PlusOnePlay

Privacy Policy

Last updated: July 18, 2026

PlusOnePlay (“we,” “us”) helps you track your game library and decide what to play next. This policy explains what we collect, why, and your choices. We don't sell your data.

What we collect

  • Account. If you sign in with email, your email address. If you sign in with Steam, your Steam ID and public Steam profile (display name, avatar, country). Steam accounts are issued an internal placeholder email that we never display.
  • Your game data. The library, wishlist, ratings, playtime, statuses, notes, and settings (region, display name, sort preferences) you add or import.
  • Recommendation interactions. Which recommendation cards were at least half visible, feedback you give, and clicks on recommended-game launch links. These records are tied to your account so we can personalize future picks and measure aggregate activation; a launch-link click does not tell us whether you actually played.
  • Anonymous taste previews. For a no-account preview made from two games, we store the two catalog game IDs you chose, the catalog game ID returned, the recommendation-engine version, a closed broad channel such as Reddit, Google, X, other referral, or direct, and allowlisted interactions with that result such as view, good/not for me, retry, start over, share, or clicking connect Steam. Previews made from three or four games contribute only non-identifying step events and aggregate success counts; they do not create this detailed run record. A random preview-run ID connects the detailed two-game actions for 24 hours. It is stored as the run's opaque database key; your browser holds it only in that page's memory, never in a cookie, local storage, or the URL. We do not attach the run to an account, Steam ID, IP address, device fingerprint, or persistent advertising identifier, and we do not store the first-touch timestamp, exact UTM values, game-search text, or full referring URL with it. Detailed preview runs stop being available at 90 days and are then hard-deleted automatically; non-identifying aggregate totals may be retained longer.
  • How you found us. On your first public visit, we may remember normalized campaign labels from the link and the hostname of an external referring site. If you create a new account with Steam, that first-touch source is stored with the account so we can measure aggregate signup and activation by channel. We do not store the full referring URL, search terms, or form contents for this purpose.
  • Technical. Basic request and error logs, plus anonymous page-performance measurements such as load speed and responsiveness, needed to run and improve the service. We configure error reports to omit request and response headers and bodies, form contents, query strings, account identity, and raw IP addresses. They can include the app route, recent network endpoint paths without query strings, device/browser context, and coarse city and country context derived by our error-monitoring provider. If anonymous web analytics are enabled, we also collect basic pageview counts and named sign-in and no-account-preview step events. Those third-party analytics events contain no form contents, search text, or selected games. Analytics URLs are stripped of query strings and account-owned route identifiers; sign-in/reset pageviews and all internal-dashboard events are excluded. Separately from the detailed preview runs described above, we keep daily aggregate counts of Steam handoffs, verified returns, and successful no-account previews. Those counters contain no IP, account or session identifier, Steam ID, URL, search, or selected game.

How we use it

To provide the service: build your library, generate and improve taste-based recommendations, show store prices for your region, understand which preview inputs and results lead to retries or signup, find where users get stuck, and improve the product. We don't use your data for third-party advertising.

Service providers

We use trusted processors to operate PlusOnePlay: Supabase (database & authentication), Vercel and Railway (hosting), Sentry (error monitoring), and the Steam Web API and IGDB/Twitch (to fetch game and library data you ask us to).

Cookies & local storage

We use cookies/local storage for sign-in sessions, your preferences, and a first-party first-touch record that expires after 30 days. We do not use third-party advertising cookies or cross-site tracking.

Your choices

You can view and edit your data in the app, and you can ask us to export or delete your account and its data at any time by emailing support@plusoneplay.com. Deleting your account also deletes its stored recommendation-interaction and first-touch acquisition records. We do not connect anonymous preview runs to account records; they stop being available at 90 days and are hard-deleted automatically. PlusOnePlay isn't directed at children under 13.

Changes & contact

We'll update this page if our practices change. Questions? support@plusoneplay.com.

This is a plain-language policy, not legal advice; if you operate in a specific jurisdiction you should have it reviewed.