Kingdom Chess is built for children ages 5 and up and the adults who play with them. This notice explains, in plain English, what happens with information that passes through the game — and what does not.
1. Accounts and what we do not collect
A parent or guardian creates one adult account with an email address and password. Children never have an email address or a login of their own: a parent creates a child play profile (a first name or nickname plus an animal emoji) and a short PIN, and authorises the device the child plays on.
- No advertising identifiers, no third-party analytics, no tracking pixels.
- No child email addresses, no phone numbers, no home address, no photographs.
- We do not profile children for advertising and we never sell any information.
2. Voice chat — the most important part
Voice chat is only available in the online two-player mode. When you press and hold the talk button, your microphone records a short clip (about 12 seconds max) and sends it directly to the other player over an encrypted realtime channel.
- Voice clips are never written to a database, file, bucket, log, or backup on our servers. They travel through a live message channel only.
- Clips are deleted from the recipient's device as soon as they are played, and any unplayed clip is purged automatically after three minutes of silence.
- We do not transcribe, analyze, moderate, or listen to voice content, and we do not use it to train any model.
3. Voice consent record
Because a child's voice is personal information, US and international law (COPPA, GDPR-K, and similar) requires verifiable parental consent before it is captured. Before voice chat turns on, a parent or guardian must tick a consent box. We store a small record of that consent so we can prove it was given:
- A random reference ID (for example
VC-K9F3-2X7Q). - Timestamp, the room ID, a random device ID, browser user-agent, and the IP address of the request.
- The version of the notice that was accepted.
This record contains no voice audio. It exists only to answer the question "was consent given?" and it lives for exactly as long as the child play profile it belongs to: if the parent withdraws consent the withdrawal is recorded on the same row, and if the profile or the family account is deleted the consent and withdrawal records are deleted with it. It is never kept indefinitely and there is no separate archive copy.
4. Gameplay data
For online rooms we store only what is needed to keep the game in sync: the current board position, whose turn it is, the last move, and the running score for that session. Rooms are ephemeral and are automatically cleaned up. Local and computer-play modes store nothing on our servers.
4a. How long we keep each kind of information
Every category below is deleted automatically by a scheduled job once its period ends — nothing about a child is kept indefinitely. Periods are counted from the moment the record is created or last used.
| Category | Why we keep it | How long |
|---|---|---|
| Child play profile (first name or nickname, animal emoji, PIN in hashed form) | So the child can sign in on an authorised family device and see their own games | While the parent keeps the profile; deleted immediately when the parent removes it or closes the account |
| Authorised play device record | To keep a child's play limited to devices the parent approved | 180 days of inactivity, then it must be re-authorised; a removed or expired device record is purged after 30 days |
| Child sign-in session | To keep the child signed in for one play period | 8 hours, then the session is deleted |
| PIN attempt counters and lockouts | To stop repeated PIN guessing | Lockout lasts 5 minutes; attempt records are purged after 24 hours |
| Family device / activation codes | To let a parent authorise a new device once | Code is valid 30 minutes; used or expired codes are purged after 24 hours |
| Friend invitations (email of the other adult, invitation status) | So the other child's parent can review and approve the friendship | Invitation is valid 72 hours; invitation and delivery history is kept 90 days for child-safety review, then deleted |
| Game challenges between friends | To offer and accept a game | 30 minutes, then expired and purged |
| Guest game links | To let an invited adult join a single game | Link lives 60 minutes; the seat handle lives 30 minutes; both purged after use |
| Live rooms, moves, seat handles and connection signalling | To keep a game in sync between two players and allow a return to an unfinished game | An unfinished friend game stays resumable for the period set by the Kingdom Chess administrator, currently 24 hours after the last legal move; only a legal move (or starting the game) restarts that period, while viewing, refreshing, leaving or talking does not. When that period passes the game simply expires with no winner, no loser and no scorecard result — the moves are not deleted at that moment. Once a game is finished, cancelled, resigned or expired, the room, its moves and its connection signalling are kept for the administrator-configured retention period, currently 24 hours, and then deleted. Seat handles expire after 8 hours; connection signalling after 60 minutes |
| Finished-game scorecard and progress records (result, colour, date, opponent's play name) | So a child and their parent can see progress over time | 730 days (2 years), then deleted |
| Voice consent and withdrawal record | Proof that a parent permitted (or later refused) voice for that child | Kept only while the child play profile exists; deleted with the profile or on account closure |
| In-app notifications to parents | To tell a parent about approvals, invitations and safety events | 90 days, then deleted |
| Support/service records | To answer a family's request and check it was resolved | 10 days after the case is closed, then deleted |
| Family audit trail (device added, PIN changed, friendship approved) | So a parent can see what changed in their own family | Kept with the household and deleted when the account is closed |
| Adult account security records (invitations, email-change requests, recovery credentials) | To keep adult and administrator accounts secure | 30 days, then deleted; a re-authorisation window lasts 5 minutes |
| Account closure | To confirm the closure actually happened | Every child profile, device, session, game, invitation, friendship and consent record is deleted at closure; only a dated closure confirmation without personal details remains |
Some of these periods are configurable by our platform administrators within safe limits. This notice is updated whenever a published period changes, and the table above always reflects the periods currently in force. A parent can ask us at any time to delete a child's records sooner — see section 8.
5. Cookies and local storage
We use a small amount of browser localStorage to remember that consent was given and to keep the app installable as a Home Screen app. We do not set advertising or tracking cookies.
6. Children under 13 (COPPA)
Voice chat is gated behind an adult consent screen with formal legal language and cannot be started by a child alone. Parents may revoke consent at any time by clearing browser storage or by contacting us (see below) — we will delete the associated consent record on request.
7. Third parties
The app runs on the Lovable Cloud hosting platform, which uses Cloudflare (edge/CDN) and Supabase (managed database and realtime messaging) as sub-processors. When voice chat is switched on, the live audio between the two children is carried by Cloudflare RealtimeKit, Cloudflare's realtime audio service, acting as our sub-processor: it creates the short-lived conversation, issues each side a single-use joining token and routes the audio. Recording is switched off, so no voice audio is stored by Cloudflare or by us; it only ever handles audio in transit, plus the technical identifiers needed to connect the two sides. These providers process data only to deliver the service. They do not receive voice audio at rest and do not receive any advertising signal from us.
Responsibility for third-party outages or incidents. Kingdom Chess is a free, volunteer-run hobby project. While we design the app to minimize what any third party can see, we cannot and do not accept liability for loss of data, downtime, security incidents, or other events caused by a third-party provider (including but not limited to Cloudflare, Supabase, your internet service provider, your device manufacturer, or the browser vendor). We share this responsibility with you: you agree that your use of the service is at your own risk with respect to such third-party events, to the fullest extent allowed by law. See our Terms & Conditions for the full limitation of liability.
8. Your rights
Depending on where you live (California CCPA/CPRA, EU/UK GDPR, and similar laws) you may have the right to know what we have, to correct it, to delete it, and to opt out of any sale or share of personal information. We do not sell or share personal information. To exercise a right, contact us at the email below and reference your consent ID if you have one.
9. Contact
Questions or requests about privacy: privacy@kingdomchess.space.
10. Changes
If this notice changes in a way that meaningfully affects consent, the consent screen will be shown again the next time you start an online game.