Extra Special Tracker — Privacy Policy
How EST handles your data. Short version: your API tokens and analytics stay on your PC. We do not run a cloud backend for EST.
1. Who we are
Extra Special Studio (“we”, “us”) distributes Extra Special Tracker (EST), a free local Windows desktop application. This policy covers EST and the EST product page on extraspecialstudio.co.uk.
For privacy questions about EST, contact us via our public Discord or open an issue on the EST GitHub repository.
2. Summary
- EST is local-first. Download history, project catalog, issues, and inbox cache are stored on your computer.
- Your CurseForge, Modrinth, and GitHub API tokens are stored in an OS-encrypted vault (Windows DPAPI). We do not receive or host those tokens on our servers.
- When you refresh data, EST talks directly from your PC to CurseForge, Modrinth, and GitHub using tokens you provide. We are not a middleman for that traffic.
- We do not sell your personal data. EST does not include advertising or third-party analytics SDKs. (Our public website may show optional ads — see the site privacy policy.)
3. Data stored on your device
EST may store the following locally (typically under your Windows user profile app data):
- API tokens (encrypted where the OS supports it)
- Project catalog and profile settings
- Download snapshots and derived analytics used for charts
- Cached GitHub issues and Modrinth notifications (if you sync them)
- Optional encrypted backup files you export yourself (`.estbak`)
You can delete this data by uninstalling EST and removing its app data folder, or by clearing tokens and profiles inside the app.
4. Data that leaves your device
4.1 Platform APIs (you control this)
When you use EST features, your machine may send requests to:
- CurseForge (
api.curseforge.com) — project download counts and related metadata, using your CurseForge Core API key. - Modrinth (
api.modrinth.com) — project stats, creator analytics, and notifications, using your Modrinth personal access token. - GitHub (
api.github.com) — repository issues for projects you configure, using an optional GitHub token.
Those services process requests under their own privacy policies. EST only sends what is needed to fetch the stats and messages you asked for.
4.2 CurseForge search fallback
If the official CurseForge API cannot resolve a project slug, EST may query a public read-only proxy (
api.curse.tools) with the slug only — not your API key.
4.3 Support links
If you click Support links (website, Discord, donate), your default browser opens those pages under their own policies. EST does not embed third-party advertising.
4.4 Local agent API
EST optionally exposes a localhost-only HTTP API on 127.0.0.1 (default port 8791) so
local tools such as Cursor can trigger refreshes. It is not reachable from other devices on your network by
default and does not expose raw tokens in responses.
4.5 Links you open
When you click external links (CurseForge Authors, Modrinth, GitHub Releases, etc.), your default browser opens those sites under their own policies.
5. Website (extraspecialstudio.co.uk)
Our studio website may show optional third-party display advertising on wide screens (see the site privacy policy). The EST desktop app does not show those ads.
6. Legal bases (UK / EEA)
Where UK GDPR or similar law applies:
- Legitimate interests — providing EST, improving the app, preventing abuse, and operating our website.
- Consent — where you choose to add API tokens and sync third-party data (you can withdraw by removing tokens).
7. Retention
- On your PC — until you delete it or uninstall EST.
- Support messages — retained as long as needed to resolve your request.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal data we hold about you (chiefly support records — not data that exists only on your PC).
Contact us via Discord or GitHub. You may also complain to your local data protection authority.
9. Children
EST is not directed at children under 13. We do not knowingly collect personal data from children.
11. Changes
We may update this policy. The effective date at the top will change. Continued use of EST after an update means you accept the revised policy for new processing.
See also: Terms of Service (EULA)