This policy covers rustolia.net ("Rustolia") – a self-hosted, team-shared dashboard for Rust's Rust+ companion protocol – and the Rustolia Steam Pairing Helper Chrome extension, which exists solely to help you sign in to Rustolia. There is no separate company behind Rustolia; it's operated directly by its developer. Questions about either can be sent to privacy@rustolia.net.
Rust+'s own pairing flow expects to run inside Facepunch's official mobile app, which hands a login token to that app through a bridge (window.ReactNativeWebView) that only exists inside a real app WebView. The extension exists to stand in for that one bridge when you complete that same login in an ordinary browser tab instead, so Rustolia receives the token the way the mobile app normally would.
That is the extension's entire job. Specifically, it:
companion-rust.facepunch.com – the single page Steam redirects you to when you choose to sign in for Rust+ pairing. It does nothing on any other site, including the rest of Rustolia.The token and SteamID it forwards are only meaningful to whoever is already signed in to Rustolia – see "Rust+ pairing data" below for what happens to them next.
Rustolia uses Steam's own sign-in (OpenID) – you authenticate directly with Steam, and Rustolia never sees your Steam password or any other Steam credential. On a successful sign-in, Steam tells Rustolia your SteamID64, display name, and public avatar image, which are stored so the dashboard can recognize you on future visits and show your name/avatar to your teammates. A signed session cookie (not readable by other sites) keeps you signed in for up to 30 days.
Access to Rustolia itself is allowlisted – a SteamID has to be explicitly added before it can sign in at all, by an existing admin.
Once you complete Rust+ pairing (with or without the extension), Rustolia stores the credential Facepunch issues for that pairing, encrypted at rest, so it can maintain a live connection to your Rust server on your behalf – the same kind of connection the official Rust+ app maintains, just running on Rustolia's server instead of your phone.
Through that connection, Rustolia receives and stores live gameplay data for the specific Rust server(s) you've paired: your team's live player positions, team chat messages, in-game death locations, map markers your team places, and the state of any smart switches or cameras your team has added. Because Rust+ is inherently team-based, this includes the same live location and chat data your teammates would also see through the official app – Rustolia doesn't expose anything to your team that Rust+ itself doesn't already share with them. Access to any given server's data is limited to people currently on that in-game team who have also completed Rust+ pairing themselves.
Rustolia doesn't use advertising networks, analytics/tracking scripts, or any service that profiles you across other sites.
Data is kept for as long as your account and paired servers remain active, so the dashboard keeps working across sessions. To request deletion of your account, your Rust+ pairing credentials, or any other data Rustolia holds about you, email privacy@rustolia.net and it will be removed.
All traffic to Rustolia is served over HTTPS. Sensitive credentials (Rust+ pairing tokens) are encrypted at rest, separately from the database rows that reference them. Session cookies are signed and marked HTTP-only, so they can't be read by page scripts or other sites.
Rustolia is not directed at children and isn't knowingly used by anyone under 13.
If this policy changes, the "last updated" date at the top of this page will change with it. Continued use of Rustolia after an update means you accept the revised policy.
Questions, requests, or concerns about any of the above: privacy@rustolia.net