Some things are worth stating first, because they are the ones people are actually worried about:
- Your Steam password. Sign-in happens on Steam’s own site through OpenID; Emerald only ever receives your SteamID back.
- Your Steam Guard code or mobile authenticator.
- Your full card number or CVV. Card details go straight to our payment provider, and Emerald stores only their opaque reference plus the brand and last four digits for display.
- Your session token. Only a SHA-256 hash of it is stored, so a copy of our database cannot be used to sign in as you.
- Your password in readable form. Passwords are stored as scrypt hashes.