifier, extension version, and creation timestamp used by the aggregate game counter. It also stores submitted bug-report text, optional contact information, extension version, browser user-agent, uninstall feedback, and submission timestamps. Optional report screenshots are stored in private Cloudflare file storage and are not made publicly accessible.

Completed-game counter records are retained to keep the aggregate count accurate and prevent duplicates. Bug reports, attached screenshots, and uninstall feedback are retained only for as long as reasonably needed to investigate problems, understand failures, and improve Chess Sidebar. We limit stored fields, validate submitted data, and restrict uploaded file types and sizes.

Data sharing

Counter, report, and uninstall data is shared only with Cloudflare, which provides the hosting, database, file-storage, delivery, and security infrastructure used by the Chess Sidebar site and APIs. User-selected Chess.com moves are sent to the open Chess.com game tab. When Lichess is connected, authorization requests, supported game state, account identity, and user-selected moves are exchanged directly between the extension and Lichess through its OAuth and Board APIs.

We do not sell personal information, share data with data brokers, use game data for advertising, or build advertising profiles. We do not otherwise disclose collected information except when required by law or necessary to protect the service and its users.

Chrome permissions

  • Side panel: displays the mirrored board and game controls beside the current tab.
  • Storage: keeps local preferences, Lichess authorization when connected, and recently counted game identifiers.
  • Identity: opens Lichess's authorization page and securely returns the OAuth authorization result to the extension.
  • Tabs: finds the active Chess.com game, communicates with it, returns to it on request, and opens Chess Sidebar support pages.
  • Host access to Chess.com: reads the active live game and submits only moves selected by the user.
  • Host access to Lichess: signs in with OAuth and uses the official Board API to locate supported games, stream their state, and submit selected moves.
  • Host access to chessmirror.pages.dev: updates the aggregate completed-game counter and opens Chess Sidebar support pages.

All executable extension code is packaged with the extension. Chess Sidebar does not download or execute remote code.

Contact and policy changes

For privacy questions or data requests, email rishidv2005@gmail.com or use the Chess Sidebar report form and include a contact email if you want a reply.

If this policy changes materially, the effective date at the top of this page will be updated. Continued use after an update is subject to the revised policy.