What this site stores
Short version: the application holds your secrets on your own machine and sends them nowhere. This website holds nothing about you unless you file a report, and what a report holds is listed below with how long it lives.
The application is the part that matters, and it is the part that stores nothing
Open Desktop Authenticator keeps your Steam Guard secrets in an encrypted vault on your computer. There is no account, no sync, no server of ours for them to reach, and no telemetry — the security page explains the design. Nothing on this page describes your secrets, because we never have them.
If you file a report
The support form is the only place this site collects anything. It stores:
- What you wrote
- The kind of report, the one-line summary and the detail. Submissions that look like they contain a Steam secret are refused and never written — that check reads text, so it cannot see inside an image.
- A reply address, only if you give one
- Optional, and never shown on the report page that anyone holding the link can read. Leave it blank and the report still works; you just cannot be asked a follow-up question.
- Screenshots or clips, only if you attach them
- Stored under a name we generate, readable only through the report they belong to, and served as the file type their own bytes say they are. Check a screenshot before you choose it — a code or an account name in the corner is ours to hold once you send it.
- Ordinary server logs
- The web server records requests — address, time, page, user agent — as any web server does. Kept 14 days, then rotated away.
How long each thing lives
| What | Kept for |
|---|---|
| An upload you never attached to a report | 2 hours |
| An open report, and anything attached to it | Until it is closed |
| A resolved or declined report | 90 days after it was closed, then deleted with its attachments |
| Web server request logs | 14 days |
| Backups of the report database | Same 90-day cycle; a deleted report leaves the backups as they age out |
Deletion runs on a clock inside the service, hourly, whether or not anybody visits. It used to run only when somebody uploaded a file, which meant a quiet week was a week when nothing expired.
Having something removed sooner
Reply on your own report and ask — the reference is the only thing needed, and the support page explains how to get back to it. We will delete the report, its replies and its attachments, and say when it is done. There is no account to close because there was never one to create.
If you attached something by mistake and have not submitted yet, Remove on the file deletes our copy immediately rather than just hiding the thumbnail.
Who else is involved
- Cloudflare
- Sits in front of this site and terminates TLS, so it sees requests to it. We run no analytics product — not Cloudflare's, not anybody's — and there is no tracking script on any page here.
- GitHub
- Hosts the source and the eventual releases. If the application's update check is on, it asks GitHub's public releases page whether a newer version exists; GitHub sees an address and that the application is running, the same as any visitor to that page. Nothing about you or your accounts is sent.
- Nobody else
- No advertising network, no analytics vendor, no third-party fonts or scripts, and nothing sold or shared. Donations are cryptocurrency only partly for this reason — taking cards would mean a payment processor holding donor names against a project whose whole argument is that it holds nothing.
Reaching us about this
Use the report form. For a security issue, the routes are on the security page and in security.txt.
Published by MASTERPANEL LLC. Last reviewed 2026-08-12.