Privacy Policy
Last updated: May 24, 2026
What We Collect
Scanline collects the minimum data needed to provide the service:
- Account information — your email address and hashed password.
- Game store credentials — OAuth tokens and session tokens for services you connect (Steam, GOG, Epic, PlayStation Network, Xbox, itch.io). These are used solely to import your game library.
- Library data — your game ownership, play history, and subscription information as imported from connected stores.
- Preferences — platform selections, theme, and other settings.
How We Use Your Data
Your data is used exclusively to power Scanline's features:
- Importing and displaying your game library across stores.
- Showing which games are playable with your subscriptions.
- Authenticating you and maintaining your session.
- Recording anonymized usage events (searches, page views, feature usage) to improve the product and generate aggregate industry insights. These events contain no personally identifiable information — only internal user IDs, never names or emails.
We do not sell, share, or rent your personal data to third parties. We do not serve ads. We may share anonymized, aggregate usage data (such as trending games or platform popularity) as industry insights — no individual user data is ever included.
Third-Party Store Tokens
When you connect a game store, Scanline stores authentication tokens (OAuth refresh tokens or session tokens) to access your library data. Specifically:
- Steam — your Steam ID (public).
- GOG, Epic — OAuth refresh tokens, scoped to library access.
- PlayStation Network — an NPSSO session token. Sony does not offer a public API; this token is used only to read your game list and play history.
- Xbox — OAuth refresh tokens obtained via Microsoft's auth flow.
- itch.io — your API key, scoped to library access.
You can disconnect any store at any time from your settings page, which deletes the stored token.
Browser Extension
The Scanline Helper browser extension streamlines connecting your game store accounts. When you complete a store login, the extension detects the authentication token on the redirect page and forwards it to your open Scanline tab.
- The extension only runs on specific game store authentication pages (Epic Games, GOG, and PlayStation Network login redirects). It does not monitor or access any other browsing activity.
- Tokens are forwarded directly to open Scanline tabs in your browser. No data is sent to any external server by the extension itself.
- The extension does not store any data — tokens pass through immediately and are not persisted in extension storage.
- The extension does not collect browsing history, analytics, or personal information.
The extension is optional. All store connections can also be completed without it.
Data Storage & Security
Your data is stored in a PostgreSQL database. Passwords are hashed using bcrypt. Store tokens are stored as-is in the database and are only accessible to the application server. All connections to Scanline are encrypted via HTTPS.
Your Rights
You can:
- Delete your account — available in Account Settings. This permanently removes all your data.
- Disconnect stores — remove any connected store and its associated token from your settings.
- Contact us — email hello@scanline.gg with any privacy questions or data requests.
Affiliate Links
Scanline participates in affiliate programs, including the Impact.com partner network. When you click a purchase link on a game page, it may be an affiliate link — meaning Scanline earns a commission if you make a purchase. This comes at no additional cost to you.
- Affiliate links are routed through third-party tracking services (such as Impact.com) that may set cookies to attribute purchases.
- Scanline does not receive any personal data about your purchases — only that a referred transaction occurred.
- Affiliate relationships do not influence which games appear in your library, search results, or recommendations.
Cookies & Analytics
Scanline uses the following types of cookies:
- Essential cookies — a session cookie for authentication. This is required for the service to function and cannot be disabled.
- Analytics cookies — we use Google Analytics (GA4) to understand how the site is used, such as which pages are visited and general usage patterns. Google Analytics may set cookies to distinguish users and track sessions. No personally identifiable information is sent to Google. You can learn more about how Google uses data at Google's partner sites policy.
- Third-party cookies — affiliate links are routed through tracking services (such as Impact.com) that may set cookies to attribute purchases.
When you first visit Scanline, a cookie banner gives you the choice to accept all cookies or use essential cookies only. If you choose essential only, analytics cookies are not loaded. Your preference is stored in your browser and can be reset by clearing your local storage.
Changes
We may update this policy as the service evolves. Material changes will be communicated via the app.
Contact
Scanline is operated by BitAndBrush, LLC. For privacy inquiries, contact hello@scanline.gg.