Privacy Policy
Last updated: 26 September 2026
This policy explains what personal data we collect when you use the SkinAuto website, account portal and desktop app, why we collect it, who it is shared with and how long we keep it. It sits alongside our Terms of Service.
The short version
A plain-language summary, so you do not have to read twelve sections to know where you stand. The numbered sections below are the full and governing version; where this summary is less precise, they are what applies.
- We hold very little: an account identifier, your email address, a one-way hash that identifies your computer, your subscription state, your payment records, and the note that you accepted these documents.
- Your Steam credentials and mobile-authenticator secrets never reach us. They are encrypted on your own computer. We could not read them if we wanted to, and we cannot recover them for you.
- There is no analytics, no tracking and no advertising anywhere on this site or in the app. The only cookies are the ones that keep you signed in.
- We never sell, rent or share your data for marketing.
1. Who is responsible, and how to reach us
The controller of your personal data is the operator of SkinAuto, an individual trader. Every privacy request — access, correction, deletion, or a complaint — goes to [email protected].
We do not publish our name, address or country here. We will provide our full legal identity, address and country on written request to that address, and wherever the law requires it — including to a supervisory authority or a court.
2. What we collect, and why
When you create an account
- An account identifier issued by our sign-in system, which is how every other record is linked to you.
- Your email address — to identify your account, let you sign in and recover access, and contact you about your subscription or a service problem.
- The date the account was created.
- Which version of our terms and privacy policy you accepted, and when — the record that you agreed, without which the agreement is unprovable.
When you run the desktop app
- A one-way hash of identifiers from your computer (a machine GUID and a network-adapter address, hashed together — we never store the raw values). Its only purpose is to tie one subscription to one machine at a time, so a single subscription cannot be shared between people.
- A count and timestamp of how often you have moved your subscription to a different machine, because moves are limited to a small number per week.
- The app version you run, so the server can require a current version and deliver updates.
When you pay
- Payment records: the plan you bought, the amount, the currency, the status, the timestamps and the invoice reference given to us by our payment provider. Your subscription's status and expiry date are stored with them.
- We never see your card details or your wallet's private keys. Payment happens at our payment provider, and what comes back to us is a reference and a confirmation.
Automatically, when you use our servers
- Your IP address, used transiently to apply rate limits and block abuse. We do not build profiles from it.
- Server logs and technical telemetry — requests, errors, timings, and the account identifier they relate to — used to find faults and detect attacks.
When you contact support
- Whatever you choose to put in your message, and your email address so we can reply.
3. What we never receive
This is the most important section, and it is the deliberate design of the product rather than a promise about our good behaviour. The following stay on your own computer, encrypted there with keys that never leave it, separately for each trading profile, and are never transmitted to us:
- your Steam password or any marketplace password;
- your Steam mobile-authenticator secrets and your revocation code;
- your marketplace API keys;
- your inventory, your trade history, the prices you set, your buy and sell lists, and your settings.
We cannot read, export, reset or recover any of it. The consequence is worth stating plainly: if you lose your computer and your own backups, we cannot restore your authenticator or your trading data — there is nothing on our side to restore it from.
4. Why we are allowed to process it
- To perform our contract with you — running your account, activating and checking your subscription, delivering updates, taking payment.
- Our legitimate interests — keeping the service secure, preventing abuse and fraud, rate limiting, and enforcing one-subscription-one-machine. We use the least identifying method we can for this, which is why the device identifier is stored only as a hash.
- Legal obligation — keeping payment and accounting records for as long as tax law requires.
5. Cookies and browser storage
Everything we keep in your browser is strictly necessary, and there is not much of it:
- Sign-in state for the account portal, set by our sign-in system to keep you authenticated. It lives in your browser's own storage on the portal's address, and it is what signing out clears.
- A session hint cookie (
mb_session) — a non-secret flag with no token in it, kept for 30 days, so this website can show you the right button ("create your account" or "go to your account") without a flash of the wrong one. - Two short-lived flags that survive only the current tab: the page you were heading for when you were asked to sign in, and the fact that you ticked the acceptance box on the sign-up form. Both are discarded as soon as they have been used.
There are no analytics, statistics, advertising or third-party tracking cookies, and no tracking pixels or fingerprinting scripts. That is also why you are not being asked to click through a consent banner: there is nothing on this site to consent to.
6. Who else processes your data
We use a small number of providers, each only for what it is named for:
- Our sign-in system, which we run on our own server infrastructure, and which holds your email address and sign-in credentials.
- An email delivery provider, which sends sign-in and account emails and therefore processes your email address.
- Our payment provider, which processes your payment and returns a reference to us. It is an independent controller for what it collects from you directly, under its own privacy policy.
- Our hosting provider, which rents us the servers the application and database run on, and object storage holding the app installer.
We will name the current providers, and the country each one processes in, on request to [email protected]. We do not sell or rent your data, and we do not share it with advertising networks. We disclose data to an authority only where the law obliges us to.
7. International transfers
We are established outside the European Economic Area, and our providers process data in various countries, some of them inside it. Where data moves between countries we rely on the lawful transfer mechanisms available to us — an adequacy decision where one applies, and otherwise contractual safeguards with the provider. Ask us for the detail for a specific provider, or for the country we operate from.
8. How long we keep it
We publish a fixed period only where one genuinely exists. Everywhere else the rule we apply is that data is kept while it still serves the purpose it was collected for, and deleted when it stops serving it.
- Account data (identifier, email, device hash, subscription state) — kept while your account exists. Ask us to delete it and we will, apart from anything the next point obliges us to keep.
- Your acceptance of these documents — kept for as long as your account exists, and alongside a payment for as long as that payment record is kept. It is the evidence that the agreement was made, so it lasts as long as the agreement can matter.
- Payment records — kept for as long as tax and accounting law obliges us to keep them, which is longer than your account. These outlive account deletion: we are not permitted to destroy them on request.
- Server logs and technical telemetry — short-lived. They are the running server's output, rotated and discarded by our hosting provider; we keep no long-term log archive.
- Support email — kept in the support mailbox while it is useful for support and as a record of what was agreed. Ask us to delete a conversation and we will, unless it concerns a payment.
- The session-hint cookie — 30 days, in your browser, and you can clear it yourself.
9. Security
- Everything between the app, this site and our servers travels over encrypted connections.
- The device identifier is stored only as a one-way hash, and your trading credentials are never transmitted at all (section 3) — the strongest protection available is not holding the data.
- Access to the production database is limited to the operator.
- If a breach happens that puts your rights at risk, we will notify the relevant supervisory authority and you, as the law requires.
- If you find a vulnerability, please report it to [email protected] before disclosing it publicly.
10. Your rights
Depending on where you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your data, subject to the payment records we must keep;
- restrict or object to processing we base on legitimate interests;
- port your data to you or another provider in a machine-readable form.
Email [email protected] from the address on your account and we will answer within 30 days. There is no self-service delete button today — we handle these by hand, so please say plainly what you want done. Exercising any of these rights is free and we will not treat you worse for it.
If you are in the EEA or the UK you can also complain to your national data-protection authority, and elsewhere to whichever authority supervises data protection where you live. We would rather you told us first, so we can fix it.
11. Children
The Service is not for anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
12. Changes to this policy
The date at the top always shows the current version. If a change materially affects you, we will tell you by email or in the app before it takes effect.