Privacy Policy
Last updated: 2026-03-11
Introduction
We are committed to protecting your personal data and respecting your privacy. This website is operated in compliance with the General Data Protection Regulation (GDPR) and applicable German data protection law.
Data Controller
The data controller is: Luca Nerlich (Steam5.org)
What data we collect
- Account-related data when you log in with Steam (your SteamID and basic profile info as provided by Steam).
- Gameplay interactions (e.g., guesses and scores) for the purpose of providing the service.
- Basic technical request data processed by our servers (for example IP address in server logs) for security and operations.
- Privacy-friendly analytics via our self-hosted Umami instance.
Analytics
We use a self-hosted Umami Analytics instance to understand high-level usage. Umami is configured in a privacy-friendly way and does not use marketing cookies. Analytics data is hosted by us. For details, see Umami documentation.
Hosting and infrastructure
Steam5 is self-hosted on infrastructure in Germany (Hetzner), managed via Coolify on Ubuntu servers.
External data sources (Steam/Valve)
Game metadata and image, video and media assets are loaded from Steam/Valve services. When your browser requests this content, technical data (such as your IP address, user agent, and request metadata) is transmitted to Valve. Please review Valve's legal information and policies: https://store.steampowered.com/legal/.
Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) for providing the game and related features.
- Legitimate interests (Art. 6(1)(f) GDPR) for ensuring security and preventing abuse.
Data retention
We retain data only as long as necessary to provide the service or as required by law.
Your rights
- Right of access, rectification, erasure, restriction, and data portability.
- Right to object to processing based on legitimate interests.
- Right to lodge a complaint with a supervisory authority.
Data sharing
We do not sell personal data. Data may be shared with service providers strictly necessary to operate the site (for example infrastructure hosting). Steam/Valve receives data directly when third-party Steam resources are loaded by your browser.
International transfers
Our own primary hosting is in Germany. However, when Steam/Valve resources are loaded, data processing may occur outside the EU/EEA under Valve's responsibility. Where we initiate international transfers ourselves, we use appropriate safeguards (for example Standard Contractual Clauses) where required.
Security
We use industry-standard security measures and HTTPS everywhere to protect your data.
Contact
For privacy inquiries, contact: luca.nerlich at gmail.com