Privacy Policy
This document reflects what the Vestige Play app and backend technically do, based on the current codebase (Alpha 4.1), and was written against Argentina's Ley 25.326 (data protection), Ley 24.240 (consumer protection), and general international good practice (GDPR, where relevant). Vestige is built by a small university team, not a law firm; this is our good-faith current policy, and we'll revisit it as the product and team grow.
Last reviewed: 2026-07-18.
1. Who we are
Vestige Play is developed by Vestige Team, an independent/university team based in Buenos Aires, Argentina. Vestige Play ("Vestige", "the app", "we", "us") is a free desktop application for Windows that connects to your Steam library to help you plan what to play, when, and for how long.
Vestige Team is the party responsible for the processing of your personal data described in this policy ("responsable del tratamiento" under Argentina's Ley 25.326) and can be reached at the contact below for any question or request related to your data.
Contact: [email protected] (confirm this is the right address to publish, swap for a dedicated support/legal address if you have one).
Your consent. By logging in with Steam and using Vestige, you consent to the collection and processing of your data as described in this policy, as required under Ley 25.326. You can withdraw that consent at any time by deleting your account (see Section 4); this doesn't affect the lawfulness of processing that already took place before withdrawal.
2. What data we collect and why
2.1 Steam login (OAuth)
When you sign in, Vestige uses Steam OpenID; you're redirected to Steam's own login page, and Steam sends us back a verified SteamID64 (a public numeric identifier). We never see or store your Steam password. Our backend verifies the OpenID response directly against Steam before trusting it (server/src/auth.js), so it can't be spoofed.
After login, we issue our own session token (a JWT, valid 30 days) that your copy of the app uses to authenticate to our backend. This token identifies your device's session, not you personally beyond the SteamID.
2.2 Your Steam library data
Using your SteamID, our backend calls the official Steam Web API on your behalf (via a dedicated API key that lives only on our server, never on your device) to read:
- Your owned games list and playtime per game.
- Recently-played games.
- Achievement progress for games you own (if your Steam profile/achievements are set to public; if they're private, we simply can't read them, and no key can bypass that, since this is a Steam-side restriction that applies to everyone equally).
- Public game metadata (Metacritic score, genres, review percentage, current player count), which is about the games, not you.
You may optionally provide your own personal Steam Web API key in Settings. If you do, it's stored locally on your device and sent to our backend only to make requests on your behalf (more accurate recent-activity detection). We do not sell it, share it with third parties, or use it for any purpose other than making Steam API requests on your behalf.
2.3 Game duration data (HowLongToBeat)
To estimate how long a game takes to finish, Vestige looks up game names (not your personal data) against data published on HowLongToBeat.com, via a local helper script that queries the same endpoint HowLongToBeat's own website uses for its search feature (see our Terms of Use, Section 6, for more detail on this data source). No personal or account data is sent in this lookup, only the game's title.
2.4 Your progress and preferences
As you use Vestige, we store:
- Your scheduling preferences (available hours, how many games you play at once, session-length preferences).
- Your gaming plan, goals, and season participation.
- A history of milestones (games finished, platinum trophies, goals completed) with the real timestamp they were detected.
- Daily snapshots of your library stats (used for streaks and progress charts).
- Session tracking: Vestige can detect when you start and stop playing a Steam game on your PC, by periodically checking a Windows registry key that Steam itself maintains while a game is running. This is a lightweight, undocumented-but-observable Steam behavior (not a hack, not code injection, not keystroke/screen capture); it only tells us "game X is running" or "not running," nothing about what happens inside the game or on your screen. If a session lasts more than a minute, we ask you how it felt (a short mood check-in: amazing / normal / emotional / frustrating). This is optional to answer and used only to build your personal "Mood Map."
- Your theme and language preference.
This data is stored locally on your device (in a config file managed by Electron), and synced to our cloud database (MongoDB Atlas) so it isn't lost if you reinstall Vestige or use it on a different PC. Sync is tied to your SteamID; it is not shared with, or visible to, other users.
2.5 What we do not collect
- We do not collect your Steam password, payment details, or real name/email (Steam OpenID does not share these with us).
- We do not use advertising trackers, ad networks, or third-party analytics SDKs in the app.
- We do not read your keyboard input, take screenshots, or monitor any application other than detecting whether a Steam game process is running.
- We do not sell your data to third parties.
3. Third-party services involved
| Service | What it's used for | Their own policy |
|---|---|---|
| Steam / Valve | Login (OpenID), library/achievement/game data | Valve Privacy Policy |
| Render (backend hosting, Oregon, USA, US West region) | Hosts our backend server (vestige-backend.onrender.com) | Render Privacy Policy |
MongoDB Atlas (database, AWS São Paulo, Brazil, sa-east-1 region) | Stores your synced progress data | MongoDB Privacy Policy |
| Cloudflare R2 | Hosts the app installer and update-check manifest (no personal data sent, just a version check) | Cloudflare Privacy Policy |
| Tally | Powers the optional in-app bug report form | Tally Privacy Policy |
| Ko-fi / Cafecito | Process voluntary donations; we never see or store your payment details, these platforms handle payment directly | Ko-fi Privacy / Cafecito's own policy |
| Discord | Hosts our community server (optional, separate account) | Discord Privacy Policy |
Where your data is processed: your synced Vestige data is stored on a database physically located in São Paulo, Brazil, and passes through a backend server located in Oregon, USA on its way there. If you're located outside of Brazil/the USA, this means your data crosses borders as part of normal operation of the service. We rely on our providers' (AWS/MongoDB Atlas, Render) own security and compliance standards for that infrastructure; we don't operate our own servers.
Legal basis for this transfer: under Article 12 of Ley 25.326, this international transfer is made because it is necessary for the performance of the service you requested (syncing your progress so it isn't lost across devices or reinstalls), and in reliance on the consent you give by using Vestige (see Section 1). Argentina is itself recognized by the European Commission as providing an adequate level of data protection; we are not aware of an equivalent adequacy finding covering Brazil or the USA for this purpose, which is why this transfer is instead grounded in the contractual- necessity and consent bases described above rather than in an adequacy decision.
If Vestige's user base grows to include a meaningful number of users based in the European Union, we'll revisit whether additional cross-border transfer safeguards (e.g., Standard Contractual Clauses) are advisable under GDPR, in addition to the Ley 25.326 basis described above.
4. Data retention and deletion
- Logging out of Vestige clears your data from your local device, but does not delete your synced copy from our cloud database (this lets you log back in later without losing progress).
- Self-service deletion: in the app, go to Settings → Delete my account & data (at the bottom of the page). This permanently deletes your synced progress from our cloud database and everything stored locally on your device, and signs you out immediately. This action is irreversible and takes effect immediately; we don't hold a "grace period" copy after you confirm it.
- Alternatively, you can request deletion by contacting us at [email protected] with your SteamID64.
5. Children's privacy
Vestige Play is not directed at children under 13. We adopt 13 as our own operational baseline because it aligns with Steam's own age requirements (Vestige requires a Steam account to function); Argentine law does not set that specific numeric threshold for data processing the way some other countries' laws do, so this is a policy choice on our part, not a claim about Argentine statutory law. Separately, see our Terms of Use, Section 3, for how minors' capacity to accept these terms is treated under Argentina's Código Civil y Comercial. We do not knowingly collect data from children under 13. If you believe a child has used Vestige and provided data to us, contact us and we'll remove it.
6. Security
- We never handle your Steam password; authentication happens entirely on Steam's side (OpenID).
- The desktop app runs with Electron's
contextIsolationenabled and a strict allowlist of IPC channels between the interface and the system, which limits what a compromised web-facing part of the app could ever do. - Communication with our backend happens over HTTPS.
- Our Steam Web API key lives only on our server and is never exposed to the client app or any third party.
No system is 100% secure, and we can't guarantee absolute security, but we follow the practices above as a baseline (see also our public SECURITY.md in the project repository for more technical detail).
7. Your rights and choices
Under Argentina's Ley 25.326, you have the right to:
- Access the personal data we hold about you.
- Rectify or update it if it's inaccurate or outdated.
- Delete it (supresión), see Section 4 for how to do this yourself in the app, at any time, without needing to justify your request.
- Object to certain processing, to the extent applicable.
To exercise any of these rights, contact us at [email protected] with your SteamID64. If you believe we haven't properly addressed your request, you have the right to file a complaint with Argentina's data protection authority, the Agencia de Acceso a la Información Pública (AAIP), at aaip.gob.ar.
You can also, more informally, at any time:
- Decline to provide your own Steam Web API key; Vestige works with reduced accuracy using only our shared backend key.
- Skip the mood check-in after a session (it auto-closes after 60 seconds).
8. Changes to this policy
We may update this policy as Vestige evolves (e.g., when the planned cosmetics/Market feature launches, or if we add a self-service data export). Material changes will be reflected here with an updated review date at the top of this document.