Privacy policy
Last updated July 26, 2026
What we collect
When you sign in, we store your SteamID64, display name, session data, and account preferences. When you use analysis features, we may store provider responses, historical snapshots, searches, watchlists, comparisons, teams, processing jobs, and subscription state. IP addresses are hashed before operational logging.
Why we process it
We use this data to authenticate you, provide requested analytics, maintain historical charts, enforce plan limits, prevent abuse, process legitimate demos, support billing, and secure the service.
Provider boundaries
Steam and FACEIT data is requested through supported official APIs. Private profiles and unavailable values are respected. Stripe processes payment details; StormStats does not store full card numbers.
Retention and deletion
Provider cache entries expire automatically. Historical snapshots remain while needed for the service or until account deletion, subject to lawful retention obligations. Account deletion removes account-owned records through database cascades.
Your controls
You can export stored data, change profile visibility and notification preferences, unlink access by deleting your account, or contact the operator for access and correction requests.
Cookies
StormStats uses essential session, OpenID nonce, and CSRF cookies. Non-essential analytics or advertising cookies are not enabled in the default deployment, so no consent banner is shown.
Security
Sessions use secure HTTP-only cookies, state-changing requests require CSRF validation, authorization is checked on the server, and secrets are never shipped in frontend bundles.