Legal

Privacy Policy

Last updated: 13 July 2026

This policy explains what personal data the Steam Data API (“we”, “us”) collects, why, how we protect it, and the rights you have over it. We collect the minimum needed to run the Service - we do not sell your data.

1. What we collect

We do not require or collect your Steam account, Steam credentials, or inventory in order to use the API. (If you voluntarily pass a public SteamID to the inventory endpoint, we query that public profile on your behalf and do not retain it beyond a short cache.)

2. How we use it

Under the GDPR, our legal bases are performance of our contract with you (running the Service), our legitimate interests (security, abuse prevention, improving the Service), and consent where required.

3. Who we share it with

We share data only with the processors needed to run the Service, under appropriate data-processing terms:

We may also disclose data if required by law or to protect our rights. We do not sell or rent your personal data, and we don’t use it for third-party advertising.

4. Cookies

We use a single strictly-necessary cookie (sdk_session) to keep you logged in to the dashboard. Your light/dark theme preference is stored locally in your browser. We do not use advertising or cross-site tracking cookies.

5. Data retention

We keep account and billing data for as long as your account is active and as required for legal/accounting purposes. Detailed request logs are retained on a rolling basis (typically up to a few months) and then aggregated or deleted. When you delete your account, we delete or anonymise your personal data except where we must retain it by law.

6. Your rights

Depending on where you live (e.g. the EU/EEA under GDPR, or California under CCPA), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can update or delete your account from the dashboard, or contact us to exercise any of these rights. You also have the right to complain to your local data-protection authority.

7. Security

We protect your data with encryption in transit (HTTPS), hashed credentials, scoped access controls and API-key isolation. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.

8. International transfers & children

Our providers may process data in regions outside your own; where required we rely on appropriate safeguards. The Service is not directed to children, and you must be at least 16 (or your country’s age of digital consent) to use it.

9. Changes

We may update this policy; material changes will be posted here with a new “last updated” date and, where appropriate, notified to you.

10. Contact

For any privacy question or request, contact our data controller at [email protected] or via our Discord.