This Privacy Policy describes how Dispattern / Disfinity ("we", "us", "our") collect, use, process, store, and share user data for:
-
the browser extension DisExtension (Chrome Web Store item ID
pchanhmaapdlmdlgoiplnegjlffeomml, and the Firefox listing where published), and - related first-party services used by the extension: Dispattern.com, disfile.dispattern.com, inspect2.dispattern.com, and dislounge.com.
Chrome Web Store policy requires a privacy policy that explains collection, use / processing, storage, and sharing of user data. This page is that disclosure. Our Terms of Service are published separately.
If we use information received from Google APIs, that use will follow the Chrome Web Store User Data Policy, including Limited Use requirements.
1. Who this policy covers
This policy applies when you install or use DisExtension, or when the extension calls our first-party APIs while you use it.
DisExtension helps Steam users inspect Counter-Strike 2 items and trade activity on supported Steam pages using Dispattern-powered pattern visuals and trade context tools. It is designed for inspection and analysis workflows. It is not designed for account automation, credential harvesting, or automated trading.
2. Collection
DisExtension and connected Dispattern services collect only data needed for the disclosed purpose: CS2 pattern inspection, Steam trade context, reverse-risk warnings, optional database contribution features, and diagnostics you choose to enable.
2.1 Data we may collect
Depending on which features you use, we may collect:
| Category | Examples | Notes |
|---|---|---|
| Steam identifiers and public profile context | SteamID64, public profile URL, display name, public Steam level / mini-profile fields already visible on Steam Community | Used for profile and reverse-risk features |
| Inventory and item metadata | Item names, asset IDs, inspect links, pattern seeds, float values, stickers, charms, collections, and related CS2 fields | Used for pattern previews, overlays, and pricing / sales context |
| Trade context | Trade offer IDs, partner IDs, trade tokens, trade URLs, timestamps when you open or detect a Steam trade offer | Used for trade helpers |
| Reverse-trade events | Counterparty profile URLs, item lists, event timestamps, reverse signatures from Steam trade-history pages | Used for reverse-risk warnings |
| Steam session cookie (device only) | Steam Community sessionid cookie read on your device |
Used only for Steam actions you start in the browser. Not uploaded to Dispattern or Dislounge servers |
| Preferences you set | Feature toggles, currency / price-source choices, custom API URL or API key if you configure one | Stored locally |
| Optional diagnostic logs | Sanitized page paths, extension events, browser basics (user agent, language, timezone, platform), performance counters | Only if diagnostic logging is enabled. Cookies, credentials, chat text, and full page HTML are excluded |
| Optional contributions | Public inspect links and related public item / owner metadata from pages you can already access | Only if contribution / discovery features are enabled |
| Automatic server logs | IP address, user agent, request time, endpoint called | Created when the extension or site talks to our servers |
2.2 Data we do not collect
We do not collect:
- Steam passwords or Steam Guard codes
- Payment card numbers or government IDs
- Email addresses through the extension itself
- Browsing history outside the sites the extension is allowed to run on
2.3 Sites where the extension may run
Supported or optional hosts include Steam Community, Steam Store pages needed for listed features, Dispattern / Dispeek / Dislounge / Disfinity pages, and optional integrations such as CSFloat, reverse.watch, a public currency API, Twitch, and X when those features are enabled.
2.4 Chrome Web Store data types
In the Chrome Web Store privacy disclosures, DisExtension currently declares handling of:
- Personally identifiable information (for example Steam identifiers and related profile context used by the features above)
- Website content (item, inventory, market, and trade page content needed for overlays and analysis)
3. Use and processing
We use and process collected data only to operate and improve DisExtension and related first-party features, including to:
- Show pattern images, float, stickers, charms, and gem / phase badges on inventory, market, and trade pages
- Open Dispattern item pages with the correct pattern value filled in
- Verify trade-offer context and show reverse-risk banners or summaries
- Resolve a Steam vanity URL to a SteamID64 so profile features work
- Convert currencies through a public exchange-rate API when you choose a non-USD display currency
- Keep a shared public item / pattern database accurate when contribution features are enabled
- Debug crashes or support tickets when you export or send diagnostics
- Authenticate first-party API calls with a short-lived owner token derived from your SteamID64
We do not use this data for:
- Personalized advertising
- Selling leads
- Credit scoring or lending decisions
- Tracking you across unrelated websites outside the extension's disclosed purpose
Data obtained by the extension is used only for the single purpose disclosed in the Chrome Web Store listing and in the extension interface.
All transmissions of user data use HTTPS. Steam cookies and passwords are never sent to our servers. Diagnostic exports redact cookie, token, bearer, password, and secret fields.
4. Storage and retention
4.1 On your device
DisExtension stores data locally with the browser extension storage API
(chrome.storage.local), including:
- Feature settings and interface preferences
- Cached inspect / inventory metadata used to speed up overlays
- Your resolved SteamID64 and a first-party API bearer token for reverse / discovery features
- Local trade-history and reverse-event caches used by the popup
- Diagnostic log entries, if you enable diagnostic logging (capped locally)
Local data stays on your device until you clear extension storage, disable a feature, or uninstall DisExtension.
4.2 On our servers
First-party APIs may store:
- Inspect-link / pattern / float records needed for pattern previews and the public database
- Reverse-trade ingest records (owner SteamID64, reverser SteamID64, items, event time) used for reverse-risk summaries
- Discovery-task results (inspect previews from public inventories) when that optional feature is on
- Standard server access logs (IP, user agent, timestamp) for security and abuse prevention
4.3 Retention
Server-side item and reverse-risk records are retained while they remain useful for the public database or reverse-risk feature. Access logs are retained only as long as needed for security and operations.
You can delete local extension data by clearing storage or uninstalling the extension. To request deletion of server-side records associated with your SteamID64, email [email protected].
5. Sharing
We do not sell, rent, or trade user data. We do not share user data with advertising platforms, data brokers, or information resellers.
Data is shared only in these cases:
| Recipient | What may be shared | Why |
|---|---|---|
| First-party services we operate (Dispattern, Disfile, Inspect2, Dislounge) | Item, inspect, trade, and reverse-risk data described above | Required for the extension to function |
| Steam (steamcommunity.com / store.steampowered.com) | Page reads and user-initiated actions using your existing browser Steam session | Inventory load, trade context, and actions you start |
| reverse.watch | Public SteamID64 lookups | Extra reverse-status context on profile banners |
| open.er-api.com | Anonymous currency-rate requests (no Steam identifiers) | Display currency conversion |
| CSFloat | Public inspect links and owner metadata visible on those pages | Only when CSFloat market / FloatDB contribution is enabled. Data is sent to our first-party database |
| Discord | Sanitized diagnostic export | Only if you click Send diagnostics (our webhook or a webhook URL you configure) |
| Legal / safety | Relevant records | If required by law, or to investigate abuse, fraud, or security incidents |
| Business transfer | User data needed to continue the product | If Dispattern is merged or sold, after notice, and only for the same limited purposes |
Public reverse-risk totals derived from submitted trade-history events may be shown to other extension users who view the same Steam profile. We do not publish Steam session cookies, passwords, private inventories, or diagnostic exports.
6. Permissions
DisExtension requests browser permissions required for the features above, including:
- storage: save settings and caches on your device
- cookies: read the Steam Community
sessionidcookie locally for user-initiated Steam actions - activeTab / scripting: inject the overlay on supported pages
- alarms: schedule background discovery / trade-offer checks
- declarativeNetRequestWithHostAccess: limited request adjustments on allowed hosts
- Host access: Steam Community, Steam Store, Dispattern / Dislounge / reverse.watch, optional CSFloat / Twitch / X, currency API, and Discord webhooks as needed for enabled features
7. Your choices and rights
You can:
- Turn off Background discovery tasks, friend-inventory contribution, market inspect enrichment, CSFloat contribution, or diagnostic logging in Settings
- Clear local data by resetting settings or uninstalling the extension
- Email [email protected] to ask what we store for your SteamID64 or to request deletion
If you are in a region with additional privacy rights (for example access, correction, deletion, or restriction), contact us at the email above and we will handle the request as required by applicable law.
8. Children
DisExtension and Dispattern are not directed at children under 13, and we do not knowingly collect personal information from children under 13.
9. Security
We use HTTPS for network transfers of user data. Sensitive fields are redacted from diagnostic exports. No method of transmission or storage is perfectly secure. We work to protect data with reasonable technical and organizational measures.
10. Changes
We may update this Privacy Policy. The Last updated date at the top will change when we do. Material changes may also be noted on https://dispattern.com/extension or in the extension update notes. Continued use of the site or extension after an update means you accept the revised policy.
11. Contact
Questions about collection, use / processing, storage, sharing, or deletion of user data: