Move Forge Privacy Policy

This version applies from 20 August 2026. When you register, Move Forge processes the data needed to create an account, sign you in, and provide technical support: your nickname, email address, a securely hashed password, and information about an active subscription.

Optional Google sign-in supplies only a permanent sub identifier, email and email_verified status; the profile scope is not requested. Facebook supplies id, email, name, first_name and last_name. Move Forge stores the provider, identifier, email, supplied names, link and last-sign-in dates, and account reference. A provider token is used only during the callback and is not persisted in the database. A verified exact-match Google email may link an existing account automatically; Facebook is not linked automatically.

Payment history is retained to settle purchases. If you request an invoice, Move Forge collects the buyer details needed to issue it: a business name or first and last name, address, and a Polish tax number or VAT ID for a business. The legal bases are compliance with tax and accounting obligations under Article 6(1)(c) GDPR and performance of the contract under Article 6(1)(b) GDPR. The data may be transferred to an accounting-system provider, Poland’s National e-Invoicing System (KSeF), or authorized public bodies and is retained for the period required by tax and accounting law; structured invoices are stored in KSeF for 10 years.

If you use game history, the application may retrieve public games from Chess.com or Lichess.org using a supplied username or an authorized account connection. The data is used for analysis, reports, and the creation of training tasks.

Google AdSense requests remain disabled during the remediation period. After site approval, manual ad placements may appear only beside selected eligible public content, including complete articles and editorially complete public Move of the Day pages. They remain outside the interactive chessboard and controls and are not mounted on private user screens, empty states, account panels, or administration pages. Google may then use cookies and similar technologies for ad measurement, personalization, and security.

With voluntary consent, Move Forge may enable Google Analytics 4 to measure page views, traffic sources, approximate country, device type, time spent, and anonymous feature-use events. It does not send Google message content, FEN positions, PGN records, moves, usernames, tokens, or login data. Consent can be rejected or changed later. Independently, technical application logs are retained for 30 days, unexpected-exception logs for 90 days, and account-ban decision records for 7 years unless ongoing proceedings require longer preservation. Access is limited to authorized administrators and the logs are used for security, diagnostics, appeals, and legal claims.

The necessary MF_OAUTH_STATE cookie contains a random OAuth-protection identifier, is HttpOnly, SameSite=Lax, Secure over HTTPS, and expires after the callback or within five minutes. A session JWT may remain in localStorage until sign-out, site-data removal, or session expiry, currently no more than 30 days. Cloudflare Turnstile may process a one-time token and IP address and may use necessary cf_clearance where pre-clearance or WAF is enabled.

To remove a Google or Facebook link or close an account, email support@moveforge.pl from the account address and identify the provider and request scope. Removing the link does not delete the provider account, and provider-side revocation does not automatically delete Move Forge. If social sign-in is the only access method, first set a password through password recovery.

For privacy and account questions, contact support@moveforge.pl or use the support-case panel after signing in.