Legal

Privacy Policy

What Rust Server Admin collects, why it needs it, and who else sees it. This covers both the website at rustserveradmin.com and the desktop app.

Last updated: August 13, 2026

Who this covers

Rust Server Admin is operated by rustserveradmin as a sole operator. “We” and “us” below mean that operator; “you” means the person using the app to administer a Rust game server.

The desktop app and the web app are not the same in privacy terms, and the difference matters more than anything else on this page: the desktop app can be used entirely locally, in which case your server credentials and plugin data never reach us at all. Signing in and saving a server on the web is what causes data to be stored on our side.

Your account

There is no password to create. You sign in with Discord or Steam, and we store what those providers return:

Account identifier
Your Discord or Steam ID, returned when you sign in. This is what your servers and settings are attached to.
Display name and avatar
Shown in the app so you can tell which account you are signed in as.
Email address
Provided by Discord if you sign in that way. Steam does not release an email address, so Steam accounts are given a placeholder in the form of a steamcommunity.com address that is never used to contact you.
Subscription state
Whether you have an active subscription or trial, and when it ends.

Your servers

Everything in this section only exists once you save a server while signed in on the web. The desktop app stores the equivalent data in a local file on your own machine.

Connection details
Host, port, username, protocol and plugin path for each server you save. Stored as ordinary text because the app has to show you what it connects to.
SFTP and RCON passwords
Encrypted with AES-256-GCM before they are written to the database. Only saved if you add a server while signed in on the web — the desktop app keeps them on your machine.
Plugin inventory
Which plugins are installed on your server, their versions, and what the marketplaces list as current.
Console history
Recent RCON console output is cached in your browser so the console survives a page reload. It can include in-game chat and connect lines.

The security page goes into detail on the encryption, what is never logged, and the limits.

Data about your players

This is data about other people

The Players page keeps a history for everyone who connects to a server you administer. Those people are not users of this app, they have not agreed to this policy, and in most places the law treats you — the server owner — as the party responsible for their data. We store it on your behalf so your admin tools work; deciding whether you should be collecting it, and telling your players if your jurisdiction requires it, is yours.

For each player seen on your server, we keep:

SteamID64
Identifies the player across sessions and is the key the rest of the record hangs off.
Display name and recent aliases
The last few distinct names a player has used, for recognising name-changers.
Playtime and session counts
Total time played, number of connections, first and last seen.
F7 reports
In-game reports the player has filed and reports filed about them.
Team membership
Team ID and whether they lead it.
Last IP address and country
The raw IP a player last connected from, plus the country it resolves to. This is the one piece of directly identifying data about a third party that the product stores, and it exists to make shared-IP alt detection work.
Family Sharing owner
If the Rust licence is family-shared, the SteamID of the owning account — also used for alt detection.

This history is visible only to the account that owns the server. IP addresses are left out of API responses unless explicitly requested, and are not used for anything beyond alt detection and resolving a country flag. We do not sell it, share it between accounts, or use it to build any cross-server profile.

One related detail: the RCON console output cached in your browser can contain chat messages and connect lines, which include player IPs. That cache lives in your browser, not on our servers, and is cleared when you sign out or switch accounts.

Payments

Subscriptions are handled by Stripe. Card numbers, expiry dates and security codes go to Stripe directly and never reach our servers — we store only a customer reference and your subscription status. Stripe's own privacy policy governs what they hold.

Analytics

The website uses aggregate visitor analytics — Statcounter, Vercel Analytics, and Cloudflare's traffic analytics — to see which pages people find useful. These report counts and trends, not individual profiles, and none of them receive your server credentials or player data.

The desktop app runs no analytics at all. Every analytics script is excluded from the desktop build, so using the desktop app sends us no usage telemetry.

Who else is involved

Stripe
Payments and subscription management. Card details go to Stripe directly and never reach our servers.
Discord
Sign-in, and the community server. We receive your Discord ID, username and avatar.
Steam
Sign-in via Steam OpenID. We receive your SteamID and public profile name.
MongoDB Atlas
The hosted database where accounts, servers and player history are stored.
Vercel
Hosts the web application and provides aggregate page analytics.
Statcounter
Aggregate visitor statistics for the marketing site.
Cloudflare
Sits in front of the site and provides aggregate traffic analytics.

When the app checks for plugin updates it requests public pages from uMod, Codefling and Lone.Design. Those requests come from our servers on your behalf and carry no information about you.

What is stored on your own device

The web app keeps your settings, plugin inventory and console history in your browser's local storage so the app is usable without refetching everything on every page load. When you sign out or sign in as a different account, that cache is wiped so one account's data cannot be left behind for the next.

The desktop app keeps the equivalent data in its own configuration file in your user profile directory.

Retention and deletion

Data is kept while your account exists. Ending a subscription does not delete anything — your servers, plugin inventory and player history stay, and stay readable; what stops is the ability to send commands to your game server.

You can delete individual servers and their stored credentials from the app at any time. To have your account and everything attached to it removed, ask on Discord and we will do it. Deleted server credentials are removed from the database rather than retained in an archive.

Changes to this policy

If this policy changes materially, the date at the top of the page changes with it. The version published here is the current one.

Contact

Questions about this policy, requests to delete your data, or anything else — reach us on Discord. It is the fastest route and it is where support already happens.