Back to your games

Privacy Policy

Last updated 25 August 2026

The short version: Everything stays in your own browser unless you sign in. Signing in creates an account, and from then on your library and your play history are stored on our servers, the same way Steam’s own servers already store yours. We never sell your data, never use it for ads, and never show your game list or your play history to anyone but you. The one thing another person can ever see is a summary, and Privacy & security is where you decide who sees it, sign out your other devices, download everything we hold, or delete the account outright. Your own Steam API key, if you use the advanced option, is never stored on our servers either way.

If you don’t sign in

You can use Sifter without ever signing in. Your imported game library, your wishlist, the playtime Sifter measured on this device, your play history, your theme choice and your Steam ID all stay in your browser’s localStorage, on that device only. Nothing is transmitted to us except a single request through our proxy to Steam, which is discarded once it has been answered. You can erase all of it at any time from Settings, or by clearing your browser’s site data — no request to us required.

Signing in creates an account

There are two ways in. Through Steam: Steam confirms your identity and shares your public 64-bit Steam ID with us, and that ID is the whole credential — we never see your Steam password. With an email and password: we store the email and a salted scrypt hash of the password, never the password itself. Either way, from then on our servers store what an account needs: your account ID, your imported library across every store you connect, your wishlist, when games entered and left your library, and anything you actively use — friend requests, discussion posts, mod entries.

If your account has an email address, we use it for account mail — password resets and address changes — and, as Steam does, to tell you when a game on your wishlist goes on sale. That one is on until you turn it off: every sale email has a one-click unsubscribe link, and Privacy & security has the switch. We keep a record of which sales we have already emailed you about, so the same one is never sent twice.

This mirrors how Steam’s own servers work. Valve always has full visibility into what you own, and its privacy settings control what other players can see, not what Valve itself collects. Sifter works the same way: your raw game list, your play history and your friend requests are shown to nobody but you. The only thing another person ever sees is a small summary — your game count, total hours, number of stores and most-played title — and only to friends you have accepted, and only for as long as you keep that connection.

What other people can see, and how to change it

That summary is the entire surface. Steam splits the same idea into “game details” and a separate switch for total playtime, and Privacy & security does the same: your library summary and your hours are each set to anyone, friends only or only me, and hours are never shown more widely than the summary they sit inside. Both start at friends-only, which is where every account already was before the setting existed.

What those settings do not govern is what Sifter itself stores, and that is deliberate rather than a gap. It is the same split Valve draws: Steam’s servers have always had full visibility into your library, and its privacy settings govern other players. Anything you post in public — a discussion thread, a mod listing — is public by its nature and carries the display name you chose.

Keeping your account secure

Your session is a signed cookie that lasts thirty days. You can end every other one at any time from Privacy & security — a browser you left signed in somewhere, or a session you think someone else has. Changing your password, or completing a password reset, does the same thing automatically: the old sessions stop working rather than running out their thirty days. Sign-out reaches every device within a minute.

Two-factor authentication is available from the same page, using any authenticator app. Once it is on, both ways into your account ask for a code — the email-and-password sign-in and the Steam one. You get ten single-use recovery codes when you switch it on; we keep only hashes of them, so that screen is the only time they are shown.

Passwords are stored only as salted scrypt hashes, and your two-factor secret is encrypted at rest with a key that is not in the database. Tokens from stores you connect (Xbox, Epic, GOG, Amazon, itch.io) are encrypted the same way, and none of these are ever included in a data export, even to you.

Play history

The desktop app watches for the game after you press Play, so it can show that you are playing, time the session, and close a launcher it opened for you. Five of the stores Sifter reads report no playtime at all, so for those games this stopwatch is the only record that exists.

Each finished session — the game, when it started, when it ended, and how long it ran — is kept on your device, and synced to your account when you are signed in. Sessions shorter than a minute are not recorded at all. We keep this indefinitely rather than expiring it, because its whole value is being able to look back at years rather than weeks; the same reasoning Steam applies to the playtime it has held for you since 2003. It is never shown to another user and never sold. You can export the whole history as a file, or erase it, from Settings.

Connecting other stores

Xbox, Epic, GOG, Amazon and itch.io are connected by signing in to that store, exactly as you normally would. Sifter stores the token that store gives back, encrypted, and uses it to read what you own — nothing else. Disconnecting a store deletes its token. Some libraries can only be read by the desktop app looking at what is installed on that PC; nothing about those installs leaves your machine except the list of games itself.

Your own Steam API key (advanced option)

If you choose the advanced import and paste your own Steam Web API key, it travels from your browser to Steam through our proxy as a request header, is used for that single request, and is then discarded. It is never written to our servers or our logs. It is stored only in your browser.

Server logs & abuse prevention

Like any website, our hosting provider may process standard request metadata (such as your IP address) transiently to serve pages and to rate-limit abuse of our Steam proxy. We do not use this to build a profile of you.

Third parties

To fetch game data we contact Valve’s Steam services (the Steam Web API and store). Your use of Steam is governed by Valve’s Privacy Policy. We may use privacy-friendly, aggregate analytics to understand overall usage; if enabled, it does not track you across other sites.

The desktop app sends counts and nothing else: that a device ran Sifter for the first time, that one was open on a given day, which stores its scan found, which of those produced a Play button, and which app version reported it. Those are added to a daily total — “on this day, this many devices on this operating system did this” — and there is no field a game, a file path, an account or a device identifier can travel in, so no row can be traced back to you or joined to another one.

Separately, once a day the desktop app sends an anonymous “Sifter is installed” ping so we can tell how many copies are in use, not just how many times something happened. It carries three things: a random number the app made up the first time it ran (not taken from your computer, your hardware or your account), your operating system, and the app’s version. We never store that number as sent — only a scrambled one-way fingerprint of it, with the day. It is sent without your sign-in, so it is never linked to your account. Deleting the app’s settings folder makes a new number. You can turn it off in Settings under “Send an anonymous daily ‘Sifter is installed’ ping”.

Your rights & choices

Take it with you. Settings exports the copy held in this browser — your library, your wishlist, your play history and the playtime Sifter measured. Privacy & security exports the copy held on our servers: every table that keys anything to your account, as one file, with store tokens and password hashes redacted. Keeping your data indefinitely and letting you take all of it are two halves of the same deal, and one without the other is not one.

Erase it. If you have never signed in, everything lives in your browser and Settings clears it outright. If you have signed in, Privacy & security deletes the account yourself, without asking us: your library, wishlist, play history, posts, mods, friend connections and any store tokens you connected. There is no grace period and nothing is kept afterwards. Signing out, separately, just ends the session on that device.

Where privacy laws such as the GDPR (EU/UK) or CCPA/CPRA (California) apply: we do not sell or share your personal information, and we do not use it for targeted advertising. Access, export and deletion are all self-serve above; email us for anything those buttons do not cover, such as correcting a record, and we will help.

Children

Sifter is not directed to children under 13, and we do not knowingly collect their data.

Changes

We may update this policy; the “last updated” date above will change when we do.

Contact

Questions about your privacy? Email hello@siftergames.com.