Who we are
syky is a utility client for Minecraft, run by an independent developer. For everything on this page, including any request about your data, write to support@sykyclient.com. We answer within a month, usually much sooner.
This page covers the syky client, the syky servers it talks to, this website and the account pages at sykyclient.com.
What we collect, and why
Your account
If you create one: your username, your email address and your password, stored as an Argon2id hash that cannot be turned back into the password. If you sign in with Google or Discord instead, we keep that service's account number and your email address from it; your name there is only used to suggest a username.
Then whatever you add: a profile picture, the Minecraft profiles you prove you own, your friends, the messages you send them, the players you block and any reports you file. We also keep when you joined and how many hours you have played with syky, which your profile shows.
Your game install
The first time the client goes online, the server gives it a random install number and a secret token; we keep only a hash of the token. With it we keep the syky and Minecraft versions, your operating system, when the install was first and last seen, how long it has played, and which account it is signed in to, if any.
From syky 0.1.4 the client also sends a fingerprint of the computer: SHA-256 hashes of the computer's SMBIOS UUID, the motherboard, the system disk and the operating system's install id. The identifiers themselves never leave your PC, and a hash cannot be turned back into a serial number. We record which installs and accounts were seen with each hash and when. This lets us count computers rather than installs, and recognise the same computer behind several accounts when we look into abuse.
While you play
With online features on, the client tells the server which server you are playing on, and your in-game name and UUID there. This lives in the server's memory only, while you are connected. Your friends see that you are online and, unless you turn server sharing off, which server you are on — the network's name, such as hypixel.net, never the address you typed. We keep, per day, how many syky players were on each network at most, which names nobody.
To show badges and cosmetics, the client asks which players around you use syky, sending their in-game names and UUIDs. The server compares them with who is online and stores nothing about them.
Statistics
For each install, we record the days it connected, with its versions and operating system, and add up how long the game ran. That is how we know how many people use syky and whether they come back.
Which modules you use, how long each is on and how often you switch it on, is counted only if you turn it on with .syky account stats on. It is off unless you do.
This website and our logs
Like every web server, ours note each request: your IP address, the page asked for and your browser's name. We use these logs to keep the service running and to stop attacks, and delete them after 30 days. One-time secrets in links, such as a password-reset token, are cut out before a line is written.
The site runs no analytics and loads nothing from other companies: its fonts and scripts are our own. The account pages set only the cookies they need to work:
| Cookie | What it does | Lasts |
|---|---|---|
__Host-syky_session | Keeps you signed in | 30 days |
__Host-syky_trust | Remembers a browser that already confirmed a sign-in by email | 90 days |
__Host-syky_login | Holds a sign-in while you type the emailed code | 10 minutes |
syky_oauth | Protects a Google or Discord sign-in in progress | 10 minutes |
syky_signup | Holds a Google or Discord sign-up until you pick a username | 1 hour |
We only send email about your account: confirming it, a sign-in code, a password reset, and a warning when someone tries to sign up with your address. No newsletters. A message leaves our queue as soon as it is sent.
Who else receives data
We never sell data, rent it, or share it for advertising. These services see some of it, for the reasons given:
| Service | What it sees | Why |
|---|---|---|
| OVH (Warsaw, Poland) | Everything on our servers | Hosts the servers and the database |
| Brevo (France) | Your email address and our email to you | Delivers account email |
| Cloudflare | Only which of our addresses you looked up | Answers DNS for sykyclient.com; your traffic does not pass through it |
| Google, Discord | That you signed in to syky | Only if you choose to sign in with them |
| Microsoft (Mojang) or Ely.by | Your in-game name | Confirms you own the Minecraft profile you play as |
| Have I Been Pwned | The first 5 characters of a hash of your new password | Warns you if the password is known from a leak; the password itself is never sent |
| GitHub | Your download request | Only if our own download server does not answer |
Some modules fetch things from other services while you use them, straight from your PC: Tier Tagger looks up players' names on tier lists (mctiers.com, qaztiers.net, atiers.net, mytiers.ru, cistiers.com), and the music card looks up album covers with Apple's iTunes Search. Those services see your IP address and what was looked up. Discord Rich Presence talks only to the Discord app on your own computer.
How long we keep it
| What | Kept |
|---|---|
| Your account, picture, friends, blocks, verified Minecraft profiles | Until you delete the account |
| Messages | 180 days |
| Being signed in on a browser | 30 days; a trusted browser 90 days |
| An unconfirmed sign-up · a reset link · a sign-in code | 24 hours · 1 hour · 10 minutes |
| An install | 180 days after last seen; 1 year if signed in to an account |
| The days an install connected | 130 days, then only totals that name nobody |
| Module statistics per install | 8 days, then only totals that name nobody |
| Hardware hashes and where they were seen | 2 years after last seen |
| Server logs with IP addresses | 30 days |
| Reports you filed | As long as moderation needs them |
| Backups of the database | At most 30 days |
Deleting your account
Go to Account → Settings → Delete account. Your account, profile picture, sign-in methods, friends, messages (in both people's chats), blocks, verified Minecraft profiles and cosmetics are deleted at once, and every install signed in to it is signed out.
A few things stay for a while, not tied to your account any more: your installs until they expire as above, hardware hashes for up to 2 years (to prevent abuse), reports you filed without your name, logs for 30 days and backups for 30 days. Your username stays reserved for 30 days so nobody can take it to pretend to be you. If you want an install's or your hardware's records removed too, write to support@sykyclient.com.
Your controls in the game
| Command | What it does |
|---|---|
.syky account online off | Turns every online feature off: the client connects to nothing and sends nothing |
.syky account stats on | off | Starts or stops module statistics |
.syky account share on | off | Shows or hides from friends which server you are on |
.syky account logout | Signs this install out of your account |
On the website, Account → Devices lists every install signed in to your account and signs any of them out.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to limit what we do with it, or object to it, and to receive it in a format you can take elsewhere. Write to support@sykyclient.com from the email address on your account, or tell us your username, and we will do it within a month. If you think we handle your data wrongly, you can also complain to the data protection authority where you live.
Why we are allowed to
Your account and everything it does (friends, messages, cosmetics, hours played) is the service you asked for. Security, logs, hardware hashes, activity counts and stopping abuse are our legitimate interest in keeping syky working, safe and honest, kept to the minimum above. Module statistics rely on your consent, which you can withdraw at any time with .syky account stats off.
Children
syky is not meant for children under 13. Where the law sets a higher age for agreeing to this on your own (up to 16 in parts of the EU), you need a parent's permission to create an account. If we learn that an account belongs to a child under 13, we delete it; parents can write to support@sykyclient.com.
Security
Everything between the client, the website and our servers is encrypted. Passwords are hashed with Argon2id; install tokens, sign-in codes and email links are stored only as hashes; a new browser confirms its first sign-in with a code sent to your email. If data about you is ever exposed in a way that puts you at risk, we will tell you.
Changes
When this page changes, the date at the top changes with it. If a change affects what we collect, we will say so on our Discord and on this site before it takes effect.