Anish Shah

Privacy · personal streams

Personal data stays deliberately small.

These connectors retrieve Anish’s own public activity after owner-authorized setup. They do not collect a visitor’s Steam, Spotify, Discogs, MyAnimeList, Hardcover, or Strava account data.

Owner-controlled · sanitized public snapshots only

Six deliberately different connections

Each provider has a narrow input, a bounded public output, and an explicit deletion path.

MyAnimeList · Watch
Studio stores an encrypted app client secret plus renewable access and refresh tokens. A pending authorization stores only a hashed state and encrypted transaction for at most ten minutes. D1 stores a complete sanitized library snapshot so status, genre, era, and score distributions reflect the whole collection. The public endpoint returns those distributions, one bounded gallery page, and a profile link derived from the authorized identity. Cover URLs are reduced to host-free references and served only through the bounded same-origin artwork endpoint while the snapshot remains published.
Hardcover · Read
Studio stores one encrypted owner API token. The authenticated user ID is used only to request the owner library; it is not published. D1 stores a complete sanitized shelf snapshot; the public endpoint returns whole-shelf reading and rating distributions, one bounded gallery page, recent books, and a profile link derived from the authenticated username. Cover URLs are reduced to host-free references and never exposed to browser code.
Spotify · Listen
Studio stores an encrypted app client secret plus renewable access and refresh tokens. It requests only the permissions needed to identify the owner and retrieve Spotify’s Top Tracks affinity for its approximate four-week, six-month, and one-year windows. D1 stores at most twelve ordered tracks per window, reduced artwork references, synchronization dates, and the owner’s separate publication choice. The site does not store play counts, listening history, popularity, preview audio, country, subscription, or raw provider responses; it does not infer listening time, genre, trends, or a taste profile. An optional official track, album, or playlist Embed is blocked until a visitor explicitly chooses to load it.
Discogs · Collect
Studio stores an encrypted consumer secret, access token, and access-token secret after owner-authorized OAuth. D1 stores one sanitized snapshot of the owner’s physical collection. The public endpoint returns titles, artists, release years, normalized physical formats, copy counts, format and decade distributions, and a profile link. Copies and distinct releases remain separate counts. Images, conditions, ratings, notes, acquisition dates, folders, wantlists, inventory, marketplace data, pricing, sales, account identifiers, and raw provider responses are excluded.
Steam · Play
Studio encrypts the Web API key and SteamID64 together. D1 stores the complete public game library with rounded hours. The public endpoint returns whole-library totals and playtime bands, one bounded gallery page, and at most eight highlighted titles. Passwords, exact minutes, presence, friends, bans, achievements, inventories, real names, locations, remote artwork URLs, and raw responses are excluded. Documented game icon hashes may be stored as host-free references and served through the same-origin artwork endpoint.
Strava · Move
No Strava API credential or custom activity dataset is stored. Studio keeps the public athlete profile, an optional exact Strava-generated profile-feed, summary, activity, or route iframe URL, and its last anonymous frame check. A redirecting or blocked widget is not shown publicly; visitors receive the athlete-profile link instead. A working third-party iframe remains blocked until a visitor explicitly chooses to load it.

Storage and retention

MyAnimeList, Hardcover, Spotify, and Steam refresh no more than once every 12 hours unless the protected owner Studio requests a refresh. Discogs becomes refreshable after four hours and its catalog becomes unavailable six hours after the last successful synchronization. D1 retains at most the latest two complete sanitized snapshots for the other API providers and one current Discogs snapshot. Transient failures preserve only snapshots still inside their documented public window. Steam’s public fallback and Spotify’s API-derived display expire after 72 hours; expired Spotify metadata is deleted after 30 days.

Raw provider responses are processed in memory and discarded. Operational history is limited to provider, result, timestamps, safe error codes, and item counts; it never contains credentials, OAuth codes, or raw payloads.

Steam’s encrypted credential, sanitized snapshots, and operational sync metadata are declared as stored in: United States.

Disconnect means delete and unpublish

Disconnecting any stream removes that provider’s encrypted credentials or embed configuration, sanitized snapshots, pending OAuth transaction, sync history, and provider-specific audit history. The public stream becomes unavailable immediately. A minimal deletion event containing no provider values remains.

Replacing credentials invalidates in-flight work, clears the prior provider state, and requires a successful refresh before a new snapshot is public. If Steam stops returning public game details, every prior Steam snapshot is removed and replaced by a non-public visibility marker. Private games are never reconstructed or inferred.

Visitors and provider terms

Selecting Watch, Read, Listen, Collect, or Play requests only this site’s sanitized first-party snapshot. The Discogs catalog is not requested until Collect is active. Spotify album artwork is requested only after Listen is active. The Spotify player has a separate consent gate and is not requested until the visitor chooses to load it. Selecting Move requests the stored embed configuration, but no request reaches Strava until the visitor grants consent. The site does not collect a visitor’s account data from any of these providers.

Spotify content is attributed to Spotify and links back to the corresponding Spotify surface. Top Tracks means Spotify-calculated affinity for the labeled time window, not play counts or a listening-history export. This is a personal, noncommercial Spotify surface. The optional Spotify Embed may set or read provider cookies after consent. Review the Spotify Developer Terms and Spotify Embed Terms.

Discogs data is presented as a personal, noncommercial physical catalog and links back to individual Discogs release pages. This application uses Discogs’ API but is not affiliated with, sponsored or endorsed by Discogs. Review the Discogs API Terms of Use.

Data provided by Steam. This independent personal site is not endorsed by or affiliated with Valve. Review the Steam Web API Terms and Steam Profile Privacy guidance.

Steam Web API data is shown “as is,” “with all faults,” and “as available,” without warranties of accuracy, availability, or fitness. To the maximum extent permitted by law, Valve, Steam game publishers and developers, and their suppliers are not liable for damages arising from use of the Steam Web API or Steam data.

Accessibility and issue reporting

This site targets WCAG 2.2 Level AA and is tested with keyboard, screen-reader, zoom, reduced-motion, and high-contrast settings. That target is an ongoing practice, not a legal certification.

If something is difficult to use—or you notice a privacy or security concern—contact Anish through LinkedIn. Include the page, browser or assistive technology, and what you expected to happen when those details are safe to share.