Last updated: August 28, 2026
Spymace is a public social network, and most of what you put on it is meant to be seen. This policy sets out exactly which parts are public, what we collect besides that, who else it reaches, and how to get it back or have it deleted. Our Terms of Service cover the rest of the arrangement.
Contents
- Who we are and what this covers
- What is public, and what is not
- Information we collect
- How we use this information
- Legal bases (EEA and UK)
- Who else sees it
- Media loaded from other websites
- Cookies
- Retention and deletion
- Your rights
- Security
- Children
- International transfers
- Changes to this policy
- Contact
1. Who we are and what this covers
Spymace is operated by Magic Ingredient LLC, which is the controller of the personal information described here. This policy explains what we collect when you use Spymace, why, who else can see it, how long we keep it, and what you can ask us to do about it.
It does not cover other websites. In particular, it does not cover YouTube, or the servers that host the images that members link to — see Media loaded from other websites.
2. What is public, and what is not
This is the most important section of this policy, so it comes first. Spymace profiles are public web pages. Anyone can read them without an account and without signing in, including search engines. The same is true of blog entries, bulletins, comments, and member search and browse.
| Public to anyone: | Your display name, @handle and avatar; headline, mood and tagline; About Me and Who I'd Like To Meet; all of your interests; your blog entries and their comments; your bulletins; comments on your profile; your friends list and Top 8; your photos, albums and captions; the YouTube video on your profile; your profile theme and custom CSS; your profile view count; and roughly when you last signed in. |
| Public, in derived form: | Your date of birth is stored but never displayed. Profiles show only your age in years and your zodiac sign, both calculated from it. |
| Only you: | Your email address, which we store but never show on the site or in search. |
| You and the other person: | Private messages. They are private between the two of you — they are not end-to-end encrypted, and administrators of the service can technically read the database. |
| We never see it: | Your password. It is held by our identity provider and is never sent to us. |
The profile fields include several that many privacy laws treat as sensitive categories — among them religion, sexual orientation, ethnicity, relationship status, and income. Every one of them is optional and every one of them is blank until you fill it in. If you complete them, you are choosing to publish that information about yourself to the open internet, and you are asking us to display it on that basis. You can clear any of them at any time in profile settings.
3. Information we collect
Account information
Accounts are created and secured through Clerk, a third-party identity provider. When you sign up, they collect and hold your email address and your password.
Signing in from a device we do not recognise requires a verification code emailed to you. To decide whether a device is recognised, our identity provider records information about the devices and browsers you sign in from. We do not ask for or store a phone number.
From that account we keep a local copy of your user identifier, email address, display name, whether your email is verified, and your @handle. We keep the email copy so we can contact you and so that account records line up; it is not displayed anywhere on the site.
Profile information you choose to give us
Everything on your profile is optional and supplied by you: headline, mood, tagline, About Me, Who I’d Like To Meet, your interests, and the details table — gender, date of birth, city, region, country, relationship status, orientation, religion, smoking and drinking, occupation, education, body type, ethnicity, height, income, and children. Also your avatar address, the YouTube video on your profile, your theme, and your custom CSS.
Content you create
Blog entries and their comments, bulletins, comments you leave on other people’s profiles, private messages you send and receive, albums, and the pictures you upload together with their captions.
Pictures you upload
Photos and avatars are uploaded from your browser, or from the Spymace app, directly to our storage provider and served from our content delivery network. Alongside the image itself we record its file type, size in bytes, and pixel dimensions, so that pages can be laid out without shifting and so limits can be enforced without re-reading the file.
Embedded metadata is removed before the picture is sent. Photographs often carry camera details and, on many phones, the GPS coordinates where the picture was taken. Whichever way you upload — the website or the Spymace app — the file is rewritten on your own device to drop all of that before anything leaves it, so those coordinates never reach us and are not in the file we serve. We never receive the original: pictures go straight from your device to our storage provider, so there is no untouched copy for us to hold.
How the rewriting works depends on the picture. On the website, photographs are re-encoded, which may scale them down to fit within 2048 pixels on the longest edge. In the app the metadata blocks are removed without re-encoding, so the picture keeps its original quality — except a photograph taken with the phone turned sideways, which has to be rotated and re-encoded, and may then be scaled to the same limit. Animated GIFs are never re-encoded on either: they keep their original size, frames and timing, and have their metadata blocks removed instead. A picture we cannot clean is not uploaded.
Your connections
Friend requests you send and receive, whether they were accepted, when, and the order in which you rank people in your Top 8.
Information collected automatically
- Sign-in and session data, handled by Clerk: IP address, device and browser information, and sign-in times, used to keep you signed in, to apply rate limits, and to detect suspicious sign-ins.
- Server logs kept by our hosting and database providers, which typically record IP addresses, requested pages, timestamps and error details.
- A profile view counter. When someone other than you opens your profile, a single number goes up by one. We do not record who viewed your profile or when — there is no visitor list, and we could not produce one.
- The time you last signed in, which drives the “Online Now!” badge on your profile.
- Page-view analytics that we run ourselves, so we can see which parts of Spymace get used and whether anything is broken. It isUmami, self-hosted on our own server, and the details matter:
- Nobody else receives it. The measurements go to a machine we run, not to Google or any other analytics company. There is no third party in this at all — nothing to share with, and nothing sold.
- It sets no cookies and stores nothing in your browser. There is no visitor id, so there is nothing to opt out of and no banner asking you. To count a visit only once, the software turns your IP address and browser into a short scrambled code using a secret that is thrown away and replaced every day. Your IP address itself is not stored, the code cannot be turned back into it, and yesterday’s code cannot be matched to today’s.
- Addresses are stripped before they are sent. A visit to a profile is recorded as
/u/[username]— the shape of the page, never the person. Entry, bulletin and message addresses are reduced the same way, page titles are replaced with a placeholder, and anything you type into the search box is dropped. The record says a profile was read; it does not say whose, or by whom. - We tag a handful of milestones — an account created, a friend request sent or accepted, an entry published, a picture uploaded — as counts and nothing more. No name, handle, account id or content goes with them.
- It records the town a visit came from. Your IP address is turned into a rough place — country, region and city — and the place is kept while the address is thrown away. That lookup happens on our own machine against a list we hold, so your address is not sent anywhere to do it. We would rather say this plainly than have you find it in a chart: on a site this small, a town is a narrower thing to know about a visit than a country is. It is never attached to your account, and no page view is ever recorded with your name against it.
Beyond that we use no advertising networks, no tracking pixels and no third-party cookies. We do not buy personal information about you from anyone, and we do not build profiles of you beyond the one you write yourself.
4. How we use this information
- to create your account and sign you in;
- to display your profile and your content to the people it is meant for, and to let other members find you through search and browse;
- to deliver private messages, comments, bulletins and friend requests;
- to show notification counts for unread mail and pending friend requests;
- to keep the Service working and secure — debugging, backups, rate limiting, and investigating abuse;
- to enforce our Terms of Service and respond to reports; and
- to comply with the law and to respond to lawful requests.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use it to train machine-learning models, our own or anyone else’s.
5. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR:
| Contract: | Creating and running your account, showing your profile, and delivering messages — the things you asked us to do by signing up. |
| Legitimate interests: | Keeping the Service secure and available, preventing abuse and spam, defending legal claims, and understanding which parts of the site get used. We consider these against your rights and interests — which is why the analytics runs on our own server, without cookies and with addresses redacted, so it needs no consent, involves no third party, and builds no record of you. |
| Consent: | The optional profile fields that reveal sensitive categories — religion, sexual orientation, ethnicity and the like. Filling them in and saving your profile is the consent; clearing the field withdraws it, with no effect on what we did beforehand. |
| Legal obligation: | Responding to valid legal requests and keeping required records. |
7. Media loaded from other websites
Pictures you upload are hosted by us. But members may still point an avatar at a file kept somewhere else, as people did in 2005, and your browser fetches those directly from that server when the profile loads.
That means the server hosting the file sees you. It receives your IP address, your browser and device details, and the fact that you loaded the page that referenced it. We have no control over what those servers do with that information or what their own privacy policies say, and we cannot tell you in advance which profiles link out this way.
YouTube videos
A member may set one YouTube video as their profile media. We store only the video’s id and render YouTube’s own embedded player; we never fetch, proxy or store the video or its audio ourselves.
When you open a profile with a video on it, your browser contacts YouTube. YouTube receives your IP address, your browser and device details, and the address of the page the player is embedded in. We use the privacy-enhanced youtube-nocookie.com host, which means YouTube says it will not use what you watch there to personalise browsing — but the request to YouTube still happens, and YouTube may still set storage or cookies once you press play. What YouTube does with any of this is governed by Google’s Privacy Policy, not by this one.
If this matters to you, a content blocker or a browser configured to block third-party requests will prevent it, at the cost of not seeing the pictures or the video. It is the honest trade-off of a site built the way this one is.
9. Retention and deletion
We keep your account information and your content for as long as your account exists. Your content stays up until you remove it or delete your account.
You can delete your account yourself, at any time, in account settings or from the Settings screen of the app. It happens immediately and cannot be undone: there is no waiting period, no deactivated state and no copy kept for you.
Deleting it removes your record at our identity provider — your email address, your password and any second factor — and, from our database, your profile, your wall and the comments written on it, your albums and photos, your friendships, your Top 8 entries, the people you blocked, your push devices and your copy of every message. The picture files themselves are deleted from our storage provider, not merely unlinked.
What you wrote on other people’s pages stays, with your name taken off it. Comments you left on somebody’s wall or under somebody’s blog entry, your bulletins and your blog entries remain readable and are shown as “[deleted user]”. They no longer carry your name, your handle, your picture or a link to any page, and nothing in them leads back to you. We do it this way because deleting an account should not blow holes in other people’s conversations.
Your @handle is released when the account goes, and somebody else may claim it afterwards. Nothing that survives your deletion carries it.
If you would rather we did it, or something above does not match what you see, write to support@enginyyr.com from the email address on the account and we will handle it within 30 days.
Deleting a single photo does the same for that one file: the stored object is removed, not just the row pointing at it. Copies already cached by our content delivery network can survive briefly afterwards until they expire.
Two more things survive it, and we would rather say so plainly:
- Private messages you sent to other people. A message is stored once and read from two ends. Deleting a message, or your account, removes your copy; the other person keeps theirs, in the same way an email you sent stays in the recipient’s inbox. It is shown to them as from “[deleted user]”, and they cannot reply to it.
- Backups and server logs. These roll over on their own schedule and may hold your information for a short period after deletion. They are not used for anything except restoring the Service after a failure.
We may also keep the minimum necessary to enforce a ban, to comply with a legal obligation, or to defend a legal claim.
Note that we cannot recall copies of public content that other people or search engines already made.
10. Your rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your account and the information attached to it;
- restrict or stop a particular use of your information; or
- withdraw consent you gave for an optional profile field, by clearing it or by asking us.
Most of these you can do yourself and immediately, without asking anyone, in profile settings, account settings and delete account.
EEA and UK
You additionally have the right to data portability, the right to object to processing based on legitimate interests, and the right to lodge a complaint with your local data protection authority. We would appreciate the chance to put things right first.
California
You have the right to know what we collect and why, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is no opt-out to offer.
Making a request
Write to support@enginyyr.com from the email address on your account. We will respond within 30 days, or tell you why we need longer. If we cannot verify that the request is really yours, we will decline it rather than risk handing your information to somebody else. You may use an authorised agent where the law allows, with proof of authorisation.
11. Security
Passwords are handled by Clerk and never reach our servers, and signing in from an unrecognised device needs an emailed code as well as the password. Traffic to Spymace is encrypted in transit. Custom CSS submitted by members is filtered and confined to the profile it belongs to, so that it cannot alter the rest of the site. Uploads are restricted by type and size, and the storage links we issue are short-lived and good for a single file, so the browser never holds credentials for our storage provider. Access to the database is limited to those who need it to run the Service.
No service is perfectly secure, and this one is a personal project rather than a funded security programme. Please use a password you have not used anywhere else, and keep the email account your sign-in codes go to secure — you can review your account in account settings. If you become aware of a vulnerability, report it to support@enginyyr.com and we will not pursue you for reporting it in good faith.
12. Children
Spymace is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child under that age has created an account, write to support@enginyyr.com and we will delete it.
13. International transfers
Our providers may store and process information in countries other than yours, including the United States. Where information is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or another transfer mechanism permitted by law. A public profile is, by its nature, readable from anywhere in the world.
14. Changes to this policy
We may update this policy. When a change materially affects how we handle your information, we will update the “last updated” date at the top and give notice on the site, by email, or both, before it takes effect. If a change requires your consent, we will ask for it rather than assume it.
15. Contact
For privacy questions, data requests, or account deletion:
Magic Ingredient LLC
support@enginyyr.com
Magic Ingredient LLC, 8245 E 96th St #1158, Indianapolis, IN 46256, United States
Privacy Policy · last updated August 28, 2026 · see also Terms of Service