Privacy policy
Last updated August 11, 2026
HumbleShare is a private, invite-only site for sharing spare Steam keys and Humble gift links with a small group of friends. This policy explains what data an instance stores and why.
Each operator runs their own copy of HumbleShare. The operator of the instance you use is responsible for how that copy is hosted and who can access it.
What we collect
Depending on how you use the site, an instance may store:
- Account data: email address, password hash (not the plain password), display name, optional bio, Steam gamertag, Discord tag, and avatar image URL.
- Sign-in data: session tokens, optional authenticator (2FA) secrets, and linked OAuth identities (Google, Discord, or Steam) when you connect them.
- Access requests: email and optional note when you request an invite.
- Claim history: which inventory item you claimed and when, so keys are not handed out twice.
- Inventory data (admins): game titles, Steam store metadata, key or gift-link values, import source, and admin notes. Keys and gift links are only shown to admins and to the person who successfully claims them.
How we use data
- To create and secure your account, and to keep you signed in.
- To approve access requests and send invite email.
- To let you claim a key or gift link and record that claim.
- To show profile details you choose to set (name, bio, tags, avatar).
- To let admins manage inventory, users, and access.
We do not sell your personal data. We do not use it for advertising.
Third-party services
An instance may talk to:
- Steam: store search and app details for game metadata; Steam OpenID if you link Steam for login.
- Google / Discord: OAuth sign-in if you choose those providers.
- Email provider (for example Mailgun): invite and account-related mail.
- Object storage (for example Cloudflare R2): optional avatar uploads.
- Cloudflare Turnstile (if enabled): bot checks on public forms.
- Humble Bundle: when an admin imports orders or gift links, the admin’s Humble session cookie is sent only for that request. It is not stored by HumbleShare.
Those services have their own privacy policies. Steam store pages and gift links you open leave HumbleShare and follow Steam or Humble’s rules.
Cookies and sessions
HumbleShare sets an HTTP-only session cookie after you sign in so the site can recognize you. Clearing cookies or using Logout ends that session on this browser.
Retention
Account and claim data stay until an admin removes them or the operator deletes the instance database. Access requests may be kept for moderation history. Session records expire after the configured session lifetime.
Your choices
- Update profile fields and password in Settings.
- Enable or disable 2FA, and link or unlink OAuth providers where the UI allows.
- Ask an admin to delete your account if you no longer want access.
Security
Passwords are stored as salted hashes. Sessions use server-side tokens. Still, no system is perfect. Protect your password, use 2FA when you can, and only claim keys on devices you trust.
Children
HumbleShare is not directed at children under 13. Access is invite-only for people the operator chooses to include.
Changes
Operators may update this policy when the product or hosting setup changes. The “Last updated” date at the top reflects the latest draft for this codebase.
Contact
Questions about privacy on a specific instance should go to that instance’s operator or admins. If you reached this page from a hosted copy, use the contact method they provide to members.