Privacy Policy
Last updated: June 27, 2026
QCoop is built on the principle of minimal data collection. This document explains exactly what we collect, why, and how you can remove it at any time.
Information We Collect
QCoop is built to work without ever creating an account — connecting Steam or Epic and matching games with friends never requires signing up. We collect only what each feature actually needs:
- Account Information (only if you register): Your email address, password, and an optional display name — collected only if you choose to create a QCoop account. Passwords are handled entirely by our authentication provider (Supabase); we never see or store them in plain text.
- Steam Account Data: Your Steam ID, public game library, and public friends list — obtained through Steam OpenID authentication. We never see or store your Steam password.
- Epic Games Account Data: Your Epic Account ID, display name, and OAuth access/refresh tokens — obtained through Epic's official OAuth 2.0 login.
- System Specs (optional): If you enter your computer's specs (OS, CPU/GPU tier, RAM, VRAM, storage), we use them to check whether a game will run well for you and the friends you're matching with.
- Xbox / Game Pass Status: A self-reported indicator of whether you hold an active Game Pass subscription, kept only in your browser. No Xbox account credentials are collected or stored.
- Browser Extension Data (only if installed): Our optional Chrome extension reads the one-time login code Epic's own page displays after you sign in, and relays it inside your browser to the QuickCoop tab you already have open — see "Browser Extension" below for details.
We do not collect payment information, real names (unless you choose to type one as your display name), health or financial data, message contents, or your browsing activity outside of QCoop.
How We Use Your Information
The data we collect is used exclusively for:
- Identifying which games you and your friends share across platforms.
- Displaying your connected account status within the QCoop interface.
- Generating multiplayer game recommendations based on your combined libraries.
- Checking whether everyone's hardware can run a given game, if you provided your specs.
- Keeping your Steam/Epic connection active across visits, if you created an account.
- Caching trending game data locally in your browser to reduce load times.
- Completing the Epic login handshake automatically instead of asking you to copy/paste a code, if you installed our browser extension.
We do not sell, rent, or share your data with third parties for advertising or marketing purposes.
Data Storage & Security
How much of your data reaches our servers depends entirely on whether you create a QCoop account:
- Without an account: Your Steam ID, Epic ID, specs, and imported games live only in your browser (localStorage/sessionStorage). An Epic connection is held only in temporary server memory, identified by a random session cookie — it is never written to our database, and is lost if our server restarts.
- With an account: We persist which store accounts you've connected (provider + your public account ID) and, for Epic, your OAuth tokens — encrypted at rest with AES-256-GCM before they ever reach the database. Public and authenticated database access to encrypted tokens is revoked at the database level; only our backend service can decrypt them. We also remember which games you own and the specs you provided, so you don't have to reconnect every visit.
- Passwords & credentials: We never store your Steam or Epic password. We only ever receive the identifiers and tokens those platforms issue after you log in directly with them.
- Friends lists: Your Steam/Epic friends list is fetched live from Steam/Epic each time you open matching — we do not store a copy of it.
- Encryption in transit: All communication between your browser and our servers uses HTTPS.
Browser Extension
QCoop offers an optional Chrome extension with a single purpose: making the Epic Games login handshake automatic instead of requiring you to copy and paste a code by hand. Concretely:
- After you log in on Epic's own page, the extension reads the one-time authorization code Epic displays there — the same code you'd otherwise copy yourself.
- It relays that code locally, inside your browser, to the QuickCoop tab you already have open. The extension itself never makes any network request — the QuickCoop page you're already using sends the resulting login request to our backend, exactly as it would for a manual paste.
- The extension does not read, store, or transmit anything beyond that one code. It has no analytics, no remote code (every script ships inside the extension package), and no storage permission — it keeps nothing after the page receives the code.
- It only activates on Epic's official login redirect page and on quickcoop.me — it does not run on any other site.
Not installing the extension does not limit any functionality — you can always connect Epic by pasting the code yourself.
Third-Party Services
QCoop talks to the following third parties to do its job:
- Steam & Epic Games: Used to authenticate you and fetch your library/friends list directly from the platform you connect. This is the core of what QCoop does.
- Supabase: Our database and authentication provider. It stores your account (if you register) and any encrypted tokens, hosted on infrastructure we manage.
- Vercel Analytics: Anonymous, aggregate page-view and performance metrics (e.g. load times) on our production site — no personal identifiers.
We do not use advertising networks, trackers, or any service that resells your data.
Your Rights & Data Deletion
You're always in control of your data:
- If you never created an account, closing or refreshing the tab clears your session, and clearing your browser's local storage removes everything else QCoop kept on your device.
- Disconnecting Steam or Epic from within the app immediately deletes that connection — and, for Epic, its encrypted tokens — from our database.
- You may revoke QCoop's access from your Steam or Epic account settings directly, at any time.
- If you registered, you can email us to request deletion of your account and all associated data.
If you have any questions about your data or wish to request its deletion, please contact us using the details below.
Contact
QCoop is a student project built for a UI/UX course. If you have questions, concerns, or requests regarding this privacy policy, you can reach us at:
We will respond to all privacy-related inquiries within 30 days.
This privacy policy applies to quickcoop.me and to the QCoop browser extension, and does not cover the practices of any third-party services linked from this page. We may update this policy as the product evolves — the "Last updated" date at the top will always reflect the most recent version.