OpenSpec Index Privacy Policy
Effective date: EFFECTIVE_DATE
This policy explains what OpenSpec Index collects when you use openspecindex.com or api.openspecindex.com, why we collect it, and what you can do about it. The Service is operated by KnightDevs, a sole proprietorship organized under the laws of [STATE], mailing address [MAILING ADDRESS].
The short version: we log request metadata so we can enforce rate limits and stop abuse. We do not run user accounts, we do not hold passwords, we do not process payments on the site, and we do not sell your data.
1. What We Collect
1.1 Request logs. When you load a page or call the API, we log:
- - your IP address,
- - your user agent string,
- - the endpoint you requested,
- - the query parameters you sent,
- - the timestamp, the response status, and basic response metadata.
1.2 API key requests. If you email us to request an API key, we keep your email address, the name and organization you give us, and our correspondence with you. We use it to issue and manage your key, to contact you about limits and changes, and to keep a record of the request.
1.3 API key usage. For keyed traffic, request logs are associated with the key rather than only with an IP address.
1.4 Correspondence. If you email either of our addresses, we keep the message.
1.5 That is the list. We do not collect names, addresses, phone numbers, government identifiers, precise location, biometric data, or any special category of personal data through the Service itself.
2. What We Do Not Collect
2.1 No user accounts. There is no signup, no login, and no password on the Service. We hold no password hashes.
2.2 No payment data. We do not take payments on the Service and we do not store card numbers or bank details there. Where a paid arrangement exists, it is handled under a separate agreement and outside the Service.
2.3 No advertising and no ad networks. We do not run ads and we do not share data with ad networks or data brokers.
2.4 No cross-site tracking. We do not build advertising profiles and we do not participate in cross-site tracking.
3. Why We Collect It
We use request logs for these purposes and no others:
3.1 Rate limiting. The free API tier is metered per IP address. We need to see the IP to count it.
3.2 Abuse prevention. Detecting and blocking scraping, quota evasion, key sharing, denial of service attempts, and other violations of the Terms of Service.
3.3 Operations. Debugging errors, monitoring performance and uptime, and diagnosing broken endpoints.
3.4 Aggregate understanding. Counting traffic and understanding which endpoints and queries are used, in aggregate, so we can decide what to build and what to index next.
3.5 Legal. Responding to lawful requests and establishing or defending legal claims.
Our legal basis, where a basis is required, is our legitimate interest in operating a service that is not overwhelmed or abused, and in some cases compliance with a legal obligation.
4. Query Logging and How to Opt Out
4.1 By default we log the query parameters of requests, including the search terms and part numbers you look up. We do this for rate limiting, abuse detection, and debugging.
4.2 API key holders can turn query logging off. Each API key account has a log_queries flag. Set it to off and we stop recording the query parameters and search terms for requests made with that key. We continue to count requests for rate limiting, and we continue to record the endpoint, timestamp, and status.
4.3 To turn it off, email [email protected] from the address associated with your key and ask us to disable query logging. We will confirm when it is done.
4.4 Free tier traffic without a key cannot be opted out this way, because there is no account to attach the setting to. If you do not want your queries logged, request a key.
5. Cookies and Local Storage
5.1 No tracking cookies. We do not set cookies for advertising, profiling, or cross-site tracking.
5.2 Theme preference. The website stores your light or dark theme preference in your browser's localStorage. It stays on your device, it is not sent to us, and clearing your browser data removes it.
5.3 Analytics. Microsoft Clarity analytics is wired into the site but is currently inactive as of EFFECTIVE_DATE. It is not collecting data. If we activate it, we will update this policy with the effective date of the change before or at the time it goes live, and we will describe what Clarity collects (which can include page interactions, clicks, scrolls, and session replay) and how to opt out.
6. Who We Share It With
6.1 We do not sell personal information. We do not share it for cross-context behavioral advertising.
6.2 We share request data only with:
(a) Infrastructure providers who host and serve the Service, who process the data on our behalf and only to run the Service. Current providers: Cloudflare (DNS, CDN, Pages hosting, tunnel, and email routing).
(b) Legal recipients, when we are required by law, subpoena, court order, or other valid legal process, or when we believe disclosure is necessary to protect our rights, prevent fraud, or address a security incident.
(c) A successor, if the business or its assets are sold, merged, or transferred, subject to this policy.
7. How Long We Keep It
7.1 Request logs: retained for [RETENTION PERIOD, for example 12 months], then deleted or aggregated into non-identifying counts.
7.2 Aggregate counters: retained indefinitely. They contain no IP addresses and no query text.
7.3 API key records and correspondence: retained while your key is active and for [RETENTION PERIOD, for example 24 months] after it is revoked, for billing, dispute, and abuse history purposes.
7.4 Abuse records: where we have blocked an IP address or a key for a violation, we may keep the minimum record needed to keep the block in place.
8. Security
8.1 The Service is served over HTTPS. API keys are stored hashed, not in plain text. We cannot recover your key for you, we can only issue a new one.
8.2 Access to logs and databases is limited to the operator of KnightDevs.
8.3 No system is perfectly secure. We do not promise that our safeguards will prevent every incident. If we become aware of a breach affecting personal information, we will notify affected parties and regulators as required by applicable law.
9. Your Rights
9.1 Depending on where you live, you may have the right to request access to the personal information we hold about you, correction of it, deletion of it, a copy of it, or restriction of how we use it. You may also have the right not to be discriminated against for exercising these rights.
9.2 To make a request, email [email protected]. Tell us what you want and give us enough detail to find the records. For key holders, email from the address on the key. For free tier traffic, we generally need the IP address and an approximate time window, and often we cannot verify that a shared or dynamic IP address is yours. Where we cannot verify a request, we will say so rather than hand data to the wrong person.
9.3 We will respond within the time required by applicable law, generally within 30 to 45 days.
9.4 We may decline a deletion request where we need the record to enforce a rate limit, to keep an abuse block in place, or to comply with a legal obligation. If we decline, we will tell you why.
9.5 If you are in the EEA or the UK, you also have the right to object to processing based on legitimate interests and to lodge a complaint with your supervisory authority.
10. International Users
10.1 The Service is operated from the United States and data is processed there. If you use the Service from outside the United States, you are sending your data to the United States, where privacy laws differ from those in your country.
11. Children
11.1 The Service is a business and engineering tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, email [email protected] and we will delete it.
12. Data About Parts, Not About People
12.1 The index itself is product data: part numbers, specifications, prices observed on a date, and source URLs from public manufacturer and distributor pages. It is not built to contain personal information.
12.2 If personal information appears in an indexed record by accident, email [email protected] and we will remove it. The takedown process in Section 9 of the Terms of Service also applies.
13. Changes to This Policy
13.1 We may update this policy. When we do, we will change the effective date at the top and post the new version at openspecindex.com.
13.2 For material changes, including activating analytics or expanding what we log, we will update the policy before the change takes effect and will make reasonable efforts to notify keyed API users by email.
14. Contact
Privacy questions and requests: [email protected]
Business and commercial: [email protected]
Mail: KnightDevs, [MAILING ADDRESS]