CSCity

Privacy

Short version: your trade log lives in your browser and is never uploaded. To price it, the extension has to ask our server what items are worth — so we do see item names, including the ones in your inventory. We never see what you paid, who you traded with, or anything from your Steam account.

What the extension stores, in your browser

Your logged trades, item details (float, phase, stickers, charms), your settings, and your Steam web API token — the one Steam already puts in the page for its own scripts, read from steamcommunity.com while you are signed in. All of it lives in chrome.storage on your machine. None of it is uploaded to us.

We never receive your Steam password, and we never ask Steam for permission to act on your account. The token is used only to read your own trade history, offers and inventory, and it is only ever sent to Steam.

What the price API actually receives

Prices are looked up by item name, so pricing your inventory means sending us the names of the items in it, and pricing an old trade means sending an item name together with the date to price it at (rounded to a 6-hour window). Over time that is a meaningful picture of what you hold and roughly when you traded it, and we would rather say so plainly than hide it behind “we only receive item names”.

What is not sent, in any request: what you paid, your profit, your notes, your trade partners, your Steam token, offer contents, or anything identifying an individual item you own beyond its name.

Requests carry the key linked to your browser, which identifies your subscription. Our abuse-prevention counters — the ones that detect a key being shared or used to bulk download the dataset — key on a one-way hash of that, not on your SteamID.

Where data goes

DestinationWhat is sentWhen
Steam
api.steampowered.com, steamcommunity.com
Your Steam web API token and your own SteamID Whenever the extension reads your trades, offers or inventory
This service
api.cscity.xyz
Item names — including every item in your inventory when it is valued — each with a date when an old trade is being priced, plus the key linked to your browser. Never your prices paid, profit, notes, partners or Steam token. When items need prices: valuing your inventory, and backfilling trade history
Steam's image CDN
*.steamstatic.com
Nothing but the image request itself, which reveals your IP address to that host Whenever item icons are shown
Discord The trade summaries you choose to post Only if you configure a webhook. No webhook, no contact.
api.faceit.com, api.csgo-rep.com A trade partner's SteamID, so their public profile can be shown When you open or hover a partner's profile card
api.frankfurter.dev Currency codes only When converting to your display currency
flagcdn.com Nothing but the image request itself, which reveals your IP address to that host When a partner profile shows a country flag

What this site stores

Your SteamID64, your Stripe customer and subscription IDs, and the keys you have linked to a browser (with the date each was created and last used). Card details are handled entirely by Stripe and never reach our servers. Signing in with Steam tells us your SteamID64 and nothing else — Steam never gives us a password or any ability to act on your account.

What the price API logs

The item names requested, the key that requested them, and the request's IP address. Used to run the service, to enforce rate limits, and to detect one key being shared or used to bulk download the dataset. Not sold, not shared, not used for advertising.

Deleting your data

Revoking a key on the account page deletes that link immediately. Cancelling ends the subscription. To have the remaining record removed entirely, email us and we will delete it. Clearing the extension's data in your browser removes everything held locally.