What this site stores
Short version: the application keeps your secrets in encrypted files on your own machine. It has no ODA backend, ODA account, cloud sync, or telemetry. Steam operations you request contact Valve; direct GitHub builds can optionally check GitHub for a newer release; and the in-app browser contacts the sites you open and resources those sites load. Those sites can set cookies and collect their own data. This website separately uses web-server request logs normally removed within 14 days, Cloudflare in front of it, Google Analytics, Yandex Metrica, and Trustpilot on the pages that ask you for a review. A delayed or failed log rotation can delay deletion. All of that is listed below, along with what a report holds, how long it lives, the Yandex analytics preference, and the one thing the download page keeps in your own browser.
The application stores secrets locally; the publisher does not receive them#
Open Desktop Authenticator keeps your Steam Guard secrets in an encrypted vault on your computer. No ODA backend. No ODA account. No cloud sync. No telemetry. The app sends the data required for user-requested Steam operations to Valve, but it does not send vault contents to us. Exports you request are unencrypted maFiles; they need secure storage even though the vault remains encrypted. The security page explains the boundaries.
If you file a report#
The support form and replies to an existing report store the text you submit. Request logs and analytics can be collected without a submission. The support service stores:
- What you wrote
- The kind of report, the one-line summary, the detail and subsequent replies. A text check rejects recognised Steam-secret patterns before storing a report or reply. It cannot detect every secret or read images. Never include passwords, maFiles, recovery codes or authentication tokens.
- A reply address, only if you give one
- Optional, and never shown on the report page that anyone holding the link can read. Leave it blank and you can still read and answer follow-up questions on your report's private link. The service does not send automatic emails.
- Screenshots or clips, only if you attach them
- Uploaded before you submit the report, stored under a generated name, and accessible through the report once attached. Our operators also have access. File signatures are checked to recognise supported formats; this is not a malware scan or removal of embedded metadata. Crop or redact sensitive details before choosing a file. Anyone with your private report link can read its text and download its attachments.
- Ordinary server logs
- The web server records requests — address, time, page, user agent — as any web server does. The logs are rotated daily and normally removed within 14 days. A delayed or failed rotation can delay deletion.
How long each thing lives#
| What | Kept for |
|---|---|
| An upload you never attached to a report | Eligible for deletion after 2 hours; normally removed within a few hours |
| An open report, and anything attached to it | Until it is closed |
| A resolved or declined report | 90 days after it was closed, then deleted with its attachments |
| Web server request logs | Normally within 14 days; a delayed or failed rotation can delay deletion |
| Backups of the report database and attachments | Each archive becomes eligible for deletion at 90 days old, at the next daily backup cleanup. Copies may therefore remain for about 90 additional days after deletion from the live service. |
Live-service deletion runs hourly while the service is running, and at startup. Failed removals are retried until they succeed. Outages, failed cleanup or failed backup jobs can delay deletion. Open reports have no automatic expiry; ask for removal if you no longer need one. These periods describe our own storage, not retention by the external providers listed below.
Having something removed sooner#
Reply on your own report and ask. You need the private link you were given when you filed it — the short reference identifies a report but is not enough to open one, deliberately, because a reference short enough to read out is short enough to guess. The support page explains how to get back to a report. We will remove the report, its replies and its attachments from the live service. Existing backup copies age out on the schedule above. If you need a confirmation after the report is deleted, include a contact address; its page will no longer open. There is no account to close because there was never one to create.
If you attached something by mistake and have not submitted yet, Remove requests deletion. After the server confirms success, the live copy is gone. If removal fails, the page shows an error and the service retries during cleanup. Existing backup copies follow the schedule above.
Who else is involved#
- Cloudflare
- Sits in front of this site and terminates TLS, so it can process requests, including support submissions, your IP address and request URLs. Our local log-retention schedule does not set Cloudflare's retention. See Cloudflare's privacy policy.
- Google Analytics
- This site runs Google Analytics 4 to count visits and see which pages people arrive on. It sets cookies in your browser and sends Google your IP address, the page you are reading, and general device and referrer information. Page addresses can include query parameters; Google Analytics also supports interaction measurement controlled in its service settings. Do not put private information in website URLs. Our own code does not send support text or attachments as analytics events, and private report pages do not load our Google Analytics scripts. See Google's measurement documentation. ODA's own interface has no analytics; websites opened in its optional browser can use their own. This website's scripts have no direct access to ODA's local vault. Do not submit secrets or put them in page addresses. To block Google Analytics, use a content blocker configured to block it, or Google's opt-out add-on. The guides and support form work without Google Analytics.
- Yandex Metrica — public website pages only
-
We use Yandex Metrica to count visits to public website pages and help discover updated pages.
Yandex receives the public page address and basic request, browser and device information,
including your IP address, and may use analytics cookies. We strip query strings and fragments
from addresses we send; we do not forward document titles, original referring-page addresses,
form contents, filenames, uploads, Steam secrets or account identifiers.
Private ticket pages, admin and API routes are excluded. Our integration disables
session replay, click maps, link tracking and ecommerce. Other optional Yandex requests
are blocked by this website's security policy.
This is website analytics only; the desktop application's no-telemetry behavior is unchanged.
Global Privacy Control, Do Not Track, or the switch below disables Yandex collection.
The choice is stored only in this browser as
oda_metricaand can be changed here. This switch does not control the other services listed on this page.Yandex analytics respects your browser privacy settings.
- GitHub
- Hosts the source and releases. In a direct GitHub build, if the optional update check is on, it asks GitHub's public releases API whether a newer version exists. GitHub receives the request and its source IP, but no Steam account or vault data. Microsoft Store builds do not perform this check.
- Cloudflare Web Analytics
- Cloudflare sits in front of this site, and its Web Analytics is switched on at the edge — so a small measurement script is added to pages on their way to you, without being part of the files we build. It records page views and performance timings. Cloudflare describes Web Analytics as using neither cookies nor browser local storage to measure visits; this is separate from Cloudflare's other security services. See Cloudflare's Web Analytics privacy description.
- Trustpilot, on the pages that ask for a review
- Only the pages that ask you for a review load Trustpilot's script — this page does not, and neither does any page that is not asking. Where it loads, Trustpilot sees the request the same way any embedded widget's host does: your IP address, your browser, and which of our pages you were on. We do not send it Steam account, vault, or support-form data. Writing a review takes you to Trustpilot, where its own account, cookie and privacy rules apply. See Trustpilot's privacy policy.
- Support access cookie
- Opening a private report link sets a cookie for that report, expiring after 12 hours. It keeps the access key out of subsequent page URLs and is marked Secure, HttpOnly and SameSite=Lax. Keep the original private link so you can return after the cookie expires or you clear your browser data. The short report reference alone does not grant access.
- Download-page preference kept in your own browser
-
The download page remembers a flag in your browser's local storage:
oda.review-prompt.dismissed, set if you turn the review prompt down, follow the link to write a review, or carry on to a build from the prompt itself. It exists so the page can ask you about a review once and then stop asking. This site cannot tell whether you actually downloaded or installed anything, and does not try to. It never leaves your machine, nothing on the server reads it, and clearing your site data removes it. It does not expire on its own. - Donations and data sharing
- This site loads no advertising-network integration or third-party fonts. The services above receive data as described; calling that "nothing shared" would be inaccurate. Donations are cryptocurrency only. Transactions on the listed networks are public, and a wallet or exchange may collect additional information. Cryptocurrency is not a promise of anonymity.
Reaching us about this#
Use the report form. For a security issue, the routes are on the security page and in security.txt.