Privacy Policy
EFFECTIVE 2026-07-09 · VERSION 1.0
This is the Privacy Policy for the noban.gg CS2 arbitrage desktop application ("the Software") and the noban.gg website, provided by Practical Systems ("we", "us"), a US-based business. Privacy contact: support@noban.gg.
1. Local-first by design
The Software is local-first. It runs on your machine, stores its data in a local SQLite
database on your device, and forks its backend on loopback (127.0.0.1). Your API keys,
Steam secrets, dashboard token, trade history, watchlists, license, and analytics stay on
your device. We do not collect or have access to them in the course of normal operation.
Secrets are read from your local, git-ignored .env; the desktop app stores the dashboard
token in your OS keychain, not in plaintext.
2. What we do NOT collect by default
By default the Software sends no telemetry, analytics, or usage data to us or any third party. There is no account login required to use simulation. The Software does not transmit your secrets, keys, or trade data off your device as part of its core function.
The noban.gg website is a static site: it sets no tracking cookies and runs no analytics or advertising scripts. Our hosting provider (Vercel) processes standard technical server logs (such as IP address and user agent) to serve and protect the site, under its own privacy policy.
3. What we DO process when you buy a license
When you purchase, we receive from Stripe and keep a minimal purchase record: the email address you used at checkout, the product purchased, payment identifiers (never your card number), and the license we issue you. We use this record to deliver your license, resend it if you lose it, operate the 14-day refund policy, maintain the signed license-revocation list, and meet our tax and accounting obligations. It is stored in an offline fulfillment log under our control — not in any cloud CRM — and is retained while your license is active and for as long as tax law requires. We do not use your purchase email for marketing without your consent, and we do not sell or share personal information (as "sell"/"share" are defined in the CCPA/CPRA).
4. Opt-in error monitoring (telemetry), scrubbed
Error monitoring (Sentry) is strictly opt-in and disabled by default
(SENTRY_ENABLED=false). If — and only if — you enable it and provide a DSN, diagnostic error
events may be sent to your configured Sentry project. Before any event is sent, a beforeSend
scrubber removes personally identifying and sensitive data, including IP addresses, email
addresses, Steam IDs, API keys/tokens, webhook/bot-token URLs, and dollar amounts. You control
this entirely; leaving it off means no such data leaves your machine.
5. Opt-in notifications
Notification channels (Discord, Telegram, email, desktop, ntfy) are opt-in and off by default. If you enable a channel, the Software sends the notifications you configure to the third-party service you chose (e.g. Discord, Telegram, your email provider, ntfy), using the credentials you supply. That data is then handled under that third party's privacy policy, not ours. We do not receive a copy.
6. Third-party marketplaces and APIs
When you connect a marketplace or price API (CSFloat, Steam, Skinport, DMarket, Buff163, Bitskins, Waxpeer, CS.MONEY, Pricempire), the Software communicates directly from your machine with that service using your credentials. Your interactions with those services are governed by their privacy policies and terms, and you are responsible for reviewing them.
7. Payments and licensing
Purchases are processed by Stripe, our payment processor, under its own privacy policy; we
never see or store your full payment details. A license issued to you is verified
offline on your device against a baked-in public key; the verify path makes no network
call. The optional LICENSE_REVALIDATE_URL re-check, if you configure one, is a soft,
non-blocking call you control. What we retain from a purchase is described in Section 3.
8. Data retention and deletion
Your local data persists on your device until you delete it. To remove it, delete the local
database (default data/bot.sqlite or the desktop app's user-data directory) and your
.env. Uninstalling the desktop app and clearing its user-data directory removes local app
data. The Ledger and any tax/cost-basis worksheet are likewise stored locally and removed the
same way.
Our purchase record (Section 3) is kept while your license is active and then as long as tax and accounting law requires. You may request deletion earlier by email; note that deleting the record revokes our ability to resend or support your license, and some billing records are retained by Stripe under its own policy.
9. Your rights and requests
Depending on your jurisdiction (including under GDPR/UK GDPR and CCPA/CPRA), you may have rights to access, correct, delete, or port personal data, and to object to or restrict certain processing. Because the Software is local-first, most such data is already on your own device and under your control. For anything we hold (Section 3), email support@noban.gg from the email address used at checkout — that address is how we verify the request is yours — and we will respond within the time required by your jurisdiction (at most 45 days). We will never discriminate against you for exercising a privacy right.
10. Children
The Software and website are not directed to children and may not be used by anyone under 18.
11. Changes
We may update this policy. Material changes will be posted at noban.gg/legal/ with an updated effective date, and (for paying customers) sent to the email address from your purchase when reasonably practicable.
Contact: Practical Systems · support@noban.gg