Security & Trust
Last updated: October 2026
Your Steamworks key
What it allows: reading, once a day, the wishlist and sales reports of the game you declare, through Valve's official API (IPartnerFinancialsService).
What it does not allow: changing your store page, prices, discounts or builds; accessing personal data about players (Valve only provides aggregates); acting on your Steamworks account or payments.
Transparency: Valve attaches this key to a "Financial API Group" that covers all apps of your partner account. We only read the app you declare and ignore the rest.
Recommended setup (step-by-step guide during onboarding):
- Create a dedicated group for NextWishlist, so you can revoke it without affecting other integrations.
- Add our server IP addresses to the group's allowlist: the key then becomes useless from anywhere else.
- Revoke the key at any time in Steamworks. In NextWishlist, "Disconnect Steam" deletes the encrypted key immediately.
Your social accounts
Official OAuth, read-only connections. We never post, like, vote, comment or message on your behalf. You can revoke access from NextWishlist or from the platform itself.
How we protect data
| Measure | Details |
|---|---|
| Encryption | TLS everywhere; keys and tokens encrypted at rest (envelope encryption), never displayed or logged |
| Isolation | Each account is isolated at database level (row-level security), checked by automated tests |
| Data storage | European Union (database) |
| AI | Only numerical summaries are sent to models; no training on your data |
| Tracking links | No cookies; visitor IPs never stored in clear text (daily-rotated salted hash) |
| Deletion | "Delete my account" removes all your data within 30 days |
What we never collect
Passwords (Steam or social), personal data about players, private messages, other users' content, raw IP addresses of your link visitors.
Report a vulnerability
Please write to security@nextwishlist.com. We answer within 72 hours.