Privacy Policy
Last updated: 27 June 2026
1. Controller
The controller responsible for the processing of your personal data is:
2. What data we collect
We collect and process the following categories of personal data:
- •Account data: email address, hashed password, account creation date
- •Game data: chess moves, game results, AI difficulty settings
- •Coaching conversations: messages exchanged with the AI coaching system
- •Subscription data: subscription plan, payment status (payment details are processed by Stripe)
- •Usage data: pages visited, features used, browser type, IP address, timestamps
3. Purpose of processing
We use your data for the following purposes:
- •Account management: creation and maintenance of your user account
- •AI coaching: providing personalized chess coaching services based on your games and conversations
- •Service improvement: analysis of usage patterns to improve our Service
- •Billing: processing subscriptions and payments
- •Communication: sending service-related notifications and, with your consent, marketing emails
AI transparency: Rookion is an AI-powered system. The coaching is generated by an AI language model (Google Vertex AI, Gemini) and may contain errors; it does not replace personal chess instruction. AI-generated content is marked accordingly in the product. We will observe the transparency obligations under Article 50 of the AI Regulation (EU) 2024/1689, which apply from 2 August 2026.
4. Legal basis of processing
We process your personal data on the following legal bases of the GDPR:
- •Consent (Art. 6(1)(a) GDPR): for web analytics and heatmaps (via cookie banner), marketing communication and other optional data processing for which we ask for your express consent
- •Performance of a contract (Art. 6(1)(b) GDPR): for providing the AI chess coaching service, managing your account and processing payments
- •Legitimate interest (Art. 6(1)(f) GDPR): for service improvement, security, fraud prevention, maintenance, error analysis, administration as well as legal and security defense
- •Legal obligation (Art. 6(1)(c) GDPR): We log consent actions (grants and withdrawals) together with timestamps, IP addresses and browser information in order to comply with our accountability obligations under Art. 5(2) and Art. 7(1) GDPR. We generally store consent logs for up to 24 months; afterwards we delete or shorten the IP address and browser information insofar as they are no longer required for the proof. A reduced record (time, category, action, source as well as the banner/privacy version in force at the time of the decision) may remain stored for legal defense until the expiry of statutory limitation periods.
5. Third-party providers and data sharing
We use the following third-party providers to operate our platform:
Supabase (database & authentication)
Provider & registered office: Supabase, Inc. (USA); database hosting in the EU (Frankfurt)
Purpose: database, authentication, storage of your content
Data categories: account data, game data, coaching conversations as well as feedback/support messages (incl. optionally provided contact email). Feedback is stored in the database and processed by the operator in an internal admin view.
Role: processor (Art. 28 GDPR)
Region: EU (Frankfurt)
Transfer: processing in the EU; data processing agreement concluded, incl. EU Standard Contractual Clauses for any US connection of the provider
Google (sign-in via OAuth)
Provider & registered office: Google Ireland Ltd. (Ireland), possibly Google LLC (USA)
Purpose: optional sign-in/registration with your Google account (OAuth), only if you actively choose this login method
Data categories: the basic profile data provided by Google during login (email address, name/profile identifier); no access to other Google services
Legal basis: Art. 6(1)(b) GDPR (performance of the usage relationship at your request)
Role: Google is an independent controller for the login process; authentication is handled technically via Supabase Auth
Transfer: insofar as a US connection arises, based on the EU-US Data Privacy Framework (Google certified) and EU Standard Contractual Clauses
Stripe (payment processing)
Provider & registered office: Stripe Payments Europe, Ltd. (Ireland), where applicable Stripe, Inc. (USA)
Purpose: processing of payments and subscriptions
Data categories: name, email, plan, amount, currency, payment/invoice status, Stripe customer number, subscription ID, where applicable billing address as well as refund/chargeback events. Full credit card data is processed exclusively by Stripe; we do not store it.
Role: For certain payment, compliance, fraud prevention and financial network processing, Stripe is an independent controller; insofar as Stripe processes technical platform and subscription functions on our behalf, Stripe acts as a processor (Art. 28 GDPR). Stripe is PCI-DSS compliant.
Region: EU/USA
Transfer: USA based on the EU-US Data Privacy Framework (Stripe certified), EU Standard Contractual Clauses as a fallback; data processing agreement concluded
Google Cloud / Vertex AI (Gemini, AI coaching)
Provider & registered office: Google Cloud (Google Ireland Ltd., Ireland; Google LLC, USA)
Purpose: generation of the AI coaching responses via the Gemini language model on Google Vertex AI
Data categories: position and game data, your coaching inputs as well as the generated model responses
Role: processor (Art. 28 GDPR; Google Cloud Data Processing Addendum)
Region: processing in an EU region of Vertex AI
Transfer: insofar as a US connection arises, based on the EU-US Data Privacy Framework (Google certified) and EU Standard Contractual Clauses
Special features: Your inputs are not used to train the models. Google may briefly log data to a limited extent for abuse and security monitoring. We deliberately do not give a blanket assurance that all data remains in the EU.
Vercel (hosting)
Provider & registered office: Vercel, Inc. (USA)
Purpose: hosting and delivery of the application
Data categories: IP address and request metadata in server logs
Role: processor (Art. 28 GDPR)
Region: USA (global content delivery network)
Transfer: USA based on the EU-US Data Privacy Framework (Vercel certified), EU Standard Contractual Clauses as a fallback; data processing agreement concluded
PostHog (web analytics)
Provider & registered office: PostHog, operated on the EU cloud (eu.posthog.com)
Purpose: web analytics: page views, event tracking and heatmaps, exclusively with your consent
Data categories: page views, click and usage events, device and browser information, shortened IP address
Role: processor (Art. 28 GDPR)
Region: EU
Transfer: processing in the EU; data processing agreement concluded
Special features: Session replay (session recording) is used exclusively with your consent (analytics opt-in) and with full masking: all text inputs and visible text content (including the coaching dialog) are masked, so that no plaintext content is recorded. Only interaction behavior, navigation and clicks are captured, for analyzing user guidance and usability. The game and coaching area, as well as pages with personal content (game history, dashboard, settings, repertoire, import), are fully excluded from recording; no recording takes place there at any time. Only public pages (e.g. home, pricing, help) are recorded, and there too in masked form.
Resend (email delivery)
Provider & registered office: Plus Five Five, Inc. (trading as "Resend"), San Francisco, California, USA
Purpose: transactional email delivery (order confirmation under §312f German Civil Code, withdrawal and cancellation confirmations, account and administrative notifications)
Data categories: name, email address, contract/order/subscription information, reference numbers, withdrawal/cancellation status, refund information, delivery/error logs
Role: processor for delivery; for its own account, security and abuse processing, Resend may act as an independent controller
Region/sub-processor: delivery infrastructure inter alia via Amazon Web Services, Inc. as sub-processor; where technically configured, via an EU region. Due to Resend's US registered office and the sub-processors used, a third-country connection (in particular the USA) cannot be excluded.
Transfer: third-country transfer to the USA (Resend), based on EU Standard Contractual Clauses (as well as the EU-US Data Privacy Framework, insofar as the respective provider is certified); data processing agreement under Art. 28 GDPR with Resend.
STRATO (mailbox and inbound email)
Provider & registered office: STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
Purpose: hosting the email mailbox and receiving inbound email (e.g. replies and contact messages to info@rookion.de)
Data categories: email address and content of the respective email
Role: processor (Art. 28 GDPR)
Region: Germany/EU
Transfer: No third-country transfer (EU provider). Legal basis: Art. 6(1)(b) and (f) GDPR; data processing agreement under Art. 28 GDPR with STRATO.
Development, maintenance and administration (AI tools)
Provider & registered office: Anthropic PBC (third country, USA)
Purpose: Anthropic is used exclusively for development, maintenance, error analysis and administrative support. Personal production data is generally avoided, pseudonymized or shortened. Access takes place only in individual cases, insofar as necessary for error analysis, security or administration
Data categories: account, feedback, support, technical log and contract reference data (only in individual cases)
Role: processor
Region: third country (US connection)
Legal basis/transfer: Art. 6(1)(f) GDPR. Third-country transfer to the USA on the basis of a data processing agreement incl. EU Standard Contractual Clauses (Art. 46 GDPR). Only Anthropic products/accounts with a data processing agreement are used (no consumer/private use for production data)
Insofar as data is transferred to the USA, in particular with Vercel, Resend, Anthropic as well as with the US connection of Google, Stripe and Supabase, we base the transfer, insofar as the respective provider is certified, on the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR). Insofar as no adequacy decision applies or is additionally required, we use EU Standard Contractual Clauses (Art. 46 GDPR). A copy of the relevant safeguards can be requested via info@rookion.de. With service providers acting as processors for us, we have data processing agreements under Art. 28 GDPR in place. Insofar as providers are independently responsible for certain processing operations, the processing takes place under their own privacy terms. We deliberately do not make a blanket statement that all data remains exclusively in the EU.
We do not sell your personal data to third parties. Data is only shared with the services mentioned above insofar as this is necessary for providing our Service.
Optional voice input (Web Speech API)
In the coaching chat you can optionally use voice input, only after actively clicking the microphone icon (opt-in). Technically this uses the browser's built-in speech recognition (Web Speech API).
Depending on the browser, the recorded audio may be transmitted to and processed by the servers of the respective browser vendor for recognition (e.g. Google for Chrome and Chromium-based browsers, Apple for Safari). This is outside Rookion's control and is subject to the privacy policy of the respective browser vendor.
Rookion itself does NOT record or store the audio; only the recognized text is inserted into the input field and can be reviewed and edited by you before sending. Please do not dictate particularly sensitive content.
Legal basis: your consent through active use (Art. 6(1)(a) GDPR) as well as performance of the usage relationship (Art. 6(1)(b) GDPR).
6. Data retention
The retention periods below are guideline values; what is decisive is the respective purpose of processing as well as statutory retention obligations. In individual cases, deviating periods may apply.
- •Account data: for as long as your account is active. After account closure or upon request, deletion generally takes place within 30 days (backup copies may persist for up to 30 additional days).
- •Game and coaching data: for as long as your account is active, in order to enable coaching insights; removed upon account deletion.
- •AI coaching inputs (Google Vertex AI): not stored by Google for training purposes. Any logs for abuse and security monitoring are kept by Google only briefly according to its specifications (generally a few days up to a maximum of a few weeks).
- •Web analytics (PostHog): only with consent. Raw event data generally up to 12 months, then deletion or aggregation.
- •Server and security logs (Vercel): see Section 11; generally 90 days, extended in the case of security-relevant incidents.
- •Email delivery logs (Resend): briefly for delivery control, generally up to 30 days, unless longer storage is required for security, abuse or evidentiary reasons.
- •Payment records (Stripe): in accordance with applicable tax and commercial law, in Germany generally 10 years.
- •Consent and approval logs: generally up to 24 months; afterwards the IP address and browser information are deleted or shortened. A reduced record (time, category, action, source, applicable text version) may be retained until the expiry of statutory limitation periods (obligation of proof under Art. 7(1) GDPR).
- •Support and contact requests: until final processing; afterwards in accordance with any commercial and tax-law retention obligations.
7. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- •Right of access: request a copy of your personal data
- •Right to rectification: request correction of inaccurate data
- •Right to erasure: request deletion of your personal data ("right to be forgotten")
- •Right to data portability: request your data in a machine-readable format
- •Right to object: object to processing based on legitimate interests
- •Right to restriction of processing: request restriction of processing under certain circumstances
- •Right to withdraw consent: withdraw a previously given consent at any time
- •Right to lodge a complaint: lodge a complaint with a supervisory authority (e.g. with your competent data protection authority)
To exercise any of these rights, contact us at info@rookion.de.
The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Wuerttemberg (LfDI BW), Lautenschlagerstrasse 20, 70173 Stuttgart, Germany. You may also lodge a complaint with the supervisory authority of your habitual residence.
8. Cookies & analytics
We use the following categories of cookies:
- •Essential cookies: strictly necessary for authentication and session management. No consent under Section 25(2) TDDDG is required for them; the processing is based on Art. 6(1)(b) and (f) GDPR.
- •Analytics cookies (optional): set only if you expressly consent in the cookie banner. We use PostHog (EU instance, hosted at eu.posthog.com) for the following purposes:
- •Page views & usage analytics: which pages are visited, which features are used, device type, browser type
- •Event tracking: pseudonymized, data-minimizing capture of user interactions (e.g. coaching started, game completed) to improve the Service
- •Heatmaps: aggregated representation of click and scroll behavior to optimize user guidance
We use session replay (session recording) only with your consent and with full masking: all text inputs and visible text content (including the coaching dialog) are masked, so that no plaintext content is recorded. Only interaction behavior, navigation and clicks are captured. The game and coaching area, as well as pages with personal content (game history, dashboard, settings, repertoire, import), are fully excluded from recording; no recording takes place there at any time. Only public pages (e.g. home, pricing, help) are recorded, and there too in masked form.
The analytics functions are activated exclusively after your express consent via the cookie banner. You can withdraw your consent at any time with effect for the future: via the “Cookie settings” link in the page footer (reopens the cookie banner) or by deleting your browser storage.
We currently do not use any advertising/marketing cookies. Should we use marketing tools (e.g. from Google or Meta) in the future, this will take place exclusively after your express consent via the marketing toggle in the cookie banner; without this consent, no marketing cookies are set. We do not share analytics data with advertisers.
9. Marketing communication
We send marketing emails only with your express consent (opt-in). You can unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting us at info@rookion.de. Service-related emails (e.g. password resets, subscription confirmations) are sent as part of the performance of the contract and do not require separate consent.
10. Minimum age
Our Service is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe that a child under 16 has provided us with personal data, please contact us at info@rookion.de.
11. Security and abuse logs
We process technical log data in order to ensure the security, stability and integrity of our Service, detect abuse, fend off attacks, and assert or defend against legal claims.
Recorded events include, among others: login attempts (successful/failed), rate-limit hits, unusually frequent API access, access to admin routes, security-relevant status codes (e.g. 401/403/429), consent actions for the terms and privacy policy as well as account suspensions.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of our platform and the prevention of abuse). The storage period is governed by purpose limitation and limitation periods; generally 90 days, extended in the case of security-relevant incidents.
You have the right to object to the processing on grounds relating to your particular situation (Art. 21 GDPR). Please note that essential security logging generally constitutes a compelling legitimate interest.
12. Changes to this policy
We may update this privacy policy from time to time. We will inform registered users of material changes by email. The "Last updated" date at the top of this page indicates when this policy was last revised.
13. Contact
If you have questions about this privacy policy or about exercising your data protection rights, please contact us: