Chess.com ran its product analytics on a rented platform. Identity lived inside the vendor's tool, a share of signup sessions was being credited to the wrong users, and passive server traffic was polluting activity metrics. We designed the way out and led the delivery. Nearly one petabyte of data and 79 production models moved to a first-party platform, identity was rebuilt across 2.5 years of history, and realtime consumers stayed live the entire time. Nothing was lost on the way.
Every acquisition dollar, experiment readout and product bet at Chess.com flows through its analytics. Underneath, identity had quietly drifted. A single week of production data held hundreds of millions of sessions, and millions of them were shared between multiple users. Attribution, funnels and activity metrics all carried the distortion, and the source of truth belonged to an external vendor.
We designed and delivered the migration to governed first-party events: a unified event contract spanning event generations, source reconciliation with cutover validation, and rollback protection for every downstream consumer. Chess.com now owns its identity and event data end to end. There is no per-event vendor pricing and no external dependency in the critical path.
Identity was reconstructed deterministically across 2.5 years of history. Healed session IDs, registration events as signup anchors, and contaminated multi-user sessions untangled rather than thrown away. Phantom activity was suppressed too: tens of thousands of false daily actives and millions of duplicate sessions removed every day. Every correction is explained by audit columns on the data itself.
The migration split unified events into raw, healing and final layers, so downstream models moved over gradually and safely. Realtime consumers kept running against the same contract while 79 production models were realigned underneath them. Final validation showed zero remaining multi-user sessions, zero event loss, and session coverage above 99% for logged-in activity.
An earlier proposal for a new service-level person ID was explored and deliberately dropped after architecture review. Solving identity in a healing layer, with the raw data preserved, delivered the same analytical outcome at far lower risk. Knowing what not to build is part of the job.