01 Scope and contact
This policy covers SteamShowcase Helper (the browser extension) and its integration with Showcase Maker at showcasemaker.com. Developer and operator: n1t1337 / Showcase Maker. This is an independent project, not a Valve product.
For privacy, access or deletion requests, contact the developer through the n1t1337 Steam profile or the support contact options on the official Telegram channel. Ask to communicate privately; do not post passwords, tokens or personal documents in public comments.
02 What the extension handles locally
- Selected files: images and animations, filenames, dimensions and output settings for local Browser Engine processing and preview. Local processing does not upload file contents to Showcase Maker. Downloaded results stay on your device.
- Preferences: language, theme, active tool, preview selections, favourites and a local snapshot of profile-page content used to restore the preview.
- Upload guidance: showcase type, filenames, dimensions, item order, current step and start time. The website sends this metadata to the extension; you still select files yourself in Steam.
- Relevant tabs: Steam/site tab URLs and, where needed, titles and tab IDs to open the correct tool or find a profile tab. The extension does not maintain or send a general browsing-history database, keystroke log or advertising activity profile.
Settings use browser extension storage and localStorage. Preview data can also remain in Steam's site storage. Closing the popup does not erase persistent settings.
03 Requests to Steam and credentials
The extension loads backgrounds, avatars, frames and catalog data from Steam Community, Steam APIs and Steam content-delivery domains. Steam receives the requested URLs, your IP address and normal browser/network metadata. Some Steam requests use your existing Steam session; the catalog may read the loyalty Web API token exposed on the Steam page and send it to Steam's API.
Steam passwords are not requested by the extension. It does not export Steam cookies or that Steam token to Showcase Maker. Website import instead uses a separate short-lived, single-use import ticket issued by Showcase Maker. Never send any of these credentials to support.
When you choose a file for Steam upload, it is sent to Steam through Steam's upload form; the extension prepares form settings and guides the steps. Publication and visibility are governed by the settings on Steam, not by local preview. Steam applies its own privacy policy.
04 Importing a profile into the website
When you initiate extension-based import in Showcase Maker, the extension opens your Steam profile and sends a structured snapshot to Showcase Maker over HTTPS. It can include SteamID, profile URL, nickname, displayed real name, summary, status, level, avatar/background/frame URLs, badges, awards, groups, counters, showcase text, links and media URLs, dimensions and capture time. Only profile information exposed on the loaded page can be captured; do not place information there that you do not want imported.
The site validates the import ticket, associates the snapshot with your signed-in account and stores it for the editor. It may enrich the snapshot using Steam APIs and download/cache the avatar, updating your site display name and avatar. Imported account information and saved site profiles are not disposable processing jobs and do not automatically expire after seven days. Your site display name, avatar and any public profile or gallery content may be visible to other visitors.
The bridge also reports the installed extension version to the supported site and can return Steam customization catalog results. Localhost/127.0.0.1 are supported only for local development; a locally initiated import goes to that local instance.
05 Why browser permissions are used
- scripting
- Runs the packaged helper scripts on supported Steam pages to prepare upload forms, preview and read the requested profile.
- activeTab
- Works with the active tab when you invoke a tool.
- tabs
- Finds relevant Steam tabs, reads their URLs/titles when needed and opens upload/profile/showcase pages.
- storage
- Remembers preferences and upload progress on your device.
- Site access and external messaging
- Steam Community enables on-page tools; showcasemaker.com and www.showcasemaker.com enable the integration. Localhost and 127.0.0.1 support the local development site. The bridge accepts only supported actions from allowed site origins.
06 Separate website services
Opening Showcase Maker is different from using only the local extension. Depending on the features you choose, the website processes account identifiers, email and login/session information, saved profile designs, uploads, job results, gallery publications, comments, likes, Pro access and transaction references. Payment and third-party sign-in providers handle their own forms; do not submit payment-card details in the support chat. The website uses necessary session cookies, browser settings/drafts and IP-based anti-abuse counters.
OVH hosts the application and database; Cloudflare provides the public connection, protection and, where configured, R2 media storage. Requests can create technical logs containing IP addresses, requested paths, timestamps, response status and browser metadata. These support operation, security and troubleshooting.
Optional product analytics: if you choose “Allow”, we record page and tool actions with a random identifier kept for the browser session, language, route, general file type/size range and processing outcome. Analytics does not store IP addresses, browser identifiers, email, Steam ID, filenames or media content. Operational events such as completed registration, Pro activation, processing outcome and ZIP download may be recorded server-side to operate, secure and measure the service. Detailed analytics is deleted after no more than 90 days; aggregated totals may be kept longer. Choose “Necessary only” to refuse optional browser analytics, or clear this site's storage to choose again.
Only when you use the related features: Modal processes media for GPU upscaling; Bright Data retrieves public Steam pages for server-side import; Google Gemini receives selected public-profile text and images for Profile Rating/Design Selection; Groq receives your support question, a bounded recent conversation and public help information for AI replies. Clicking a built-in FAQ answer does not itself invoke Groq. Chat messages are not deliberately saved as conversation records by our application, but providers may process or retain data under their own policies; an API option is not a guarantee of zero retention. Extension installation alone does not send your files to these AI services.
External links (including Steam, DeviantArt, payment services and social networks) open services with their own privacy rules. Some site pages load Google Fonts. This policy page itself includes no analytics, chat widget or external font requests.
07 Retention, deletion and your choices
- Device data: extension settings and upload metadata remain until replaced, cleared or the extension is removed. Steam-site preview snapshots can survive extension removal; clear Steam site storage separately to remove them (this may sign you out). Downloaded files must be deleted by you.
- Site account and saved content: remain while needed for your account and selected services, until replaced or deleted. Contact support to request access, correction or deletion of your account, imported snapshot and associated media. We may need proportionate ownership verification; never provide a password or session token.
- Temporary results: normal Process download links expire after a configured interval (24 hours by default); AI profile-history entries are configured to expire after seven days. Other media jobs and R2 objects follow their job cleanup and bucket lifecycle settings. A link expiring is not a promise that all copies are erased immediately.
- Logs, backups and providers: retention depends on operational rotation, backup and provider policies. A single verified deletion deadline for all such copies is not currently published. Residual backups are not active user profiles; legal or security obligations may require limited retention. Support can clarify the applicable retention for a particular request.
You can disable the extension or its site access, stop using import/AI services, clear local data, and use available edit/delete controls. Uninstalling the extension does not delete your website account or content already uploaded to Steam. Access, correction, erasure, restriction and objection rights may apply under your local law; you may also contact your data-protection authority.
08 Limited Use, sharing and security
Our use of data obtained through SteamShowcase Helper is limited to providing or improving its stated, user-facing functions and follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell extension user data, use it for personalised advertising or transfer it for creditworthiness or lending decisions. We do not send extension data for unrelated general-purpose AI training.
Data is shared only as needed for the features described here, with the necessary service providers, for security or legal compliance, or in an allowed business transfer with legally required notice/consent. Human access to extension data is limited to your specific consent (for example support), necessary security investigation, legal compliance or aggregated/anonymised internal operations as permitted by the policy.
Public service transfers use HTTPS. Access controls, scoped import tickets and restricted integration origins help protect data; no system guarantees absolute security. Providers may process data outside your country under their applicable terms and safeguards. This policy does not claim that every storage volume or provider is independently audited.
We use requested processing to deliver the service, necessary operational processing to secure it, consent where required for optional processing, and legal obligations where applicable. Changes to this policy will be published here with an updated date. New purposes requiring consent will require that consent before use.