Privacy Policy
What Maurchess does
with your data.
Maurchess is an unofficial iOS client for Lichess.org, provided by Parsh Jain ("we", "us"). It has no backend of its own: your data goes to Lichess, or it stays on your phone.
01What we don't do
- We do not operate a user database. The App has no server of ours to send your data to.
- We do not run advertising, marketing, remarketing, or attribution SDKs.
- We do not sell or share your personal information, and we do not disclose it to data brokers.
- We do not use App Tracking Transparency and will never ask permission to track you across other companies' apps or websites.
- We do not build profiles about you and do not make automated decisions that affect you.
02Data stored only on your device
Sign-in token
When you sign in, Lichess issues an OAuth 2.0 access token. We store it in the iOS Keychain with the WhenUnlockedThisDeviceOnly attribute. It never leaves your device except to authenticate requests to Lichess, is excluded from iCloud and iTunes backups, and is not migrated to a new device. Signing out erases it.
Preferences
Board theme, piece set, sounds, haptics, expert mode, and other Settings toggles are stored in the App's local database.
Local caches
For offline viewing and to reduce network calls, the App caches your game history, profile, puzzles, and rating history in a local SwiftData store. Signing out clears this cache; uninstalling the App removes it entirely.
03Data sent to Lichess
All gameplay, chat, follows, blocks, ratings, and profile activity happen directly between the App and Lichess.org over their public HTTP API. When you take an action in the App — play a move, send a chat message, block or report a user — the App forwards it to Lichess. We are not an intermediary that stores or inspects it.
Lichess receives your requests together with the technical information any web request carries, including your IP address. That processing is Lichess's, not ours. See lichess.org/privacy.
To close your Lichess account, use Settings → Delete account, which opens lichess.org/account/close. We cannot delete a Lichess account on your behalf.
04Crash and diagnostic reports
The App uses Google Firebase Crashlytics to collect crash reports and short diagnostic breadcrumbs (recent API calls, error events, and app-flow logs) so we can find and fix bugs.
When a crash or non-fatal error occurs, the report contains: a stack trace, device model, iOS version, App version, coarse locale, and the last few log lines. Crashlytics also processes an installation identifier and, for crash grouping, a truncated IP address.
While you are signed in, we attach your Lichess username as the Crashlytics user identifier, so a crash affecting one account can be traced and answered.
We do not collect chat message content, moves played, board positions, opponent identities, puzzle solutions, or anything else you type.
Crashlytics data is processed by Google as our processor under the Firebase privacy and security terms, and is retained by Google for up to 90 days.
05Summary of data
06Permissions the App requests
- Network access — required to reach Lichess.
- Background App Refresh — used only to check whether it is your turn in a correspondence game, so the App can raise a local notification. No push server is involved.
- Notifications — local notifications generated on-device. We do not send remote push messages and cannot send you marketing.
The App does not request access to contacts, photos, location, microphone, camera, or health data.
07Legal bases for processing
Where the UK GDPR or EU GDPR applies, we rely on:
- Contract (Art. 6(1)(b)) — storing your sign-in token and preferences so the App can do what you installed it to do.
- Legitimate interests (Art. 6(1)(f)) — crash and error diagnostics, limited to what is needed to keep the App stable.
You can object to crash diagnostics by uninstalling the App; because there is no account on our side, we have no other switch to flip on your behalf.
08Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to it. For anything held in your Lichess account, exercise those rights with Lichess, who holds the data.
For crash-report data, write to us with your Lichess username and we will locate and delete the associated Crashlytics records, or confirm that none exist. We respond within 30 days.
Under the California Consumer Privacy Act, we do not sell or share personal information and have not done so in the preceding 12 months, including for cross-context behavioural advertising. We do not process sensitive personal information for inferring characteristics. You will not be discriminated against for exercising any right.
If you are in the EEA or UK and are unhappy with our response, you may complain to your local data protection authority.
09Retention
On-device data persists until you sign out or uninstall. Crash reports expire automatically after 90 days. We keep no other records: there is no account, mailing list, or analytics warehouse on our side.
10Security
All traffic to Lichess and Firebase uses HTTPS with TLS. Your access token is held in the iOS Keychain and is scoped to this device. No security measure is perfect, and we cannot guarantee absolute security; if a breach affecting the App occurs, we will publish notice on this site and, where required, notify the relevant authorities.
11Children
The App is not directed at children under 13, and we do not knowingly collect personal information from them. Lichess offers a Kid mode that hides chat and challenges from strangers; it can be toggled in Settings → Account → Kid mode and the App honours it. If you believe a child has provided us with personal data, contact us and we will delete it.
12International transfers
The App is available worldwide through the App Store. Crash-report data may be processed by Google on infrastructure outside your country, including the United States, under the Standard Contractual Clauses incorporated in the Firebase data processing terms. Lichess is operated from France; refer to their policy for their own transfers.
13Changes to this policy
We may update this policy as the App changes. Material changes will be highlighted in the App's release notes. Continued use after an update means you accept the revised policy.
14Contact
Parsh Jain, developer of Maurchess — support@maurchess.com. We are the data controller for the limited processing described above and can be reached at that address for any privacy request.