R Repertoire /64

WEBSITE + CHROME EXTENSION PRIVACY POLICY

Private post-game coaching, by design.

Last updated August 3, 2026. This policy explains how the Repertoire /64 website and Chrome extension handle information. The service teaches chess openings and analyzes only completed public Chess.com games; it does not provide live-game assistance.

Website accounts and progress

The Free plan includes 150 courses. Premium is available as a $1.99 USD-equivalent 30-day crypto pass or an $11.99 USD-equivalent lifetime crypto purchase. The 30-day pass does not renew automatically. Both unlock all 300 courses, the deeper explanation layer, all opponent-response scenarios, and expanded rating analysis. Premium status and any expiry are tied to the same opaque account identifier and verified on the server; they are never trusted from browser storage or a browser payment redirect.

If you choose Sign in with Discord, Discord provides your user ID, verified email address, username, and optional display name after you approve the identify and email scopes. Repertoire /64 creates its own opaque account identifier and uses that identifier—not your email address—as the database ownership key for synced progress and entitlement status. Discord access and refresh tokens are used only during sign-in and are not stored.

Synced progress stores an opening ID, lesson step, attempts, correct answers, mastery percentage, and update time in the site database. Entitlement records store the opaque account identifier, product, status, source, grant and update times, optional expiry, and an optional provider reference. The browser receives only a shortened one-way hash of the account identifier to keep local progress separated on shared browsers.

Premium checkout and receipts

Premium checkout requires the verified email supplied by Discord. You must confirm the same email before payment; Repertoire /64 does not accept an unverified replacement address. The server resolves the selected plan to a fixed product, price, and duration, then sends the email, an account-bound order ID, product name, exact USD source amount, source currency, allowed cryptocurrency list, and fixed callback and return URLs to Plisio so it can create the crypto invoice and send payment or receipt notifications.

Repertoire /64 stores the account identifier, checkout email, order ID, provider transaction references, trusted Plisio invoice URL, versioned product, exact amount and currency, payment status, terms version and acceptance time, creation/update/completion times, entitlement expiry when applicable, and—when returned—paid cryptocurrency amount and currency. It does not store card details, gift-card codes, wallet private keys, seed phrases, or the full signed callback payload.

The Plisio status endpoint is publicly reachable so the gateway can deliver callbacks, but it returns no order or customer information and accepts payment updates only after verifying the gateway's signed message. Only an exact fully completed status can activate Premium. Plisio separately processes the blockchain transaction and applies its own privacy terms.

The server-generated order ID is shown before the customer leaves for Plisio and is included in that invoice's fixed return URL. A signed-in customer may later reopen only payment records owned by the same opaque account. The receipt shows a masked email, purchased plan, source price, cryptocurrency received when supplied by Plisio, confirmation time, and trusted invoice reference. Pages and APIs containing this information use private no-store responses and no-referrer protection.

If Premium is missing, support may use the order ID and checkout email to locate the server-side record. Those two values are references—not authentication, proof of payment, a role-claim credential, or authority to grant access. Payment is confirmed only from the stored signed gateway callback, and support verification is limited to authorized Cloudflare/D1 operators rather than a public lookup.

Checkout currently accepts Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Bitcoin Cash (BCH), and Solana (SOL) on their named networks. Store-brand gift cards and Visa or American Express card details are not accepted through Discord or support tickets.

Data providers

Chess.com receives the public username requested for analysis. Lichess may receive an opening position, time-control selection, and approximate rating band for aggregate statistics; it does not receive the signed-in email or Chess.com username from that calculation.

Information the extension handles

How information is used and stored

Your username is sent over HTTPS only to api.chess.com to retrieve public player and completed-game data. The username, preferences, completed game and analysis results are stored in Chrome's local extension storage on your device. Access from extension content scripts is disabled; only trusted extension pages and the background worker can request that storage. Stockfish analysis runs inside the extension on your device.

Repertoire /64 does not operate an extension analytics server and does not receive your username, PGNs, engine results or browsing history. Data is not sold, used for advertising, shared with data brokers, or made available for human review.

Permissions

Retention and control

Extension information remains in Chrome's local extension storage until you overwrite it, use Delete local data in the extension, clear the extension's data, or uninstall it. Website progress remains in account-separated local browser storage until you choose Delete saved progress or clear site data. The same delete control removes signed-in progress from the website database.

Payment, receipt, and entitlement records are retained while needed to provide Premium, let the purchasing account retrieve its receipt, resolve disputes, prevent duplicate activation, keep financial records, and meet applicable legal obligations. You may request deletion through official support; some transaction records may need to be retained where law or fraud-prevention requirements apply.

Local browser and extension storage is not encrypted by Repertoire /64. Someone with access to the same unlocked Chrome/operating-system profile, browser developer tools, or device malware may be able to inspect local data.

Limited Use commitment

Information is used only to provide or improve the extension's disclosed post-game coaching features. Repertoire /64 complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Support and moderator applications

The support-team application form is hosted and processed by Google Forms under Google's policies and the form owner's settings. Repertoire /64 support staff may review the responses you choose to submit when considering your application.

Responses remain in the form owner's Google account until they are no longer needed for recruitment or moderation records. Access should be limited to the server owner and designated support leads. You may request deletion through the official support Discord.

Provide only information relevant to the application. Never submit passwords, authentication codes, API keys, wallet seed phrases or private keys, payment details, or unnecessary sensitive personal information.

Discord support triage bot

The support triage bot reads messages only in selected bug-ticket channels or threads and the designated ⭐ reviews location. It does not read other server channels or direct messages. Messages are treated as untrusted input: their text receives automated, best-effort sanitization and redaction before a triage record is stored in a private GitHub repository. Attachments and linked content are not downloaded.

Negative sentiment, criticism, or a low review never causes a fix or any other code change. A reported issue must be independently reproduced before it may produce a tested draft change for human review. The bot never merges, deploys, or publishes a change automatically.

Sanitized triage content remains while the ticket is open and is scheduled for purging 30 days after closure. Minimal audit metadata—such as Discord message or channel IDs, a content hash, and triage status—may be retained to prevent duplicate handling. You may request earlier deletion through the official support Discord.

Automated redaction cannot guarantee detection of every secret or personal detail. Do not post passwords, authentication codes, API keys or tokens, wallet seed phrases or private keys, payment details, or unnecessary personal or sensitive information in tickets or reviews.

Changes and contact

Material changes will be reflected here and, when they alter data practices, disclosed in the extension interface before the changed practice begins. Ask for help or report a bug in the official Repertoire /64 support Discord.

← Back to Repertoire /64Official support Discord ↗Apply to join support ↗Chess.com Published Data API ↗