Privacy Policy
Effective date: 2026-05-27 · Last updated: 2026-09-04
This is the initial draft of our Privacy Policy, pending review by external legal counsel.
Covenant Alpha Pty Ltd, trading as Ferzia (
'Ferzia', 'we', 'us') operates the Ferzia app, web app, and related services (the 'Service'). This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices you have. If you have any questions, email
[email protected].
1. Who this applies to
This policy applies to anyone who creates a Ferzia account, plays games, or otherwise uses the Service. The Service is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13.
2. What we collect
Information you provide
•
Account information: email address, username, password (stored as a bcrypt hash), and, if you sign in with Apple or Google, the verified ID token from that provider. We use your email address to sign you in, to secure your account, and — unless you opt out — to send you product news and company updates.
•
Profile information: display name, avatar, country (optional), bio (optional).
•
External chess account links: Lichess and chess.com usernames if you choose to link them. We do not receive your passwords for those services.
•
Gameplay data: the PGN of every game you play in Ferzia, plus the PGN of any games you import.
•
Counselor chat history: messages you send to the counselor, the assistant’s responses, and thread metadata.
•
Support requests: the contents of any support ticket you submit and the email address tied to your account.
•
Images and files: avatars, documents, and chessboard images you choose to upload. Board-scan images are sent to our server and processing provider to recognise the position, are held only in temporary processing storage, and are deleted after processing. We may retain a one-way image hash and the recognised or corrected board position to improve scan accuracy.
•
Voice input: when you choose dictation, your device's speech-recognition service processes microphone audio and Ferzia receives the resulting transcript. Ferzia does not store raw microphone audio.
Information we generate as you use the Service
•
Mastery data: per-concept skill estimates derived from your gameplay and training activity.
•
Device and connection data: your IP address and the two-letter country we derive from it, plus device type, operating system, app or browser version, and language. Your IP address is what lets us fill in your country flag when you register, rate-limit abuse, and detect suspicious sign-ins. We do not use it to locate you more precisely than country level.
•
Usage data (app and website): the screens and pages you open, the buttons you tap, the features you use, session length, the route you came from, and your platform and app version. Analytics properties accept only bounded identifiers, enum-like values, numbers, booleans, and null; values containing free-form prose are rejected at ingest.
•
Engagement: records of counselor surface opens, review opens, and plan adherence.
•
Server logs: request metadata (including IP address), error reports, and performance traces.
Information from third parties
•
Payment data: Our third-party payment processor handles direct web payments. Apple and Google process purchases made through the App Store and Google Play. We receive provider identifiers and transaction details such as the purchased product, subscription tier, purchase status, billing email, country, currency, and amount where available. We never see or store your full payment-card number.
•
OAuth providers: when you sign in with Apple or Google we receive a verified ID token from that provider.
Optional microphone and camera features
Dictation may process microphone audio, and board capture may process a camera or photo-library image, only after you choose the feature and grant the relevant permission.
Information we do NOT collect
•
Real names (unless you choose to put one in your display name)
•
Precise or device-level location — no GPS, no street-level tracking. From your IP address we derive only an approximate country
•
Browsing history outside Ferzia
3. How we use your information
We use the information above to:
•
Provide and operate the Service (authenticate you, save your games, sync your settings, run the counselor, render the opening explorer, etc.).
•
Personalise the experience (tailor counselor output, plan suggestions, and review commentary to your mastery profile and stated goals).
•
Process payments and manage your subscription.
•
Communicate with you about your account, security alerts, and significant product changes, and — unless you opt out — send you product news, new-feature announcements, and other company updates by email.
•
Detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service.
•
Improve the Service through aggregate analytics, A/B tests, and product research.
•
Show your country flag on your profile, in games, and on leaderboards, using the country we derive from your IP address when you register. You can change it or clear it at any time in Settings → Profile.
•
Keep the Service secure and available — rate limiting, abuse and fraud prevention, and detecting suspicious sign-ins — for which we use your IP address.
•
Comply with legal obligations.
4. Third-party processing
The counselor features in Ferzia — game review, the chat counselor, multi-week plan generation, and weekly reports — are powered by third-party processing providers.
When you use those features, we send our processing provider:
•
The PGN of the game being reviewed (review feature),
•
The current user message and recent thread context (chat counselor),
•
Your mastery profile snapshot and chosen counselor persona,
•
Goals and time budget you have declared (plan generation),
•
Summarised gameplay statistics (weekly report).
We do not send our processing provider your password, payment data, other users’ data, or server logs.
Per our processing provider’s standard API terms, requests are not used for model training but request and response logs are retained by our processing provider for approximately 30 days for abuse-monitoring purposes. We do not currently have a Zero-Data-Retention agreement in place with our processing provider. Your game data and mastery snapshots therefore transit through our processing provider’s retention window for that period.
5. Cookies and similar technologies
On the web we use a small number of strictly-necessary cookies and localStorage keys to keep you signed in, remember settings, and protect against CSRF. We also store a random client identifier so that usage events from the same browser or app install can be counted together; it is not linked to any advertising profile. We do not use third-party advertising cookies and we do not run cross-site tracking pixels.
6. Who we share data with
We share data only with service providers acting on our behalf, and only to the extent necessary to operate the Service:
Category
Purpose
Data shared
AI processing provider
Counselor, game review, training plans, weekly reports
Game data, mastery snapshots, and conversation content described in section 4
Payment processors (web)
Subscription billing for purchases made on the web
Email and card details entered on the processor’s hosted forms
App stores (Apple App Store, Google Play)
App distribution, native purchases, and subscription management
Account and transaction identifiers, purchased product, purchase status, country, currency, and amount where available
Cloud hosting and infrastructure providers
Application servers, database, backups, web hosting, content delivery, DNS, and security
All Service data, encrypted in transit and at rest; IP address and request metadata
Email delivery provider
Transactional and notification email
Your email address and the contents of email we send you
Push notification provider
Mobile notifications
Device push tokens
Sign-in providers (Apple, Google)
Federated login
Verified ID token only
We do not sell your personal information. We do not share your personal information with advertisers.
These providers process data in Australia, the United States, and other regions (see section 7). A current list of the service providers we use is available on request at
[email protected].
We may disclose information if required by law, valid legal process, or to protect the rights, property, or safety of Ferzia, our users, or the public.
7. International transfers
Ferzia is operated from Australia, and our primary application servers and database are hosted in Australia. Some of our service providers — including our AI processing provider, payment processors, and hosting, content-delivery, and email providers — process data in the United States and other regions. By using the Service you acknowledge that your information may be transferred to and processed in countries other than your own.
Where personal data is transferred out of the EEA, the UK, or another region with transfer restrictions, we rely on the data processing agreements we hold with those providers — which incorporate the European Commission’s Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum — together with the technical measures described in section 10.
8. Data retention
We keep personal data only for as long as we need it for the purpose we collected it for, and then delete it or strip it of anything that identifies you. Where the law of your country sets a longer minimum (tax and accounting records, for example) or a shorter maximum, that requirement takes precedence over the periods below.
•
Account and profile data: retained until you delete your account.
•
Gameplay, mastery, and counselor chat data: retained until you delete your account. A game you played against another person is a joint record, so the game itself stays in their history with your side anonymised.
•
IP addresses: the IP address on a session record is erased automatically 90 days after that session was last active, by a scheduled daily job. IP addresses attached to usage events are dropped together with the event, 90 days after it was recorded. We do not build or keep a long-term IP history.
•
Usage and engagement events: retained for 90 days on a rolling basis, then permanently dropped.
•
Server logs: retained for 30 days on a rolling basis.
•
Payment records: retained by our payment processor under its own policies, and by us for as long as tax, accounting, and consumer-protection rules require — generally five to seven years in Australia, and sometimes longer in other jurisdictions.
•
Unsubscribe and bounce records: if you unsubscribe, or mail to your address hard-bounces, we keep a one-way hash of your email address indefinitely. That record is the only thing that stops us emailing you again, so deleting it would defeat your own opt-out.
•
Encrypted backups: database backups run on a rolling daily / weekly / monthly / yearly schedule. Data you delete disappears from the live Service immediately but remains inside existing backup snapshots until those snapshots expire. Backups are restored only for disaster recovery, never to bring a deleted account back.
•
Aggregate / anonymised research data: may be kept indefinitely. Once data is aggregated or de-identified it can no longer be traced back to you and is no longer personal data.
What happens when you delete your account
Deletion is immediate — there is no grace period and no hidden soft-delete. Your sessions, tokens, push tokens, notification history, linked chess accounts, imported games, repertoires, training progress, achievements, rating history, club and tournament memberships, and membership record are deleted outright, and any active subscription is cancelled.
Because a chess game is a joint record that your opponent is entitled to keep, we cannot remove the game rows themselves. Instead we irreversibly anonymise your account — email address, username, password, bio, and avatar are destroyed — which satisfies the right to erasure by de-identification. You can start this at any time from Account → Account details → Delete Account.
Regional retention requirements
Retention rules differ by country. Where yours is stricter than ours, we apply yours.
•
EU / UK (GDPR, UK GDPR): storage limitation under Article 5(1)(e) — we hold personal data in an identifiable form no longer than is necessary for the purposes set out in section 3.
•
Australia (Privacy Act 1988, APP 11.2): we destroy or de-identify personal information once it is no longer needed for any purpose for which it may lawfully be used or disclosed, unless a law or a court or tribunal order requires us to keep it.
•
California (CCPA / CPRA) and other US state privacy laws: the periods listed above are our disclosed retention periods. We do not keep any category of personal information for longer than the period stated for it.
•
Canada (PIPEDA), Brazil (LGPD), Japan (APPI), South Korea (PIPA), India (DPDP Act), and comparable regimes: the same principle applies — we retain data only for the declared purpose and delete or de-identify it once that purpose ends, subject to any local statutory record-keeping minimum.
•
Tax, accounting, and consumer-law records: kept for the minimum period the relevant jurisdiction requires, even after you delete your account. These records are retained for compliance only and are not used to profile you or to contact you.
We may keep specific records beyond these periods where we need to comply with a legal obligation, establish or defend a legal claim, investigate fraud or a fair-play violation, or enforce our Terms of Service. Where we do, we keep only what is necessary for that purpose and delete it once the purpose ends.
9. Your rights
Depending on where you live you may have the right to:
•
Access the personal information we hold about you.
•
Correct inaccurate information.
•
Delete your account and the data associated with it.
•
Export your data in a portable format.
•
Object to or restrict certain processing.
•
Withdraw consent where processing is based on consent.
•
Unsubscribe from product and company email at any time. Every such message carries a one-click unsubscribe link, and opting out never stops account-security email such as password resets and sign-in alerts.
•
Opt out of usage analytics — ask us to stop recording usage events against your account. Email
[email protected] and we will set the opt-out; events already recorded age out on the 90-day cycle in section 8.
•
Ask how long we keep something — section 8 is our standing answer, and you can ask us to confirm the period for a specific category.
You can exercise account deletion directly in the app via
Account → Account details → Delete Account. For any other request, email
[email protected]. We will respond within the time frame required by applicable law (typically 30 days).
EU / UK users (GDPR)
The legal bases we rely on are: (a) performance of a contract — providing the Service you signed up for; (b) our legitimate interests in operating, securing, and improving the Service, which covers processing your IP address for security and country-level geolocation and processing usage data to improve the product; (c) compliance with legal obligations; and (d) your consent where required — for example, for marketing email and optional analytics in jurisdictions that require opt-in consent.
You also have the right to lodge a complaint with your local data-protection authority.
California users (CCPA / CPRA)
We do not sell or share personal information for cross-context behavioural advertising. California residents have the right to know what we collect, request deletion, request correction, know how long each category is retained (section 8), limit the use of sensitive personal information — we do not collect any — and not to be discriminated against for exercising those rights.
10. Security
We use industry-standard measures to protect your data, including HTTPS / WSS in transit, encryption at rest for database backups, bcrypt password hashing (12 rounds), OAuth ID-token verification, rate limiting at the API layer, daily usage caps, and regular dependency / security audits. No system is perfectly secure; if you believe your account has been compromised, contact
[email protected] immediately.
11. Children
The Service is not directed at children under 13 and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, contact
[email protected] and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes we will notify you in-app and update the 'Last updated' date above. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact