Rustolia

Privacy Policy

Last updated August 26, 2026

What this covers

This policy covers rustolia.net ("Rustolia") – a self-hosted, team-shared dashboard for Rust's Rust+ companion protocol – and the Rustolia Steam Pairing Helper Chrome extension, which exists solely to help you sign in to Rustolia. There is no separate company behind Rustolia; it's operated directly by its developer. Questions about either can be sent to privacy@rustolia.net.

The Chrome extension, specifically

Rust+'s own pairing flow expects to run inside Facepunch's official mobile app, which hands a login token to that app through a bridge (window.ReactNativeWebView) that only exists inside a real app WebView. The extension exists to stand in for that one bridge when you complete that same login in an ordinary browser tab instead, so Rustolia receives the token the way the mobile app normally would.

That is the extension's entire job. Specifically, it:

  • Only ever runs on companion-rust.facepunch.com – the single page Steam redirects you to when you choose to sign in for Rust+ pairing. It does nothing on any other site, including the rest of Rustolia.
  • Requests no browser permissions at all – no access to your browsing history, other tabs, cookies, bookmarks, or any site other than the one above.
  • When that page produces a login token and your SteamID (the same values Facepunch would normally hand to the official app), the extension forwards exactly those two values – nothing else – to Rustolia over HTTPS, and nothing further runs after that.
  • Doesn't use browser storage, doesn't phone home anywhere else, contains no analytics, trackers, or ads, and doesn't modify any page's content or behavior beyond providing that one bridge.

The token and SteamID it forwards are only meaningful to whoever is already signed in to Rustolia – see "Rust+ pairing data" below for what happens to them next.

Signing in to Rustolia

Rustolia uses Steam's own sign-in (OpenID) – you authenticate directly with Steam, and Rustolia never sees your Steam password or any other Steam credential. On a successful sign-in, Steam tells Rustolia your SteamID64, display name, and public avatar image, which are stored so the dashboard can recognize you on future visits and show your name/avatar to your teammates. A signed session cookie (not readable by other sites) keeps you signed in for up to 30 days.

Access to Rustolia itself is allowlisted – a SteamID has to be explicitly added before it can sign in at all, by an existing admin.

Rust+ pairing data

Once you complete Rust+ pairing (with or without the extension), Rustolia stores the credential Facepunch issues for that pairing, encrypted at rest, so it can maintain a live connection to your Rust server on your behalf – the same kind of connection the official Rust+ app maintains, just running on Rustolia's server instead of your phone.

Through that connection, Rustolia receives and stores live gameplay data for the specific Rust server(s) you've paired: your team's live player positions, team chat messages, in-game death locations, map markers your team places, and the state of any smart switches or cameras your team has added. Because Rust+ is inherently team-based, this includes the same live location and chat data your teammates would also see through the official app – Rustolia doesn't expose anything to your team that Rust+ itself doesn't already share with them. Access to any given server's data is limited to people currently on that in-game team who have also completed Rust+ pairing themselves.

Other services Rustolia talks to

  • Steam / Valve – for sign-in (OpenID) and profile info, as described above.
  • Facepunch's Rust+ companion service – the live game-server connection every feature is built on.
  • BattleMetrics – used, where configured, to look up a server's current population and online player names. Only the server's IP and port are sent to BattleMetrics for this – no account or personal data.
  • Railway – the hosting provider Rustolia runs on.

Rustolia doesn't use advertising networks, analytics/tracking scripts, or any service that profiles you across other sites.

What Rustolia never does

  • Never sells or rents any data to anyone, for any reason.
  • Never shares your data with advertisers.
  • Never uses the data it holds for anything other than running the dashboard you and your team asked it to run.

Data retention and deletion

Data is kept for as long as your account and paired servers remain active, so the dashboard keeps working across sessions. To request deletion of your account, your Rust+ pairing credentials, or any other data Rustolia holds about you, email privacy@rustolia.net and it will be removed.

Security

All traffic to Rustolia is served over HTTPS. Sensitive credentials (Rust+ pairing tokens) are encrypted at rest, separately from the database rows that reference them. Session cookies are signed and marked HTTP-only, so they can't be read by page scripts or other sites.

Children's privacy

Rustolia is not directed at children and isn't knowingly used by anyone under 13.

Changes to this policy

If this policy changes, the "last updated" date at the top of this page will change with it. Continued use of Rustolia after an update means you accept the revised policy.

Contact

Questions, requests, or concerns about any of the above: privacy@rustolia.net

Back to Rustolia