Privacy
Last updated August 2026.
Who runs this site
The controller for the account service is Garrett, the operator of Skintel.gg. Questions about this notice, your account data, or a rights request can be sent tolegal@skintel.gg. This page explains what the account features store, why they store it, and how long it stays here.
Who this notice covers
The account service is offered to people in the United Kingdom and the European Union on purpose, not merely reachable from them. Both the UK GDPR and the EU GDPR therefore apply to the account data described below, and the sections on lawful basis, retention, transfers, and your rights should be read as covering both.
Some of what this notice should name is not in place yet. We are working on an EU GDPR Article 27 representative, a Digital Services Act Article 13 legal representative and an ICO registration reference, and each will be named here once it is confirmed. Until then, legal@skintel.gg reaches the operator directly for anything those roles would handle, including a rights request or a complaint.
Steam sign-in
Sign-in uses Steam OpenID. Steam confirms your SteamID64 and sends your browser back toSkintel.gg; Steam never sends us your password, and we never see or store it. We do not use a persona name or avatar as an identity key. If an optional Steam profile lookup is available, we request it at sign-in only and store the smallest display cache needed for your account.
What we store and why
The account service runs in Cloudflare D1 in the ENAM region. We group the stored fields by the job they do:
Account identity and status
- Internal account id (
users.id): the identifier Skintel uses inside the account service to connect your records. It is separate from your public profile name. - SteamID64 (
users.steam_id): the verified Steam identity key used to create, find, secure, and delete your account. This is necessary to provide the account features you request, with the account-service basis in Article 6(1)(b) of the UK and EU GDPR, or a documented legitimate interest in account security where that contract basis does not apply. - Persona name and avatar URL (
users.persona_nameandusers.avatar_url): optional Steam display data used to label your account and show its avatar. The values are fetched only at sign-in when the server has aSTEAM_API_KEY, are refreshable, and can be removed on request. We do not store avatar image bytes. - Profile refresh time (
users.profile_fetched_at): records when the optional Steam display data was last fetched, so the cache can be refreshed without treating a display change as a new identity. - Account role (
users.role): records whether the account is a regular user, moderator, or owner so the site can protect moderation controls. - Account timestamps (
users.created_at,users.last_seen_at, andusers.deleted_at): record when the account was created, when it was last seen, and whether it was deleted. A deleted account keeps an anonymous tombstone so retained moderation records remain attributable without retaining the live SteamID64.
Sign-in and session security
- Session record (
user_sessions.idanduser_sessions.user_id): identifies a session and links it to your account. The database stores a SHA-256 hash of the opaque browser token, not the bearer token itself. - Session times (
user_sessions.created_at,user_sessions.expires_at, anduser_sessions.last_seen_at):record when a session began, when it expires, and when it was last used. Unused sessions expire after 12 hours. Signing out revokes the current session, while account deletion revokes all sessions. - One-time sign-in token (
auth_nonces.idandauth_nonces.expires_at): records the callback nonce that binds a Steam sign-in to the browser that started it. A nonce value is kept for at most 10 minutes, then it is pruned.
Saved catalog data
- Favourites (
item_favourites.user_id,item_favourites.item_id, anditem_favourites.created_at):link your account to each saved catalog item and record when you saved it. Favourites are private, are not counted for anyone else, and are not used as a ranking signal. - Albums: album titles, descriptions, item membership, visibility, share slug, moderation state, and timestamps for albums you ask us to store and display. Private albums stay owner-only. Unlisted and public albums are available according to their stated visibility. The basis is the requested hosting and publication feature under Article 6(1)(b).
Reports and moderation
- Report identity and target (
content_reports.id,content_reports.target_kind, andcontent_reports.target_id):identify the report and the item or album it concerns. - Report author and content (
content_reports.reporter_user_id,content_reports.reason, andcontent_reports.note): link the report to the account that sent it, store its structured reason, and keep the optional note. Please do not include unnecessary personal or sensitive information in a report note. - Report state and times (
content_reports.state,content_reports.created_at, andcontent_reports.resolved_at):record whether a report is open, actioned, or dismissed, when it was sent, and when it was resolved. - Resolving moderator (
content_reports.resolved_by_user_id):links a resolved report to the moderator account that resolved it. - Moderation record id and actor (
moderation_actions.id,moderation_actions.actor_kind,moderation_actions.actor_user_id, andmoderation_actions.actor_token_id): identify an audit record and whether the action came from a moderator account or an approved machine token, with the corresponding actor identifier. - Moderation decision (
moderation_actions.action,moderation_actions.target_kind,moderation_actions.target_id,moderation_actions.reason, andmoderation_actions.created_at):record what happened, which item, album, or account it concerned, why it happened, and when it was recorded. These records explain decisions, support appeals, and defend legal claims. They are restricted to authorised moderation views.
We do not collect Steam profile history, advertising identifiers, marketing preferences, or data for unsolicited marketing. There is no solely automated decision-making with legal or similarly significant effects in the account service.
Storage and retention
The account tables live in Cloudflare D1, ENAM region (United States and Canada). Cloudflare processes those records as our infrastructure provider. Steam handles its own OpenID and Web API processing under Steam's terms. We disclose this storage location because Steam's Web API terms require us to name the country or countries where Steam Data is stored.
That location is outside the UK and the EEA, so storing your account data there is a restricted international transfer. It relies on the standard contractual clauses in Cloudflare's data processing addendum, amended for UK data by the Information Commissioner's International Data Transfer Addendum. You can ask us at legal@skintel.gg for a copy of the safeguards that apply to your data.
- An unused session record expires after 12 hours. Using the site while signed in extends it to a fresh 12 hours, so the window is one of inactivity rather than a hard limit.
- Favourites and albums remain until you delete them or delete your account.
- A resolved report is deleted 12 months after it was resolved. An open report is never swept out from under an unfinished case, however old it is.
- Moderation records are deleted 12 months after they are written.
- Both are deleted by a later moderation write. Reports are created when someone reports something and audit records when a moderator acts, and every moderator action also clears whatever has passed its period, so the store cannot grow without being trimmed. There is no legal-hold mechanism that keeps a record past its period.
- When you delete your account, the account row is tombstoned indefinitely so surviving audit entries remain attributable without retaining the live SteamID64. Sessions, favourites, albums, and album items are deleted. Reports are anonymised to the tombstone where a record must remain for the stated retention period.
Your rights and account controls
You can request access, correction, deletion, restriction, objection, and a portable copy of your account data. Visit /account/data while signed in to export the account data as JSON or start immediate deletion. You can also emaillegal@skintel.gg if you cannot use the account controls. We normally respond to a rights request within one month. We may extend that period where the law permits and will explain why.
Deleting an account revokes its sessions and removes its private account data. A narrow moderation or legal record may remain for the retention period above when it is necessary for an unresolved report, appeal, fraud prevention, or the establishment, exercise, or defence of a legal claim. We will not keep the live SteamID64 in that retained record.
If you are in the UK you can complain to the Information Commissioner's Office. If you are in the EU you can complain to the supervisory authority for the country you live or work in, or where you think the problem happened; the European Data Protection Board lists them. We would prefer to resolve a question first at legal@skintel.gg.
Cookies and browser storage
The authentication cookies below are strictly necessary to provide the sign-in service you request. They are not used for advertising, analytics, profiling, or cross-site tracking. Secure is omitted on local HTTP development requests. On the main site, the domain is scoped to .skintel.gg; other hosts use a host-only cookie.
| Cookie | Purpose and access | Lifetime and scope |
|---|---|---|
skn-session | Opaque authentication token. HttpOnly and read by the server only through the session accessor. | Browser session cookie with no Max-Age or Expires, and a 12-hour server-side inactivity expiry that active use extends. Secure, SameSite=Lax, Path=/, and the site domain. |
skn-signed-in | Value 1 used by client JavaScript to choose the account-menu shape before the account response. It is never read by SSR. | Browser session cookie with no Max-Age or Expires. Secure, SameSite=Lax, Path=/, and exactly the same domain scope as skn-session. |
skn-openid-state | Short-lived, HttpOnly value that binds the Steam callback to the browser that started sign-in. | Maximum 600 seconds. Secure, SameSite=Lax, Path=/auth/steam. |
There is no persistent remember-me cookie.
The separate dlk-nsfw-mode cookie stores a visitor's display preference, with values of hide, blur, or show. It is not an authentication cookie and is not linked to the account session. It has its own purpose and is documented separately from sign-in storage.
Valve and Steam
Skintel.gg is an unofficial, fan-made site. It is not affiliated with, endorsed by, or sponsored by Valve or Steam. Steam and Valve names, marks, and services belong to their respective owners. We use Steam OpenID and optional Steam Web API profile data only to provide the account features described here and never to imply Valve approval.
Contact
Privacy questions and rights requests can be sent tolegal@skintel.gg.