Legal · Updated 17 September 2026
Privacy Policy
What VaultShuffle collects, how it is used and how to manage your data.
Privacy at a glance
VaultShuffle stores profile details, a copy of your imported library and the choices you save in the app. This supports recommendations, collections and progress tracking. Steam handles sign-in; VaultShuffle never receives your Steam password or changes your Steam account.
Product analytics and session replay are enabled by default. You can turn them off in . You can also ask to access, correct or delete your VaultShuffle data through Contact Us.
Who to contact
VaultShuffle is responsible for the personal data described in this policy. Send privacy questions or requests to access, correct or delete data to support@vaultshuffle.com or through Contact Us.
Account and Steam data
Steam OpenID confirms your SteamID when you sign in. We then use Steam's API to read public profile details, including your name and avatar, and visible library data such as game IDs, titles, playtime and last-played dates. We do not receive your Steam password.
If you import a public profile without signing in, we store a separate, unverified VaultShuffle profile on the server. A session cookie gives this browser access to it. Entering a public profile does not prove ownership of, or give access to, the Steam account.
We also store the collections, notes, progress, pins and game statuses you save. If you add family profiles, we store their public profile details and library information used to identify potentially shared games. The Steam Data page explains these imports.
How we use data
We use account and game data to:
- maintain your VaultShuffle profile, browser session and library
- estimate progress and personalise game recommendations
- save game statuses, notes, pins and collections
- prevent abuse and diagnose faults
- respond to support requests and understand usage when product analytics are enabled
- produce anonymous statistics about how libraries are played, some of which we publish
We process account and library data to provide the service you request. Security and reliability work also supports our legitimate interests in keeping the service safe and functional.
The statistics we publish, on the blog and elsewhere, are counts and averages taken across all libraries at once. One example is the share of owned games that have never been launched, or how often a particular game gets finished. They never name an account and we never publish anyone’s library, playtime or progress individually. Per-game figures are only published where enough separate libraries own the game for no one of them to be identifiable.
Cookies, analytics and session replay
Cookies and browser storage maintain your session, remember preferences and save your analytics choice. Vercel Web Analytics and Speed Insights separately collect site-usage and performance information. The PostHog setting below does not disable those services.
PostHog product analytics are enabled by default, with a notice on your first visit. They use cookies and local storage to associate visits. When you connect a library, analytics can be linked to your VaultShuffle user ID, account type, verification status, SteamID, display name, profile URL and avatar. Analytics identities may be joined when you verify and link a public-profile account through Steam.
PostHog records selected usage events, errors and session replays to help us understand problems and improve the app. Input values are masked in replays, but visible page content and interactions may be recorded. Heatmap collection is disabled.
You can turn PostHog analytics off at any time in .
Service providers
Providers used by VaultShuffle include:
- Steam — optional sign-in, public profile and game data
- Supabase — database and session infrastructure
- Vercel — hosting, site analytics and performance monitoring
- IGDB — game metadata
- PostHog — product analytics, when analytics are enabled
These providers process data to deliver their services, either on our behalf or under their own terms. Processing may take place in countries other than the one where you live.
Messages, retention and security
Contact and feedback submissions are stored as private support records. They can include your message, contact details, page information and browser details used to investigate an issue. We retain account and library data while your account is active. Support, analytics and operational records are retained as needed for support, service improvement, security, legal obligations and backups.
We use encrypted connections and provider access controls to protect data. No online service can guarantee complete security. Signing out ends this browser's session; it does not delete stored data.
Your choices and rights
Depending on your location, you may ask for:
- a copy of your personal data
- correction of anything inaccurate
- deletion, restriction or portability
- the ability to object to certain uses of your data
You may turn PostHog analytics off at any time in . To exercise any other right, or if you would like help doing so, email support@vaultshuffle.com or use Contact Us.
Age limits and policy updates
VaultShuffle is not directed to children under 13. We may update this policy as the service changes and will make significant changes reasonably prominent. The date above identifies this version. Our Terms of Use also apply.