Chess Mutator

Maintenance in progress

Chess Mutator is temporarily unavailable while we make a safe update.

Skip to content
♔CHESSMUTATOR
The GameMutationsGalleryFAQSupport
Play ↗Login

Legal / 01

Privacy
policy.

Effective date: 16 August 2026

Privacy matters. This notice explains what information the current Chess Mutator website and account flows process, why they process it, which providers are involved, how long information is kept, and how you can exercise applicable rights.

1. Who is responsible

The controller or operator for the Chess Mutator project is the person or entity publishing and operating Chess Mutator. The public contact for privacy, account, and data requests is bugraksaglam@gmail.com. If the project is operated through a registered company or other legal entity, that entity’s legal name and service address should be added to this notice before formal commercial distribution.

This Privacy Policy applies to chessmutator.com, its official pages, web account and authentication flows, support communications, and any official app or service that links to this notice. It does not control third-party websites, app stores, operating systems, or services that publish their own notices.

2. Information we process

Account and authentication information

When you register, sign in, confirm an email, reset a password, or use an account, the authentication service may process your email address, a user identifier, confirmation state, authentication events, session information, and security-related metadata. The website does not intentionally receive or store your password in plaintext; the password is submitted to and handled by the authentication provider.

Support and communications

If you email bugraksaglam@gmail.com or otherwise contact support, we process the email address, message, attachments, screenshots, and other information you choose to provide. We may also process the page, account action, device, operating system, browser, app version, and error details you include to reproduce and resolve a problem.

Technical and security information

Hosting, security, email, and authentication providers may generate technical records such as IP address, request time, browser or device characteristics, approximate location derived from an IP address, referrer, error information, and security or abuse signals. We do not use the current website to intentionally collect precise location, contacts, microphone, camera, or advertising profiles.

Local browser data

The browser authentication client may store session data locally so that a signed-in session can persist and refresh. The current website does not use advertising cookies or intentionally run cross-site behavioral advertising. Clearing browser storage or signing out may remove the local session, but does not by itself delete an account or provider records.

3. Why we use information

We process information only for specified and necessary purposes, including:

  • creating, authenticating, securing, maintaining, and recovering accounts;
  • delivering requested pages, game information, account functions, and support;
  • sending account confirmation, password reset, security, service, and legal messages;
  • detecting abuse, fraud, unauthorized access, attacks, and violations of the Terms of Use;
  • diagnosing errors, improving reliability, maintaining compatibility, and protecting the service;
  • responding to privacy, legal, consumer, and support requests; and
  • meeting legal, regulatory, accounting, dispute-resolution, and law-enforcement obligations where required.

Depending on the jurisdiction and context, the legal basis may be performance of a contract or requested service, compliance with a legal obligation, legitimate interests in security and operation, or consent where consent is required. We do not sell personal information and do not use account information for targeted advertising on the current website.

4. Service providers and disclosures

We may disclose information to providers that process it on our behalf or are necessary to deliver the service, including:

  • Supabase: authentication, account identity, session, and related service infrastructure;
  • Cloudflare or hosting infrastructure: website delivery, caching, security, and operational logs;
  • email providers: delivery of support messages and authentication emails; and
  • app stores and platform providers: only when you use their store, device, or app services.

We may disclose information if required by law, valid legal process, a court or regulator, an emergency involving safety, or the protection of rights, security, users, or the service. We may also disclose information in connection with a merger, acquisition, restructuring, financing, or transfer of the project, subject to applicable law and appropriate notice where required.

5. International processing

Our providers may process or store information in countries other than the country where you live, including countries that may have different data-protection rules. Where applicable law requires safeguards for an international transfer, the responsible provider or operator will use a recognized transfer mechanism or other lawful safeguard. Provider-specific locations, subprocessors, and retention periods may change; consult the provider’s current privacy materials for its own processing.

6. Retention

We keep information only for as long as it is reasonably necessary for the purposes described above, unless a longer period is required or permitted by law.

  • Account information is generally kept while the account is active and for a limited period needed to complete deletion, prevent abuse, resolve disputes, or meet legal obligations.
  • Support correspondence is kept for as long as needed to answer the request, document a security or legal issue, and protect our rights.
  • Operational and security logs are retained according to the applicable provider’s settings, security needs, and legal requirements.
  • Backups and residual copies may take additional time to expire under normal backup cycles and are protected from ordinary use while retained.

7. Security responsibilities

We use reasonable administrative, technical, and organizational measures appropriate to the service, such as managed authentication infrastructure, access controls, secure transport, limited public client configuration, and rate-limited account actions where supported. No website, email account, device, network, or storage system is completely secure. We cannot guarantee that unauthorized access, loss, or interruption will never occur.

You must use a unique password, protect your email account, avoid shared-device sessions, keep software updated, and report suspected compromise promptly. Do not send credentials or reset links by email. If we become aware of a legally reportable incident, we will follow applicable notification requirements.

8. Your rights and choices

Subject to applicable law and its conditions or exceptions, you may request information about processing, access to your personal information, correction of inaccurate information, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated decisions. In Türkiye, the rights available under Article 11 of the Turkish Personal Data Protection Law (KVKK) may apply. In the EEA or United Kingdom, GDPR or equivalent rights may apply. You may also have rights under the law where you live.

Send a request to bugraksaglam@gmail.com from the relevant account address where possible. State the request clearly, identify the account or communication involved, and provide a safe way to respond. We may request reasonable identity verification before disclosing, correcting, or deleting information. We will respond within the period required by applicable law or explain why additional time or a lawful exception applies.

Deleting a browser session does not delete a server account. Account deletion requests may be subject to security holds, fraud-prevention needs, unresolved disputes, backups, or legal retention. We will not require you to provide a password by email.

9. Children

The services are not directed to children in circumstances where collection would be unlawful. We do not knowingly request unnecessary personal information from children. If a parent or guardian believes a child provided personal information unlawfully, contact us at bugraksaglam@gmail.com; we will review the request and take appropriate action under applicable law.

10. Changes to this policy

We may update this Policy when the service, providers, data practices, security measures, or law changes. The effective date at the top will change for a new version. Where required, we will provide additional notice or request consent. Your continued use after an effective update means the updated notice applies to future processing, subject to your rights under applicable law.

11. Contact and complaints

For privacy questions, access, correction, deletion, portability, objection, security, or account requests, contact bugraksaglam@gmail.com. You may also have the right to complain to the data-protection authority or supervisory body in the country where you live, work, or believe a violation occurred. We encourage you to contact us first so we can investigate and try to resolve the issue.

CHESS MUTATOR

A changing board. A sharper mind.

PrivacyTermsSupportAccount
The contact squarebugraksaglam@gmail.com
© 2026 Chess MutatorBuilt for players who read the board twice.