privacy
this privacy policy applies to the ForceBuy download that runs on your machine. the web version at forcebuy.net has its own: forcebuy.net/privacy.
what data is collected?
none. ForceBuy has no account, no sync, no analytics, no crash reporting and no advertising. nothing about you, your machine or your inventory is sent anywhere by the app itself.
which connections does the app make?
only the lookups the app needs to do its job, and only to the sources you allow. steam is queried for the inventories and, once you connect the account, for the inventory and market history that goes with them. prices come from the daily lists of CSFloat, Skinport and Buff163 and from the steam community market. if you add a CSFloat API key or a Buff163 login, your own trades there are read and matched to your items, and your current CSFloat listings are shown. the CS2 catalogue is downloaded from the public ByMykel/CSGO-API dataset, and exchange rates come from the european central bank. every outbound request is a GET, so nothing you own, add or change is uploaded.
third parties
those services are operated by others and have their own terms and
privacy policies. your ip address reaches them, as with any web
request. steam sees the steam id, vanity name or profile url that you
added. CSFloat and Buff163 see your key or login only if you entered
one, and only on requests to their own site (csfloat.com,
buff.163.com); without it they, Skinport and the
catalogue source see only the technical requests they need to answer.
the ecb sees a plain request for the daily reference rates. YouPin898
is not connected and makes no network calls.
your steam session
connecting an account is optional and pastes one cookie
(steamLoginSecure) from a browser you are already signed
in to. it is validated against steam once, checked against the account
you pasted it into, and only sent to steamcommunity.com
over https, never carried across a redirect. it is stored in a
separate secrets.json file so a copy of the data folder or
a cloud sync does not carry it along by accident, and it can be revoked
from the same panel at any time. there is no password field and there
never will be.
what stays on your machine?
the folder you pick during setup. it holds the database with
your items, prices, holdings, history and dashboards, your settings,
the steam session cookie and marketplace logins in their own file,
cached images and catalogue,
and the sync logs. defaults are %APPDATA%\ForceBuy on
windows, ~/Library/Application Support/ForceBuy on macos
and ~/.local/share/forcebuy on linux. everything is local
and can be deleted by removing that folder.
who can reach the local API
the API binds to 127.0.0.1, so only programs on your own
machine can reach it. two checks in front of every request make sure a
web page you have open cannot be turned into a way in: cross-origin
requests are answered only for pages served from this machine, and
requests whose Host header names something other than localhost are
refused, which is what stops DNS rebinding. binding to anything else
via FORCEBUY_HOST is only for people who know why they
are doing it.
changes
if a future version processes data differently, this page will be updated before it does.
contact
questions about privacy? [email protected]
last updated: september 2026
datenschutz
diese datenschutzerklärung gilt für den ForceBuy-download, der auf deinem gerät läuft. die web-version unter forcebuy.net hat ihre eigene: forcebuy.net/privacy.
welche daten werden erfasst?
keine. ForceBuy hat kein konto, keine synchronisierung, keine analyse-werkzeuge, keine absturzberichte und keine werbung. die app selbst sendet nichts über dich, dein gerät oder dein inventar irgendwohin.
welche verbindungen baut die app auf?
nur die abfragen, die für die arbeit der app nötig sind, und nur zu den quellen, die du freigibst. steam wird für die inventare abgefragt und, sobald du das konto verbunden hast, auch für die dazugehörige inventar- und markt-historie. preise kommen aus den täglichen listen von CSFloat, Skinport und Buff163 und vom steam community market. wenn du einen CSFloat-API-key oder einen Buff163-login einträgst, werden deine eigenen trades dort gelesen und deinen items zugeordnet, und deine aktuellen CSFloat-angebote werden angezeigt. der CS2-katalog wird aus dem öffentlichen datensatz ByMykel/CSGO-API geladen, wechselkurse kommen von der europäischen zentralbank. jede ausgehende anfrage ist ein GET, es wird also nichts hochgeladen, was du besitzt, hinzufügst oder änderst.
dritte
diese dienste werden von anderen betrieben und haben eigene
nutzungsbedingungen und datenschutzerklärungen. deine ip-adresse
erreicht sie, wie bei jeder web-anfrage. steam sieht die steam-id, den
vanity-namen oder die profil-url, die du eingetragen hast. CSFloat und
Buff163 sehen deinen key oder login nur, wenn du einen eingetragen
hast, und nur bei anfragen an ihre eigene seite
(csfloat.com, buff.163.com); ohne ihn sehen
sie, Skinport und die katalogquelle nur die technischen anfragen, die
sie beantworten müssen. die ezb sieht eine einfache abfrage der
täglichen referenzkurse. YouPin898 ist nicht angebunden und macht keine
netzwerkaufrufe.
deine steam-sitzung
das verbinden eines kontos ist optional und geschieht über einen cookie
(steamLoginSecure) aus einem browser, in dem du bereits
angemeldet bist. der cookie wird einmal gegen steam geprüft, gegen das
konto abgeglichen, in das du ihn eingesetzt hast, und ausschließlich
über https an steamcommunity.com gesendet, nie über eine
weiterleitung mitgetragen. er liegt in einer eigenen
secrets.json, damit eine kopie des datenordners oder eine
cloud-synchronisierung ihn nicht versehentlich mitnimmt, und lässt
sich jederzeit aus derselben ansicht widerrufen. es gibt kein
passwortfeld, und wird es nie geben.
was bleibt auf dem gerät?
der ordner, den du beim setup wählst. dort liegen die datenbank
mit deinen items, preisen, beständen, verlauf und dashboards, deine
einstellungen, der steam-cookie und die marktplatz-logins in einer
eigenen datei, gecachte bilder
und der katalog sowie die sync-protokolle. voreinstellungen sind
%APPDATA%\ForceBuy unter windows,
~/Library/Application Support/ForceBuy unter macos und
~/.local/share/forcebuy unter linux. alles bleibt lokal
und lässt sich durch löschen des ordners entfernen.
wer erreicht die lokale API?
die API bindet sich an 127.0.0.1, es können also nur
programme von deinem eigenen gerät auf sie zugreifen. zwei prüfungen
vor jeder anfrage stellen sicher, dass keine geöffnete webseite als
einstiegspunkt missbraucht werden kann: cross-origin-anfragen werden
nur für seiten beantwortet, die vom eigenen gerät ausgeliefert werden,
und anfragen mit einem Host-header, der nicht auf localhost zeigt,
werden abgewiesen, was DNS-rebinding stoppt. das binden an etwas
anderes über FORCEBUY_HOST ist nur etwas für leute, die
wissen, warum sie das tun.
änderungen
sollte eine künftige version daten anders verarbeiten, wird diese seite vorher aktualisiert.
kontakt
fragen zum datenschutz? [email protected]
stand: september 2026