Legal

Privacy Policy

How Dispattern and DisExtension collect, handle, store, and share user data.

Last updated: August 13, 2026

This Privacy Policy applies to Dispattern.com, related first-party services (disfile.dispattern.com, inspect2.dispattern.com, dislounge.com), and the browser extension DisExtension (Chrome Web Store item ID pchanhmaapdlmdlgoiplnegjlffeomml), operated by Dispattern / Disfinity ("we", "us").

If your product handles personal or sensitive user data, Chrome Web Store policy requires a privacy policy that describes collection, handling, storage, and sharing. This page is that disclosure. The corresponding Terms of Service are published separately.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Collection

DisExtension and connected Dispattern services collect only the data needed to provide the extension's disclosed purpose: CS2 pattern inspection, Steam trade context, reverse-risk warnings, and optional shared-database accuracy features.

Depending on which features you use, we may collect:

  • Steam identifiers and public profile context: SteamID64, public profile URL, display name, and public Steam level / mini-profile data already visible on Steam Community.
  • Inventory and item metadata: item names, asset IDs, inspect links, pattern seeds, float values, stickers, charms, collections, and related CS2 item fields required to render pattern previews and pricing context.
  • Trade context: trade offer IDs, partner IDs, trade tokens, trade URLs, and timestamps when you open or detect a Steam trade offer.
  • Reverse-trade events: when you visit Steam trade-history pages, the extension may collect counterparty profile URLs, item lists, event timestamps, and reverse signatures so we can show reverse-risk warnings.
  • Steam session cookie (local use only): the extension may read the Steam Community sessionid cookie on your device to complete actions you initiated on Steam (for example accepting a trade offer). That cookie is not uploaded to Dispattern or Dislounge servers.
  • Preferences you set: feature toggles, currency / price-source choices, custom API URL or API key if you configure one, and similar settings.
  • Optional diagnostic logs: when Diagnostic logging is enabled, the extension stores sanitized page paths, extension events, browser basics (user agent, language, timezone, platform), and performance counters. Cookies, credentials, chat text, and full page content are excluded.
  • Optional contributions: if you leave Background discovery tasks, market inspect enrichment, friend-inventory contribution, CSFloat market contribution, or FloatDB contribution enabled, the extension may collect public inspect links and related public item / owner metadata from pages you already can access.
  • Automatic server logs: when the extension or website talks to our servers, those servers receive standard request metadata such as IP address, user agent, request time, and the endpoint called.

We do not collect government IDs, payment card numbers, email addresses, Steam passwords, or browsing history outside the sites the extension is allowed to run on (Steam Community, Steam Store add-funds pages, Dispattern family sites, and optional integrations on CSFloat, Twitch, and X when those features are enabled).

Handling

We handle collected data only to operate and improve DisExtension / Dispattern:

  • Show pattern images, float, stickers, charms, and gem / phase badges on inventory, market, and trade pages.
  • Verify trade-offer context and display reverse-risk banners or summaries.
  • Resolve a Steam vanity URL to a SteamID64 so profile features work.
  • Convert currencies via a public exchange-rate API when you choose a non-USD display currency.
  • Keep a shared public item / pattern database accurate when contribution features are enabled.
  • Debug crashes or support tickets when you export or send diagnostics.
  • Authenticate first-party API calls with a short-lived owner token minted from your SteamID64.

We do not use this data for personalized advertising, credit scoring, selling leads, or tracking you across unrelated websites. Data obtained by the extension is used only for the single purpose disclosed in the Chrome Web Store listing and in the extension UI.

All transmissions of user data use HTTPS. Steam cookies and passwords are never sent to our servers. Diagnostic exports redact cookie, token, bearer, password, and secret fields.

Storage

On your device. DisExtension stores data locally with the browser extension storage API (chrome.storage.local), including:

  • Feature settings and UI preferences
  • Cached inspect / inventory metadata used to speed up page overlays
  • Your resolved SteamID64 and a first-party API bearer token for reverse / discovery features
  • Local trade-history and reverse-event caches used by the popup
  • Diagnostic log entries, if you enable diagnostic logging (capped locally)

Local data stays on your device until you clear extension storage, disable a feature, or uninstall DisExtension.

On our servers. First-party APIs may store:

  • Inspect-link / pattern / float records needed to serve pattern previews and the public database
  • Reverse-trade ingest records (owner SteamID64, reverser SteamID64, items, event time) used for reverse-risk summaries
  • Discovery-task results (inspect previews from public inventories) when that optional feature is on
  • Standard server access logs (IP, user agent, timestamp) retained for security and abuse prevention

Server-side item and reverse-risk records are retained while they remain useful for the public database or reverse-risk feature. Access logs are retained only as long as needed for security and operations. You can delete local extension data by uninstalling the extension. To request deletion of server-side records associated with your SteamID64, email [email protected].

Sharing

We do not sell, rent, or trade user data. We do not share user data with advertising platforms, data brokers, or information resellers.

Data is shared only in these cases:

  • First-party services we operate: Dispattern, Disfile, Inspect2, and Dislounge receive the item, inspect, trade, and reverse-risk data described above so the extension can function.
  • Steam: the extension talks to steamcommunity.com / store.steampowered.com using your existing Steam session in the browser to read pages and perform actions you start (inventory load, trade accept, etc.).
  • reverse.watch: public SteamID64 lookups for additional reverse-status context shown on profile banners.
  • open.er-api.com: anonymous currency-rate requests (no Steam identifiers).
  • CSFloat: only when CSFloat market / FloatDB contribution is enabled, public inspect links and owner metadata visible on those pages may be sent to our first-party database.
  • Discord: only if you click "Send diagnostics". The sanitized diagnostic export is posted to a Discord webhook we operate (or a webhook URL you configure). This is an explicit user action.
  • Legal / safety: we may disclose data if required by law, or to investigate abuse, fraud, or security incidents.
  • Business transfer: if Dispattern is merged or sold, user data may move with the product after notice, and only for the same limited purposes.

Public reverse-risk totals derived from submitted trade-history events may be shown to other extension users who view the same Steam profile. We do not publish Steam session cookies, passwords, private inventories, or diagnostic exports.

Permissions

DisExtension requests these browser permissions because they are required for the features above:

  • storage — save settings and caches on your device
  • cookies — read the Steam Community sessionid cookie locally for user-initiated Steam actions
  • activeTab / scripting — inject the overlay on supported pages
  • alarms — schedule background discovery / trade-offer checks
  • declarativeNetRequestWithHostAccess — limited request adjustments on allowed hosts
  • Host access — Steam Community, Steam Store, Dispattern / Dislounge / reverse.watch, optional CSFloat / Twitch / X, currency API, and Discord webhooks

Your choices

  • Turn off Background discovery tasks, friend-inventory contribution, market inspect enrichment, CSFloat contribution, or diagnostic logging in Settings.
  • Clear local data by resetting settings or uninstalling the extension.
  • Email [email protected] to ask what we store for your SteamID64 or to request deletion.

Children

DisExtension and Dispattern are not directed at children under 13, and we do not knowingly collect personal information from children under 13.

Changes

We may update this Privacy Policy. The "Last updated" date at the top will change when we do. Continued use of the site or extension after an update means you accept the revised policy.

Contact

Questions about collection, handling, storage, or sharing of user data: