Privacy Policy
Last updated: 26 August 2026. Applies to the Vault website (vault.tools) and the Vault desktop application ("the Tool").
1. Who we are
Vault is operated by Vault - Sebastian Bos, Marcel Croonenbroeck GbR, Josefstr. 5, 63452 Hanau, Germany (see our Imprint for full details). We are the "controller" of your personal data within the meaning of Art. 4 No. 7 GDPR for the processing described below. Given the small scale of our processing, we are not required to appoint a Data Protection Officer under Art. 37 GDPR / § 38 BDSG. For any question about this policy or your data, contact us at info@vault.tools.
2. What Vault does, in brief
Vault helps you track and organise your CS2 skin inventory and investments (purchases, sales, watchlist, trade-up and case-opening statistics) and, through the desktop Tool, overlays live in-game information while you play. To do this we sign you in with your Steam account and store the portfolio, inventory, and Pick'em data described in section 4 below.
3. Legal bases for processing
We process your data under Art. 6(1)(b) GDPR (necessary to provide the Vault service you sign up for — your account, portfolio, and inventory tracking), Art. 6(1)(a) GDPR (consent, for clearly opt-in features such as detailed product-usage analytics, Pick'em auto-picks, bug-report attachments, and Google advertising technologies where they require consent), and Art. 6(1)(f) GDPR (our legitimate interest in operating a secure, reliable service, understanding its geographic reach and client compatibility, and detecting automated traffic, including basic technical logging, coarse aggregate site-load counts by estimated country, browser family, operating-system family and client kind, short-lived diagnostic bot/automated/unknown User-Agent values, and anonymous aggregate measurement of our direct partner creatives). Google consent is requested separately through Google Privacy & Messaging; it is not part of creating or accepting the terms for a Vault account.
4. Data we collect and why
Account & sign-in. You sign in exclusively via Steam OpenID. We receive and store your SteamID64 (as your login identifier) and the email address and username you choose at registration. Your public Steam persona name and avatar are looked up live from Steam's API when needed for display and are not stored in our database. We do not set or use a password for normal sign-in; password hashes only exist for the separate, restricted administrative access path and are salted and hashed, never stored in plain text.
Portfolio & investment data. Purchases, sales, quantities, prices, and fees you record (your investment ledger), plus your watchlist entries (including any notes you write) and your display-currency preference.
Inventory data. A snapshot of your Steam CS2 inventory (item names, conditions, wear/pattern values, any custom name tags you've applied) fetched from Steam's public inventory endpoint using your Steam ID, plus — where you choose to sync it — your parsed Steam trade/market history (container openings, trade-ups, and related item details).
Pick'em data. If you use the Pick'em feature, we store the picks you make and, if you enable it, your Steam Game Authentication Code so we can submit picks to Steam on your behalf. That code is encrypted at rest and is never included in a data export.
Opt-in official match history. If you enable match synchronization, we store your encrypted Steam Game Authentication Code and encrypted sharing-code cursor while synchronization remains enabled. We request official match identifiers and demo availability from Valve, then derive and retain match metadata, scores, rounds, player statistics, economy and equipment, combat/objective/utility events, sampled player positions, grenade trajectories, and heatmap grids. A demo necessarily contains information about every participant in the match, but a match is exposed only to Vault accounts whose linked SteamID64 is confirmed as a participant. Credentials, sharing cursors, Game Coordinator tokens, demo URLs, and archive paths are excluded from personal-data exports.
Bug reports. The desktop Tool's bug-report form is entirely opt-in: nothing is sent automatically. Only if you tick the relevant checkboxes and submit a report do we receive the attachments you selected (recent log excerpts, local config files, basic system information such as OS version and RAM) together with your description and an optional contact email.
Service and usage measurement. For signed-in accounts we always keep a minimal, route-free daily activity record containing the account id, UTC day/time, Web or Tool platform, whether the account was Free, Pro, or Max at that time, session count, first successfully resolved country, and last activity. A new session means the first activity on a UTC day or activity after 30 minutes of inactivity. This is used to understand service use and contains no page, screen, component, feature, action, URL, or query value. With your separate opt-in consent we also count allow-listed page/screen views and feature actions. The account-wide choice, consent version, grant time, and withdrawal time are stored with your profile. Withdrawal stops future detailed collection immediately.
For this route-free signed-in record, Vault converts the request address to a country entirely on our own server. The raw address is not written to the analytics database.
For visitors who are not signed in, no daily connection or detailed usage row is created before explicit consent in the Vault cookie banner. After consent, the first trusted server creates a rotating pseudonymous key using HMAC(secret, UTC date | canonical IP address). The raw address is never written to the analytics database or application logs, the key changes each UTC day, and it is not linked to an account. Vault resolves a country offline and stores it with that consented daily row. Web and Tool observations with the same daily key can be deduplicated in combined reporting. Administrators see consent coverage and consent-based labels because these session, page, and feature measurements do not represent people who declined.
Technical data. Infrastructure requests are configured not to persist raw client IP addresses in Vault application logs. For direct partner creatives we also keep anonymous aggregate impression and click totals. A signed, short-lived random receipt prevents the same render event being counted twice; these advertising metric records contain no Vault user, account, Steam ID, or other audience identifier and are operational estimates rather than billing-grade analytics.
5. The desktop Tool specifically
The Tool's activity log is written to a local file on your own computer and is never transmitted to us automatically — it is only ever sent if you explicitly attach it to a bug report (see above). The Tool reads live match data from your local CS2 client via Counter-Strike's Game State Integration to drive the in-game overlay. The raw live feed is not retained, but selected match summaries and performance statistics produced by Vault may be transmitted to and stored by the Vault service when the relevant signed-in feature is used. This is separate from the opt-in official demo analysis described above. The Tool fetches your own Steam inventory directly from Steam's public API to keep your local view current, and checks for updates against our own self-hosted update server (vault.tools) — no third-party update service is involved.
6. Cookies, local storage, analytics, and advertising consent
Vault itself uses strictly necessary cookies for your sign-in session, an anti-forgery security token,
a short-lived status message, and the regional number and date format the page is rendered in. These are
essential to operate the site; the format cookie stores only a locale name such as
de-DE and no identifier. Vault separately stores your
first-party analytics choice. It is optional and independent of Google advertising consent. Signed-in
choices synchronize to the durable account profile across Web and Tool; the Tool provides the equivalent
first-run/settings control. On free website accounts,
where Google advertising is enabled, Google may additionally use cookies, local storage, device data,
IP address, advertising identifiers, consent signals, and information about the page and ad interaction
to select, deliver, measure, prevent fraud in, and report advertising. Those non-essential technologies
are controlled through Google Privacy & Messaging, our Google-certified TCF v2.3 consent management
platform for visitors in the EEA, UK, and Switzerland, and are not loaded for an advertising placement
unless the required consent state allows it. Pro and Max users are not served placements and Vault does not
issue Google advertising requests for them.
You can change or withdraw Vault analytics in your profile and reopen anonymous cookie choices from the website footer. You can change Google advertising choices independently. Withdrawal does not affect the lawfulness of processing before withdrawal. Direct partner creatives are delivered from Vault's own database and do not receive access to Vault cookies, browser storage, APIs, or account/session state.
7. Third-party content and advertising on our pages
Vault uses third-party open-source fonts and a 3D rendering library. These assets are stored on our own servers and delivered from the same origin as the website, so loading them does not connect your browser to their original distribution providers. Dynamic Steam avatars and item images may still be loaded from Valve's Steam services as part of the features described below.
The free Vault website may show either explicit Google AdSense display units or creatives supplied directly by a partner. Google units connect your browser to Google only after the central entitlement, deployment-readiness, and consent checks succeed. Direct partner images are copied into and served from Vault rather than hotlinked. Optional partner HTML, CSS, and inline JavaScript runs in a separately sandboxed frame with an opaque origin: external scripts, network requests, forms, frames, media, workers, storage, and access to Vault APIs or session state are blocked. Every partner link is rewritten to one reviewed HTTPS destination and passes through Vault's anonymous aggregate click counter.
8. Who we share data with
We do not sell your data. We share data only where necessary to provide the service:
Valve/Steam. Signing in, syncing your inventory, and (if enabled) retrieving official match history necessarily involves your Steam ID being sent to and data being read from Valve Corporation's Steam services. Match retrieval also sends the authentication code and current sharing cursor supplied by you. Valve processes those requests under its own privacy policy as an independent controller.
Hosting. Our database and servers are hosted in Germany/the EU. Where we use a processor (e.g. our hosting provider) to process data on our behalf, we have a data processing agreement with them under Art. 28 GDPR.
Google advertising and consent. If Google advertising is enabled and permitted by your consent choices, Google Ireland Limited and other Google group companies and approved advertising partners may receive the advertising and device information described in section 6. Google may process data outside the EEA/UK, including in the United States, using applicable transfer safeguards such as adequacy decisions (including the EU-US Data Privacy Framework where applicable) and standard contractual clauses. Google acts under its own privacy terms for this processing. We do not send Google your Vault account ID, Steam ID, portfolio, inventory, or subscription details.
Direct advertising partners. We may publish a partner's creative and destination link, but do not disclose your Vault account data to that partner. The partner receives a normal browser request only if you choose to follow its HTTPS link; its destination site then applies its own privacy information.
9. How long we keep your data
We keep your account and app data for as long as you maintain a Vault account. If you delete your account (see section 10), we erase the associated portfolio, inventory, watchlist, Pick'em, linked match analytics, and preference data from our active systems; residual copies may persist in encrypted backups for a limited period (up to 30 days) before being purged as part of routine backup rotation. Opt-in bug reports are kept for as long as reasonably needed for support purposes and are deleted on request.
User-linked usage rows and daily anonymous HMAC rows, including their country field, are kept for 13 months. Before those detailed rows are purged, Vault finalizes non-identifying daily audience and feature totals. These aggregate totals are kept indefinitely by default because they can no longer be traced to an account or daily pseudonymous actor. Withdrawing analytics consent is prospective; deleting the account erases the identified usage and consent history. Anonymous daily HMAC data cannot be located from an account and therefore cannot be included in an account request.
Sanitized raw User-Agent diagnostics for bots, automated clients, and unknown clients are kept for 90 days. Daily coarse browser-family, operating-system-family, client-kind, country, and site-visit aggregates are kept indefinitely by default for compatibility, capacity, and traffic-integrity reporting. They are not linked to an account or daily pseudonymous actor and therefore cannot be located through an account request.
Short-lived anonymous advertising receipts expire after 30 minutes and are routinely purged. Aggregate impression and click totals remain with the partner creative for its operational lifetime. Google sets its own retention periods for data it processes; consult Google's privacy and advertising information through the consent interface for current details.
Official demos are normally temporary processing files and are deleted after analysis. An operator may optionally preserve the original compressed demo in separate, access-controlled archive storage. That archive is not available through Vault or its download links, is managed under the operator's separate retention, backup, access-control, and deletion procedures, and is not automatically deleted with an account. Requests concerning an archived demo must therefore be handled through the contact address in section 10. Valve-hosted demo links are offered only for recent matches and may stop working earlier.
10. Your rights, and how to exercise them
Under the GDPR you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict (Art. 18), and port (Art. 20) your data, and to object to processing based on our legitimate interest (Art. 21). You can exercise the most common of these yourself, at any time, from Account → Manage → Personal Data in the Vault website:
- Download your data — get a machine-readable JSON export of everything Vault stores about you, including your account details and your investment, inventory, watchlist, Pick'em, legacy match statistics, linked official match analytics, route-free session records, consented detailed feature usage, and analytics consent history.
- Delete your data — permanently erases the same identified data, including analytics and consent records, and closes your account. Non-identifying finalized totals remain.
For anything else — rectification, restriction, objection, or any question — email us at info@vault.tools. You also have the right to lodge a complaint with a data protection supervisory authority; as our registered seat is in Hesse, Germany, the competent authority is the Hessischer Beauftragter für Datenschutz und Informationsfreiheit (HBDI), though you may also contact the authority in your own EU member state.
Consent for Google advertising can be changed independently and immediately through Privacy and cookie settings in the footer; changing it does not close or otherwise change your Vault account.
11. Security
We use industry-standard measures to protect your data, including encrypted transport (HTTPS/TLS) everywhere, hashed/salted credentials where applicable, and purpose-separated encryption at rest for stored Steam Game Authentication Codes and sharing-code cursors. No system can be guaranteed 100% secure, but we take reasonable steps appropriate to the sensitivity of the data involved.
12. Children
Vault is not directed at children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.
13. Changes to this policy
We may update this policy as Vault's features change. We'll update the "Last updated" date above when we do; material changes will be highlighted on the site.