Steam
- The documents do not say whether your data trains AI.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared only with the providers who run the service.
- The documents do not say who can read your content.
Steam collects account, play, device, and chat data, does not sell it, and lets you manage or delete much of it in a dashboard.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account info, payments, chats, game stats, device IDs, IP address, and cookies.
Read the exact line
Privacy policy
“Personal Data we collect may include, but is not limited to, browser and device information, data collected through automated electronic interactions and application usage data.”
Training
They use it to run Steam, stop cheating, recommend games, and send similar-product marketing.
Read the exact line
Privacy policy
“We may process information collected under this section 3 so that content, products and services shown on the pages of the Steam store and in update messages displayed when launching the Steam Client can be tailored to meet your needs”
Sharing
They say they do not sell data, but providers, CDNs, and game makers can get some of it.
Read the exact line
Privacy policy
“Valve does not sell Personal Data. However, we may share or provide access to each of the categories of Personal Data we collect as necessary for the following business purposes.”
Kept
Deleted after account closure except legal holds, including tax records for up to ten years.
Read the exact line
Privacy policy
“Please note that Valve is required to retain certain transactional data under statutory commercial and tax law for a period of up to ten (10) years.”
Controls
A Privacy Dashboard lets you see, fix, or delete data; marketing emails have an unsubscribe link.
Read the exact line
Privacy policy
“This gives you access to your Personal Data, allows you to rectify and delete it where necessary and to object to its use where you feel necessary.”
Fine print
Policy is dated Feb 14, 2025; full lawsuit, refund, and account-closure rules are not in these pages.
Read the exact line
Privacy policy
“Revision Date: February 14th, 2025”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Open the Privacy Dashboard to view, fix, or delete data
https://help.steampowered.com then My Account -> Data Related to Your Steam Account
Request full account deletion
Steam support page (30-day restore window)
Unsubscribe from marketing emails
Unsubscribe link in emails or the email setting page
Limit store recommendation tracking in the client
Steam Client settings, Interface section: turn off automatic loading of the Steam store page and notifications
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
Even after you leave, some purchase records can stay for a decade because of tax law.
Read the exact line
Privacy policy
“Please note that Valve is required to retain certain transactional data under statutory commercial and tax law for a period of up to ten (10) years.”
For example, if you delete Steam, Valve may still keep years of wallet and purchase history.
Anyone can look up your Steam ID and see at least your name, avatar, and cheat bans.
Read the exact line
Privacy policy
“This information can be accessed by anyone by querying your Steam ID. At a minimum, the public persona name you have chosen to represent you on Steam and your Avatar picture are accessible this way”
For example, a website can query your Steam ID and show your public name without asking you.
Community chats and forum posts are treated as public, not private messages.
Read the exact line
Privacy policy
“When posting a message to a board, forum or chat area, please be aware that the information is being made publicly available online; therefore, you are doing so at your own risk.”
For example, a joke you type in a Steam forum can be copied by anyone on the internet.
They place cookies and ad-style tags to measure use and improve marketing.
Read the exact line
Privacy policy
“we use "Cookies", which are text files placed on your computer, and similar technologies (e.g. web beacons, pixels, ad tags and device identifiers) to help us analyze how users use our services, as well as to improve the services we are offering, to improve marketing”
For example, visiting the store can set cookies used to tailor later offers.
Playing games sends Valve your progress, playtime, OS, device IDs, and crash logs.
Read the exact line
Privacy policy
“By game statistics we mean information about your games' preferences, progress in the games, playtime, as well as information about the device you are using, including what operating system you are using, device settings, unique device identifiers, and crash data.”
For example, how long you played a title and your device ID can be stored with your Steam ID.
They state they do not sell your personal information.
Read the exact line
Privacy policy
“Valve does not sell Personal Data.”
For example, they say they would not sell your email list to an unrelated advertiser.
Account deletion is not instant; you have 30 days to undo it.
Read the exact line
Privacy policy
“We allow you to restore your Steam User Account during a grace period of 30 (thirty) days from the moment you of your Steam User Account.”
For example, if you click delete by mistake, you can restore the account within 30 days.
You must be at least 13; they rely on that rule rather than a strong ID check described here.
Read the exact line
Privacy policy
“The minimum age to create a Steam User Account is 13. Valve will not knowingly collect Personal Data from children under this age.”
For example, a 12-year-old is not supposed to make an account, but the policy does not describe ID verification.
They say they use ordinary encryption and other safeguards when moving data.
Read the exact line
Privacy policy
“ of data Industry-standard encryption Provision of access to data on a need-to-know basis”
For example, they list encryption among steps to protect data sent outside Europe.
You can stop marketing emails with an unsubscribe link or by changing email settings.
Read the exact line
Privacy policy
“You can opt out or withdraw your consent to receive marketing emails at any time by either withdrawing the consent on the same page where you previously provided it or clicking the "unsubscribe" link provided in every marketing email.”
For example, you can click unsubscribe in a Steam sale email.
Words to know
Legal words from the lines above, in plain English.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- cookies
- Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
- tracking pixels
- Tiny invisible images or bits of code in a page, app or email that report back when and where you opened it. For example, a pixel in a marketing email tells the sender the moment you read it.
- device identifiers
- Codes that single out your phone or computer, used to recognise you across apps and sites. For example, the advertising ID on your phone lets two unrelated apps know they are seeing the same person.
- right to erasure
- Your right to have a company delete the personal data it holds about you, with some exceptions. For example, you can ask a social app to wipe your old posts and profile and it must, unless a law says otherwise.
- pseudonymous
- Your name is swapped for a code, but the company keeps the key and can still link the data back to you. For example, your chats are filed under user 48213 instead of your name, but staff can still look up who that is.
- opt out
- Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
- consent
- Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
How we got here · grade D · score 39/100 · 15 of 15 policy answers backed by a verified quote · 8 not stated
What does the app collect beyond what it needs to work?
Besides account and what you type, they collect device info, unique device IDs, IP address, cookies, game stats, and crash data.
Does it record your voice, face or body, and what happens to that?
Not stated in the documents.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They use cookies, pixels, and ad tags for analytics and marketing, plus tailored store recommendations and marketing emails you can unsubscribe from.
Do they sell or share your data, and can you opt out?
They say they do not sell personal data. They share it with Valve companies, support vendors, CDNs, and game makers via Steamworks, and public profile fields are queryable.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
You can delete via the Privacy Dashboard or account deletion (30-day grace), but some data stays for law, including tax records up to ten years, and some match data is only anonymized.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
They describe encryption, need-to-know access, pseudonymization, and Data Privacy Framework certification, not a public bug-bounty program.
Is there a real age gate, and are teens protected?
The minimum age is 13, with parental consent where a country requires a higher age. No ID check is described.
Will they tell you when the rules change, and is the policy specific?
The privacy policy is dated February 14th, 2025, but it does not say they will give advance notice of changes.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
Not stated in the documents.
The privacy policy is 4,659 words at a college level (Flesch reading ease 45.9); the terms are 142 words at an easy to read level.