Privacy

Tool inputs stay in your browser unless you choose to save them. Saved configs, their optional attachments and administrator media are stored on our server. There are no analytics.

Last updated

Your files stay on your computer

Converting a .vcfg, decoding a share code, merging two configs, checking one for dead lines, comparing two, and building binds all happen in your browser, in JavaScript, on your machine. Using those tools does not upload the files you choose. Saving a config, uploading an overlay background, or uploading media as an administrator are separate, explicit actions described below.

When you are signed in and press Save, the config and any optional attached files you selected are sent to our server and kept in your account, as described under Accounts below.

One consequence worth spelling out: the bind builder will put a server password into a config for you, and that password never reaches us — but it is then sitting in a plain text file on your machine, and a config is the file people send each other when they want help. The builder says so at the point you type it.

You do not have to take that on trust. Open your browser’s developer tools, switch to the network tab, and convert a file: no request goes out. The browser-based config tools still work after the page has loaded if you disconnect from the internet.

Cookies only when you sign in, no analytics, no third parties

This site does not:

  • set a cookie on anyone who has not pressed “Sign in”. Signing in sets two, and they are the only ones: __Host-vora_login for the ten minutes a Steam sign-in takes, holding a random number that proves the answer from Steam belongs to the sign-in you started, and __Host-vora_session while you are signed in, holding a random token. Neither can be read by scripts, both are sent over HTTPS only and to this domain only, and signing out deletes the session on our side as well as the cookie;
  • store anything in your browser beyond a few small conveniences, each kept only on your machine and never sent to us:
    • the stream overlay’s two “change” figures, described below;
    • which map is behind the pictures on a crosshair list;
    • the id of an announcement you closed, so it stays closed;
    • if you press Save while signed out, the config on screen, in session storage, so that it is still there when you come back from signing in;
    • while signed in, which support replies you have already been told about, in session storage, so the bell does not ring twice for one;
    • in an overlay, a note that it has reloaded itself once after a site update, in session storage, so it does not keep reloading;
  • run analytics, of any kind, first-party or otherwise;
  • load scripts, fonts, or images from anyone else’s server;
  • embed social buttons, trackers, pixels, or advertising.

There is one sponsor line in the footer, and it does not change any of that. It is a name, a sentence and a link — no ad network, no auction, no pixel, and nothing that learns anything about you. A sponsor’s logo is copied onto this server and served from this domain like every other image here, because a logo loaded from somewhere else would tell that somewhere else which pages you read. The site is free and a server is not; that line is how it is paid for, and it is the whole of it.

The fonts are served from this domain rather than a font CDN, specifically so that loading a page here does not tell a third party you were here.

What the server records

The site runs on a server we rent and administer. Like essentially every web server, it writes one line to an access log for each request. That line contains:

  • your IP address;
  • the date and time;
  • the page requested, and the method and protocol used to request it;
  • the HTTP status code and the number of bytes sent back;
  • the referring page, if your browser sent one;
  • your browser’s user-agent string;
  • how long the request took to serve, and which TLS version it used — facts about the server rather than about you.

That is the whole line. Cookies are not logged, nothing is recorded about what you dropped onto the page, and no identifier is attached that would connect one visit to another.

The log exists to keep the server running and to block abuse — it is what an automated ban tool reads when something starts hammering the site. It is not analysed, not aggregated into statistics, and never shared or sold. Log files rotate daily and are deleted after 14 days; the rotation rule that enforces that is in the same repository as this page, so the promise and the mechanism ship together.

The application itself, behind the web server, keeps no request log at all. It records only that it started and anything it crashed on.

Under the GDPR and Türkiye’s KVKK an IP address counts as personal data, and the basis for keeping it is our legitimate interest in operating the service securely. If you would rather that record not exist, write to us and we will remove the entries we can identify — bearing in mind that after two weeks there is nothing left to remove.

The FACEIT overlay and its server request

The FACEIT overlay is the exception to everything above, and it is worth being exact about. It shows your live FACEIT rating on a stream, and that rating can only come from FACEIT — so the nickname in the overlay’s address is sent to our server, which asks FACEIT for that player’s public profile and passes the answer back.

The nickname is the only thing sent, it is already public, and it goes no further than FACEIT. The answer is held in memory for a few seconds — up to a minute and a half for rankings and recent matches, and five minutes for a name FACEIT does not know — so that several scenes pointing at the same name ask FACEIT once, and it is never written to disk. Nothing is stored. There is no account, no history and no record that a particular overlay was ever loaded, beyond the ordinary server log line described above.

If the overlay is set to show your avatar, our server fetches that picture from FACEIT and passes it on as well, rather than your browser fetching it directly. That is deliberate: it means the machine watching your stream never contacts FACEIT at all. Country flags are images kept on this site, not fetched from anyone.

The two “change” figures — since you went live, and since midnight — are worked out in your own browser and kept there, because FACEIT does not publish the numbers they would otherwise be calculated from. They are two small entries in your browser’s local storage holding an elo and a timestamp, nothing else, and clearing your browser data removes them. They never reach us.

VIP overlays keep a few more things. A key, which is a random string in the overlay’s address: it is how a browser source proves the overlay belongs to a VIP, since OBS carries no sign-in. The FACEIT account the key is locked to — its FACEIT player id and nickname, taken from FACEIT the first time the overlay opens — so that the key works for that account and no other. And, if you upload one, a single background image, which is stored on our server in the database rather than on anyone else’s. It is decoded and re-encoded here before it is stored, so nothing that travelled inside the file you picked — camera details, location, colour profiles — is kept. Only your overlay’s key can fetch it. Removing it from the editor deletes it, and deleting your account deletes it with everything else.

When you sign in, our server sends your Steam ID to FACEIT’s public API and asks which FACEIT account, if any, is connected to it — FACEIT indexes players by the Steam account they linked. If there is one, your account keeps its FACEIT player id and nickname and when we last asked, so the overlay editor can open on your own player. If the answer is wrong you can choose a different FACEIT account on the overlay page, and that choice is kept instead. Nothing else is fetched from FACEIT for your account.

Admin media uploads

An administrator can add site images and MP4/WebM videos up to 100 MB through the media library. Files are stored in the site database and served from this domain. Media URLs are public to anyone who has the URL, and files remain available until an administrator deletes them. Images are decoded and re-encoded as WebP, removing the original image metadata. Videos are kept in their original format; embedded recording metadata may remain in the file. After deletion, a copy may remain in an administrator-only database backup for up to 14 days before that backup expires.

The mark on generated files

Every .cfg this site generates carries a signature: a visible header comment, one echo line at the end so you can see in the game console that the file actually loaded, and an invisible zero-width payload riding on the header.

That payload contains exactly four things: a format version, the build id of the site that generated it, the build date to the day, and a checksum of the config body. It contains nothing about you — no Steam ID, no account, no IP address, no session, not even a local clock time, because a clock time and a timezone together are enough to narrow down a person. Two different people converting the same config on the same day get byte-identical output, and there is a test that fails if that ever stops being true.

It is there so a file can be traced back to the tool and checked for edits, not to follow anyone. It is plaintext in a text file: if you do not want it, delete the four lines at the top and the echo at the bottom, and nothing breaks.

Accounts

Every tool works without one. An account only adds somewhere to keep configs and crosshair lists, and a profile page to show the public ones on.

You sign in on Steam’s own page, so this site never sees your password, and Steam tells us one thing: your Steam ID. Steam in turn learns that you signed in to vora.tools. From your Steam ID our server then asks Steam’s public API for your profile name and the picture you use — the same two things anyone can see on your Steam profile — and asks again at most once a day while you keep using the site, so a name you change on Steam changes here too.

Your account keeps:

  • your Steam ID, your Steam profile name, and an identifier for your Steam picture;
  • when you first signed in and when you last did;
  • one record per signed-in browser, holding a scrambled form of its token (not the token itself) and when it expires. Sessions end after thirty days without a visit;
  • the configs and crosshair lists you save, with their titles and descriptions;
  • optional files saved with a config: video settings, a video backup, launch options, launch configuration and the trusted-launch report. The report may contain local software names or file paths. These files follow the config visibility: public and unlisted files are available with the config, while private files are visible only to you;
  • the FACEIT account connected to your Steam account, if there is one — see above;
  • if you have one, your role (VIP, support or admin), when a time-limited VIP ends, the handle a VIP chooses, a VIP’s overlay key and the FACEIT account it is locked to, whether you have been told a time-limited VIP ended, and — if an admin ever banned the account — when, and the reason they wrote;
  • which “this config has commands CS2 no longer reads” notices you dismissed, so they are not shown again.

It does not keep an email address, a password, your friends list, your inventory, or your IP address. Your Steam picture is fetched by our server and served from this domain, so people looking at your profile never contact Steam.

Who sees what you save is yours to choose, for each config and list. Public ones are listed on your profile. Unlisted ones are not listed anywhere, but anyone with the link can open them — the link is long and random, so it cannot be guessed. Private ones are seen by you alone, while signed in; admins cannot open them either.

Admins can hide a public or unlisted config or list that breaks the terms, and can ban an account. Every such action is written to an audit log that records who did it, to which account, and when. The audit log is kept even after an account is deleted — it names Steam IDs, not people’s content — because it is the record of what admins did.

Deleting your account is a button on your account page. It removes your profile and every config and list at once and signs you out on every browser. What is left afterwards is only what this page already describes as kept elsewhere: audit log entries about your account, if an admin ever acted on it, and ordinary server log lines until they expire. The database is also copied to a backup once a day, readable only by the server’s administrator, and each copy is deleted after 14 days — so two weeks after you delete your account, no copy of it is left anywhere.

VORACUP is gone. The tournament side of this site - matches, rosters, map vetoes, the game server and its demos - was removed on 24 September 2026, and the rows it kept went with it. Nothing about a match you played in is stored here any more.

Support tickets are stored with your account: the subject, every message in the conversation, when each was written and the ticket’s number, whether you have read the latest reply, and the reason it was closed. Files the support team attaches to a reply — players cannot attach any — are kept with the ticket. Only you and the support team can read them, and messages cannot be edited or deleted once sent — by you or by us. Opening, replying to and closing a ticket each also add a line to the audit log: whose Steam ID did it, which ticket number, when, and how long the message was. The log never holds what a message said. Deleting your account deletes your tickets and their messages; those audit lines stay, for the same reason as the rest of the log.

Under the GDPR and KVKK, the basis for keeping account data is that you asked for the service it provides; the basis for the audit log is our legitimate interest in running the site safely.

Other services involved

No other company is paid to process your data, and this site sends no email. The services it does touch, and what each one sees:

  • Our hosting provider, whose server we rent and run ourselves. The server is in Türkiye, and everything described on this page is stored there.
  • Cloudflare answers DNS for the domain — it is not in front of the site and does not see your visits — and forwards email sent to hello@vora.tools to us. A message you send to that address passes through Cloudflare on the way.
  • Steam (Valve) for signing in and for your profile name and picture, as described under Accounts.
  • FACEIT for the overlay’s numbers and for finding your FACEIT account, as described above.
  • Discord: the site posts its own changelog and CS2 patch notes to our Discord server. Those posts contain nothing about any visitor.

Steam and FACEIT are outside Türkiye and the EU. The requests to them happen because you asked for what they serve — signing in, or an overlay — and carry only what is listed here: a Steam ID, or a FACEIT nickname or player id.

Children

This is a tool for editing game settings and is not directed at children. It collects no information that would identify anyone of any age.

Who is responsible, and what you can ask for

The data controller — veri sorumlusu under Türkiye’s KVKK, and “controller” under the GDPR — is vora.tools, reachable at hello@vora.tools.

Both laws give you the right to ask whether we hold personal data about you, what it is and why, to have it corrected if it is wrong, and to have it deleted. You can also object to us holding it at all, and complain to a supervisory authority — the Kişisel Verileri Koruma Kurumu in Türkiye, or your national data protection authority in the EU.

Without an account, the only personal data here is an IP address in a server log, kept for fourteen days, with nothing attached that identifies a person; to find your entries we would need the IP address you used and the rough time. With an account, everything it holds is listed under Accounts above, all of it is visible to you on your account page, and you can delete it yourself at any time. For anything else, write to us.

Changes to this policy

vora.tools may change this privacy policy, and the terms of use, at any time and without prior notice. There is no mailing list, this site sends no email, and an account holds no email address, so there is no one to notify — and we would rather be able to correct something the day we notice it than leave it wrong for a notice period.

What we do instead is make every change findable: the date at the top of this page changes, and the change is written into the changelog like everything else on the site. Continuing to use the site after a change means you accept the current version.

How to reach us

Questions, corrections and deletion requests go to hello@vora.tools. See also the terms of use.

vora.tools is operated as an independent project and is not affiliated with Valve Corporation.