Last updated August 4, 2026
This policy describes what information zen.reinit.net (the “Service”) collects, why we collect it, how long we keep it, who we share it with, and the choices you have. It applies to all users of the Service worldwide. It is written to be honest about current practice rather than to maximise compliance theatre. If you have a question, write to [email protected].
1. Information you provide
When you create an account we collect your email address, a hash of your password (never the password itself), and any display name or profile settings you choose. When you sign in we collect what is needed to establish and maintain a session.
When you use the analysis or coaching features we store the chess games, positions (FEN), moves, annotations, and notes you choose to save to your account.
When you submit coach feedback (for example flagging a coach response as wrong or unhelpful) we store the position, the move and its classification, the full text of the coach response that was shown to you, any reason you type in, and your account identifier. We use this feedback to investigate failures and improve the deterministic and any future AI-assisted coach.
When you send product feedback, we store the message, the internal Zen page where it was sent, the random analytics visitor identifier, and your account identifier if you are signed in. If you choose to attach a screenshot, the compressed image is stored privately so an operator can review it with your message.
2. Information collected automatically
We collect operational records needed to run the Service safely: request logs (including IP address, user agent, request path, and timestamps), rate-limit counters, session records, security and abuse signals, password-reset activity, and audit events for account and operator actions.
We use a small number of essential first-party cookies and local storage entries for session management, security (including Cloudflare Turnstile challenge state), and to remember your in-app preferences. We do not use advertising cookies or cross-site tracking.
We also collect limited first-party product analytics so we can understand whether Zen is useful. Your browser creates a random visitor identifier in local storage, and the Service records allowlisted events such as opening a product page, completing an analysis, using Cassia, Explore, Simulation, or cloud sync, and opening or clicking the Promote flow. If you are signed in, the event may also be associated with your account. To understand which outreach is useful, we record normalized UTM source, medium, and campaign labels or the equivalent labels from an allowlisted Zen campaign entry link, the hostname of an external referring site, and the internal Zen path where the visit began. We do not retain the full referring URL, arbitrary query parameters, or search terms. These records do not include PGN, positions, moves, prompts, email addresses, IP addresses, user agents, or free-form event metadata. We honour the browser's Do Not Track setting and do not send these events when it is enabled.
Your browser also stores chess games locally in IndexedDB so the analysis app can work without a network connection. That local storage stays on your device and is only synchronised to our servers when you explicitly save to your account.
3. Engine analysis
Stockfish engine analysis runs locally in your browser as a WebAssembly worker. The positions you analyse are not sent to our servers for that analysis. For a small number of position lookups the app may query the public Lichess Cloud Evaluation API to check whether a position already has a community-shared evaluation; that request sends the position (FEN) to lichess.org under Lichess's own terms and privacy policy.
When you import games from Chess.com or Lichess, requests are sent directly to those services to fetch your public games and avatar. Those services receive your request and act under their own policies.
4. AI features
The coach's core analysis is produced by a deterministic pipeline that combines local engine analysis with templated text. An optional AI-assisted layer may rephrase or expand that deterministic output.
When the AI-assisted layer runs, the request may send relevant board state, move history, evaluation context, the deterministic coach text, and limited technical metadata to a third-party AI routing provider (currently OpenRouter), which forwards it to an underlying model provider. We do not send your name, email, or account identity to the AI provider; abuse prevention and quota enforcement are handled on our side. Which providers and models are used, and their data-retention and training terms, depend on your plan and our current routing configuration and may change; we favour routing to providers that do not use your inputs to train their models and that retain request data only for a limited period. We may log the request, response metadata, and outcomes for abuse prevention, quota enforcement, debugging, and quality review. The AI Disclosure describes this in more detail and is updated when the production behaviour changes. Do not include sensitive personal information in prompts, annotations, or feedback text.
5. How we use information
We use the information described above to authenticate you, store your work, synchronise settings, operate analysis and coaching features, prevent and investigate abuse, enforce rate limits and quotas, debug and improve the Service, understand which product workflows are useful, communicate with you about your account, and comply with applicable law. We do not sell personal information and we do not share it for behavioural advertising.
6. Service providers we rely on
We rely on a small set of providers to deliver the Service. Each one receives only what is needed to do its job and acts under its own privacy policy:
If we add a third-party analytics or error-monitoring provider, or an additional AI provider, we will update this list and the “Last updated” date before routing user data to it.
7. Disclosure for legal reasons
We may disclose information when we believe in good faith that doing so is necessary to comply with applicable law, a lawful request from a government or regulator, or valid legal process; to enforce our terms; to protect the Service, our users, or the public from fraud, security risks, or harm; or in connection with a corporate transaction such as a merger, acquisition, or asset sale, in which case we will require the recipient to honour this policy.
8. Retention
We retain account records and content you save (including games, annotations, and coach feedback submissions) for as long as your account is active or as needed to provide the Service. After account deletion we remove personal account data within a reasonable period, except where retention is required for backups, security investigations, abuse review, financial records, or legal obligations. Operational logs are retained for shorter, rolling windows appropriate to their purpose.
First-party product analytics events and acquisition records are automatically deleted after 400 days. Deleting an account removes the account link from retained analytics events; the random visitor identifier may remain until that rolling window expires because it does not identify the account by itself.
9. Security
We use reasonable administrative and technical safeguards, including hashed passwords, scoped session tokens, rate limiting, audit logging, and infrastructure operated by Cloudflare. No internet service can guarantee absolute security. If we become aware of a security incident that materially affects your data, we will notify affected users where required by law and where contact information allows.
10. Your choices and requests
You can update your account information from within the Service. To request a copy of your data, correction, or deletion of your account, email [email protected] from the address on file. We will respond within a reasonable period. We may need to retain some information where required by law or for security and fraud prevention. Depending on your location you may have additional rights under local law (for example to object to processing or to lodge a complaint with your data protection authority); we will honour applicable rights when they apply.
11. Children
The Service is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe a child has provided personal information to us, email [email protected] and we will delete the account and associated data.
12. International users
The Service is operated globally and uses Cloudflare's distributed infrastructure. Your information may be processed in countries other than your own, including countries whose data-protection laws differ from those of your country of residence. By using the Service you understand that this processing may occur.
13. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. For material changes we will use reasonable effort to provide additional notice in-product or by email. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact
Questions, requests, and complaints about this policy can be sent to [email protected].