1. Data Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR), Art. 4 No. 7, is:
Yannik Klode
Dorfstrasse 25
24629 Kisdorf
Germany
E-Mail: info@counterguide.de
Website: https://counterguide.de
2. General Principles & No Tracking
We process personal data only to the extent necessary to provide a functional app and its content, in accordance with the GDPR and the German TDDDG.
- No advertising networks or marketing trackers (e.g. no AdMob).
- No third-party analytics (e.g. no Google Analytics).
- No location or payment data.
- All core guide features (maps, lineups, callouts, weapon/skin catalogues) are usable without an account.
- Optional features (Steam linking, verification, match analysis) are only processed on your explicit use of them.
3. Local Storage on Your Device
When you use the app without an account, data is stored exclusively on your device (SharedPreferences, local database, downloaded OTA data):
- App settings (language, colour scheme / dark mode, price threshold).
- Favourites marked locally (callouts/lineups).
- Locally cached guide data and downloaded media.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the provision of the app) in conjunction with Section 25(2) No. 2 TDDDG.
4. User Account & Cloud Synchronisation (Firebase)
If you optionally create an account in order to synchronise your favourites and settings across devices:
- Data processed: your e-mail address, a cryptographic password hash (never plain text), with Google Sign-In your Google account ID/email, a generated Firebase user ID (UID), a voluntarily chosen username and your synchronised preferences/favourites.
- Purpose: secure authentication, account management, password reset and cross-device data synchronisation.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Provider: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) / Google LLC (USA), via Firebase Authentication & Cloud Firestore. The primary data location is in the EU (Frankfurt). A data processing agreement (DPA) under Art. 28 GDPR is in place; Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF) and additionally relies on EU Standard Contractual Clauses.
5. Voluntary Steam Profile Linking & CS2 Statistics
You may optionally link your SteamID64 or your public Steam profile to view your CS2 inventory statistics and matching combo recommendations.
- Special feature: the app NEVER communicates directly with Steam/Valve. Your IP address is not transmitted to Valve. All requests are handled by our own EU-hosted server.
- Data processed: linked SteamID64, public profile name, previous Steam profile names (alias history), avatar image URL, aggregated inventory statistics, float/wear values and versioned snapshots (up to 12 versions).
- Automatic background refresh: stored records are refreshed server-side at regular intervals (at most every 7 days).
- Prerequisite: works exclusively for publicly visible Steam profiles. No Steam passwords or logins are required.
- Legal basis: Art. 6(1)(a) GDPR (your consent) and Art. 6(1)(b) GDPR. The link can be withdrawn and deleted at any time in the app settings.
6. External Data Source: Valve Corporation (steamcommunity.com)
Our EU server retrieves publicly available profile and item data via the interfaces of steamcommunity.com. Valve Corporation (USA) is an independent external data source. No connection data from your device flows directly to Valve.
7. Steam Account Verification & Match History
You may optionally verify that you control a Steam account (“Verify”) in order to receive your own CS2 match statistics.
- Data processed: the Steam support codes you enter voluntarily (account-equivalent so-called Auth/Confirmation codes) as well as a CS:GO match share code (CSGO-...) you provide.
- Encryption: your support codes are stored in the database symmetrically encrypted with a server-side key (AES, Fernet). They are never kept or passed on in plain text, including to our analysis worker.
- Purpose: proof that you control the Steam account yourself, and retrieval of the list of your own matches as the basis of the voluntary match analysis.
- Match history: to provide the analysis we retrieve your own match share codes via the official Steam interface using your support codes and store them as analysis jobs.
- Legal basis: Art. 6(1)(a) GDPR (your explicit consent) and Art. 6(1)(b) GDPR (provision of the analysis feature you requested). The verification can be revoked at any time; your codes and the verification status are then deleted.
8. CS2 Demos & Match Analysis
After successful verification we can, on your request, analyse your own CS2 matches:
- Procedure: an analysis worker operated locally by you downloads the game files (demos) belonging to your matches and calculates statistics from them. The demo files remain exclusively on your own device/worker and are not transmitted to our server.
- Data processed and stored (on our EU server): the SteamID64 of your account, the match share code, map name, match time and the statistics computed from your match (e.g. kills, deaths, K/D, headshot rate, spray analysis, opening duels, clutches, utility values).
- Overlay data: for detailed match overlays the positions of the players on the map are cached (overlay data of a match).
- Note on other players: a demo may also contain identifiers/names of other participating players. These are used exclusively to compute your match statistics and are not stored permanently or made accessible to third parties.
- Legal basis: Art. 6(1)(b) GDPR (performance of the analysis feature you requested) or, to the extent we process data you provided yourself, Art. 6(1)(a) GDPR.
- Storage period: match statistics remain stored until the analysis is deactivated or your account is deleted.
9. Content Delivery (Cloudflare R2 & CDN)
Static media (map overviews, lineup images, explainer videos, textures) is delivered via Cloudflare R2 and the Cloudflare CDN.
- Data processed: IP address, access time, requested file and HTTP header data for technical delivery.
- Purpose: fast, global and DDoS-protected delivery of media files.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in performant and secure delivery).
- Provider: Cloudflare, Inc. (USA). A data processing agreement (DPA) with EU Standard Contractual Clauses and certification under the EU-U.S. Data Privacy Framework (DPF) are in place.
10. Server Log Files of Our EU Server
When our API servers are called (e.g. Steam sync, account history, verification, match analysis) our server stores temporary log data (IP address, timestamp and target HTTP resource) for error analysis and to ensure IT security. Legal basis: Art. 6(1)(f) GDPR. Logs are deleted on a rolling basis after 14 to 30 days at the latest.
11. Outgoing E-Mail Delivery (SMTP Relay)
For sending e-mails from the domain counterguide.de (e.g. password reset via Firebase or support communication) we use an external SMTP delivery service as a processor.
- Provider: Brevo SAS, 106 Boulevard Haussmann, 75008 Paris, France.
- Data processed: sender/recipient address, subject, content and technical details of delivery.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable delivery) or, where a contractual relationship is involved, Art. 6(1)(b) GDPR.
- Brevo acts as a processor (Art. 28 GDPR) and offers EU Standard Contractual Clauses / DPF certification. Incoming mail continues to be handled by our own EU server.
12. Storage Period & Account Deletion
- Local device data: until you clear the app storage or uninstall the app.
- Firebase & Firestore data: until your user account is deleted.
- Steam data & snapshots: for the duration of the link; deleted immediately when the link is removed or the account is deleted.
- Verification data (support codes, match share codes): deleted when the verification is removed or the account is deleted.
- Match statistics & overlays: until the analysis is deactivated or the account is deleted.
- Account change log: completely removed when the account is deleted.
- Server log data: deleted on a rolling basis after 14-30 days.
13. Your Rights as a Data Subject
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), the right to object to legitimate-interest processing (Art. 21) as well as the right to withdraw any consent you have given at any time (Art. 7(3)).
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). To exercise your rights, simply send an informal message by e-mail to: info@counterguide.de
14. Technical & Organisational Security (TOMs)
We protect your data according to the current state of the art:
- Full TLS/HTTPS encryption for all data transfers.
- Sensitive Steam support codes are stored symmetrically encrypted server-side (Fernet/AES) and only decrypted when necessary.
- Secure password hashes via Firebase Auth (never plain text; we do not store passwords ourselves).
- Strict Firestore Security Rules for isolating each user's data area (users/{uid}).
- Token-based API authorisation via short-lived Firebase ID tokens (Bearer).
- Analysis worker endpoints are protected by a separate server-side secret (X-Worker-Key).
15. Updates & Changes to This Privacy Policy
We reserve the right to adjust this privacy policy if our features or the legal requirements change. The currently valid version can always be viewed at https://counterguide.de/privacy