Privacy Policy
This policy explains what personal data idlr collects, why, how long we keep it and what your rights are. The short version: we keep the minimum needed to run the service, we never see your Steam password, and we do not sell or share your data for advertising.
Обновлено 8 сентября 2026 г.
Этот документ пока не переведён. Действует английская версия ниже.
Версия за 30 секунд
- We keep the minimum: your email, your linked Steam accounts (SteamID, persona, library) and your idle history.
- Your Steam password never reaches us, unless you pick the password + email-code sign-in: it is then used once, never stored, never logged. The session token is encrypted and only the worker can read it.
- No advertising or analytics cookies, so no banner: just your session and your language.
- Providers: Hetzner, Cloudflare, Stripe, PayPal, and Discord or Google if you sign in with them.
- We sell nothing and profile no one. Your data is gone within 30 days of your deletion request.
- GDPR: access, a copy, correction, erasure, by a simple email to [email protected].
Краткая версия для удобства: действует полный текст ниже.
Who is responsible
The data controller is [Operator full name], [Operator postal address]. For anything related to your personal data, write to [email protected].
What we collect
Your idlr account:
- your email address, and the display name and avatar of your Discord or Google account if you sign in with one of them;
- the language you use the site in;
- your plan, its expiry date, and which expiry emails we have sent you;
- your support tickets and their messages, your alert settings (including the Discord webhook URL if you turn Discord alerts on), and your referral code together with which account referred you.
Linked Steam accounts:
- the SteamID64, persona name and avatar of each Steam account you link;
- the list of games in that account's library (application ids and names), refreshed when you ask;
- the session refresh token that Steam issues when you scan the QR code. It is encrypted with AES-256-GCM before storage; the decryption key exists only on the worker that opens Steam sessions and is never available to the website.
- if you choose the password + email-code sign-in (accounts without the mobile app): your Steam login and password are transmitted over TLS to that worker and used for the single sign-in request that obtains the token. They are held in memory for the duration of that request only, never logged, never stored.
Usage:
- which games you selected, when idling was started and stopped, the current status of each session;
- idle minutes per game and per day, which we also aggregate per Steam account to enforce the daily limit of the Free plan.
Technical and security data:
- the IP address and browser user agent of your sign-in sessions;
- the result of the Cloudflare Turnstile check on forms;
- page-view counts from Cloudflare Web Analytics, which uses no cookies and no identifiers;
- server logs for a short time, to diagnose problems.
Payments: the amount, currency, date and provider reference of each payment, and the plan it bought. Card and PayPal details are handled by Stripe and PayPal respectively; we never receive your card number.
Messages you send through the contact page, with your email address, and the support tickets you open from your account.
Why we use it, and on what basis
- To provide the service you signed up for (account, Steam sessions, limits, billing, expiry reminders): performance of our contract.
- To keep the service safe: preventing abuse of the Free plan, detecting compromised accounts, rate limiting, security logs: our legitimate interest in running a reliable service.
- To keep accounting records of payments: our legal obligations.
- To answer your messages: our legitimate interest in supporting users, or your request.
We do not profile you, do not use your data for advertising and do not sell it.
Who receives your data
We use a small number of providers that process data on our behalf, under contracts that bind them to protect it:
- Hetzner (hosting of the website, worker and database);
- Cloudflare (DNS, proxying, bot protection, and sending our emails);
- Stripe and PayPal (payments);
- Discord and Google (only if you choose to sign in with them).
Valve Corporation: to idle, our worker connects to Steam's servers with your session token, exactly as the Steam client on a PC would. Steam's own privacy policy governs what Valve does with that connection.
Some of these providers are established in the United States. Where data leaves the European Economic Area we rely on the European Commission's Standard Contractual Clauses or on the provider's certification under the EU-US Data Privacy Framework.
We disclose data to authorities only when the law requires it.
How long we keep it
- Account data: as long as your account exists, then deleted within 30 days of your deletion request.
- Steam tokens: deleted immediately when you unlink the account or delete your idlr account. You can also revoke them on Steam's side at any time.
- Idle history per game: deleted with the linked Steam account.
- Daily idle totals per SteamID: kept for 12 months, even after unlinking, so that the Free plan limit cannot be reset by unlinking and relinking.
- Payment records: 10 years, as French accounting law requires.
- Sign-in sessions and security logs: 30 days after they expire.
- Contact messages: 12 months.
Security
All traffic is encrypted in transit (TLS). Steam tokens are encrypted at rest with a key held only by the worker. Sign-in uses one-time links, so there is no idlr password to steal. The database and the worker are not reachable from the internet; only the website is. We restrict access to production systems to the operator.
If a breach ever affects your data we will tell you, and the supervisory authority, as the law requires.
Your rights
Under the GDPR you can ask us to:
- access the data we hold about you and receive a copy in a portable format;
- correct it;
- delete it (subject to the retention periods above);
- restrict or object to a processing based on our legitimate interest;
- withdraw a consent you gave, without affecting what was done before.
Write to [email protected] from the email address of your account. We answer within one month. You also have the right to lodge a complaint with your data protection authority; in France that is the CNIL (www.cnil.fr).
Children
idlr is not intended for people under 16. We do not knowingly collect data from them; if you think we have, contact us and we will delete it.
Changes
We will update this policy when the service or the law changes. The date at the top tells you when it was last changed; for significant changes we notify you by email or on the site.
The English version of this policy is the reference version; translations are provided for convenience.