Privacy
What the Rustexa product stores and why. Retention periods and the legal entity behind the product are not confirmed yet, and this page does not invent them.
Accounts
Creating an account asks for a username, an email address, and a password. Sign-up, sign-in, and password reset go through Supabase Auth. Rustexa application code does not store the password itself.
A confirmation email may be required before you can sign in. The account has an auth user id. The profile stores the username and, when you set them, a display name, bio, region, gameplay roles, and an avatar. Visibility toggles control whether the profile, bio, region, roles, stats, and Steam identity are shown.
Email Rustexa sends
When email is configured, Rustexa can send a welcome message after verification, a password-change notice, and a security notice. Those messages go through Resend via the Lovable connector. The from address in the product is Rustexa <noreply@auth.rustexa.com>. If the email keys are not configured, those messages are not sent.
Steam
Linking Steam is optional and uses Steam OpenID. A verified link stores the SteamID64, persona name, avatar URL, profile URL, and the time it was verified. When Steam returns them, Rust hours, last played, and the time of that check can be stored on the profile.
You can disconnect Steam from account settings. That clears the linked SteamID64, persona, avatar, profile URL, and verification time. Rust hours already stored on the profile are not cleared by that disconnect.
Discord
Linking Discord is optional. A link stores the Discord user id, username, display name, and when the name was observed or the account was linked.
The Discord bot delivers commands and alerts you configure. It stores the guild resources it manages so those Discord features can keep working.
Tracking, alerts, and community tools
While you are signed in, Rustexa can store servers you track, whether you asked for a wipe notification, alert subscriptions, in-app notifications, and skin watches (the skin, price thresholds, currency, and whether alerts are on).
Groups, LFG, and clan tools store what you submit there: listings, roles, applications, and invites.
While you are signed out, tracked server ids stay in this browser’s localStorage. They are not an account.
Public server observations
Rustexa observes public Rust servers through direct server queries and the Steam server list. Stored observations include server name, address, player counts, map identity, and wipe evidence.
A server query can include the names of players connected at that moment when the server reports them. Those names are public query data from the server. They are not Rustexa accounts.
Rustexa does not use BattleMetrics.
Browser storage
The Supabase auth client keeps the session in browser storage. The server explorer stores view and column choices in localStorage. The skin currency display preference is stored in localStorage. Signed-out tracked servers use localStorage.
Current product code does not set an analytics or advertising cookie, and Rustexa does not show a cookie banner.
IP addresses
The Discord bot bridge uses the connecting IP as an in-memory rate-limit key inside the worker process. That limiter does not write the IP to the database. No other product IP log is documented here.
Where the product runs
The application is built to run on Cloudflare Workers. Accounts and stored data go through the project’s Supabase database and auth. Account email, when configured, goes through Resend.
Retention and deletion
No retention period is published in the product. Signing out ends the browser session. You can disconnect Steam from account settings. The account page does not include a self-serve delete-account control.
To ask for access, correction, or deletion of account data, email the address on the contact page.
Sharing
The product sends data to the services it calls: Supabase for auth and the database, Resend for account email when that is configured, Steam when you link an account or when public server data is queried, Discord when you link an account or use the bot, and Cloudflare as the application host.
The product does not sell account data. A formal controller name and a complete processor list are not published on this page. See the items still awaiting operator confirmation.
Waiting on the operator
This page describes current product behaviour. It is not a finished legal notice. The operator has not confirmed a legal entity, jurisdiction, controller name, retention schedule, complete processor list, or age requirement. Those items are not guessed here.
Related pages: Terms, How we know, Contact.
Contact: support@rustexa.com