Cookie Policy
Lumichess uses cookies and browser storage, which means local storage, session storage and IndexedDB, to keep you signed in, remember your settings, cache the heavy data the app needs, and measure use. This page lists what is stored, how the consent panel behaves, and how to change your answer later. For how we handle personal data more broadly, see the Privacy Policy.
Three categories, and only one of them is optional
Essential. Storage the site cannot work without: your sign-in token, your settings, and the caches that make a page you have already opened load without fetching and analysing everything again. This is never optional and you are not asked about it. Blocking it means you cannot stay signed in and your preferences reset on every visit.
Analytics. Google Analytics, which tells us which pages and features get used. Off until you allow it.
Advertising. Google AdSense, where ads are shown. Off until you allow it. Ads are not shown to Premium members, and never inside the native apps.
One thing worth being plain about: our own product event log, described in the Privacy Policy, runs on legitimate interests rather than on the consent panel, because it is server-side and does not read or write anything in your browser beyond a session identifier. It records events like "report opened" and never anything you type.
How the consent panel behaves
The first time you visit, a panel appears in the bottom corner with three buttons. Allow all switches on analytics and advertising. Essential only keeps just the storage the site needs to work. Manage opens the three categories so you can tick analytics and advertising separately, with essential shown as always on, and then save.
Until you choose, Google's tags load in consent mode with analytics storage, ad storage, ad user data and ad personalisation all set to denied, so nothing is measured and no advertising identifier is set. Your answer is written to your browser under lumi_cookie_consent_v1 and is read again before the tags run on every later page, so the choice holds from the first frame rather than after the fact.
The panel asks once per browser and then stops. It does not appear inside the iOS and Android apps, where the stores' own disclosures apply. It also holds back on this page, the Privacy and Terms pages, and on any page with a board on it, because on a phone the card would cover the bottom rank; it waits for the next page that is not one of those. Nothing runs in the meantime, since analytics start denied.
Changing or withdrawing your consent
Open Cookie settings in the footer of any page. The same panel reopens with your current answer already ticked, and saving a new one updates Google's consent mode immediately rather than on the next page load. You can withdraw consent as easily as you gave it, and withdrawing it does not affect anything that happened while it was on.
You can also clear or block cookies and site data in your browser's own settings, and the Google Analytics opt-out add-on blocks Google Analytics on every site, not just this one.
What is actually stored
| Name | Kind | What it is for | How long |
|---|---|---|---|
| Supabase sign-in token | Local storage | Essential. Keeps you signed in between visits. | Until you sign out |
lumi_cookie_consent_v1 | Local storage | Essential. Your answer to this panel. | Until you clear site data |
centichess_setting_* | Cookies | Essential. Board theme, piece set, sounds, engine depth and the rest of your settings. | 365 days |
IndexedDB database lumichess | IndexedDB | Essential. Puzzle chunks, Learn lessons and progress, analysed games, coach chat threads and messages. | Until you clear site data |
IndexedDB database lumichess-feedback | IndexedDB | Essential. Feedback that could not reach the server yet. | Until you clear site data |
| Coach state, report caches, chat tombstones | Local storage | Essential. Keeps your training record and makes a deleted chat stay deleted. | Until you clear site data |
| Random browser identifier | Local storage | Essential. Stops the same browser being counted twice when you send feedback or react to an announcement without an account. | Until you clear site data |
lumi_analytics_session_id | Session storage | Groups the events of one visit together. | Until the tab closes |
lumi_analytics_first_touch_utm, lumi_first_seen_at, lumi_visit_count | Session and local storage | Records which link brought you here and whether you came back. | Until you clear site data |
_ga, _ga_* | Cookies set by Google | Analytics. Tells returning visitors from new ones. Only set if you allow analytics. | Google's own lifetime for these cookies |
| Google AdSense cookies and identifiers | Cookies set by Google | Advertising, where ads are shown. Only set if you allow advertising. | Google's own lifetime for these cookies |
The caches are large on purpose. Puzzle sets are downloaded to IndexedDB so puzzles load instantly and work offline, and games fetched from Chess.com or Lichess are kept so a report you have already run does not have to be run again.
Third parties
Signing in with Google, paying through Dodo Payments and playing live games on Lichess each hand you over to that provider, whose own cookies and policies apply while you are there. Each of them is named in the Privacy Policy.
Contact
Questions about cookies: support@lumichess.com