idlr.

Privacy Policy

Last updated: October 1, 2026

In short: we only store what Idlr needs to work. No ads, no tracking, no analytics tools, no selling of data. Questions or deletion requests: open a ticket at idlr.eu/support.

01Account

When you sign up we store your email address, profile name, password (only as a bcrypt hash, never in plain text), language and the times of sign-up, email confirmation, acceptance of terms/privacy and last login. For two-factor login an encrypted secret and hashed backup codes. Purpose: providing your account (Art. 6(1)(b) GDPR).

02Steam

For linked Steam accounts: SteamID, login name, display name and an encrypted login token (AES-256, revocable in Steam at any time). Your Steam password is sent to Steam once during login and never stored. Plus service data: boosted hours per game, farmed cards, inventory values, settings and statistics (e.g. number of messages received with the senders' name/SteamID, accepted friend requests, number of profile comments).

To provide the service, Idlr communicates with Steam (Valve Corporation, USA) on your behalf. Game images and avatars are loaded by your browser directly from Steam's servers – Valve or its CDN receives your IP address when that happens.

03Discord (optional)

If you link Discord, we store your Discord ID to send you notifications, assign roles and match tickets/giveaways. Discord is a service of Discord Inc. (USA). You can unlink it at any time.

04Emails

We send confirmation, login and password codes through an email service provider (Brevo (Sendinblue GmbH, Berlin)) that processes the data only on our behalf. Codes are valid for a few minutes and are stored only as hashes.

05Purchases (PayPal)

Purchases are made via a support ticket and paid with PayPal. PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, processes your payment data under its own responsibility. We receive the name and email address of your PayPal account plus the amount and time of payment, and store them to process the purchase and because of legal retention duties (Art. 6(1)(b) and (c) GDPR).

06Support, invites, giveaways

We store messages in support tickets (website and Discord) so we can help you. For invite links we record who invited whom; for giveaways the entries and winners.

07Servers and security

Idlr runs on a rented server (mc-host24.de). All connections are encrypted via HTTPS. The web server writes no access logs containing IP addresses. To prevent abuse (request limits, login locks), IP addresses are kept briefly in memory – for at most one hour (Art. 6(1)(f) GDPR).

The robot check at sign-up and login is self-hosted (ALTCHA): your browser solves a small computing task – no cookies, no third parties.

08Cookies and local storage

Only technically necessary cookies: “hf_token” (login, 7 days), “lang” (language, 1 year) and “ref” (invite link, 30 days). Your browser's local storage holds a random visitor ID for the “online now” counter and display settings (e.g. the selected Steam account). No tracking or advertising cookies.

09Retention

We keep account data as long as your account exists; afterwards it is deleted unless the law requires us to keep it. Short-lived data (codes, locks, online status) expires automatically after minutes to hours.

10Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a data protection authority (Art. 77 GDPR). Just open a ticket at idlr.eu/support.