Legal
Privacy Policy
This privacy policy is applicable to the Nexus Chess app (hereinafter referred to as "Application") for mobile devices, which was developed by Neonhex Digital SRL (hereinafter referred to as "Service Provider") as a Free service. This service is provided "AS IS".
This Privacy Policy explains how the Service Provider collects, uses, stores, shares, and protects information when you use the Application, including gameplay, accounts, progression, chat, moderation, virtual currency, cosmetics, support, analytics, crash diagnostics, notifications, user-acquisition measurement, and security.
If you want to permanently delete your Nexus Chess account and associated data, use the in-app deletion control or follow the instructions on our Account Deletion page.
What information does the Application obtain and how is it used?
The Application acquires the information you supply when you download, register, log in, contact support, participate in community features, make requests, submit reports, or otherwise use the Application. Registration with the Service Provider is not mandatory for every feature. However, some features may not be available unless you register or connect an account.
User-provided information may include usernames, display names, account identifiers, profile choices, support communications, moderation appeals, report descriptions, purchase support details, and other information you choose to provide. The Service Provider may use this information to operate the Application, provide support, send required notices, respond to requests, maintain safety, and provide marketing or promotional communications where permitted by law.
What information does the Application collect automatically?
In addition, the Application may collect certain information automatically, including, but not limited to, the type of mobile device you use, app-instance and device identifiers, the IP address of your mobile device, your mobile operating system, app version, build number, device language, approximate region, connection information, crash reports, performance diagnostics, notification delivery and interaction information, and information about the way you use the Application. Where legally permitted, enabled, and subject to applicable platform choices, this may also include an advertising identifier used for campaign attribution.
Gameplay, progression, and live-ops data
The Application may collect gameplay-related information, including match history, session activity, progression, scores, rankings, trophies, streaks, rewards, challenges, events, tutorial progress, rubies, energy, hints, owned cosmetics, selected cosmetics, inventory items, and feature usage. This information is used to provide gameplay, save progress, balance the game, operate events, prevent abuse, improve user experience, and provide live-ops features.
Chat, reports, and moderation data
If the Application includes chat, usernames, profiles, social, guild, friend, party, or other community features, the Service Provider may process user-generated content and related metadata. This may include chat messages, usernames, player identifiers, timestamps, reported content, report categories, moderation notes, warnings, mutes, suspensions, bans, appeals, and related safety records.
This information is used to operate community features, investigate reports, detect abuse, enforce rules, protect users, prevent fraud or harassment, and comply with legal obligations. Chat and moderation data may be reviewed by automated systems and/or authorized human reviewers.
Purchases, virtual currency, and cosmetics
If purchases are offered in the Application, they are processed by the applicable platform provider, such as Google Play or the Apple App Store. Purchasable content may include rubies, virtual items, cosmetics, avatars, frames, boosters, limited-time offers, and other digital entitlements.
The Service Provider may receive transaction-related information from those providers, such as purchase status, product identifiers, transaction identifiers, items purchased, currency, country, timestamps, refund status, chargeback status, fraud/risk signals, and entitlement status. The Service Provider does not collect or store full payment card numbers or full payment account details.
Advertising and ad measurement
The Application does not display third-party advertising. The Service Provider uses or is preparing to use Meta App Events solely for user-acquisition attribution, campaign measurement, fraud prevention, audience measurement, and campaign optimization.
When this integration is enabled, Meta may receive limited campaign-relevant information such as app installation and launch events, tutorial completion, Journey milestones, retention events, purchase events and values, app and device information, IP address, and an advertising or app-scoped identifier where permitted. The Service Provider does not send player names, email addresses, chat messages, guild content, support messages, or unrestricted Firebase event streams to Meta.
Meta measurement and tracking are controlled according to applicable law and platform requirements. On iOS, tracking that requires permission will not be enabled unless the user authorizes it through Apple's App Tracking Transparency prompt. Where consent is required, relevant Meta event collection will remain disabled until valid consent is obtained. Meta may process information under its own terms and privacy policy.
Local reminders and remote push notifications
The Application may schedule local reminders on your device and may send remote push notifications through Firebase Cloud Messaging on Android and Apple Push Notification Service on iOS. Notifications may include service messages, account or security notices, social and guild activity, gameplay reminders, event information, and permitted promotional messages.
To provide remote notifications, the Service Provider may process a push token, platform, app version, device or app-instance identifier, notification preferences, locale, time zone, and delivery or interaction metadata. Notification payloads are designed to use limited routing information and should not expose chat-message content or sensitive account information on the device lock screen.
You can disable optional notifications in the Application where controls are available or through your device settings. Required account, security, legal, or transactional notices may still be delivered through another appropriate channel. Push tokens are removed or disassociated when they are no longer needed, including after account deletion, subject to reasonable technical processing time.
Does the Application collect precise real time location information of the device?
This Application does not gather precise real-time information about the location of your mobile device. The Application may process approximate region or country information based on IP address, platform settings, storefront region, or analytics services for security, localization, analytics, legal compliance, or store/payment operations.
How does the Service Provider use information?
The Service Provider may use collected information to:
- operate, maintain, secure, and improve the Application;
- create accounts, save progress, provide matchmaking, progression, rewards, inventory, rubies, energy, hints, cosmetics, and live events;
- provide chat, social, community, and support functionality;
- review reports, moderate content, enforce rules, and protect users;
- process purchases, validate transactions, deliver virtual items, and handle purchase-related support;
- detect cheating, fraud, exploits, spam, abuse, account misuse, chargeback abuse, and other harmful activity;
- analyze gameplay, stability, performance, retention, crashes, and user experience;
- send requested or permitted local and remote notifications, service announcements, updates, support replies, and legal notices;
- measure and optimize user-acquisition campaigns using a limited set of campaign-relevant events;
- send permitted marketing communications;
- comply with legal, tax, platform, payment, and regulatory obligations.
Legal bases for processing (EEA / GDPR)
If you are located in the European Economic Area, United Kingdom, or another region with similar laws, the Service Provider processes personal data only where there is a valid legal basis, including:
- Performance of a contract: to provide and operate the Application and its core features.
- Legitimate interests: to secure the Application, prevent abuse, enforce rules, improve services, process purchases safely, protect players, deliver non-marketing service communications, and operate live-service features.
- Legal obligations: where processing is required by applicable law, lawful requests, tax duties, payment compliance, consumer protection, or regulatory obligations.
- Consent: where consent is required by law or platform rules, including for Meta attribution or tracking, optional analytics, marketing notifications, advertising measurement, or device-storage activities.
Do third parties see and/or have access to information obtained by the Application?
The Application transmits data to service providers only where needed to operate, secure, support, and improve the service. This can include pseudonymous account identifiers, allowlisted gameplay events, app and device information, crash diagnostics, transaction status, and information you submit through online features. The Application does not sell personal data.
The service currently uses, or has prepared for the next released build, the following platform and infrastructure providers:
- Google Play Services
- Apple App Store / Apple services
- Google Analytics for Firebase
- Firebase Crashlytics
- Firebase Cloud Messaging for Android push delivery
- Apple Push Notification Service for iOS push delivery
- Meta Platforms for user-acquisition attribution and campaign optimization
- Supabase for authentication and database infrastructure
- Microsoft Azure for server hosting, security monitoring, and product analytics infrastructure
- Vercel for website and invitation-link delivery
The Service Provider may disclose User Provided and Automatically Collected Information:
- as required by law, such as to comply with a subpoena, or similar legal process;
- when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, enforce rules, or respond to a government request;
- with trusted service providers who work on their behalf, do not have an independent use of the information disclosed to them, and have agreed to adhere to the rules set forth in this privacy statement;
- with platform providers, payment providers, analytics providers, infrastructure providers, moderation tools, and security partners where reasonably necessary to operate the Application.
International transfers
The Service Provider and its service providers may process information in countries other than your country of residence. Where required by applicable law, the Service Provider takes reasonable steps to ensure appropriate safeguards are in place for such transfers.
What are my opt-out rights?
You can halt ongoing collection by uninstalling the Application. You may use the standard uninstall processes available through your device or app marketplace. You can disable optional notifications through Application or device settings. You can deny or withdraw platform tracking permission through iOS privacy settings where applicable. Consent-dependent processing will stop after withdrawal, subject to reasonable technical processing time, without affecting processing that occurred lawfully before withdrawal.
What is the data retention policy and how can you manage your information?
The Service Provider will retain User Provided data for as long as you use the Application and for a reasonable time thereafter. The Service Provider will retain Automatically Collected information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Application, maintain security, investigate abuse, respond to reports, process transactions, comply with legal obligations, resolve disputes, and enforce Terms and Conditions.
When an account is deleted, the Application removes the active authentication account and mutable account data, including the public profile, current currency and inventory balances, progression projections, puzzle progress, active social relationships, and active guild membership. Public surfaces treat the former account as deleted.
Limited pseudonymous records may be retained where necessary for security, fraud prevention, transaction and ledger integrity, community safety, dispute resolution, or legal compliance. These may include immutable economy and progression ledger entries, puzzle completion records, transaction records, deletion tombstones, and guild or moderation audit history. Chat or audit records that must remain for community safety may identify the author only as a deleted player on public surfaces. Retained records cannot be used to reactivate the deleted account. Push tokens controlled by the Service Provider are deleted or disassociated as part of account deletion; external providers may retain campaign or diagnostic records according to their own retention obligations and policies.
For deletion instructions, visit the Account Deletion page. For other privacy requests, contact legal@neonhex.com.
Your privacy rights
Depending on your location, you may have rights regarding your personal data, including the right to access personal data, request correction, request deletion, object to processing, request restriction of processing, request data portability, withdraw consent where processing is based on consent, and lodge a complaint with a competent data protection authority.
To exercise these rights, contact the Service Provider at legal@neonhex.com. The Service Provider may request reasonable information to verify your identity before fulfilling a request.
How does the Application address children's privacy?
The Service Provider does not use the Application to knowingly solicit data from or market to children under the age of 13.
The Application does not address anyone under the age of 13. The Service Provider does not knowingly collect personally identifiable information from children under 13 years of age. In the case the Service Provider discovers that a child under 13 has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact the Service Provider at legal@neonhex.com so that they will be able to take the necessary actions.
How is your information kept secure?
The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information we process and maintain. For example, access is limited to authorized employees, contractors, and service providers who need to know that information in order to operate, develop, secure, moderate, or improve the Application. Please be aware that, although we endeavor to provide reasonable security for information we process and maintain, no security system can prevent all potential security breaches.
How will you be informed of changes to this Privacy Policy?
This Privacy Policy may be updated from time to time for any reason, including changes to the Application, SDKs, platform requirements, purchases, attribution, notifications, chat systems, moderation systems, or legal requirements. The Service Provider will notify you of material changes through an appropriate channel and will update the effective date on this page. Where renewed consent is required, continued use alone will not replace that consent.
Your choices and consent
Using the Application does not replace consent where applicable law or platform rules require a separate, specific choice. Where consent is required for optional analytics, Meta attribution or tracking, marketing, advertising measurement, notifications, or device-storage activities, the Application will request or respect that choice separately. Refusing optional consent will not prevent access to core gameplay that does not require that processing. You may withdraw consent through the available app or device controls where applicable, without affecting processing that occurred lawfully before withdrawal.
How can you contact us?
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at legal@neonhex.com.