Privacy
On this page
What we collect when you browse, contribute reports, connect Steam, or request email updates, how long we keep it, and how to manage analytics or make a privacy request.
SteamHardware.io is operated by Polar Meridian LLC. For privacy requests, contact admin@steamhardware.io.
You can view game settings, scores, and public reports without an account. Hardware tracker contributions also require no account. You can submit one guest game report at a time without connecting Steam. One private link lets you view, edit, or delete all reports in that guest collection across Steam Machine, Steam Deck, and Steam Frame. My Steam library has a separate report collection: submitting or changing those reports requires a connected Steam account and a successful ownership check for the game. Connecting Steam does not move or combine guest reports.
SteamHardware.io plans optional monthly email services described below, but sends no newsletter or reminder emails yet. It does not run preorder alerts, notify-me forms, site-run waitlists, gated downloads, affiliate tracking, or advertising profiles. Signing in does not publish a report or establish how a game performs.
SteamHardware.io may process:
We receive your SteamID64 from Steam and privately link it to your Run Scores contributor record. We store keyed hashes of session and one-time sign-in secrets, along with connection, expiry, and revocation times. Historical records of report merges may remain. Steam identity stays private.
We check game ownership when you submit or change a Steam-linked report. For browsing, we request your games only when you choose a library action: loading My Library, requesting or reloading a library filter in the finder or a device catalog, or turning on an activity list's My Library filter. Signing in alone does not load that list. Library filters are optional, and homepage cards stay public and unfiltered.
We reduce Steam's response to game App IDs, names, and whether each game was last played within the previous two weeks. We discard exact last-played times and all playtime values. In the contribution workspace, we show only owned games that currently accept Run Scores reports.
To explain filters and empty results, we temporarily count the games Steam returned, the games that accept reports, and which of those were recently played. Games with public results may also show a summary for the selected device: average Run Score, separate median FPS, resolution and graphics values, observation count, and when the results were updated. This summary contains no Steam identity, ownership proof, playtime, or private report ID.
We do not save your library, these counts, recent-play indicators, profile name, avatar, selections, or library drafts. The library and displayed public results stay in page memory, not browser storage. Of the reports you prepare in the workspace, only those you publish are stored.
The Game Settings finder, device catalogs, and activity lists match your owned App IDs with public settings or updates. Machine and Deck results stay separate, as do Frame execution and streaming contexts.
A signed token tied to your session holds those App IDs in page memory for up to 15 minutes. This lets you search and change filters without another Steam request. It contains no Steam identity, profile, or playtime. Neither the token nor personalized results are saved in a database, browser storage, public URL, or analytics. See Local browser storage for when the temporary list is cleared.
Steam Frame supports separate guest and Steam-linked reports, just like Machine and Deck. Frame has no free-text field, hardware fingerprint, or screenshot upload. A Steam-owned game list alone never proves report ownership. Frame counts are submitted reports, not verified unique players. The optional foveated-rendering value describes that dated VR run only. Steam Deck display context records only confirmed `external`; a missing value means it was not provided, not that built-in use was confirmed. Steam Machine does not accept a display-context value.
Outside the optional email signup section, do not submit email addresses. The tracker and report forms do not ask for Steam credentials, Steam IDs, usernames, order or reservation numbers, tracking numbers, street addresses, ZIP codes, screenshots, documents, account handles, payment data, or government identifiers. The Steam connection receives a SteamID64 from Steam after sign-in; do not type or send it to us yourself. Steam sign-in happens on Steam's site. SteamHardware.io never asks for or receives your Steam password, cookies, or credentials.
Do not include those details in reports, tracker issues, or source tips. If an email contains unnecessary personal information, we may delete, ignore, or redact it.
Submit only a good-faith observation that you made or are authorized to provide. Do not submit false, manipulated, duplicate, or automated reports to distort the results.
You retain any rights you have in a contribution. You give SteamHardware.io a non-exclusive, worldwide, royalty-free permission to store, publish, display, format, summarize, and aggregate the structured report to operate, explain, preserve, and improve Run Scores. We may accept, reject, moderate, limit, or remove a contribution to protect the service and keep the results useful.
Run Scores combine publicly anonymous community reports, reviewed Community observations, and cited external performance evidence. Community observations do not create a contributor, report owner, private link, or My Reports entry. Their source URLs remain private. Sourced evidence is separate from reader contributions and may remain in internal audit history after withdrawal or public-policy exclusion. Accepted sourced observations may appear in public Activity. Excluded observations do not. The combined score is not a controlled benchmark, performance guarantee, official Valve decision, or purchasing advice.
A report created through the Steam library workspace is an ordinary community report. Connecting Steam does not verify a performance claim, prove hardware ownership, add a public badge, or give the report extra aggregate weight.
SteamHardware.io uses limited information to:
Public tracker summaries may show counts, queue movement, shipping times, confidence, and recent milestones. Each report has a random public ID and a private update link. The server stores a hash of the update token, not the token itself. Anyone with the full link may be able to edit the report, so keep it private. An individual update link gives access only to that report.
When hardware collections are enabled, opening My Reports automatically connects eligible hardware reports whose valid private update links are saved in your browser. New hardware reports join the same collection. We store a random collection identifier, a keyed hash of its secret, and report memberships. This connection does not use an email address, Steam account, or browser fingerprint. Game Settings collections stay separate.
Your browser remembers the private hardware collection secret. One collection link restores access in another browser and lets anyone holding it view, edit, check in, or delete every connected report. Keep it private. Replacing that link revokes the old collection link; individual report links still work. Reports in another collection are not moved automatically. You can unlink a report or disconnect all reports in My Reports. Unlinked reports are not automatically reconnected. Removing a browser shortcut does not unlink or delete a report.
We may publish aggregate device combinations and milestone counts from connected hardware collections. These are not verified counts of people or device ownership. We do not publish collection identifiers, connections between specific reports, or member lists. Counts require at least ten collections; we also suppress counts that would reveal a small remaining group by subtraction.
If you lose every private link and all browser access, we cannot identify you to recover your reports. A public report ID alone cannot restore private access.
Steam-linked Run Scores use a protected Steam account-session cookie with a keyed server-side hash and a short-lived sign-in-state cookie. The browser sees only `Steam connected`, never the SteamID64 or Steam profile. Signing out revokes only that Steam session and hides its reports until you sign in again. Guest access stays intact.
Guest reports use a separate protected browser cookie and a private collection link. Anyone with the link can view, edit, or delete reports in that collection. Keep it private and save it somewhere safe. You can replace the link to stop the old link working. Forgetting guest access on one browser leaves the reports saved; a valid saved link restores access. If you lose every copy and all browser access, we cannot recover the collection by identifying you.
Opening a guest link preserves your Steam connection. Connecting Steam never copies guest reports, combines collections, or asks you to resolve duplicates. Older guest collection links can reopen collections that remain guest-owned; they cannot unlock reports linked to Steam. Report-specific links do not prove Steam sign-in or game ownership.
An optional public profile link shows accepted, non-deleted reports. It is read-only and exposes no name, account, contributor ID, private link, or edit token. It is not indexed or placed in the sitemap. The owner can replace or revoke it. A public link never authorizes a report submission or settings change.
Disconnecting requires a fresh confirmation on Steam, removes the stored Steam identity and every Steam account session, and leaves existing reports in the database. Disconnecting preserves any separate guest collection; it does not convert Steam reports into guest reports.
Game reports are not linked to hardware tracker reports. The site does not infer that game and hardware reports belong to the same person from browser storage, network data, dates, locations, or matching fields. Hardware connections use possession of valid private update links, not an inferred personal identity.
Tracker shortcuts and preferences stay in the browser where they were saved. Clearing browser storage can remove a saved shortcut or private update link. Run Scores keeps its Steam account-session secret in a protected cookie. Guest access uses a separate protected cookie and, when available, local storage for the private guest collection token. Opening a guest link reads its fragment and removes it from the address bar. If browser storage is unavailable, access may last only for the current page; save your private link before leaving. Replacing a guest link temporarily keeps the old and replacement access values in this browser so an interrupted request can be recovered. Replacement requires browser storage; ordinary guest reporting remains available without it.
To vary invitations to contribute reports, a weekly experiment may remember an invitation category, device, coded game slot, week, and a limited set of markers for which entry points you used. The saved values contain no game name, report ID, search query, or private access value.
Library counts, selections, recent-play indicators, filters, headline drafts, bulk edits, and reports waiting for review stay in page memory. Reloading, changing device, or leaving the workspace discards this temporary work. Changing device does not automatically load your library again.
The server tells browsers not to cache the library response (`no-store`). A batch of reports is saved only when publication succeeds, with all reports in that batch saved together.
In My Library settings search and activity lists, changing filters within the same page reuses the temporary loaded App-ID list. The finder's in-page Machine/Deck selector also reuses it. Navigating to another device catalog, leaving My Library, reloading the page, expiration, or a detected sign-out or account change clears it. Catalogs use All games / In my library to switch between public and private results. Opening the private view checks your connection but still requires Load my games, including after sign-in. Personalized library settings requests require a current Steam session. These responses use `private, no-store` and are not shared through the public settings cache. Public settings and ordinary game search require no account and remain available if your Steam library is private or empty.
Older versions saved manually added games in this browser’s local storage as an App ID and game name. Those historical entries may remain until you clear site data, but the current My Library uses games owned by the connected Steam account. It does not import the old browser list or use it as ownership proof. Choosing a library action loads the games needed for that action. The response is temporary and is not copied into browser storage.
When enabled on the canonical production site, SteamHardware.io uses Umami for aggregate analytics. Automatic tracking is disabled. URL queries and fragments are removed. A referring HTTP or HTTPS URL, when available, is reduced to its scheme and hostname before delivery; its path, query, fragment, credentials, and port are not sent. Site-authored events use allowlisted page and action values. A public Game Settings page view may include its canonical public game slug and device. Events may otherwise include broad device or browser categories, coarse location, and basic actions, but not game names, report IDs, contributor IDs, private links or tokens, scores, settings, issue details, or free text. Analytics events also exclude Steam IDs, Steam account/session IDs, owned-game lists, library selections, and library search text. Tracker events use broad categories rather than report or account details. Referrer values are optional and spoofable, so they are used only for aggregate attribution and never as an access-control or abuse signal.
When enabled, we also use Google Analytics 4 (GA4) to measure visits, page traffic, referrals, and engagement. This helps us improve the site and assess its audience before applying for advertising services. Grow is not installed.
For visitors in the European Economic Area, the United Kingdom, and Switzerland, GA4 stays off until they choose Accept analytics. We also ask when we cannot determine a visitor's country. Elsewhere, GA4 can start automatically unless you have rejected it. We use our hosting provider's country signal to choose the appropriate control; this check does not store your country or create a profile. It does not send data to Google. Missing or failed checks require opt-in.
Choose Reject analytics to keep GA4 off, or use Analytics settings in the footer to change your choice at any time. Accepting and rejecting are equally available. You can read the site, submit reports, and manage existing reports without accepting. This choice applies to GA4; the separate Umami analytics described above continues to operate.
We remember your explicit choice for 180 days in a first-party preference cookie containing its version, choice, and expiry time. It contains no unique identifier. If your browser cannot save that cookie, your choice applies only to the current page session. Clearing site data also clears your saved choice. Rejecting after accepting stops future GA4 measurement and removes this integration's analytics cookies; it does not erase data already received by Google or remove private report access.
When GA4 runs, Google receives pseudonymous browser and session identifiers, sanitized page categories, referrer origins, and technical information such as browser and device information. Google also processes the IP address needed for the request and can derive general location. GA4 cookies use the `sh_ga4_` prefix and are configured to expire within 180 days without extending their expiry on each visit. We do not send raw page queries, fragments, private report links, report or contributor IDs, Steam identity, library contents, form values, or search text. Page titles are replaced with safe page categories. See how Google uses information from partner sites.
We keep Google Signals, advertising personalization, and automatic form, search, and click measurement disabled, and do not link this property to Google Ads. In regions where opt-in is required, we block the Google tag before acceptance, including measurement without cookies. Google's consent-mode documentation explains that behavior.
Before enabling GA4, we require two-month retention for user-level and event-level data, with retention resetting on new activity disabled. This setting does not limit the retention of standard aggregate reports. A 30-day traffic review is an observation window, not a promise to erase all analytics after 30 days. See Google's retention documentation. Google may process information outside your country, including in the United States, under its applicable privacy terms and data-processing arrangements.
Requests are rate-limited to reduce spam and automated abuse. This can use a short-lived purpose-specific hash made from request information, including IP-related forwarding headers. It is used for throttling, not to follow readers across editorial pages. SteamHardware.io does not sell personal information or use analytics for personalized advertising, affiliate attribution, sale tracking, personalized content, or report-account identification.
These services have not launched, and no newsletter or reminder emails are sent yet. Hardware reporting requires no account, and email is optional. When signup is available, two separate, unchecked choices let you request:
Selecting neither sends no email address from the form. Report submission and updates do not depend on email signup, consent, or accepting a privacy policy. Signups remain unverified and inactive. Before activation, we will ask you to confirm mailbox ownership and each selected purpose. This collection phase sends no emails.
Newsletter-only requests have no report association. For reminders, we check the report's original private edit link before privately linking the address to the report. An email address cannot establish ownership, recover a report, or grant access. Reports linked to an email address are not legally anonymous just because that address is hidden.
We store your email address, separate choices, signup and expiry times, the version of the consent wording, unverified status, and a hash of the private removal token. For reminders, we also store the pending report association.
Repeating an identical request does not change its choices, extend its expiry, or reveal an earlier removal link. Different choices create a separate pending request, which expires no later than an existing request for that address. Leaving a choice unchecked does not cancel an earlier request. The response is the same for new and repeated requests, so it does not reveal whether an address already has a signup.
Keep the private removal link shown after each signup. Each link cancels only its own pending request, so keep earlier links for earlier requests. Opening a link changes nothing. Confirm removal on the email signup removal page. Cancellation does not edit a report or invalidate its private edit link.
Reminders are unavailable for delivered or removed reports. Canceling a signup ends its pending permission. Deleting a report ends its reminders but keeps any separately selected newsletter permission and its original removal link. The tracker has no separate cancellation status: if you stop tracking an order, cancel its reminder signup.
If you lose a removal link, email admin@steamhardware.io from the address concerned. Do not send private report links. We handle privacy requests without disclosing other signups or report associations.
This browser can keep a dated request receipt and private removal link. It does not save the email address, choices, or report identifier with that receipt. Receipts expire after 90 days and are cleared when you next open a signup or removal-help page. Cleanup cannot run while the browser is closed.
A receipt does not prove that signup succeeded, remains active, or that you own the mailbox. If a request is interrupted, the browser may not know whether it succeeded. Blank form fields do not cancel an earlier signup. Clearing browser storage or forgetting a receipt removes the local link, not the server signup. Save a copy of the link if needed. Storage may be unavailable, and we cannot reconstruct receipts from another device or from before this feature.
Unactivated email signups expire after 90 days and are removed from our active database during the next scheduled daily cleanup. Cleanup removes the address, permissions, report association, and removal-token hash. Expired records cannot be activated or exported for future sending, even before cleanup runs. The 90-day period is our product policy, not a legally required period.
Backup retention is separate. Our manual database backup tool excludes pending email-signup records and removal-link hashes, while keeping the database structure and other tracker data. Those backups cannot recover pending email signups. Existing archives are not automatically deleted.
Our Neon production database is in Washington, D.C., USA (East), with a two-day history and restore window. The operator confirmed on September 18, 2026 that there were no retained snapshots, scheduled snapshots, or additional database branches holding copies of production data, and that logical replication was disabled. Daily cleanup does not erase historical provider copies. After a restore, all pending email signups must be cleared before the database reconnects to the application, so recovery cannot revive a canceled signup.
Completed privacy-request correspondence and verification notes are manually deleted 30 days after resolution. Unresolved requests and documented legal preservation needs are excluded from that period.
Vercel processes signups, and our existing Neon Postgres database stores them privately. No addresses are sent or imported to Resend or another email delivery provider in this phase. The privacy contact is monitored. The operator has confirmed that the existing Vercel and Neon processing arrangements cover email storage and reviewed the storage and backup arrangements before launch. The application uses a restricted database login, with separate administrative credentials for maintenance.
If you email us, we use the message for the reason you sent it. We do not add correspondents to a newsletter, use email to grant report access, require it for downloads, or build an advertising audience from it.
SteamHardware.io uses service providers for hosting, database storage, analytics, static assets, DNS, security, and correspondence. If you use the Steam connection, Steam provides sign-in and the owned-games response. Those providers may process the technical data needed to provide their services.
Steam-linked data controlled by SteamHardware.io is stored and processed in the United States, including the production database, application hosting, and confirmed operator backup locations. Steam handles sign-in and the owned-games response on its own service, under Valve's policies.
Published pages, source lists, public tracker summaries, and aggregate Run Score results may remain available while they are useful. Active reports may be kept for queue, shipping, and Run Score summaries unless removed from public use.
Imported external research may remain in immutable audit history after withdrawal, supersession, or public-policy exclusion. A source author or publisher may email us to request a correction, public-removal review, or erasure assessment. A Run Scores delete action removes a report from public pages and aggregates by marking it deleted. The underlying row, access hashes, and moderation metadata may remain, and the service does not promise a fixed automatic erasure date.
One-time Steam sign-in attempts expire after 10 minutes. Active Steam account sessions expire after 30 days without use. Disconnecting deletes the Steam identity and its sessions; historical private merge audit counts and existing report rows may remain. Reports shown publicly do not display email or account identity. See Private report links for how disconnecting affects access. Use the request process below for reports that are no longer accessible.
Use your guest reports link, the signed-in Run Scores editor, or a tracker private update link for ordinary corrections. For privacy, removal, or erasure requests, email admin@steamhardware.io with a public report ID and enough context to identify it. Do not send a private link, token, or unnecessary personal information. SteamHardware.io is a U.S.-based independent publication, and the same address can be used for privacy-rights questions.
Source-backed settings recipes come from external research reviewed by the site operator. They are separate from reader profile information. A recipe may identify a specific game build, Proton version, source publication date, measured FPS, render scale, frame-generation state, named graphics settings, an explicit `high`, `medium`, or `limited` confidence label, and the public source link. Internal research IDs, batches, hashes, policy records, and reviewer data are not public.
For privacy, corrections, source tips, and tracker issues, email admin@steamhardware.io.