Steam Sonar for Chrome
Steam Sonar Extension Privacy Policy
The extension uses data only to identify games on X and Steam, show Steam research and related-post links, and check locally saved price watches after you give explicit consent.
Last updated:
1. Data stored in the extension
- After consent, the X content script temporarily reads visible post text, hashtags, author handle, decimal status ID, and Steam links needed to identify a game and avoid duplicate processing.
- After consent, the Steam content script reads the current public store page's Steam App ID and game title so it can show the matching card and offer a local price watch.
- Chrome extension storage keeps your watchlist, last checked prices, and notification state.
- Chrome extension storage keeps your country or region and language preferences.
- Chrome extension storage keeps your game-name correction dictionary and bounded temporary caches.
- Chrome extension storage keeps a random anonymous installation ID used for API abuse prevention; it is not an account identifier.
- Chrome extension storage keeps your consent decision and time.
2. Data sent to Steam Sonar
- For game matching, the API receives only size- and count-limited candidate text fragments extracted in the browser.
- For game matching, the API may receive bounded hashtags extracted from the current post.
- The API receives Steam App IDs for game details, prices, price history, research, and watch checks.
- The research endpoint receives the matched public game name together with its App ID and locale so it can retrieve game-specific reviews and media resources.
- An X author handle may be sent only when needed to match an official game account; it is used transiently and is not stored or logged.
- The API receives country or region and language settings needed for localized Steam results and prices.
- API requests send the random anonymous installation ID in a dedicated header for rate limiting. Steam Sonar does not store its raw value.
- Only after you click a detected game tag, the API receives the Steam App ID association and decimal X status ID so the related-post link can be confirmed.
- A click-triggered community confirmation also sends a short-lived signed proof issued by Steam Sonar; a wrong-association report sends the App ID and decimal status ID.
3. Data stored by the service
- D1 stores separate SHA-256-derived install and IP rate-limit keys, window start, and request count; it does not store the raw installation ID or raw IP.
- D1 stores game, region, currency, current and regular price, discount, and observation time as anonymous price snapshots not linked to a user or installation.
- D1 stores public official X handles found on Steam store pages, Steam App IDs, and update times for official-account matching.
- D1 stores App ID and locale keyed game-information cache rows: sanitized short description, up to three genres, player count, Steam Deck state, and refresh timestamps.
- D1 stores Steam App ID, decimal X status ID, publication state, anonymous confirmation/report counts, and related timestamps.
- D1 stores confirmation or report, creation time, and an association-scoped HMAC that cannot be used to link the same installation across different posts.
4. Data not stored by the service
- The full X post text is read temporarily on-device but is not sent to the API or stored.
- X author names are not stored.
- X author handles supplied for matching are not stored or logged.
- Images, videos, and other X post media are not sent or stored.
- Full post URLs, URL queries, and fragments are not sent or stored; public links are reconstructed from the decimal status ID.
- The raw anonymous installation ID is not stored on Steam Sonar servers.
- The raw client IP address is not stored by Steam Sonar in D1 or application logs.
5. Retention and your controls
- Rate-limit rows normally expire within two hours and fifteen minutes. Price, official-account, game cache, and anonymous community rows remain while their features operate; anonymous operational metrics currently have a three-month retention period.
- Withdrawing consent in Options stops future page analysis, API calls, community confirmations/reports, watch checks, and notifications.
- Options can delete watch items, corrections, or all extension-local data. Uninstalling the extension also removes its Chrome extension storage.
- Deleting local data or uninstalling cannot delete already shared anonymous community aggregates because association-scoped votes cannot be enumerated back to one installation.
6. Processors and Limited Use
- Cloudflare processes API traffic as Steam Sonar's service provider and hosts the Worker, D1 data, rate limiting, and fixed-shape anonymous operational metrics. Those metrics exclude App IDs, locale, origin, install ID, IP, URLs, and post data.
- Valve/Steam receives only the bounded search term, Steam App ID, country or region, and language required for search, store, review, and player-count requests. It does not receive X post text, status ID, author data, install ID, or Steam Sonar watchlist data.
- Steam Sonar's use and transfer of extension data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. The data is not sold or used for advertising, credit, employment, or unrelated profiling.
- Privacy and deletion questions can be sent to tsu.aria.kalei@gmail.com.
- This extension privacy policy was revised on 2026-07-27.