Privacy Policy
How Specys collects, uses, and protects personal data
Last updated: 4 September 2026
1. Who we are
This Privacy Policy applies to the Specys service at specys.com (the “Service”), a platform for showcasing PC hardware setups and related community features.
Specys is operated as a self-hosted web application. For privacy requests, use the contact details in §11.
2. Data we collect
Account & authentication. When you sign in with Discord (OAuth via Auth.js), we receive and store identifiers and profile fields supplied by Discord and/or you — typically provider account id, display name, email address (if provided by Discord), and avatar URL. Session state is kept in signed JWT cookies.
Connected live platforms. If you connect Twitch, Specys stores the channel identifier, OAuth access and refresh tokens, subscription identifiers, current live status, stream title, category, language, thumbnail, viewer count and synchronization timestamps. For users with the staff-assigned Content Creator badge, Twitch EventSub notifications and periodic API reconciliation keep the public live status current. Disconnecting Twitch or losing the badge hides the stream immediately and schedules remote subscription cleanup.
Profile content you provide. Username, bio, social links, cover/avatar images, setup gear (linked catalog products or custom items), setup photos, EQ preset text files attached to audio gear (visible according to your setup visibility), wishlist, product reviews (rating and text), and similar content you publish on Specys.
Social & community activity. Follows, profile views (aggregated / keyed for unique-view style metrics), team membership and invites, Pro status requests, notification preferences, and in-app notifications related to those actions.
Product suggestions. Product name, brand, category, notes and optional URLs you submit; may be linked to your user id if you are signed in.
Contact messages. Name, email address, reason for contact, and the message you submit through the contact form.
Technical & security data. Server logs, IP address and related metadata for rate limiting and abuse prevention, user-agent, and short-lived counters in a Redis-compatible cache when configured. Optional first-party analytics (page path, anonymous visitor id, Web Vitals) only after you accept the banner. A third-party measurement key (e.g. Google Analytics) is used only if the operator configured one and you consented.
3. Why we process data (purposes)
- Provide accounts, public profiles, catalog, teams, reviews, and related features
- Authenticate you and keep sessions secure
- Show community activity (e.g. who uses which gear, trending, notifications)
- Prevent abuse, spam, and attacks (rate limits, logs)
- Respond to messages submitted through the contact form
- Improve reliability and understand aggregate usage (when analytics are enabled)
- Comply with legal obligations and enforce the Terms of Service
4. Legal bases (GDPR)
- Art. 6(1)(b) — performance of a contract / steps prior to a contract (running your account and the Service)
- Art. 6(1)(f) — legitimate interests (security, abuse prevention, product improvement, public display of content you chose to publish)
- Art. 6(1)(c) — legal obligations where applicable
- Art. 6(1)(a) — consent, where we rely on it (e.g. optional non-essential analytics if presented that way)
5. Public content
Specys is designed to make setups and community activity public by default for signed-up features: profiles, gear lists, photos you upload, reviews, team pages, follows, and similar. Do not post information you do not want others to see. Email addresses are not shown as a public profile field in the product UI, but may be stored for account purposes.
6. Sharing & processors
We do not sell your personal data.
Data is processed on infrastructure we control or configure (e.g. VPS, nginx, PostgreSQL, optional Redis-compatible cache, CDN/DNS such as Cloudflare). Discord is used for OAuth sign-in and Twitch for optional account linking and live-status synchronization; their processing is governed by their own policies when you authorize the respective app.
First-party analytics stay on Specys infrastructure (PostgreSQL). If a third-party measurement key is configured, that provider receives page paths after consent. We do not use third-party advertising networks in the core product.
7. Cookies & local storage
Essential: Auth.js session cookies (JWT) to keep you signed in. Preferences: theme may be stored in local storage (next-themes). Optional analytics cookies (specys_consent, HttpOnly visitor id specys_aid) only after you accept. Raw events are dropped after about 90 days; daily totals are kept longer.
8. Retention
Account and profile data are kept while your account exists. Uploaded images are stored on the server under paths associated with your account. Rate-limit data is short-lived. Logs are rotated according to host policy. After account deletion (when requested or self-serve if available), we remove or anonymize personal data within a reasonable period, except where law requires longer retention.
9. Your rights
If the GDPR or similar laws apply to you, you may have rights to access, rectify, erase, restrict, or port personal data, and to object to certain processing. You may lodge a complaint with a supervisory authority. You can edit most profile data in Settings. For deletion or other requests, contact us (§11).
10. International transfers
Hosting location depends on where the operator runs Specys. CDN/DNS or OAuth providers may process data in other countries. Where required, appropriate safeguards (e.g. standard contractual clauses or provider terms) should be used for transfers outside the EEA.
11. Marketplace listings
If you use the community Marketplace we store listing text, brand/product snapshots, coarse location (country and region), prices, images you upload, Discord eligibility checks derived from your linked Discord snowflake, reports you file, and staff moderation/audit records. Listing images and public location region can be seen by other visitors.
Contact with other users is not processed as in-app chat. Opening Discord uses Discord under Discord's terms. We do not use Marketplace data to guarantee trades. Retention of listings, images, reports, and audit logs follows operational and abuse-prevention needs; staff actions are kept so we can review disputes about moderation, not to arbitrate your sale.
12. Contact
Privacy questions and data subject requests: contact@specys.com
13. Changes
We may update this policy when the product or law changes. The “Last updated” date at the top will change. Material changes may also be announced on the site or to signed-in users when practical.