# Privacy Policy
**Ouk Chatrang (ឬក ចត្រង្គ)**
Last updated: 6 August 2026
This policy explains what Ouk Chatrang collects, why, and what you can do about
it. It covers the mobile app and the API at `khmer-chess-api.yeanseyha.dev`.
The app is published by Yean Seyha ("we", "us"). Contact:
**support@yeanseyha.dev**
---
## You can use the app without giving us anything
Ouk Chatrang works offline and without an account. Playing the engine, solving
the daily puzzle, building a streak, and using the board and clock all run
entirely on your device. If you never sign in, we hold no email address and no
name for you.
An account is only needed for four things: online play, the leaderboard, your
rating, and carrying your progress to another device.
---
## What we collect
### If you sign in
| What | Why | Where it is stored |
|---|---|---|
| Email address | To send the sign-in code and identify your account | Supabase (identity), Neon (game database) |
| Display name | Shown to opponents and on the leaderboard | Neon |
| Full name, if Apple or Google supplies it | Filling in your profile on first sign-in | Neon |
| Sign-in method (email, Google, Apple) | Support and account recovery | Neon |
| Account created / last seen timestamps | Account lifecycle and inactive-account cleanup | Neon |
We never see or store your password, because there isn't one. Email sign-in
uses a one-time code; Google and Apple sign-in hand us a token those companies
issued. The secret always stays with them.
### Your play, if you sign in
- Rating and number of rated games
- Finished games: result, side, how it ended, number of moves, duration,
opponent's name and rating, rating change
- Progress: day streak, days played, puzzles solved and skipped, coin balance,
badges earned, engine levels beaten
- Whether you are currently online or in a game, so the app can tell an
opponent whether a rematch will reach you
### On every device, account or not
- **A device identifier we generate ourselves.** It is a random value created by
the app. It is not your phone's advertising ID, IMEI, MAC address or serial
number, and it does not follow you into other apps.
- **Usage events.** Roughly two dozen named events — the app opened, a game
started, a puzzle solved, the sign-in sheet shown or dismissed — with the time
and a small amount of context such as which engine level. They are attached to
the device identifier, and to your account if you have one. They tell us which
parts of the app people actually use.
- **The IP address** your request arrived from. It is recorded against sign-in
code requests to stop abuse, and appears in ordinary server logs.
### What we do not collect
No location. No contacts, photos, camera, microphone or calendar. No advertising
identifier. No health, financial or biometric data. We do not read anything else
on your device, and the app requests no runtime permissions to do so.
---
## Coins are not money
The app has an in-game item called a **coin** (`កាក់`). Coins have no monetary
value, cannot be bought, cannot be cashed out, and cannot be wagered against
another player. Nothing in the app is a real-money game, and we collect no
payment information at all.
---
## Why we are allowed to hold this
- To provide the service you asked for — you cannot have an online rating
without us storing a rating (contract).
- To keep the service working and unabused — rate limits, sign-in code
attempt counting, server logs (legitimate interests).
- To understand which features are used, in aggregate, so the app gets better
(legitimate interests).
If you are in a jurisdiction that requires consent for analytics, write to us
and we will exclude your device.
---
## Who else touches your data
We use these providers, and no one else. None of them are paid to advertise to
you, and we sell your data to nobody.
| Provider | What it handles |
|---|---|
| **Supabase** | Identity: your email address and sign-in tokens |
| **Neon** | The game database: profile, games, progress, analytics events |
| **Resend** | Delivers the sign-in code email |
| **DigitalOcean** | The server the API runs on (Singapore region) |
| **Google** | Only if you choose Google Sign-In — verifies who you are |
| **Apple** | Only if you choose Sign in with Apple — verifies who you are |
| **Google Play / Apple App Store** | Distribute the app; they have their own policies |
The app contains **no advertising SDK and no third-party analytics SDK**. If
that ever changes, this policy will be updated before the build ships.
Your data may be stored on servers outside your country, including in the United
States and Singapore.
---
## Other players see very little
On the leaderboard, in a game, and in your recent opponents list, another player
sees your **display name and rating only**. Your email address is never shown to
anyone.
---
## How long we keep it
- Sign-in codes are deleted shortly after they are used or expire.
- Analytics events are kept for 24 months, then deleted.
- Your account, games and progress are kept until you ask us to delete them.
---
## Deleting your account
Write to **support@yeanseyha.dev** from the email address on the account, or use
the *Contact us* link in the app's About screen. We will delete your account,
your games, your progress and your analytics events within 30 days, and confirm
when it is done.
You may also ask us for a copy of what we hold about you, or ask us to correct
it, at the same address.
---
## Children
Ouk Chatrang is not directed at children under 13, and we do not knowingly
collect personal information from them. A child can play the whole offline game
without an account and without giving us anything. If you believe a child has
created an account, write to us and we will delete it.
---
## Security
Traffic to the API is encrypted with HTTPS. Sign-in tokens are held in your
device's secure storage — the iOS Keychain or the Android Keystore. Every
request to the server is authorised against a verified token, never against
anything the app claims about itself.
No system is perfect, and we will tell affected users if something goes wrong.
---
## Changes
If this policy changes materially we will update the date at the top and, where
the change affects what we collect, say so in the app before it takes effect.
---
## Contact
**support@yeanseyha.dev**