Privacy Policy
Last Updated: August 2026
//
This Privacy Policy explains how Crystl Labs ("we," "us," or "our") handles information in connection with everything we make: our mobile applications, our websites and web-based tools, and any other product or service we offer — free or paid, released or in preview, on any platform we publish to (collectively, the "Apps"). Not every App offers every feature described in this Policy — for example, some Apps do not offer user accounts, request location access, or request contacts access, and our websites generally offer far fewer of these features than our mobile applications do. The data we actually collect depends on the features a given App offers; where an App is distributed through the Google Play Store, see that App's "Data safety" section on its listing for the specifics of that App. If a section of this Policy describes something a given App does not do, that section does not apply to it. By using our Apps, you agree to the practices described here.
1. Information We Collect
Information you provide.
- Account information (if applicable). Some Apps let you create an account, which may require an email address and a password. Passwords are stored in encrypted/hashed form; we never store or have access to your plaintext password.
- Chess.com username ("callsign"). When you enter your Chess.com username, we store it locally on your device and use it to retrieve your public game data. It is also sent to our analysis server to generate coaching feedback.
- Content you input. Any text, image, or contextual data you enter into our Apps (such as chess game data) that is needed to provide the App's features.
- Health and wellness data (if applicable). Some Apps let you record supplements and doses, reminder schedules, inventory counts, blood-test results, menstrual cycle and fertile-window entries, fasting sessions, mood and energy ratings, weight and body measurements, and photos you attach to an item, and let you import sleep, heart-rate and readiness figures from a device you connect or from Android Health Connect. See Section 14.
Information collected automatically or with your permission.
- Advertising identifiers and ad data. We use Google AdMob, and may use other advertising networks (such as Unity Ads, Meta Audience Network, or AppLovin), to display ads. These networks may collect and share your device's Advertising ID and related information, including IP-derived approximate location, app and ad interactions, diagnostic information, and device or account identifiers, to provide advertising, analytics, and fraud prevention.
- Location information (if applicable). Some Apps may request access to your device's precise or approximate location to provide location-based features. We only collect location data from Apps that disclose this feature and request the relevant device permission.
- Contacts (if applicable). Some Apps may request access to your device's contacts to provide features such as finding friends or sharing content. We only access contacts from Apps that disclose this feature and request the relevant device permission.
- Anonymized, aggregated telemetry. We and our service providers may collect anonymized, aggregated diagnostic and usage data to keep the Apps stable and improve them. This data is not used to personally identify you.
- Cloud save data (if applicable). Some Apps offer cloud save/sync, which stores your in-app progress, saved data, or settings using providers such as Google Play Games Services or Firebase so it can be restored across devices. This data is tied to your account, device ID, or player ID.
- Crash and diagnostic reports. Some Apps use a crash reporting service to report crashes and stability issues: either Firebase Crashlytics (a Google service) or Sentry (operated by Functional Software, Inc.). When an App crashes or hits an error, that service collects diagnostic information such as the type of crash, a stack trace, your device model and operating-system version, the App's state at the time, and a randomly generated installation identifier used to group related reports. We use this solely to find and fix bugs; it is not used to advertise to you. We do not send your name or your device logs to these services, and we never upload your save files. A report may include limited App state from the moment of the error, such as the screen you were on and a few in-app counters, so the problem can be reproduced.
- App usage analytics. Some Apps use Google Analytics for Firebase to understand how the App is used. It automatically records events such as when the App is opened, when a session starts, and which screens are viewed, together with your device model, operating-system version, country, a randomly generated app-instance identifier, and your device's Advertising ID. We use this to see which features are used and where players get stuck. We do not use it to identify you personally.
- Purchase information (if applicable). Some Apps offer one-time in-app purchases processed by Google Play Billing. We do not receive or store your payment card details. We receive a record of what was purchased and its current entitlement status from Google, so the App can unlock what you paid for and restore it if you reinstall or change device.
- Notifications (if applicable). Some Apps ask permission to send you notifications — a reminder you set, or an alert that something you started in the App has finished. In our Apps these notifications are generated on your device from data already stored there: no information is sent to us or to anyone else in order to produce them, and we do not learn whether you opened one. If an App ever sends notifications from a server, it would use Firebase Cloud Messaging and store a randomly generated device token so the message can reach your device; that App's Play Store "Data safety" section will say so. You can turn notifications off at any time in the App's own settings or in your device's system settings, and every App keeps working with them switched off.
- Optional voice features (if applicable). Some Apps offer optional voice-control features. While enabled, your device's speech-recognition service may listen continuously and may process audio through that service. We do not store audio recordings, and you can disable the feature in the App's settings.
If you email our support address, we will have whatever information you choose to include in that message.
2. How We Use Your Information
We use the information above to:
- Create and manage your account, where an App offers accounts;
- Provide the App's core features, including retrieving your public chess games and generating AI coaching analysis;
- Provide location-based or contacts-based features, where an App offers them;
- Display and measure advertising;
- Maintain, secure, and improve the Apps;
- Respond to your support requests;
- Deliver and restore in-app purchases, where an App offers them;
- Send you notifications, where an App offers them and you have allowed it;
- Provide cloud save/sync functionality, where an App offers it.
3. Chess.com Data
When you provide a Chess.com username, the App requests your public profile, ratings, and game history from Chess.com's public API, and retrieves chess board images from Chess.com. We only access information that Chess.com makes publicly available. Your use of Chess.com is also governed by Chess.com's own privacy policy.
4. AI Processing Providers
To generate coaching feedback, we transmit your game data (and the associated callsign) to Google LLC's Gemini API, processed on Google's servers in the United States, solely to generate your coaching analysis. We currently use Gemini for this purpose and may add or change AI processing providers in the future, in which case we will update this section. We do not permit our AI providers to use your personal inputs to train their models, and we absolutely do not sell your data to data brokers.
Health and wellness Apps. Where an App offers health tracking, the data transmitted is your current supplement list, any blood-test results and DNA-derived markers you have entered, your fasting state, and readiness or recovery figures from a wearable you have connected. It is sent only when you tap the AI feature, and only after you accept a separate consent prompt that lists those items. Nothing read from Android Health Connect is included. See Section 14.
5. Advertising
Our Apps use Google AdMob, and may use other advertising networks such as Unity Ads, Meta Audience Network, or AppLovin, to display advertisements. These networks may collect and use your device's Advertising ID and related data to serve and measure ads, including personalized ads where permitted. Each network's use of your data is governed by its own privacy policy. You can learn how Google uses this data here: policies.google.com/technologies/partner-sites.
Consent (EEA / UK). If you are in the European Economic Area, the United Kingdom, or Switzerland, we request your consent for ad data use through Google's consent form before ads are shown. You may change or withdraw your choice at any time from within the App. You can also opt out of ad personalization in your device settings (Google → Ads → "Delete/Reset advertising ID" or "Opt out of Ads Personalization").
6. Data Sharing
We share information only as needed to operate the Apps: with our AI processing providers (Section 4), with our advertising networks (Section 5), with our crash-reporting, diagnostics, and analytics providers (Firebase Crashlytics and Google Analytics for Firebase, both Google services, and Sentry, operated by Functional Software, Inc.), with Chess.com's public API (Section 3), with the wearable providers you choose to connect (Oura, Whoop) and with Open Food Facts for barcode product lookups where an App offers those features, with the cloud storage provider (such as Google Play Games Services or Firebase) used to operate cloud saves where an App offers that feature, with Google Play Billing where an App offers in-app purchases, and, where an App offers accounts, with the authentication or backend infrastructure providers we use to operate that account system. We may also disclose information if required by law or to protect our rights and users. We do not sell your personal information.
7. Data Retention & Deletion
Your callsign and cached game data are stored locally on your device and can be cleared at any time from the App's Settings screen ("Clear App Data") or by uninstalling the App. If an App offers an account, you may request deletion of your account and associated data at any time from within that App's Settings or by emailing us; we will delete it within a reasonable time, except where we must retain it to comply with law. Data sent to our AI providers is processed to deliver your results and is not retained for profiling. Cloud save data persists until you disable the feature, delete it from within the App, or request deletion as described below. To request deletion of any data associated with you, see our data deletion page or email us at the address below.
8. Your Rights
Depending on where you live (including under the EU/UK GDPR and the California CCPA/CPRA), you may have the right to access, correct, delete, or restrict the use of your personal information, to withdraw consent, and to lodge a complaint with a supervisory authority. To exercise these rights, contact us at crystllabs@gmail.com. We will not discriminate against you for exercising any of these rights.
9. Children's Privacy
Our Apps are not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact crystllabs@gmail.com and we will delete it.
Some Apps, including any health or wellness App, are restricted to users 18 years of age or older and ask you to confirm your age before the App can be used.
10. Security
We use reasonable technical and organizational measures, including encrypted (HTTPS) connections, to protect information in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. International Data Transfers
Your information may be processed on servers located outside your country. Specifically, if you use our AI coaching feature, your Chess.com callsign and associated game data are transmitted via secure API, each time you request coaching analysis, to Google LLC's Gemini API and processed on servers located in the United States, solely to generate your coaching analysis; this data is not retained by Google for model training or profiling. If you do not want this transfer to occur, simply do not enter your Chess.com username or use the AI coaching feature. Where applicable, our advertising and authentication providers may similarly process data outside your country. Where required, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for these transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date above, and continued use of the Apps after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
For any privacy questions or requests, contact us at:
crystllabs@gmail.com14. Health, Fitness and Genetic Data
This section applies only to those of our Apps that offer health or wellness tracking. It adds to the sections above and prevails over them wherever they differ. If an App does not offer health or wellness tracking, nothing in this section applies to it.
What is collected.
Supplements and doses you log, reminder schedules, inventory counts, blood-test results you enter, menstrual cycle and fertile-window entries, fasting sessions, mood and energy ratings, weight and body measurements, photos you attach to a supplement, and sleep, heart-rate, readiness or recovery figures imported from a device you connect.
Where it is stored.
On your device, in a local database. Crystl Labs operates no server for these Apps and holds no copy of your health data. API keys and wearable access tokens are stored encrypted on the device.
Genetic data.
You may optionally upload a raw DNA export from a consumer testing service such as 23andMe or AncestryDNA. The file is read on your device, a small number of nutrition-related markers are kept, and the rest is discarded. The file itself is never uploaded anywhere. This is not a clinical genetic test and is not diagnostic.
Who else can receive it, and only when you turn that feature on.
- Google (Gemini API). When you use the AI feature, after a separate consent prompt naming exactly what is sent. See Section 4.
- Oura and Whoop. When you enter an access token, the App requests your sleep, readiness and recovery figures from that provider.
- Open Food Facts. When you scan a product barcode, that barcode is sent to look up the product. No health data is sent with it.
- A destination you choose. When you export a backup or a report for your doctor, the file is written wherever you direct the system file picker. From that point the file is outside our control.
- Android Health Connect. See Section 15.
Never used for advertising.
Health, fitness and genetic data is never used to select, target or measure advertising, is never shared with advertising networks, data brokers or information resellers, and is never sold. Where an App shows advertisements, those advertisements are served without any access to the data described in this section.
Never used for eligibility decisions.
We do not use, transfer or sell health, fitness or genetic data to determine employment, insurance or credit eligibility, and we do not share it socially on your behalf.
Retention and deletion.
This data stays on your device until you remove it. The App's Settings screen offers a delete-all option that erases the local database, all saved preferences, encrypted tokens and attached photos; uninstalling the App removes the same data. Data already transmitted to Google, Oura, Whoop or Open Food Facts is governed by those providers' own policies — use each provider's own controls to delete it.
Age.
An App covered by this section is intended for adults and asks you to confirm that you are 18 or older before it can be used.
Not medical advice.
An App covered by this section provides general wellness information only. It does not provide medical advice, diagnosis, or dosing instructions, and it is not a substitute for a physician or pharmacist.
15. Android Health Connect
An App covered by Section 14 can connect to Android's Health Connect, with your permission, to use a limited set of records:
- Sleep (read). To show your sleep alongside the supplements you took.
- Heart rate (read). To show resting heart rate alongside your log.
- Nutrition (write). To write the supplements you log, so other apps you use can see them.
The App shows an explanation screen before requesting these permissions. You can revoke them at any time in Health Connect settings, and the App continues to work without them.
Data read through Health Connect is used only for the in-app features described above. It is never used for advertising, never transferred or sold to any third party, advertising platform, data broker or information reseller, and never used to determine employment, insurance or credit eligibility. It is not sent to our AI processing provider — the AI feature transmits only the items listed in its own consent prompt, and those do not include anything read from Health Connect.