Privacy
The service stores email addresses, Argon2id password hashes, session and API key hashes, request statistics and administrative audit logs. Steam accounts and inventory data are not used.
A session cookie is required to sign in. New API keys are encrypted and can be revealed by their owner. Key hashes are used to authenticate requests. Short-lived sign-in limits use a hash of the IP address.
Usage history is retained for up to 12 months and audit logs for at least 12 months.
Your language preference is stored in a cookie for one year.