Privacy Policy
Last updated: September 7, 2026
RustLite LLC (“RustLite”, “we”, “us”), a Texas limited liability company, operates the website at rustlite.com, the RustLite API, the RustLite browser extension, and related companion features for the game Rust (together, the “Service”). This policy explains what information we handle, where it comes from, who receives it, how long we keep it, and the rights you have. It forms part of our Terms of Service.
Contact us at [email protected] or (830) 316-3910.
Current availability: the wiki and tools are public; player lookup is not public; Plus is waitlist-only; and checkout is not open.
The short version
- Most player information shown on RustLite is supplied to us by third-party data providers. We do not verify it, and it is not proof of anything.
- Pairing a Rust+ server means we receive data about your teammates too, including their in-game positions and team chat. Read section 4 before you pair.
- We do not sell personal data and we run no advertising.
- Any player, account holder or not, can ask us to remove information about them. See section 14.
- RustLite is not a consumer reporting agency. Nothing here may be used to decide anyone’s eligibility for employment, credit, housing, insurance, or any similar purpose.
1. Information about you (account holders)
- Account data: your SteamID64, Steam persona name, and Steam avatar, received when you sign in through Steam. Steam sign-in uses OpenID, so we never see or hold your Steam password.
- Email address: optional. We ask for it after your first sign-in and use it for billing and account notices.
- Plan and entitlement data: your plan, plan expiry, trial status, and usage allowances (deep lookups when that feature is active).
- Payment data: when paid plans are enabled, checkout and the billing portal are hosted by Stripe. We send Stripe your account ID, SteamID, and optional email; we receive and store your Stripe customer and subscription IDs and a log of billing events (event type, amount, currency, status). We never receive or store your card number or security code.
- Activity in your account: your search history, saved favourites, tracked players, alert history, saved groups, saved and bookmarked filters, and any notes or community votes you write about other players.
- Rust+ pairing data: see section 4.
- Notification destinations: the channels you set up, which can include a connected Discord account (its user ID, tag, avatar, and OAuth tokens), a connected Telegram account and chat, browser push subscriptions, a webhook URL, a Pushover key, an ntfy topic, and, if you turn on phone alerts, the mobile phone number you provide.
- Usage and security data: request logs, IP address, browser user agent, rate-limit and abuse-prevention records, and admin audit records of staff actions on accounts.
- Analytics data: see section 8.
2. Where player information comes from
Most player-lookup information is supplied to us under contract by independent third-party data providers, including a provider located outside the United States. Broadly, they supply:
- Public Steam profile information: persona name, avatar, profile URL, Steam level, account age, country if the player has made it public, online state, profile visibility, friends, groups, owned and recent games, achievements, and Steam ban status (VAC, game, community, and trade bans).
- Rust playtime and in-game statistics: raw counters published by the game, such as kills, deaths, shots fired, and resources gathered.
- Name history and, where available, ban records published by Rust server networks and ban databases, with the source named on each record.
- Server session and play-history information used for activity and server-history views.
We also call Valve’s Steam services directly: to verify your sign-in, to resolve a profile’s display name and avatar (singly and in batches), to resolve a custom profile URL to a SteamID, and to read the current Rust player count.
We keep some of what those calls and our providers return.Steam-derived display names and avatars are stored on account records, on each entry in a user’s search history, and on profile-view records, so a search history or viewer list shows the name and avatar as they were at the time rather than as they are now. Deep-lookup credits save a snapshot of the provider’s response, which contains Steam-derived fields. Ordinary lookup responses are cached for about five minutes. The result is that RustLite holds historical Steam-derived data, not only whatever Steam returns today.
Everything RustLite presents as a calculated figure, including kill/death ratio, accuracy, headshot rate, threat or risk indicators, activity heatmaps, and predictions, is computed by RustLite from those raw inputs. Those calculations are our estimates and opinions, not statements of fact about any player.
Responsibility. Each provider is responsible for the data it supplies to us, including its accuracy, its lawfulness, and the rights needed to supply it. RustLite is responsible for how that data is displayed, stored, cached, and used on the Service. We do not own the underlying data and we do not independently verify it. It can be incomplete, out of date, mismatched to the wrong person, or simply wrong. A ban record means only that the named source reported a ban. It does not establish cheating, dishonesty, or any other misconduct, and it does not tell you whether an appeal succeeded. Do not act against anyone on the strength of it.
3. What we store about players who are not account holders
Where a page concerns a player who does not hold a RustLite account, we may hold:
- Profile view records: which profile was viewed and, where the viewer is signed in, the viewer’s account ID, SteamID, name, and avatar. Views by signed-out visitors are counted but not identified.
- Unlocked report snapshots: when an account holder spends a deep-lookup credit, we cache the provider’s response for that section so it can be re-opened without spending another credit. Each account holds a limited number and the oldest is dropped as new ones are added.
- Notes and votes written by our users about a named player. Notes are private to the user who wrote them. Votes are shown in aggregate and report only what users selected; they are not our findings.
- Search history entries held in the searching user’s account, which include the searched player’s name and avatar.
- A SteamID64 to BattleMetrics player ID mapping.
- Rust+ team records for players on a paired user’s in-game team. See the next section.
Where the GDPR or UK GDPR applies, we rely on our legitimate interests in operating a game-community information service and in preventing cheating and fraud, balanced against the interests and rights of the people concerned. Because this data usually reaches us from a provider rather than from the player, this policy is how we give notice. You can object at any time using the process in section 14.
4. Rust+ pairing and team data
Rust+ features work by connecting to Facepunch’s companion service with credentials you pair yourself. Read this section before pairing: it is the part of the Service that handles the most data about other people.
What we receive and store. For each server you pair we store the server address and port, the server name, your paired SteamID, and your Rust+ player token. If you use seamless pairing we also store a Facepunch companion authentication token and push registration credentials so we can receive pairing notifications on your behalf. While a server is paired we hold an always-on connection to it, including when your browser is closed.
What the connection sees. Through that connection we receive, for everyone on your in-game team: SteamID, display name, online and alive state, in-game map coordinates, death locations, and team chat. While team monitoring is enabled we sample teammate positions roughly every 15 seconds and keep that trail so the live map can draw movement history, and we accumulate session and AFK time per teammate. Team chat is buffered in memory (about the last 100 messages) so the live chat panel can show it; we do not write team chat to a chat-history database. If you enable a delivery channel, the sender name and the full message are sent to that channel.
These are in-game coordinates on a Rust map.They are not a real-world location, and we do not use Rust+ to collect anyone’s real-world location.
Your teammates. They may have no RustLite account and no way to know this is running. You are responsible for telling them and for getting any consent the law where they live requires before you pair or enable a relay. A teammate can ask us to delete their position and team records and to stop future logging using section 14.
Access.Rust+ team data is available to the account that paired the server and to the channels that account configures. Pairing the same server does not give one account access to another account’s team data.
5. How we use information
- To run the Service and show you the features and reports you ask for.
- To operate the companion features you configure, including delivering Smart Alarm and event notifications to the channels you choose.
- To send SMS or place automated voice calls to a phone number you provide, only for alerts you have set up yourself. These are transactional account notifications. We do not send marketing texts.
- To take payment, manage subscriptions, meter credits, and keep billing records.
- To secure the Service, enforce our Terms, prevent abuse and fraud, and handle support requests.
- To understand aggregate site usage so we can improve the Service.
- To comply with law and to establish, exercise, or defend legal claims.
Where the GDPR or UK GDPR applies, our legal bases are performance of a contract with you, our legitimate interests described above, your consent where we ask for it (for example phone alerts), and compliance with legal obligations.
6. Who receives information
We do not sell personal data, and we do not share it for targeted advertising or cross-context behavioural advertising. We carry no advertising. Information goes to:
- Other users and visitors: a player profile is returned to whoever requests it, and parts of it are visible to any visitor. Community vote totals may be public. Private notes stay private to their author.
- Infrastructure providers who run the Service for us: Hetzner (servers, Germany), Cloudflare (DNS, CDN, security, and R2 object storage), and GitHub (source and build infrastructure).
- Stripe, for payments, when paid plans are enabled.
- Google Analytics, as described in section 8.
- Our data providers, which receive the SteamID you are looking up so they can answer the request, and BattleMetrics, which receives the player or server identifier being requested.
- Delivery services you turn on yourself: Discord, Telegram, Twilio (SMS and automated voice), Pushover, ntfy, browser push services, and any webhook URL you supply. Enabling a channel sends the alert content, which can include team chat and map grid references, to that provider. Discord voice alerts send the alert text to Google’s text-to-speech service to produce the audio. An ntfy topic is public unless you use a private topic or an authenticated server, and a webhook is controlled by whoever operates it.
- Legal and safety: where we are required by law, court order, or lawful request, or where we need to protect our rights, our users, or the public.
- Business transfer: if RustLite is sold, merged, or reorganised, data may pass to the successor under this policy.
Mobile information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as message delivery providers, is permitted solely to carry out the alerts you request. All other categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.
7. SMS and voice alerts
SMS and voice alerts are opt-in. You add your own phone number in Rust+ → Connection and enable phone notifications per Smart Alarm. Only add a number you own or are authorised to use. Alerts are event-triggered and can arrive at any hour, including overnight, because that is the point of a raid alarm. Message frequency varies with the alarms and events you enable and can be high during a raid. Message and data rates may apply. Automated voice calls use a synthetic voice, identify RustLite at the start of the call, and give a callback number.
Reply STOP to any text to stop messages to that number, or HELP for help. You can also remove the number in your notification settings, call (830) 316-3910, or email us. Carriers are not liable for delayed or undelivered messages. Full details are in our Messaging Policy.
9. Browser extension
The RustLite Intel for BattleMetrics extension adds player intelligence, group tracking, profile matching, and optional Rust+ pairing to supported RustLite, Steam, Facepunch companion, and BattleMetrics pages.
BattleMetrics requests go through us. BattleMetrics requires an authorised key on every request, and that key is held on our servers, so the extension sends its BattleMetrics player, server, and session requests to the RustLite API, which forwards them and returns the response. We therefore receive the requested path, the identifiers in it, and the response. We cache successful responses briefly, up to 15 minutes depending on the endpoint, so that many users viewing the same server share one upstream request. The extension also keeps its own cache in your browser, capped at 2,000 entries and not used after one hour. Of all this, the only thing we store permanently is the SteamID64 to BattleMetrics player ID mapping.
Other extension data. Saved groups, tracked players, and settings are stored in your browser, and are synced to your account when you are signed in. Profile matching sends the public identifiers and name of the profile being viewed, and the current server shown on it. Rust+ pairing sends the captured Facepunch token to us only when you run the pairing flow. If you are signed in on rustlite.com the extension reuses your existing session token and stores it in browser storage; it never sees your password. The extension contains no advertising and no third-party analytics.
Our use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not transfer extension data for advertising, to data brokers, or for credit decisions.
10. How long we keep information
- Lookup responses from our providers: cached about five minutes, then refetched.
- BattleMetrics proxy responses: cached up to 15 minutes.
- Profile view records: deleted after 90 days.
- Rust+ team position trails: deleted after 30 days, and when you unpair the server.
- Rust+ team session and AFK statistics: deleted when you unpair the server.
- Team chat buffer: about the last 100 messages, held in memory and lost on restart.
- Unlocked report snapshots: until dropped by the per-account limit, or until you delete them or close your account.
- Account and account content: for as long as your account is open. You can delete your account yourself at any time from Account → Settings, which removes it immediately.
- Billing records: as long as tax and accounting law requires, normally seven years.
- Security and abuse logs: normally up to 12 months.
We may keep particular records longer where we reasonably need them for security, fraud prevention, billing, tax, audit, disputes, or legal claims. Closing an account does not necessarily remove records keyed to a public identifier rather than to your account, data another user submitted, aggregated or deidentified data, or backup copies waiting to be overwritten. Where no automatic rule applies, deletion is done by hand on request.
11. Security
We use administrative, technical, and organisational safeguards designed to reduce the risk of unauthorised access, use, alteration, and disclosure. Credentials you save, and third-party tokens we hold on your behalf, are encrypted with AES-256-GCM when they are newly saved or updated. That covers connected-account tokens, Rust+ player and companion tokens, webhook URLs, Pushover keys, and phone numbers. Other information sits in ordinary database fields protected by access controls, network controls, and transport encryption rather than field-level encryption. Our servers accept traffic only through Cloudflare, administrative access is key-based, and the databases are not exposed to the public internet. No safeguard removes all risk, and we cannot guarantee absolute security.
12. Security incidents
We keep procedures for assessing suspected unauthorised access to personal information. If an incident triggers a legal notification duty, we will notify affected people, regulators, and anyone else required, in the manner and within the time the applicable law sets. For a covered Texas breach that can mean notice to affected people without unreasonable delay and no later than 60 days, and notice to the Texas Attorney General as soon as practicable and no later than 30 days where at least 250 Texas residents are affected. Where the GDPR applies we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach. Report a suspected incident to [email protected].
13. Your privacy rights
Texas residents. Under the Texas Data Privacy and Security Act you may ask us to confirm whether we process your personal data and give you access to it, correct inaccuracies, delete it, provide a portable copy, and opt out of any sale, targeted advertising, or profiling with legal or similarly significant effects. We do not sell personal data, carry targeted advertising, or make automated decisions of that kind. Email [email protected] with the subject line “Privacy Request”. We respond within 45 days and may extend once by a further 45 days where reasonably necessary, with notice to you. If we decline your request we will tell you why and how to appeal; appeals are decided within 60 days, and if we deny an appeal you may complain to the Texas Attorney General at texasattorneygeneral.gov.
Residents of other US states with comparable privacy laws, including California, Colorado, Connecticut, Virginia, and others, may exercise the equivalent rights their law grants using the same contact address, and will not be treated differently for doing so.
EEA, UK, and Swiss residents. You have the right to access, rectification, erasure, restriction, portability, and objection, including objection to processing based on legitimate interests, and the right to withdraw consent at any time without affecting processing already carried out. You may also complain to your local supervisory authority.
We may need to verify your identity, normally by confirming control of the Steam account or email address concerned, before acting on a request. Please do not send us a password, a Rust+ token, or identity documents.
14. Removal and teammate requests
You do not need a RustLite account to ask us to remove information about you. Email [email protected] with the subject line “Removal Request” and include the SteamID64 or profile link concerned, together with something showing the account is yours. On a verified request we will suppress that profile from RustLite lookups and delete the records we hold about it, normally within 45 days.
Rust+ teammates.If your data reached us through another player’s pairing, you can ask us to delete your position trail and team statistics and to stop future logging for your SteamID, using the same address and the subject line “Rust+ Teammate Request”.
Disputing a record. If a ban record on your profile is wrong, sign in with Steam and raise a dispute from your own profile, or email us with the profile link, the field you dispute, and why. The record is labelled as disputed on the profile while we look at it, and we then correct, remove, or keep it based on what we find. We append a correction where we published something materially wrong.
Two limits apply. We cannot change data held by Steam, BattleMetrics, our providers, or any other site, so you may need to contact them separately. And where the information is a public record of the game, such as a ban published by a server network, suppression on RustLite does not remove it at the source.
15. Where data is processed
RustLite LLC is established in the United States. Data is processed in the United States and in Germany, where our production servers are hosted, and by the providers listed above. One of our data providers operates from Saudi Arabia and receives the SteamID needed to answer a lookup. Saudi Arabia is not covered by a European Commission adequacy decision. Where EEA or UK personal data reaches a country without an adequacy decision, we are responsible for putting an appropriate Chapter V safeguard in place with that recipient, and we are working through those arrangements with our providers. We will name the mechanism here once it is agreed and signed. Email us to ask where a particular transfer stands, or to object to it.
16. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Where local law sets a higher age for consent to online services, such as 16 in parts of the EEA and UK, users below that age need a parent or guardian’s consent. Paid plans require you to be 18 or older. If we learn that a child under 13 has given us personal data we will delete it; if you believe that has happened, email us.
17. Changes to this policy
We may update this policy. We will change the date at the top and, where the change is significant, give notice on the site or by email before it takes effect. Continued use after a change takes effect means you accept the updated policy.
18. Contact
RustLite LLC, Texas, United States. [email protected] · (830) 316-3910.
Not affiliated with, endorsed by, or sponsored by Facepunch Studios, Valve Corporation, or BattleMetrics. Rust is a trademark of Facepunch Studios.