Privacy Policy
Last updated: September 15, 2026
This Privacy Policy explains what Rustomat ("we," "us," "our") collects, why, and what rights you have over it. We built Rustomat as a small, independently-run tool for Rust players, this policy is written to actually match what the app does, not as boilerplate. For any data-related request or question, reach us at admin@rustomat.net (see Section 12).
1. What We Collect
- Account info: username, a bcrypt hash of your password (never the password itself), and an API token used to authenticate the overlay client.
- Steam ID: associated with your account once you pair Rust+, used to identify you to the game servers you play on.
- Rust+ pairing credentials: the config file generated by the RustPlus.py Link Companion extension (an FCM/Google device registration tied to your Steam account), used solely to receive the same push notifications the official Rust+ app would, so Rustomat can show them to you.
- Device and server data: the Smart Switches/Alarms/Storage Monitors and servers you've paired with, and their live state, the same information the official Rust+ app already shows you.
- Usage data: playtime per server, API call counts, and similar operational metrics, used for the stats shown on your own Account page and to keep the Service running within Rust+'s own rate limits.
- Tracked player data (optional): if you use the Player Tracking feature, the BattleMetrics player id and optional label/Steam ID you enter for players you want online/offline notifications about. This is data about someone else, not you, entered voluntarily and only used to check public online-status information.
- Technical/security data: IP addresses, for rate-limiting abuse and for security-relevant logs (e.g. tamper reports, admin action audit logs). Not used for tracking or advertising.
- Support/community data: anything you tell us directly, e.g. in a Discord ticket or support message.
What we deliberately don't collect: your Rust+ webhook URL for Discord automations lives in your own local overlay settings file and is used directly from your machine, it's never sent to or stored on our servers. We also don't currently process payment card data ourselves, see Section 5.
2. Why We Collect It
Mainly to operate your account and the features you're actively using, that's the "performance of a contract" basis if you're covered by GDPR. Security-related data (IP addresses, tamper/audit logs) is collected under our legitimate interest in keeping the Service and its users safe from abuse. Optional features, Discord community participation, Player Tracking, linking pairing credentials, are used only because you chose to use them, and you can stop at any time by not using that feature and removing whatever you'd entered for it.
3. Who We Share It With
We don't sell your data. It's shared only where the Service actually requires it to function:
- Steam / Rust+ / Facepunch: the game's own systems, which is the entire point of pairing.
- Google / Firebase Cloud Messaging: your linked pairing credentials are used to maintain the same FCM connection the Rust+ app itself uses, so we can relay its push notifications to you. We don't use this connection for anything beyond that.
- Discord: only if you link a webhook (sent directly from your own machine, see Section 1) or join our community server, which is governed by Discord's own privacy policy.
- BattleMetrics: only the BattleMetrics player ids you manually enter via Player Tracking, to check their public online status. Your own account data is never sent to BattleMetrics.
- Our hosting provider: infrastructure that stores and runs the Service, bound to keep data confidential and secure.
We may also disclose information if legally required to (e.g. a valid court order), or to protect the rights, safety, or property of Rustomat or our users.
4. International Data Transfers
Our infrastructure may be located in a country other than yours, so your data may be processed outside your home country, including outside the EEA if you're an EU user. Where that applies, we take reasonable steps to keep it protected consistent with this policy.
5. Payments
We don't currently process card payments directly, upgrades are handled via coupon codes or a manually-arranged trade (e.g. Rust/CS2 skins) coordinated through Discord, so we don't collect or store any payment card data ourselves. If we add a payment processor (e.g. Stripe) in the future, this policy will be updated to describe exactly what that processor collects on our behalf before it goes live.
6. Cookies
We use one first-party session cookie to keep you logged in and to protect forms against CSRF attacks. It's strictly necessary for the Service to function, we don't use analytics, advertising, or tracking cookies of any kind.
7. Data Retention
We keep your data while your account is active. If you ask us to delete your account, we'll delete or anonymize your personal data within 30 days, except where we're required to keep something longer for legal, security, or fraud-prevention reasons (e.g. a limited audit-log entry).
8. Security
Passwords are hashed with bcrypt, never stored in plain text. Optional two-factor authentication (TOTP) is available on every account and required for staff/admin accounts. The Service is served over HTTPS end to end. No system is perfectly secure, but we take reasonable, industry-standard steps to protect your data.
9. Your Rights
If you're in the EU/EEA/UK (GDPR): you have the right to access, correct, delete, restrict, or export your personal data, to object to certain processing, to withdraw consent at any time for anything based on consent, and to lodge a complaint with your local data protection authority.
If you're in the US: depending on your state, you may have the right to know what personal information we've collected about you, to request deletion of it, and to not be discriminated against for exercising those rights.
To exercise any of these, contact us at admin@rustomat.net. You can also just delete most of what we hold on you yourself, unlink pairing credentials, remove tracked players, or regenerate your API key, directly from your Account page.
10. Children's Privacy
Rust itself is rated for mature audiences, and the Service isn't directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us and we'll remove it.
11. Changes to This Policy
If we make a material change to this policy, we'll update the date at the top and make a reasonable effort to let active users know.
12. Contact
Questions about this policy, or a request about your data? Reach us at admin@rustomat.net or through our Discord.
MAT