Privacy Policy
1. Controller
The entity responsible for processing your data ("we", "us") in the sense of Art. 4 (7) GDPR is:
KAYDINI Software
Inhaber: Marcel Jahn
Brockendorfer Weg 9
50189 Elsdorf, Germany
Email: [email protected]
2. Overview
rustchad is a Discord bot and web dashboard for the game Rust: server monitoring, event notifications, smart-device control, and player/team tracking. This page covers the web app, the Discord bot, and the "rustchad Companion" browser extension together, since data collected by one can flow to the others.
3. Account data
Signing up stores your email address and either a bcrypt password hash or, if you use "Sign in with Google", your Google account ID - we never see or store your Google password. If you connect a Discord server, we store that server's Discord guild ID, name, and icon. If you pair a Rust server, your Rust+ credentials (player token and ID) are encrypted at rest and only ever decrypted by the bot process, never the web app. If you track players, we store their SteamID64, publicly-visible Steam name history, and (once matched) their BattleMetrics profile ID - all public identifiers, not private data about those players.
4. Cookies and the browser extension
The web app sets one cookie, app_session, to keep you logged in - no third-party or advertising cookies. Website usage is measured with a self-hosted, cookieless analytics tool (Umami); it doesn't set cookies or track you across sites.
Once you're logged in, product usage (e.g. pairing a server, toggling a smart device) and billing events (e.g. starting checkout, a subscription renewing) are also sent to that same analytics tool, tagged with your plan and a one-way, non-reversible reference derived from your account - never your email or account ID directly, and it can't be traced back to your account once it's deleted. This helps us understand which features are actually used and improve the product; it's never shared with anyone else or used for advertising.
Which link or search brought you to rustchad the first time is stored once on your account after you sign up (e.g. "from a Google search" or "from a specific ad campaign"), so we can tell which marketing efforts are worthwhile. Before signup, this is held only in your browser's local storage, not a cookie, and never leaves your device until you actually create an account.
The optional "rustchad Companion" browser extension reads that same app_session cookie (only for rustchad's own domain) to authenticate its own requests to our backend on your behalf. On Rust+'s login page, it relays the login token Facepunch's page produces to our backend to complete server pairing. On BattleMetrics server pages, it reads the visible server address and the "Active players" list already shown on that page, and reports which of your tracked players are currently online - it never sends this to anyone but our own backend, and never reads pages outside Rust+'s login flow or BattleMetrics's Rust server pages.
5. Payments
Stripe processes all payments on our behalf - we never see or store your card details. Stripe shares back a customer ID, subscription status, and renewal date, which we store to know your plan. Stripe's privacy policy ↗
6. Other third parties
Discord (server/guild info, sending bot messages), Valve/Steam (public profile names for tracked players), Facepunch/Rust+ (server and event data), and BattleMetrics (client-side only, via the browser extension - we never call BattleMetrics's own API or servers). Error reports (Sentry) may include technical details of a crash, not your account data by design.
Call Alerts phone contacts
When you use Call Alerts, we store the phone numbers and optional labels you add, plus their verification status. We send phone numbers to Twilio to deliver verification SMS and alarm calls; the spoken call also includes the alarm name. Labels and verification codes are not stored in call history or sent to analytics. You can remove contacts from Account. Recent call usage remains without the removed contact reference to enforce the weekly allowance, and is deleted after 30 days by our periodic cleanup. Deleting your account removes its contacts and call history.
7. Retention
Event history (server events, camera sightings) is kept for 3-30 days depending on your plan, and never longer than 30 days regardless of plan. Deleting your account removes your user record and everything linked to it (Discord/Rust server connections, tracked players, event history) - this can't be undone.
8. Your rights
You can view and delete your own account data from the dashboard at any time. For anything you can't do yourself there - access, correction, or a full export - contact us at [email protected].