Skip to content

Legal

Privacy

GameDock holds your library, what you paid for it, and where it lives. That is unusually personal for a games product, so this page is written to be read rather than skimmed past.

Last updated 5 Oct 2026

On this page · 14

The short version#

Your library is private to your account. Nothing is fetched from any platform until you connect one. Once you have, GameDock keeps it up to date on its own: its servers check each connected store on a schedule (Steam every six hours on Plus and daily on the free plan, the others once a day), and the extension reads the stores it handles when you press sync, or on a timer if you switch its background sync on (every six hours unless you choose another interval, from hourly to once a day, and only while Chrome is open). Disconnecting a store stops both. GameDock does not sell your data or share it with advertisers.

Who runs GameDock#

GameDock is a registered business in Australia (ABN 32 410 811 454). GameDock's founder, Adam Lang, decides how the data described here is used and is responsible for it (in some countries' terms, the data controller). Write to support@gamedock.co, use the contact form, or post to Office 4191, Ground Floor, 470 St Kilda Rd, Melbourne VIC 3004, Australia.

What GameDock stores#

Your account itself is an email address, the username you chose, and your preferences: currency, store region, timezone, digest settings, and whether your account is counted in anonymous statistics. If you subscribe, it also holds the Stripe customer and subscription ids, your plan and when the paid period ends. Each time you sign in, it records which browser and IP address the sign-in came from, so Account › Security can show you where you are signed in; that record ends with the sign-in, after 30 days at most. It also remembers for 30 days which addresses have signed in to your account, so a stranger hitting the sign-in limits cannot lock you out. Everything else arrives because you connected a platform:

  • Steam: your SteamID64, the apps and licences on your account, playtime, achievement progress, wishlist entries, DLC ownership, and the purchase history Companion reads from your own signed-in session. GameDock's own Steam Web API key is held once for the whole hub, not per account, and Steam data is only ever requested for an account that has connected Steam, on the schedule described above or when you press Sync.
  • PlayStation: the sign-in token GameDock receives for the one-time code Companion passes it, your entitlements, playtime, trophies, wishlist and purchase history.
  • Xbox: the Microsoft account tokens Companion captures, and your games, playtime, achievements and profile.
  • RetroAchievements: your Web API key and your unlocks.
  • SteamGridDB: your own API key, if you add one, which is used only to search SteamGridDB for artwork when you ask for it on one of your games. The covers you pick with it are kept for your library alone.
  • GOG: the sign-in tokens GameDock receives for the one-time code Companion passes it, your owned games, and your order history.
  • Epic: your owned games and order history, which Companion reads from your own signed-in session. No Epic token is kept.
  • A paired Linux device: the installs, volumes, disk usage, local achievement files and save archives GameDock Helper reports, for the folders you chose to let it look at.

Platform tokens are encrypted at rest. The library, purchase and play data those platforms return is stored so GameDock can show you a library without re-fetching everything on every page load.

If you share any of it, what you write for other people is stored too: a display name, a bio, favourite games, lists and their notes, and reviews, along with who you follow and what you like. Who else sees each is up to you, in Account › Privacy, and it starts as nobody. A profile you share with everyone can be listed by search engines unless you switch that off on the same page.

If you report something, GameDock keeps the report: what it is about, the reason and note you gave, a copy of the text as you saw it, when you sent it, and, if you were signed in, which account sent it, so a moderator can see who reported what and one person cannot report the same thing many times. The account you report is never told who reported it. A report is kept until the reported account is deleted; if you delete your own account first, the report stays without your name on it. If a moderator acts on your account, the action, the moderator and the reason are kept in an audit log for as long as your account exists. If you delete a review or a list that a moderator had hidden, or a review marked as containing spoilers, GameDock keeps a note that it was, with none of its text, so that writing it again does not undo the decision; the note is used up if you do write it again, and otherwise goes when your account does. If an account is closed for breaking the terms, a record that it was closed (its account number, the moderator, the reason and the date, but not its email address or username) is kept for two years after it is deleted. For the same two years GameDock keeps a keyed fingerprint of the closed account's email address, which cannot be turned back into the address, so that the address cannot open another account. If a suspended account is deleted, the same kind of fingerprint is kept with the suspension's reason and date, so that an account made with that address again starts suspended; it is deleted when that happens, and after two years otherwise. Blocks you make are stored until you lift them or either account is deleted.

A message sent through the contact form (your name if you give it, the email address for the reply, the topic and what you wrote) is emailed to support@gamedock.co and not stored by GameDock. If you are signed in when you send it, the email also says which account it came from. It stays in that inbox for as long as the conversation needs it.

What GameDock never stores#

  • Passwords. GameDock has none: signing in is a one-time code sent to your email.
  • Steam store or help-site cookies. Companion uses them in your browser and they never reach the server. When you start a remote install, a short-lived Steam access token from that session is sent for that one request and not kept.
  • Your PlayStation NPSSO token. Companion uses it in your browser to get a one-time sign-in code and sends only that code.
  • Payment card details. GameDock Plus is sold through Link, Stripe's checkout service, and the card is taken on Stripe's own pages; GameDock is told the plan and the renewal date, and never sees a card number.

This is the reason GameDock Companion exists at all. A server that held your store cookies would be a far more attractive target than one that does not, so the extension does the cookie-bearing work in your own browser and sends the hub only the result.

Where it is stored#

GameDock runs on Amazon Web Services in the United States (AWS region us-east-1). Your data, including everything retrieved from Steam, is stored and processed there. If you are outside the United States, connecting a platform means your data is transferred there.

Who else sees it#

Other players see only what you choose to share. To ensure the smooth running of the platform, GameDock's founder, Adam Lang, may be required to review your account and see the hub as you see it. This allows us to check that everything is working as it should, or to act on a suspected breach of the terms. Reviewing your account is a read-only action, and so will never change any of your data or contact any platform on your behalf. If a review does occur, it is recorded in GameDock's own audit log along with a reason for the review, and that record is deleted along with the rest of your data should you ever delete your account.

To sync, GameDock's servers contact each platform you have connected (Steam, PlayStation, Xbox, GOG and RetroAchievements) with your account id or the token you gave it, so each of those platforms sees GameDock reading your account, as it would any app you had signed in to.

GameDock fills in cover art, descriptions, release dates, completion times, prices and exchange rates from outside sources: IGDB, IsThereAnyDeal, the stores' own catalogues, the European Central Bank's published exchange rates, and community title lists such as GameTDB. Those lookups are made from GameDock's servers by game title or store id, and a price lookup also names your store's country. They never carry your name, email address or account, or anything about what you paid, although a price lookup does ask about the games in your library and wishlist.

When you scan or type a disc's barcode that GameDock has not seen before, it asks ScanDex, a shared database of game barcodes, which game it is. If ScanDex does not know and you confirm the game yourself, the barcode and that game are suggested to ScanDex for its database, so that later scans can find it. Only the barcode and the game are sent, never anything about you.

Cover art and achievement icons are loaded by your browser straight from the image servers of the stores and artwork services they come from (Steam, PlayStation, Xbox, Epic Games, RetroAchievements, IGDB and SteamGridDB). Like any website's images, those servers see your IP address and browser, and that the request came from GameDock, but not which page you were on or anything about your account.

If you add your own SteamGridDB API key, GameDock searches SteamGridDB with it when you look for artwork for one of your games, by game title or Steam id, with your key, and only when you ask. SteamGridDB can therefore tell those searches came from your SteamGridDB account. The cover you pick is kept for your library alone and is never shown to anyone else.

Email (sign-in codes, digests, billing notices, moderation notices and contact-form messages) is sent through Amazon SES. The sign-in page, the contact form and a report sent without signing in use Cloudflare Turnstile to tell a person from a bot, which means Cloudflare sees your IP address and some browser characteristics at that moment; it does not see your email address, your message or anything in your library.

If you subscribe, the subscription is sold through Link, Stripe's checkout service, and Stripe handles the payment. Checkout and the billing portal are Stripe's own pages, so your card details go to Stripe and never pass through GameDock; Stripe receives your email address, your account's internal GameDock number (so a payment can be matched to the right account) and, where tax requires it, your billing address, and it applies its own privacy policy to them. What comes back is the plan, the status and the renewal date. Stripe is told nothing about your library, your games or what you have spent on them.

Error reports and analytics#

Two services help us find what is broken and what is hard to use. Both store their data in the European Union. PostHog stores nothing on your device. Sentry keeps one entry in your browser's session storage, holding only an id for the current visit, which goes when you close the tab.

  • Sentry receives a report when something goes wrong, and timings for a sample of pages. If the error happens in your browser, the report can include a short recording of the page just before it, with all text and images hidden.
  • PostHog records which pages are visited, what is clicked (including the words on the button or link you clicked), how far pages are scrolled and how quickly they load. When you are signed in, it also records your sessions: a recording shows each page as you saw it, including your games, prices and other players' names, with anything you type hidden and your email address left out.

When you are signed out, PostHog counts your visit with a daily identifier worked out from your IP address and browser, which is never linked to an account. When you are signed in, both services know you only by your account's internal number. Neither receives your email address or anything you type, and PostHog uses your IP address only to estimate your country.

Requests to GameDock are logged for security and debugging: IP address, path, timestamp, and the filtering decisions made by the web firewall in front of the app. The load balancer's and firewall's logs are kept for 90 days and the app's own logs for 30 days, and none of them is joined to your library data.

Cookies#

GameDock sets four cookies of its own, and none of them is for advertising or follows you to other sites: one that keeps you signed in, for 30 days at most and gone when you sign out; one that holds no identity and only tells GameDock's public pages that you are signed in, so they can show the right buttons and so PostHog knows how to count the visit; one that remembers, for a little over a year or until you sign out, that this browser has signed in to your account before, so the limits that stop strangers guessing at sign-in codes do not also keep you out, and which signs nobody in on its own; and one that remembers for a year whether you like the guide wide or narrow. A few choices about how pages look, such as your library's layout, are kept in your browser's own storage and never sent anywhere.

Statistics about players, never about you#

GameDock may combine information from across all accounts into anonymous statistics (how many players own a game, how long a game tends to take on a Linux handheld) and may share or license those statistics to others, such as game studios, publishers or researchers. That is one of the ways a free plan can stay free.

What is shared is only ever a total, an average or a share across many players, never a record about one of them. GameDock never shares, sells or licenses anything that identifies you or could be traced back to you: not your email, your username, your store accounts or IDs, your devices, your library, your playtime, your achievements, or what you bought and paid. No figure is shared unless it covers at least 50 accounts, so no one can be singled out from it. Nothing GameDock Companion reads in your browser (what you paid, your Epic Games orders, achievements on a private profile) is ever used for them.

Every account is included when it is created, and you can turn this off at any time in Account › Privacy; it takes one switch. Statistics already made are not about you, so they are not withdrawn if you later turn it off or delete your account, but either keeps you out of any made afterwards.

Why GameDock uses your data#

  • To run your account and the features you use, such as syncing your library, sending sign-in codes and billing a subscription, because that is the service you signed up for.
  • To keep the billing records tax law requires, because the law requires them.
  • To keep GameDock secure and working, understand how it is used and produce anonymous statistics, because GameDock has a legitimate interest in doing so, weighed against yours.

You can object to any use in the last group, or ask about any of this, at support@gamedock.co. You can also complain to the data protection authority where you live.

How long it is kept#

Library data is kept while your account exists, because it is your library. Platform tokens are kept until they expire or you disconnect that platform, which you can do at any time from Settings › Sync: it revokes the credential immediately, and can take everything that platform added with it if you ask it to. A paired device is the same story from Settings › Devices, which invalidates its token immediately. If you have subscribed, the subscription record is kept while the account exists; Stripe keeps its own payment records for as long as its obligations require, which is not something GameDock controls or can delete on your behalf.

Sentry keeps error reports for 30 days. PostHog keeps session recordings for 30 days and other analytics for a year.

When you delete the account, all of that goes at once (see below). The single exception is a billing record, and only if you have ever actually subscribed: the Stripe customer and subscription identifiers, your email address and the dates are kept for seven years, because tax law requires records that explain a transaction to outlive the transaction. It holds nothing about your library, and an account that never subscribed leaves nothing at all.

Getting it back, or getting rid of it#

Both are self-service. Account › Your data exports the library, playtime, play history, ratings and notes, reviews, lists, profile, follows, achievements, purchases, value history, physical copies, wishlist and collections as JSON or CSV, on either plan (on the free plan, purchases and value history cover the last 12 months, the same as the app shows), and a personal API key reads your library, achievements, playtime and purchases live (on Plus, with GameDock's library value, spending summary and merged achievement progress besides).

Account › Delete account closes it. Nobody is asked, nothing is queued for review, and it happens as soon as you confirm: the library, playtime, achievements, purchase history, wishlists, price alerts, physical copies, save archives, paired devices, platform tokens, preferences, API key and sign-in sessions are deleted, along with the email address and username themselves. A live subscription is cancelled in the same action. There is no recovery window, which is the honest version of the promise: a month spent holding everything back in case you change your mind would not be deletion. The one delay is in file storage: a deleted save archive is kept as a hidden earlier version for up to seven days, and a deleted cover image for up to thirty, so that a mistaken overwrite can be undone, and is then removed for good.

Two things are deliberately not deleted, and neither is about you. The shared games catalogue (titles, cover art, release dates, achievement and trophy lists, series and store metadata) describes games rather than people, so a game that first reached GameDock because you owned it stays for everyone else, carrying nothing that says it came from your account. And the billing record described above, if you ever subscribed.

Because it cannot be undone, deleting asks for a code sent to your email address as well as your password-free session: a browser session can be stolen, and this is the one action that could not be put right afterwards. Export first if you want to keep anything. Disconnecting one platform rather than closing the account is self-service too, from Settings › Sync, either keeping what it has already added or erasing that as well. Writing to support@gamedock.co, or through the contact form, still gets you a correction, or a copy in a form the export does not cover. Depending on where you live you may have a statutory right to some of these; GameDock does not ask which, and honours the request either way.

Minimum age#

GameDock is not meant for anyone under 16, and does not knowingly hold data about anyone that young. If an account turns out to belong to someone under 16, it is deleted with everything in it. A parent or guardian who thinks this has happened can write to support@gamedock.co. Every part of an account starts private, and nothing becomes visible to anyone else until its owner shares it.

Changes#

If this policy changes in a way that affects what is collected or where it is stored, the change is announced in the app before it takes effect, not quietly backdated here.