RustCenter

Privacy Policy

Last updated: October 1, 2026

Summary

  • We keep only what the Service needs to work and what the law requires: your account, your plan, your servers, and access and security records.
  • We do not sell your data, use it for advertising, or use third-party analytics or tracking tools.
  • Sign-in is handled by Clerk and payments by Stripe; we never receive your password or your card details.
  • You can access, correct, export or delete your data.

1. Who is responsible for your data

This Policy explains how RustCenter (the rustcenter.org website, the RustCenter app, the Server Monitor plugin and related services) handles your personal data, and supplements the Terms of Use. It follows the applicable data protection laws, such as the LGPD and the GDPR.

For any privacy matter, including exercising your rights, write to eremitasfaq@gmail.com. This is our channel for data subjects and data protection authorities.

2. What data we process

  • Account: name, e-mail, profile picture and account identifiers, provided by you or by the sign-in service you choose, through Clerk, our authentication provider. Clerk also processes technical sign-in data, such as IP address and device, to protect your account. Passwords are held by Clerk; we have no access to them. We also record when you accept the Terms of Use and this Policy.
  • Sessions and security: sign-in and sign-out date and time, device type, operating system, browser, a partially masked user agent and, when available, approximate country and city. In these records, the IP address is stored only in encoded (hashed) form.
  • Access logs: the IP address and the date and time your account uses the website and the app, stored encrypted. The law requires keeping them for 6 months, and they are only disclosed to others under a court order.
  • Subscription and payments: Stripe customer and subscription identifiers, plan, status and billing dates. Card details are entered directly with Stripe; we never receive the full card number.
  • Servers (Server Monitor): server name, IP address and port, token and access level, plugin list and versions, performance metrics (such as FPS, entities, plugin execution time and number of players online), events, alerts and the notes you create. Remote console commands and server responses are relayed in real time and are not recorded. When a token is used from an unexpected IP address, we record that IP and user agent to alert you.
  • Plugin inventory: the list of plugins detected on your servers, stored encrypted, for features such as comparing servers.
  • CodeFling account (optional): username and identifier, access token (stored encrypted), public profile data, purchases (product, date, price and license) and favorites.
  • Plugin reviews: the ratings, titles and comments you post.
  • Desktop app: for sign-in, plan checks and updates, the app tells the website its version, operating system and architecture.
  • Support: whatever you send us when asking for help.
  • Preferences: language and interface preferences.

We do not ask for sensitive personal data, and we do not use advertising cookies or third-party analytics or tracking tools.

Data about the players on your server. Server Monitor stores only aggregate numbers, such as how many players are online. Player information that passes through the Service, such as the response to a command that lists players, is shown in real time and is not recorded. For that data, you, as the server owner, are the controller, and RustCenter acts as a processor following your instructions.

3. Why we use data and on what legal basis

PurposeLegal basis
Creating and maintaining your account, signing you in on the website and the app, and providing the features you use (monitoring, console, catalogs, CodeFling integration)Performance of a contract
Billing subscriptions, keeping payment records and meeting legal and tax obligationsPerformance of a contract and legal obligation
Security, fraud and abuse prevention, auditing and alerts about token misuseLegitimate interest and exercise of rights
Keeping access logs for the period required by lawLegal obligation
Communications about your account, billing and changes to the ServicePerformance of a contract and legitimate interest
Handling support and data subject requestsPerformance of a contract and legal obligation
Defending rights in judicial, administrative or arbitration proceedingsExercise of rights

We do not sell, rent or trade personal data, and we do not use it for advertising.

4. Who we share data with

We share data only when needed to provide the Service, with providers that process it on our behalf:

  • Clerk — sign-in and account management;
  • Stripe — payments and subscriptions;
  • Hostinger — servers that run the website and the database;
  • GitHub — delivery of app downloads and updates;
  • CodeFling and uMod — access to the public catalogs; if you link your CodeFling account, requests about your account use your token;
  • Discord — only if you set up integrations in the app; in that case, the messages you choose to send go to Discord.

We may also share data to comply with the law or an order from a competent authority, to protect the rights of RustCenter, users or others, and with whoever comes to operate the Service in our place, who will be bound by this Policy.

5. International transfers

Some providers, such as Clerk and Stripe, process data in other countries, mainly in the United States. These transfers are necessary to provide the Service and are covered by the contractual safeguards those providers offer.

6. How long we keep data

  • Account, plan, servers and other Service data: for as long as your account exists.
  • Session records: 60 days.
  • Access logs (IP, date and time): 6 months, including after account deletion, as the law requires.
  • Audit and security records: 90 days, including after account deletion, to prevent fraud and defend rights.
  • Server Monitor metrics: up to 30 days.
  • Plugin inventory: deleted automatically after 50 days without updates.
  • Database backups: taken weekly and replaced within about six weeks.
  • Payment records at Stripe: for as long as required by law and payment network rules, under Stripe's policy.

When you delete your account, the data linked to it is deleted from our database, except for the records above that the law allows or requires us to keep. Plugin reviews you posted may remain visible without identifying you.

7. Your rights

Under the applicable data protection law (such as the LGPD or the GDPR), you may request at any time:

  • confirmation that we process your data, and access to it;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
  • data portability;
  • deletion of data processed based on your consent;
  • information about who we share your data with;
  • information about the option not to consent and its consequences, and withdrawal of consent;
  • objection to processing that does not comply with the law;
  • review of decisions made solely by automated processing.

You can do much of this directly in the dashboard: edit your profile, unlink your CodeFling account, remove servers and delete your account. For anything else, write to eremitasfaq@gmail.com from your account e-mail. We may ask for information to confirm your identity, and we reply within 15 days. You may also file a complaint with the data protection authority of your country.

8. Security

We use encrypted connections (HTTPS), store tokens and third-party credentials encrypted, store IP addresses encrypted or in encoded form, restrict access to our systems and keep backups. No system is completely secure: if a security incident may pose a significant risk or harm to you, we will notify you and the authorities as required by law. You help too by protecting your account, devices and tokens.

9. Cookies and browser storage

  • Essential cookies from Clerk keep you signed in and protect your session. On the payment page, Stripe uses its own cookies to prevent fraud.
  • Local browser storage keeps your language, interface preferences and a copy of the public prices.
  • We do not use advertising or analytics cookies. Because the cookies above are needed for the Service to work, we do not ask for consent to them; blocking them may prevent you from signing in.

10. Children and teenagers

The Service is not directed at people under 18, who may only use it with the permission of a parent or guardian. We do not knowingly collect data from children. If you learn of an account belonging to a child, write to eremitasfaq@gmail.com so we can delete it.

11. Users in Europe and the United Kingdom

If you are in the European Economic Area or the United Kingdom, the legal bases above correspond to those of the GDPR: performance of a contract, legitimate interests and legal obligation. You have the rights in section 7, including the right to complain to the data protection authority of your country. Use the same channel: eremitasfaq@gmail.com.

12. Changes to this Policy

We may update this Policy. The date at the top shows the version in effect, and material changes will be announced on the website or by e-mail.

13. Contact

RustCenter — E-mail: eremitasfaq@gmail.com