Security
Updated: 2026-08-12
Reporting a vulnerability
Email support@scanchess.com with "Security" in the subject. Describe how to reproduce it and what it lets someone do. We reply within 3 business days and tell you the outcome once it is fixed.
We will not pursue legal action over good-faith research, provided you do not access, change, or exfiltrate anyone else's data, do not run denial-of-service or spam tests, and give us a chance to fix the issue before disclosing it. There is no paid bounty programme, but we will credit you by name if you want that.
How your data is protected
- Everything travels over HTTPS; the site and API sit behind Cloudflare.
- Passwords are stored as salted bcrypt hashes — we cannot read yours.
- Web sessions use signed JWTs in HttpOnly cookies; changing a password revokes previously issued sessions and password-reset tokens.
- We never handle payment details: web checkout is hosted by Waffo, our merchant of record, and we receive only an order id and subscription status.
- Deleting an account really deletes it — profile, games, and uploaded images go, and cannot be recovered.
The images you upload
Scoresheet photos are sent to the third-party AI model provider we use for recognition; the Privacy Policy sets out exactly what is shared. Images belong to your account: delete a single game at any time, or delete the account to remove all of them.
What we do not have
Plainly: no SOC 2, no ISO 27001, no third-party audit, and no paid bounty programme. ScanChess is built by a small team. If your school, federation, or employer needs compliance paperwork, write to us and we will tell you honestly what we can and cannot provide.
See also: Privacy Policy · Service status · support@scanchess.com
