Privacy Policy
Last updated 16 September 2026
The short version
csreport shows you which Twitch and Kick streamers played in your Faceit CS2 matches. To do that it stores your account, the Steam and Faceit identity you link to it, and the matches where you and a streamer appear on the same scoreboard.
It does not sell your data, does not run advertising, and does not use third-party tracking or analytics cookies. Card details never reach it — PayPal handles payment entirely.
Who is responsible
csreport is operated by an individual, not a company. For anything in this policy — including access or deletion requests — write to privacy@csreport.app.
What is stored, and why
Your account. Your email address and a hashed password, held by our database provider's authentication service. Needed to have an account at all.
Your linked identities. If you link Steam, we store your Steam ID (a public 17-digit number) and the Faceit nickname and player ID it resolves to. This is what lets us tell which encounters are yours — without it, your dashboard is empty.
Your encounters. For each match where you shared a scoreboard with a tracked streamer, we store the match ID, the map, when it was played, the streamer, and a link to their VOD if one exists. This is public Faceit match data, organised around you.
Your subscription. If you subscribe, we store the PayPal subscription ID, the plan, its status and when the paid period ends. We never see or store your card or PayPal login details.
Error reports. When a page or request fails, we record the error message, the page or route it happened on, your browser's user-agent string and — if you were signed in — your account id, so we can find and fix it.
Discord alerts. If you connect Discord, we store the webhook URL Discord gives us plus the server and channel it belongs to. That webhook only lets us post messages into the one channel you chose. It cannot read your messages, your servers, or anything else about your Discord account. We never show the webhook URL back to you or to anyone.
Followed streamers. If you follow streamers, we store which ones.
The streamer registry and streamer pages. To recognise streamers in a match we keep a registry of channels: the Twitch login or Kick channel name, the Faceit nickname and player ID behind it and its Steam ID — all public — and, for every match we saw a channel play, the match, the map, when it was played and a link to the broadcast if one exists. Every channel with recorded matches has a public page at /streamer/ followed by its channel name, listing those matches and nobody else. If you stream and want no part of this, write to support@csreport.app from your channel's contact address and we switch on streamer mode for the channel: it is left out of detection, search results, match pages and the sitemap from that moment, and its page is removed. Records of matches already played stay in the histories of the players who were in them, without your perspective.
Operational records. Rate-limit counters keyed to your account (or, if you are signed out, your IP address), short-lived single-use tokens that protect the Steam and Discord linking flows against forgery, and cached copies of public match data from Faceit, Twitch and Kick so the site does not re-request the same thing endlessly.
Usage counts. We record which nicknames were searched and how many streamers were found, so we can see whether the service is working. These rows are not linked to your account. Separately, when a signed-in user views a streamer's match, we record that view against that streamer's analytics so the streamer can see how many people watched — this does record your account ID.
Legal bases
Under the GDPR, we rely on:
- Performance of a contract — your account, your linked identities, your encounters, and your subscription. Without these the service cannot be provided.
- Consent — Discord alerts. You give it by connecting a channel, and you withdraw it by pausing or disconnecting, at any time, from your dashboard.
- Legitimate interests — caching, rate limiting and abuse prevention, and aggregate usage counts. The interest is keeping the service available and affordable to run.
Who else receives data
We use a small number of providers. Each receives only what it needs.
- Supabase — hosts the database and handles account sign-in. It holds everything described above.
- Contabo — rents us the server in the EU that runs the application. Like any host it can see the traffic that reaches that server, IP addresses included.
- Cloudflare — sits in front of that server. Every request passes through it, so it processes request metadata including IP addresses to serve the site and shield it from attacks. We also use its Web Analytics: a small script Cloudflare adds to each page reports the page address, browser type, country and load timings to Cloudflare, without cookies and without an identifier for you. It tells us how many people open a page, not who. That is the only page-view count on the site.
- PayPal — takes payment and tells us whether a subscription is active. Your payment details are theirs, not ours.
- Discord — receives the alert messages we post to the channel you chose, and only if you connected one.
We also read public data from Faceit, Twitch, Kick and Steam. Doing so necessarily discloses the nickname, channel name or Steam ID being looked up to that service. Nothing else about you is sent to them, and none of them receive your email address.
Some of these providers operate outside the EU/EEA. Where that is the case, transfers rely on the safeguards those providers put in place, such as Standard Contractual Clauses.
How long it is kept
- Account, linked identities, encounters, subscription, Discord settings, follows — kept while your account exists, and deleted when you ask us to delete it.
- Linking tokens — minutes to 24 hours. They are single-use and expire automatically.
- Rate-limit counters — a rolling window of minutes to an hour.
- Worker and payment-event records — about a week, then removed automatically.
- Error reports — 30 days, then removed automatically.
- Cached public match data — kept as long as it is useful. It describes matches, not you.
Your rights
If you are in the EU/EEA or the UK you have the right to access, correct, delete, restrict and object to our use of your personal data, and to receive it in a portable form. You can also complain to your national data protection authority.
Portability is built in. Subscribers can download their encounters and VOD links as CSV or JSON from the dashboard at any time.
Deletion. Delete your account yourself from the dashboard. It removes your account, linked identities, encounters, Discord settings and follows immediately, and cancels an active PayPal subscription first — if that cancellation fails, nothing is deleted and you are told so. You can also email privacy@csreport.app from the address on your account and we will do it within 30 days.
One thing deletion cannot do: disconnecting Discord removes the webhook from our side, but we do not own it and cannot delete it inside your server. Remove it in that server's settings if you want it gone entirely.
Cookies
The only browser storage we use keeps you signed in. There are no advertising, tracking or third-party analytics cookies, so there is no consent banner to click through.
Children
csreport is not intended for anyone under 16, and we do not knowingly create accounts for them.
Changes
If this policy changes in a way that affects you, the date at the top changes and material changes will be announced on the site before they take effect.