Privacy Policy
Last Updated February 15, 2026
This Privacy Policy explains how Ethobyte ("we", "us", "our") operates RuneSpec and processes personal data when you use our website, dashboard, APIs, and related services (collectively, the "Services"). It also describes your rights under applicable data protection laws, including the EU/UK GDPR and the ePrivacy rules.

We are committed to transparency and lawful, fair processing. If you have questions or wish to exercise your rights, contact us at legal@runespec.com.
  1. Controller & Contact
  2. Data We Collect
  3. We collect and process the following categories of data:
    • Account & Authentication: Discord OAuth identifiers (user ID), username, discriminator, avatar, access/refresh tokens, scopes; basic guild membership info and permissions to enable premium features you request.
    • Profile & Service Data: RuneScape name you provide; clan and server selections; configuration you set on the dashboard; site preferences.
    • Subscription & Billing: PayPal subscription IDs, plan IDs, status events, timestamps, and non-card billing metadata returned by PayPal webhooks and APIs. We do not receive or store your full payment instrument details; those are handled by PayPal.
    • Technical Data: session identifiers, CSRF tokens, server logs (IP address, user-agent, timestamps, pages and API routes accessed), and cookie data necessary to operate the site.
    • Derived/Analytics: limited aggregate statistics about bot usage and service performance. We currently do not deploy non-essential analytics without your consent.
  4. Purposes & Legal Bases
  5. We process personal data only when we have a lawful basis:
    • Contract: to provide the Services you request, including login via Discord, guild management for premium features, and subscription provisioning.
    • Legitimate Interests: service security, fraud detection, preventing abuse, improving reliability, and maintaining service availability. We balance these interests against your rights.
    • Consent: for any non-essential cookies/trackers or optional communications. You may withdraw consent at any time.
    • Legal Obligations: to meet accounting/tax, anti-fraud, and regulatory requirements related to subscriptions and transactions.
  6. Cookies & Similar Technologies
  7. We use strictly necessary cookies (e.g., session and CSRF). Non-essential cookies (such as analytics or preference tracking beyond essentials) will only be set with your consent via a cookie banner or settings when enabled. You can change cookie choices at any time using the banner or your browser settings.
  8. Sharing & International Transfers
  9. We share data with service providers solely to operate the Services:
    • Discord (OAuth and guild information).
    • PayPal (subscription management and webhook events).
    • Hosting & Infrastructure partners that run our website and databases.
    Some recipients may be outside your country. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) or other valid transfer mechanisms under GDPR.
  10. Retention
  11. We retain personal data only for as long as necessary:
    • Account data: for the life of your account and for a reasonable period after closure to resolve disputes and enforce our terms.
    • Subscription/billing records: for the period required by applicable tax and accounting laws.
    • Logs and security data: typically up to 12 months, unless needed longer for security or legal reasons.
    We will anonymize or securely delete data when retention periods expire.
  12. Your Rights
  13. Subject to applicable law, you have the right to request: access, rectification, erasure, restriction, objection (including to processing based on legitimate interests), and data portability. Where processing relies on consent, you may withdraw consent at any time without affecting prior processing.

    To exercise rights, email legal@runespec.com. We will respond within one month (extendable by two months for complex requests). We may need to verify your identity to protect your privacy.
  14. Security
  15. We implement technical and organizational measures to protect personal data, including encrypted transport, access controls, session protection, and least-privilege practices. No online service is 100% secure; please use strong passwords for your Discord account and keep your devices updated.
  16. Children
  17. The Services are not directed to children. Do not use the Services if you are under the age of 13 (or under 16 where required by local law) without verified parental consent. We will delete accounts known to be created by minors without appropriate consent.
  18. Third‑Party Intellectual Property
  19. RuneSpec is a community tool and is not affiliated with or endorsed by Jagex Ltd. RuneScape content, trademarks, and imagery are the property of Jagex Ltd. We do not claim any rights over Jagex assets and only reference public information for user features.
  20. Changes to This Policy
  21. We may update this Privacy Policy to reflect changes in law or our practices. We will post the updated version and update the "Last Updated" date. If changes materially affect your rights, we will provide additional notice as required.
  22. Contact
  23. Questions or requests: legal@runespec.com.