Last updated September 5, 2026
This page explains exactly what PlayRadix stores about you, why, and how to get rid of it. It describes what the site actually does today — not what a template assumes a website does.
PlayRadix is a personal, non-commercial project that compares PC game prices across stores. Downloading or deleting your data is self-service in your account settings; for anything those don't cover, write to privacy@playradix.com.
For GDPR purposes, the operator of PlayRadix is the data controller for the account data described below.
Nothing in this section applies until you choose to create an account. Browsing the site anonymously creates no record of you beyond the preference cookies you set yourself and the ordinary server logs of our hosting providers.
A username, and an optional display name. An email address only if you register with one — signing in with Steam provides no email, and accounts made that way have none. If you set a password we store only an argon2id hash of it, never the password. If you sign in with Steam we store your Steam ID, and the profile name and avatar URL Steam publishes for it.
Each active session is recorded with the browser's user-agent string and when it was last used, so you can see and revoke your own devices. Signing in from a browser and operating system we have not seen before is recorded — as a coarse fingerprint of the browser and OS family, never versions — together with the IP address of that sign-in, so we can tell you about it. Failed sign-in attempts are counted against an IP address to slow down guessing. Security events (sign-ins, password and two-factor changes, deletions) go to an append-only audit log. If you enable two-factor authentication its secret is encrypted at rest; backup codes are stored only as hashes. For a passkey we store only the public key — the private key never leaves your device.
Your wishlist, your library of owned games, any collections you create, your price alerts and their thresholds, your notification preferences, and the in-app notifications you have been sent. These reference games by an id only — a game's title, art and price are fetched fresh from the catalog every time a page renders, never copied into your account.
We ask Steam for the games on the account you signed in with, and store each matched game together with the playtime and last-played time Steam reports, exactly as reported. This runs only when you ask for it. If your Steam profile is private, Steam tells us nothing and we store nothing.
The theme and display currency you pick are stored in cookies so the page renders correctly on the first paint, and — if you are signed in — on your account too, so they follow you between devices.
When a search matches no game, the search text alone is sent to our catalog service so the game can be looked up and added — that is how the catalog grows toward what people actually search for. Nothing identifying travels with it: no account id, no IP address, no session. Your IP is used only on our own server, before that, to limit how many such reports one visitor can trigger.
Under the GDPR, each piece of the above rests on one of these grounds:
9 cookies, all of them either strictly necessary or a preference you set yourself. There are no analytics, advertising or third-party cookies on this site, which is why you are not being asked to consent to any. If that ever changes, a consent banner will appear before the cookie does.
| Cookie | What it is for | How long it lasts |
|---|---|---|
session | Keeps you signed in. Holds an opaque random token; the server stores only its SHA-256 hash, so a database leak cannot be replayed as a login. | 30 days, renewed as you use the site; cleared on sign-out |
session_user | Your username and display name, so the header can show who is signed in without a database lookup on every page. Never carries your role or email. | 30 days |
session_verified | A presence-only marker set just after your session was checked against the database, letting the next few page loads skip that check. Carries no data and grants no access. | 60 seconds |
steam_auth_nonce | Ties a “Sign in with Steam” round trip to the browser that started it, so someone else's login cannot be completed in your browser. | 10 minutes |
webauthn_challenge | A single-use challenge for registering or using a passkey. | 5 minutes |
theme | The light, dark or system appearance you chose. | 1 year |
currency | The display currency you chose. | 1 year |
lens | The platforms whose prices you chose to compare. | 1 year |
display | How much detail game cards show (compact or per-platform prices). | 1 year |
The first five are strictly necessary: without them you could not sign in or stay signed in. The last four exist only because you picked something and we are honouring it — clearing them simply restores the defaults.
We do not sell your data, and we do not share it for anyone's marketing. A small number of providers process it on our behalf so the service can run:
We would also disclose data where the law genuinely requires it. Nothing of that kind has ever been requested.
Wherever you are, and in the terms the GDPR uses, you can:
To exercise anything that is not already a button in your account, write to privacy@playradix.com. We will not ask you to justify the request, and we will answer within 30 days.
Your profile is private unless you deliberately make it public, and every section of it — wishlist, library, collections, playtime — is separately off until you turn it on. Having never touched those settings is treated as private, not as undecided. Public profiles are also marked so search engines do not index them.
Passwords are hashed with argon2id. Session tokens, email links and two-factor backup codes are stored only as hashes, so what is in the database cannot be used to sign in. Two-factor secrets are encrypted at rest. Passkeys store only a public key. All traffic is over HTTPS, and the account database is separate from the catalog, which has no user data in it at all.
Our providers operate internationally and may process data outside your country. Where they do, they rely on the European Commission's standard contractual clauses or an equivalent safeguard.
This site is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has made an account, write to privacy@playradix.com and we will remove it.
If this policy changes in a way that affects what we collect or why, we will update the date at the top and, where the change is significant, tell account holders directly rather than relying on you to re-read this page.