Privacy Policy

Last updated: August 10, 2026

HLTB for Steam has no accounts, analytics, advertising, telemetry, or dynamic developer-operated backend. The developer does not receive, collect, sell, or analyze user data. A public GitHub Pages endpoint distributes signed static snapshot files.

Data processed

When a supported Steam game page is opened, the extension processes public website content: the Steam App ID, game title, and artwork URL. In Chrome and Firefox, the game title is sent over HTTPS directly to HowLongToBeat to request current completion-time information. This tells HowLongToBeat which title is being looked up, and HowLongToBeat processes that request under its own privacy practices. Inside Steam's embedded browser, the title is not sent to HowLongToBeat.

At most once every 24 hours while the extension is in use, it requests the same fixed update URLs from devln737.github.io/hltb-for-steam-data. When a newer signed version exists, it downloads a fixed manifest and data-only snapshot pack. These requests contain no Steam page URL, App ID, title, browsing history, or persistent user identifier. The extension accepts a snapshot only after its signature, fixed schema, and SHA-256 checks pass.

Successful network responses, the requested title, Steam App ID, and extension preferences are stored locally in browser extension storage. Cache retention is configurable to 1, 7, or 30 days. Signed snapshots are stored separately in IndexedDB; the active and previous versions are retained so a failed update cannot replace working data. Steam artwork is displayed from its existing HTTPS URL and is not stored by the extension. Users can clear cached game data from the extension popup.

The data is used only to display completion times and operate settings and cache. It is not used or transferred for advertising, profiling, credit decisions, or sale. Use of information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Permissions

Contact

For privacy questions, use the project's support page. Security reports should follow the private process in the Security Policy.