---
title: "Privacy policy — Spectra"
canonical_url: "https://usespectra.app/privacy"
last_updated: "2026-09-03T14:39:57.187Z"
meta:
  description: "What we collect, why, who we pass it to and what you can do about it. No hand-waving — below is the actual list of data this site and the launcher process."
  "og:description": "What we collect, why, who we pass it to and what you can do about it. No hand-waving — below is the actual list of data this site and the launcher process."
  "og:title": "Privacy policy"
  "twitter:description": "What we collect, why, who we pass it to and what you can do about it. No hand-waving — below is the actual list of data this site and the launcher process."
  "twitter:title": "Privacy policy"
---

# **Privacy policy**

What we collect, why, who we pass it to and what you can do about it. No hand-waving — below is the actual list of data this site and the launcher process.

Last updated: 28 August 2026

## **Who is responsible**

The data controller is —, who runs the Spectra project. For anything about personal data, write to —.

Spectra is not an official Minecraft product and is not approved by or associated with Mojang Studios or Microsoft.

## **Using Spectra without an account**

The site and all of its tools work without signing in. So does the launcher: instances, mods, worlds and skins need no Spectra account.

Without an account we build no profile and keep no usage history. The server keeps standard request logs, described below.

## **Account data**

Creating an account means giving an email address and a password. We never store the password itself — only a cryptographic hash it cannot be recovered from.

The account also holds a username, a display name, an optional avatar and, if you turn it on, two-factor configuration.

If you sign in through Discord, Google, GitHub or Microsoft, we receive an account identifier, email address, name and profile picture from them. We never receive your password to that service.

## **Minecraft profile**

You can link a Minecraft account. We then store its UUID and name so the skin and cape can appear on your public profile.

Linking is optional and reversible. The skin and cape themselves are not stored here — we fetch them from Mojang when the page is rendered.

## **Social data**

Friend lists, invitations and notifications are stored, because those features cannot work without them.

The launcher sends a presence heartbeat so friends can see whether you are online and whether a game is running. You can hide your presence in the settings.

Who can see your friend list is your choice, in the Privacy tab of your account page. By default only mutual friends can.

## **Shared modpacks**

Sharing an instance uploads its contents and metadata: name, game version, loader and mod count. Files are stored in Cloudflare R2 object storage.

We also record who a pack was sent to and which revision they installed, which is what lets recipients be told about updates.

Share codes expire, and the stored files are removed with them.

## **Activity and badges**

When the launcher is signed in, we store a daily summary: number of launches and time played. It exists only for the activity graph and the statistics on your public profile. It is on by default and you can switch it off — the launcher asks on first run, and the same switch stays in its privacy settings.

Automatically granted badges record when they were granted.

## **Site analytics**

We count visits with Umami, which we host ourselves at analytics.makoto.com.pl. The data never reaches a third-party company.

Umami stores no cookies and nothing else on your device, and creates no identifier that could follow you between sites. It collects aggregate information: the page visited, where you came from, an approximate country, device type and browser.

Your IP address is used only momentarily to derive the country and is not stored. These records cannot be traced back to you.

We also record events describing what gets used — that the launcher download was clicked, or which tool was opened. They are counters, tied to no account.

## **Launcher telemetry**

The launcher sends anonymous telemetry: a random install identifier, application version, operating system, architecture and language, plus coarse event counters.

That identifier is tied to no account and no personal data, and we keep it in a separate table precisely so the two cannot be joined.

A crash report is only ever sent when you click to send it. Everything else the launcher sends, including the Discord status showing what you are playing, is on by default and can be switched off — the launcher asks on first run, and the same switches stay in its privacy settings.

## **Server logs**

The server keeps standard request logs: IP address, time, requested address, response code and browser header. They exist to find failures and abuse.

Traffic is served through Cloudflare, which processes the same data to protect against attacks.

## **Legal bases**

Account and social data are processed to perform the service agreement (Art. 6(1)(b) GDPR).

Logs, abuse prevention and anonymous telemetry rest on our legitimate interest (Art. 6(1)(f) GDPR) in keeping the service running and improving it.

Linking a Minecraft account and making your friend list public rest on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.

## **Who we share data with**

Cloudflare — hosting, content delivery, bot protection and file storage.

Mojang Studios and Microsoft — when a skin or cape is displayed, we query their servers for public Minecraft profile data.

External sign-in providers — Discord, Google, GitHub, Microsoft — strictly for signing in.

We do not sell data and we do not pass it on for advertising.

## **How long we keep it**

Account data is kept until the account is deleted. Deleting an account removes the profile, friends, notifications, badges, activity, avatar and shared packs.

Shared packs disappear when their code expires. Server logs and anonymous telemetry are kept for the limited period needed to investigate problems.

## **Your rights**

You have the right to access your data, correct it, delete it, restrict its processing, port it, and object to processing based on legitimate interest.

Most of this you can do yourself on the account page: change your details, set visibility, unlink external accounts and delete the account.

For anything else write to —. You may also complain to your national data protection authority.

## **Security**

The connection to the site is encrypted. Passwords are stored only as hashes, and you can add two-factor authentication.

No system is immune to breaches. If an incident puts your rights at risk, we will tell you about it.

## **Children**

The service is not aimed at people under 16. If we learn an account belongs to a younger person without a guardian consenting, we remove it.

## **Changes**

We may update this policy. The date of the last change is at the top of this page, and material changes will be announced on the site or in the launcher.