Skip to content
chessskins.beta
ExploreHow it works

Beta policy · Updated September 12, 2026

Privacy Policy

This policy describes the Chessskins beta website, subscription service, and Chrome extension. Operator identity and a private privacy-contact address must be added before public paid launch; see Support for the current contact route.

Accounts and saved preferences

Firebase Authentication handles email/password and Google sign-in. We use your account ID, email, verification status, and optional display name to operate your account. Firestore stores your favorites, saved loadouts, billing references and access status. Passwords are managed by Firebase; Chessskins application records do not contain your password.

Email/password accounts must verify their email within 48 hours of registration. Scheduled cleanup deletes accounts still unverified after that deadline, after rechecking Firebase. Accounts with billing activity are excluded from that cleanup. Verification delivery is limited to five requests per hour with at least a minute between requests.

Payments and introductory trials

Stripe collects and processes payment details. We store Stripe customer and subscription IDs, subscription status, trial or paid-period expiry, and checkout-consent records. We never store raw card numbers or security codes.

To enforce one introductory trial per eligible customer, we retain keyed hashes of the account ID, normalized email, and Stripe payment-method fingerprint, plus a trial attempt identifier and claim date. These records prevent account recreation or reuse of a trial-used payment method from trivially resetting eligibility. They are not used for advertising, cross-site tracking, or blanket IP bans.

Eligibility hashes and minimal deletion tombstones are retained for the lifetime of the introductory-trial program, including after account deletion; they are removed when that program is permanently retired. Checkout operation and consent records are retained while needed to reconcile billing, and are deleted or stripped of account and payment references during account deletion. Stripe may retain its transaction records under its own policies and applicable requirements. Fingerprints have limitations: wallets, replacement cards and regional differences can produce different identifiers.

Discord linking

Joining the public Discord is free. If you choose to connect Discord, we obtain your Discord user ID and username through Discord authorization. We do not use matching email addresses as proof of ownership or payment. We keep the link and role-sync status to grant or remove subscriber-channel access according to backend entitlement, including eligible trials. OAuth tokens are used temporarily to identify you and are not saved.

Disconnecting or deleting your Chessskins account removes subscriber access and deletes the link after role removal succeeds. Failed role updates remain queued until they can be retried. You are not removed from the public server.

The extension and browser storage

The extension uses Chrome storage for your sign-in session, account preferences, selected preset, and a bounded cache of authorized assets. It accesses Chess.com pages to replace board and piece visuals. It does not provide engine assistance or collect a browsing-history feed. Firebase session data enables authentication; the website uses browser storage for draft loadouts and navigation, and a short-lived, HttpOnly cookie protects Discord authorization.

Access is checked by the server. Previously authorized offline access lasts only until the earlier of the entitlement expiry or the configured offline window, which defaults to 24 hours. Signing out clears account-specific extension access and caches.

Service providers and controls

Firebase/Google supplies authentication, application storage and hosting; Stripe supplies payment processing; Discord supplies the optional community connection. Requests to these providers are subject to their own policies. Service logs may include request and operational error information; credentials and raw payment details must not be logged. Chessskins does not sell account data or use these records for targeted advertising.

Administration and service analytics

Authorized administrators can review account creation and sign-in dates, subscription records, favorites, and saved loadouts to operate and improve the service. Aggregate reports use these existing records; we do not track gameplay or a browsing-history feed. During testing, registration may be limited to an administrator-managed email allowlist. Administrative changes are recorded with the administrator’s account ID, email, action, affected setting, and time. Allowlist changes can include the affected email. Audit records contain no secret values and are retained for security review while the service operates.

Use Account settings to change your profile, manage sign-in methods, disconnect Discord, cancel renewal, or request account deletion. Deletion immediately stops subscription access and renewal, then removes the profile, loadouts and linked-account data once external cleanup succeeds. Limited anti-abuse records described above remain. For privacy questions, use Support; do not post passwords or payment information in public Discord.

chessskins.beta

Custom boards and pieces for Chess.com. Built with our community, in beta.

Chess setsDashboardMembershipAccountPrivacyTermsBilling & refundsSupportFree Discord

Chessskins is an independent cosmetic extension and is not affiliated with Chess.com.