1. Overview
This Privacy Policy explains how SkinAlyze ("we," "our," or "us") collects, uses, and protects information when you use our website and services.
SkinAlyze provides a data analytics and portfolio tracking platform for CS2 skin traders.
Most services process analytical data. When an owner uses Native Cashout, Skinbux receives and holds the selected items for settlement and SkinAlyze stores the transaction records needed to release the locked stablecoin payout.
2. Information We Collect
a. Account Information
- Email address, used for login, notifications, and support
- Encrypted password, we never store or see the plain text version
b. Trading and Portfolio Data
- Item names, purchase and sale prices, marketplace tags, and other trading metrics that you import or enter manually
- Linked Steam or marketplace account names, if provided for tracking purposes
This data is stored securely and used only to display your analytics dashboard, charts, and reports.
c. Browser Extension, Steam Sync, and Instant Sell Quote Data
If you choose to install and pair the SkinAlyze browser extension, we may collect and store data that the extension syncs from your browser for your account, including:
- Steam inventory item details, such as item names, asset IDs, images, float, paint seed, stickers, and tradability status where available
- Steam trade offer and trade history details used for imports, received date tracking, and inventory review
- Optional Instant Sell quote results, including grouped item names, normalized quote rows, prices, statuses, timestamps, source or provider labels, and sanitized provider diagnostics
- Extension pairing records, client identifiers, extension version, sync timestamps, and sync status or error logs
The extension does not intentionally send us your Steam password, Steam cookies, trade confirmation access, marketplace cookies, marketplace auth headers, marketplace session or api tokens, raw marketplace HTML, or screenshots.
You can revoke an extension connection from Settings at any time.
d. Technical Information
- Basic usage logs such as browser type, device type, and approximate region for performance and debugging
- Cookies or local storage for session management to keep you logged in
We do not use tracking cookies for advertising and we do not sell analytics data to any third party.
e. Optional Legal and Tax Information (User-Provided)
If you choose to use the tax report and legal identity features, you may optionally provide:
- Full name or business name
- Address, including street, city, postal code, and country
- Entity type, individual or business
- Email and phone number
- Tax id, such as Steuer-id
- Vat id, if applicable
Providing this information is entirely optional. The platform can be used fully without entering any legal or tax identity data.
This data is used only to generate personalized report headers and documents within your account.
We do not verify this information, and we do not submit it to any authority or third party.
f. Subscription and Billing Information
If you start a checkout or make a purchase, we may receive and store information needed to provision and support your access, including:
- Billing contact email, country, and limited billing identity or business details
- Provider customer, transaction, subscription, invoice, and adjustment identifiers
- Product, billing interval, amount, currency, tax summary, payment status, service period, cancellation state, and refund or dispute status
- The legal-policy version associated with the checkout and relevant timestamps
Whop or NOWPayments collects payment details in its own checkout. SkinAlyze does not receive or store full card numbers, card security codes, cryptocurrency private keys, or wallet secrets.
g. Personalization, Alerts, and Scheduled Reports
When you use personalization or automation features, we store account appearance choices, per-workspace navigation and page layouts, saved views, workspace templates, listing-strategy definitions, alert rules, delivery-channel preferences, report templates, schedules, and run history.
- Alert rules may process item, listing, market-price, balance, and integration-health events needed to evaluate the recipe you select.
- In-app notifications contain the alert title, message, workspace, deep link, read status, and timestamps.
- Email, Telegram, and Discord delivery uses the destination connected by each recipient. Workspace managers can see whether a member's channel is available, but not that member's private destination details.
- Scheduled report runs store an immutable template and permission snapshot, delivery status, and a private generated artifact when applicable.
h. Native Cashout and Wallet Information
- Linked Steam account, eligible inventory asset IDs, item names, Skinbux prices and phases, Steam offer and provider transaction identifiers, and settlement status
- Your Steam trade URL, encrypted per linked Steam account; its token is not returned to the browser after saving
- Your confirmed ERC-20 payout address, encrypted at rest, plus a non-sensitive hash and last four characters used for matching and display
- Immutable quote values, pricing inputs and adjustments, selected token and network, accepted cashout-terms version, review actions, payout amount, and Ethereum transaction hash
We do not request or store a wallet private key, seed phrase, wallet password, or the plaintext Steam trade token in application logs or audit payloads.
3. How We Use Your Data
We use your data only to:
- Operate and maintain your account
- Display your portfolio, trades, and statistics
- Sync Steam inventory and trade offer data through the optional browser extension
- Fetch, cache, and display optional Instant Sell quote results for Listing Helper
- Create and administer Native Cashout quotes, send selected inventory and locked trade details to Skinbux, reconcile holds and settlement, and manually release ERC-20 payouts
- Generate charts, summaries, and reports
- Generate optional tax and legal report headers based on data you voluntarily provide
- Save and synchronize your appearance, navigation, page layouts, views, and workspace templates
- Evaluate alert recipes, prevent duplicate events, and deliver notifications through channels you enable
- Generate and deliver scheduled reports after rechecking workspace membership and report permissions
- Send important service notifications, such as email verification and password resets
- Administer trials, subscriptions, payments, invoices, refunds, disputes, entitlements, and customer support
We may use anonymized and aggregated usage data internally to improve system performance and design.
5. Data Storage and Security
Your data is hosted on secure servers managed by Supabase and protected using encryption in transit and at rest.
Access to your account requires authentication, and only you can view your personal trading data.
Optional legal and tax identity data is stored using the same security protections as other account data. Access is limited to the authenticated account owner and authorized personnel who need access for security, support, legal, or operational purposes.
Notification inbox items, delivery audit records, and generated scheduled-report artifacts are retained for up to 90 days. Saved preferences, rules, templates, and schedules remain until you delete or reset them, your workspace access ends, or the account is deleted, subject to legally required retention.
Native Cashout trade URLs and payout addresses are encrypted at rest. Cashout quotes, item records, lifecycle events, manual approvals, and transaction hashes may be retained as transaction, accounting, security, dispute, and fraud-prevention records even after an account-deletion request where applicable law or legitimate operational needs permit.
6. Data Export and Deletion
- You may export your data in csv format at any time through your account interface.
- You may request account deletion by contacting [email protected]. We delete or anonymize account data unless limited retention is required for security, fraud prevention, billing, tax, accounting, disputes, legal claims, or another legal obligation.
- You may revoke paired browser extension clients from Settings to stop new extension syncs.
- You may reset personal preferences and delete permitted saved views, alert rules, strategies, report templates, and schedules through the application. Resetting preferences does not alter financial or ledger data.
- This includes any optional legal or tax identity information you may have provided.
7. Diagnostics
We process limited, scrubbed diagnostic and performance data through Sentry to detect errors, entitlement leakage, and billing failures. Raw provider webhook payloads are not retained in Sentry.
8. Subscription and Billing
For card purchases, SkinAlyze is the seller and supplier of the service, and Whop provides checkout and payment processing. Whop may act as merchant of record for card-network and settlement purposes and, only where Whop Collects and Remits applies in a supported jurisdiction, for eligible transaction-tax collection and remittance. Whop's Buyer Terms and Privacy Policy apply to its processing.
For separately offered cryptocurrency purchases, NOWPayments processes the payment for a manually renewable fixed term sold by SkinAlyze. SkinAlyze maintains the billing and service-period records required to reconcile the transaction and provide an appropriate receipt or invoice.
Billing documents and subscription records are scoped to the account or workspace that made the purchase. Account owners and authorized workspace administrators can retrieve documents for their billing subject.
We retain billing records for the period required to provide service, reconcile provider records, handle refunds and disputes, and meet applicable tax, accounting, fraud-prevention, and legal obligations. SkinAlyze does not store full payment-card details, private keys, wallet secrets, or raw payment-provider webhook payloads in application logs or Sentry.
9. Children's Privacy
SkinAlyze does not target or knowingly collect personal data from individuals under 13 years of age.
10. Policy Updates
- We may update this Privacy Policy periodically.
- The latest version will always be available at
/privacywith the effective date shown above. - If major changes occur, users will be notified by email or through an in-app notification.
11. Contact
For questions, support, or data requests:
- 📧Email: [email protected]
- 💬Discord: Join our Discord server
- 🐦X (Twitter): @SkinAlyze
- 🐙GitHub: github.com/SkinAlyze-app