Privacy policy
Last updated: August 22, 2026
1. Who we are
GameBuro is an entertainment service that creates cards, receipts, tier lists, recommendations and other results from public Steam profile data and also provides GameBuro accounts. The service is not affiliated with Valve Corporation and is not an official Steam product. For data questions: contact@gameburo.com.
2. What data we use
We process data needed to operate and protect the service:
- GameBuro account data: stable public ID, unique nickname, email, password hash, email verification status, account language preference, profile description, privacy settings, creation/sign-in dates, accepted policy version/time, and optional saved links to Steam, DTF, VK and Telegram. Session information, IP addresses and browser technical data may be stored for security. Nickname, email, Steam/DTF/VK/Telegram-link and public-ID history may be retained for moderation. See the account policy and service rules.
- Public Steam profile data provided by the user: nickname, avatar, game library, playtime, level, achievements and other public data available through Steam Web API. We never request your Steam login or password and have no access to them.
- IP address and technical request data such as request time and page are used to prevent bots, brute force and abuse. For some counters the IP is stored as an irreversible hash; when protection is triggered, the original IP may be kept temporarily to block the source of an attack.
- First-party site statistics: visited page, language, referring domain, clicks and aggregate device, operating-system and browser categories. Full User-Agent is not kept for ordinary statistics.
- Recommendation preferences: “interested”, “not interested” and “played” marks, shown and selected games. They may be associated with an irreversible HMAC hash of SteamID and device without keeping the raw SteamID, profile URL, nickname or full device identifier in the preference database.
- Social connections, internal messages and moderation: follows, mutual-friend relationships, friend requests and their status, in-site notifications, administration-chat messages, read state, warnings and revocations, blocking reasons and expiry dates, public-profile reports and related service records.
- Cookies and local storage: language, notice state, security tokens, user/admin sessions; notice state and other required local records.
3. Why the data is needed
- create and operate accounts, sign users in and restore access;
- verify email addresses and deliver security/service messages;
- run GameBuro features using a user-provided public Steam profile;
- temporarily cache results and reduce load on Steam and other APIs;
- measure site usage and interface activity;
- remember recommendation feedback and improve future results;
- protect the site and accounts from spam, bots, brute force and other abuse.
4. Cookies and browser storage
GameBuro uses required cookies and local records such as language, security tokens, user/admin sessions, notice state and other technical data needed by the selected feature. They are not used for advertising. Third-party web analytics is disabled on the test version of the site. GameBuro's own aggregate server counters operate separately and do not use third-party analytics cookies.
You can remove cookies and local data in your browser settings. Removing the account session cookie signs that device out.
5. Retention and deletion
- Account data — while the account exists or while reasonably needed for security and service operation. Nickname, description, language, privacy, saved profile links, email and password can be changed in the profile. Account deletion can be scheduled there as well; it is carried out after a 7-day grace period and can be cancelled before then.
- Unfinished registrations, verification codes, email-change requests and password resets have limited validity and may be automatically removed after expiry.
- Account sessions — until expiry, sign-out, sign-out-everywhere, password change or administrative blocking.
- Result cache — usually about one hour to one day, then expires.
- Counters and rate limits using hashed IPs are short-lived and cleaned automatically.
- Technical anti-abuse IP log — entries used for attack prevention and automated limits are kept for no more than 4 days since that IP's last recorded activity. The account's own security-event history may be retained with the account and is available to administrators for diagnostics and abuse prevention.
- First-party statistics — short-lived IP hashes expire after roughly one hour; aggregate daily counters may be retained long-term without the original IP or full User-Agent.
- Recommendation history — pseudonymous events and preferences tied to an HMAC hash may be kept long-term to improve results and can be removed on request or when the recommendation database is reset.
6. Third-party services
- Steam Web API (Valve) — source of public Steam profile data.
- Configured AI provider — receives only public profile data or tier-list content needed for the requested AI feature. Login credentials, passwords and payment details are not sent.
- Mail provider — receives the recipient email address and technical message content needed to deliver account service emails.
- The site may link to external platforms and resources. Their own privacy rules apply independently of GameBuro.
7. Your rights and controls
You can change account details and privacy settings in your profile, terminate individual or all active sessions, schedule account deletion with a 7-day cancellation period, and request information or correction by contacting contact@gameburo.com. Locating a pseudonymous recommendation record may require the public SteamID so the same HMAC hash can be recomputed. Public-profile, messaging, reporting and moderation rules are described in the GameBuro account policy.
8. Policy changes
This policy may be updated as GameBuro evolves. The current version is always published on this page with the update date shown above.