R Repertoire /64

WEBSITE + CHROME EXTENSION PRIVACY POLICY

Private post-game coaching, by design.

Last updated August 10, 2026. This policy explains how the Repertoire /64 website and Chrome extension handle information. The service teaches chess openings and analyzes only completed public Chess.com games; it does not provide live-game assistance.

Website accounts and progress

The Free plan includes 150 courses. Premium is available as a $1.99 USD-equivalent 30-day cryptocurrency pass or an $11.99 USD-equivalent lifetime purchase through cryptocurrency or, when available, an isolated PayRam card-to-crypto checkout. The 30-day pass does not renew automatically. Both unlock all 300 courses, the deeper explanation layer, all opponent-response scenarios, and expanded rating analysis. Premium status and any expiry are tied to the same opaque account identifier and verified on the server; they are never trusted from browser storage or a browser payment redirect.

If you choose Sign in with Discord, Discord provides your user ID, verified email address, username, and optional display name after you approve the identify and email scopes. Repertoire /64 creates its own opaque account identifier and uses that identifier—not your email address—as the database ownership key for synced progress and entitlement status. Discord access and refresh tokens are used only during sign-in and are not stored.

You may instead sign in with a passwordless email link. The short-lived sign-in record contains the normalized destination email, a one-way hash of the random single-use link token, a separate one-way browser-challenge hash, a local return path, and creation, expiry, and optional use times. The hashes and link expire after 15 minutes, the link must be confirmed in the browser that requested it, and successful use invalidates it. Cloudflare Email Service receives the destination address and email contents to deliver the link; delivery and security logs may contain the recipient, subject, delivery status, and limited message metadata. If Cloudflare's optional Email preview setting is enabled, it may retain the full message content for about seven days. No password is created or stored.

Synced progress stores an opening ID, lesson step, attempts, correct answers, mastery percentage, and update time in the site database. Entitlement records store the opaque account identifier, product, status, source, grant and update times, optional expiry, and an optional provider reference. The browser receives only a shortened one-way hash of the account identifier to keep local progress separated on shared browsers.

Cloudflare automatically processes network and request metadata, including the connecting IP address, to deliver the site and protect it from denial-of-service and automated abuse. Repertoire /64 uses coarse, temporary Cloudflare edge counters for dynamic requests and, only if a future Cloudflare plan supplies genuine Bot Management metadata, may apply a tighter budget to high-cost automated requests. Verified service callbacks and static assets follow separate rules. Repertoire /64 does not write IP addresses or bot signals to D1, browser storage, or an application analytics database, and Worker observability remains disabled.

Optional Meta analytics

On the signed-out home page only, you may choose to allow Meta Pixel for advertising measurement. Before you allow it, the browser does not request Meta's Pixel library or send a PageView. If allowed, Meta may use cookies and receive the page visit, device and browser information, and fixed parameter-free events for a successful Elo analysis, starting a tutorial, Premium interest, or extension interest. Repertoire /64 disables automatic Pixel configuration and does not send the Chess.com username, rating, opening or course name, training progress, account information, email, order ID, payment details, or custom event parameters.

The Pixel is not loaded for signed-in users or on privacy, purchase terms, authentication, checkout, payment-return, receipt, or API pages. A query-string home page also fails closed. You can change your choice with Meta analytics settings on the signed-out home page. Declining keeps the Pixel off; withdrawing consent stops future Repertoire /64 Pixel events. Meta processes Pixel information under Meta's Privacy Policy.

Signed-out sponsor banner

On the signed-out home page only, Repertoire /64 embeds one AADS advertising frame from acceptable.a-ads.com. Loading that frame necessarily shares ordinary network and request metadata, such as the connecting IP address, browser and device headers, and advertising unit ID 2451620, with AADS. Repertoire /64 does not put an account ID, email address, Chess.com username, training progress, order ID, or payment information into the frame URL.

The frame is restricted to its exact HTTPS provider origin, uses a limited browser sandbox, sends no referring page URL, and is not included for signed-in users or private routes such as account, authentication, checkout, receipts, payment-return, or APIs. Closing the banner hides it for the current page view. AADS controls the advertisement and its destination under AADS's Privacy Policy.

Premium checkout and receipts

Premium checkout requires the verified email belonging to the signed-in Repertoire /64 account, whether that account was verified through Discord or a passwordless email link. You must confirm the same email before payment; Repertoire /64 does not accept an unverified replacement address. The server resolves the selected plan to a fixed product, price, and duration, then sends the email, an account-bound order ID, product name, exact USD amount, currency, and fixed callback data to Plisio for cryptocurrency checkout or to the isolated PayRam service for card-to-crypto checkout.

Repertoire /64 stores the account identifier, checkout email, order ID, payment provider, provider transaction references, trusted hosted-checkout URL, versioned product, exact amount and currency, payment status, terms version and acceptance time, creation/update/completion times, entitlement expiry when applicable, and limited settlement details returned by the provider. It does not store payment-card numbers, card security codes, wallet private keys, seed phrases, or full callback payloads.

Payment callback endpoints are publicly reachable so the gateways can deliver status notifications, but they return no order or customer information. Plisio callbacks must pass the gateway signature checks. PayRam callbacks must present the private server API key and are treated only as notifications; the application independently retrieves the payment from the fixed PayRam origin and matches its reference, account-bound order ID, exact amount, and completed state before granting Premium. PayRam's card on-ramp provider separately processes card and identity information under the terms shown during checkout. Legacy Chain2Pay records and authenticated callbacks remain supported only so existing receipts and already-created payments are not stranded; new Chain2Pay checkout creation is disabled.

The server-generated order ID is shown before the customer leaves for the selected provider. A signed-in customer may later reopen only payment records owned by the same opaque account. The receipt shows a masked email, purchased plan, source price, limited settlement details when supplied, confirmation time, provider, and trusted checkout reference. Pages and APIs containing this information use private no-store responses and no-referrer protection.

If Premium is missing, support may use the order ID and checkout email to locate the server-side record. Those two values are references—not authentication, proof of payment, a role-claim credential, or authority to grant access. Payment is confirmed only from the stored gateway-verified record, and support verification is limited to authorized Cloudflare/D1 operators rather than a public lookup.

Plisio crypto checkout currently accepts Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Bitcoin Cash (BCH), and Solana (SOL) on their named networks. Lifetime Premium may also offer isolated PayRam card-to-crypto checkout after verification. Repertoire /64 does not receive the card number or security code from that hosted on-ramp.

If you initiate a private gift-card payment ticket in the official Discord, support may receive the ticket messages and the gift-card information you choose to provide for manual verification. Do not post codes publicly or send them by unsolicited direct message. Gift-card codes are not copied into the Repertoire /64 application database; Discord processes and stores the ticket messages under Discord's policies and the support retention rules described below.

Data providers

Chess.com receives the public username requested for analysis. Repertoire /64 reads bounded monthly archives newest-first, keeps rating pools separate, and uses only completed rated standard-chess games from the selected active time class. It may inspect the public PGN, game-end time, player ratings, result, ECO information, and time class to recognize positions, weight recent results, and compare performance with opponent strength when ranking practical fit. Partial upstream coverage is disclosed rather than silently replacing a failed recent archive with older data. These analysis PGNs are processed for the response and are not added to the website account database.

Lichess connection is optional. If you approve it, Repertoire /64 requests no named Lichess permissions, reads your public Lichess ID and username, and uses the OAuth token only to authenticate aggregate Opening Explorer requests. Lichess may receive an opening position, matching time-control selection, recent month range, and approximate rating band; it does not receive the signed-in email or Chess.com username from that calculation. The token is encrypted at rest with AES-256-GCM and account-bound authenticated context, never sent to the browser or extension, and expires on the provider's schedule. You may decline and continue with Chess.com-only analysis, connect later in Account settings, reconnect, or request disconnect and revocation. If Lichess cannot confirm revocation, the encrypted token is disabled from analysis and retained only long enough to retry or let you revoke it in Lichess settings.

Information the extension handles

How information is used and stored

Your username is sent over HTTPS only to api.chess.com to retrieve public player and completed-game data. The username, preferences, completed game and analysis results are stored in Chrome's local extension storage on your device. Access from extension content scripts is disabled; only trusted extension pages and the background worker can request that storage. Stockfish analysis runs inside the extension on your device.

Repertoire /64 does not operate an extension analytics server and does not receive your username, PGNs, engine results or browsing history. Data is not sold, used for advertising, shared with data brokers, or made available for human review.

Permissions

Retention and control

Extension information remains in Chrome's local extension storage until you overwrite it, use Delete local data in the extension, clear the extension's data, or uninstall it. Website progress remains in account-separated local browser storage until you choose Delete saved progress or clear site data. The same delete control removes signed-in progress from the website database.

Payment, receipt, and entitlement records are retained while needed to provide Premium, let the purchasing account retrieve its receipt, resolve disputes, prevent duplicate activation, keep financial records, and meet applicable legal obligations. You may request deletion through official support; some transaction records may need to be retained where law or fraud-prevention requirements apply.

Unused or consumed email sign-in records contain only the normalized email, hashed link token, hashed browser challenge, return path, and timestamps. They expire after 15 minutes and are removed during routine authentication cleanup. Lichess connection records are removed after confirmed revocation; a disabled revocation-pending record may remain encrypted until revocation can be retried or you ask support to remove it after revoking it directly with Lichess.

Local browser and extension storage is not encrypted by Repertoire /64. Someone with access to the same unlocked Chrome/operating-system profile, browser developer tools, or device malware may be able to inspect local data.

Limited Use commitment

Information is used only to provide or improve the extension's disclosed post-game coaching features. Repertoire /64 complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Support and moderator applications

The support-team application form is hosted and processed by Google Forms under Google's policies and the form owner's settings. Repertoire /64 support staff may review the responses you choose to submit when considering your application.

Responses remain in the form owner's Google account until they are no longer needed for recruitment or moderation records. Access should be limited to the server owner and designated support leads. You may request deletion through the official support Discord.

Provide only information relevant to the application. Never submit passwords, authentication codes, API keys, wallet seed phrases or private keys, payment details, or unnecessary sensitive personal information.

Discord support triage bot

The support triage bot reads messages only in selected bug-ticket channels or threads and the designated ⭐ reviews location. It does not read other server channels or direct messages. Messages are treated as untrusted input: their text receives automated, best-effort sanitization and redaction before a triage record is stored in a private GitHub repository. Attachments and linked content are not downloaded.

Negative sentiment, criticism, or a low review never causes a fix or any other code change. A reported issue must be independently reproduced before it may produce a tested draft change for human review. The bot never merges, deploys, or publishes a change automatically.

Sanitized triage content remains while the ticket is open and is scheduled for purging 30 days after closure. Minimal audit metadata—such as Discord message or channel IDs, a content hash, and triage status—may be retained to prevent duplicate handling. You may request earlier deletion through the official support Discord.

Automated redaction cannot guarantee detection of every secret or personal detail. Do not post passwords, authentication codes, API keys or tokens, wallet seed phrases or private keys, payment details, or unnecessary personal or sensitive information in tickets or reviews.

Changes and contact

Material changes will be reflected here and, when they alter data practices, disclosed in the extension interface before the changed practice begins. Ask for help or report a bug in the official Repertoire /64 support Discord.

← Back to Repertoire /64Official support Discord ↗Apply to join support ↗Chess.com Published Data API ↗