Privacy
Last updated 20 August 2026.
The short version
Rustconnect stores what it needs to talk to your Rust servers on your behalf, and nothing else. We do not sell data, we do not run advertising, and we do not share anything with third parties except the services listed below that make the product work.
What we store
- Your Steam account
- Your SteamID, display name and avatar, from signing in with Steam. We never see your Steam password — that is typed on Steam’s own site, and Steam only tells us who you are.
- Your Rust+ credentials
- An authentication token issued by Facepunch, plus push-notification credentials. These let us receive the pairing notifications Rust sends when you pair a server or device in game. Both are encrypted at rest.
- Your servers and devices
- Server addresses, the pairing tokens Rust issues for them, and the smart switches, alarms and storage monitors you pair. Pairing tokens are encrypted at rest.
- Game activity
- Team chat messages, player positions, deaths, alarm triggers and connection events, so the dashboard and Discord alerts can show them. This is data your own Rust server sends us about your own team.
- Discord configuration
- Which Discord server and channels you have chosen. We do not read Discord messages outside the channels you configure for the chat bridge.
- Support tickets
- If you use the report button, what you wrote and which page you were on.
The browser extension
The Rustconnect Linker extension exists to do one thing. Facepunch hands your Rust+ token to a component that only exists inside their mobile app, so on a desktop browser it cannot be delivered. The extension reads that token from Facepunch’s own page and sends it to Rustconnect.
- It can only access
companion-rust.facepunch.com. It cannot read any other website. - It never sees your Steam password. You sign in on Steam’s own domain, and the extension only runs afterwards.
- It sends one thing: your Rust+ token, with a single-use code that says which Rustconnect account it belongs to.
- It stores that code in browser storage until it is used, then deletes it. It collects no browsing history and no analytics.
Who else sees it
Only the services needed to run the product:
- Facepunch — Rust+ itself. Your token is registered with them so they can send pairing notifications.
- Google and Expo — the push notification delivery Rust+ uses.
- Discord — if you connect a Discord server, the messages and alerts you have configured.
- Steam — to verify your sign-in and read your public profile name and avatar.
- Cloudflare — anonymous page-view counts, so we can see which pages people visit. It sets no cookies and does not build a profile of you or follow you to other sites, which is why there is no cookie banner on this one.
- Our hosting and database providers — who store the data on our behalf and do not use it.
Getting rid of it
Unpair a server in the dashboard and its pairing token and devices are deleted. Uninstalling the extension removes anything it stored in your browser. To delete your account and everything attached to it, email support@rustconnect.net and we will remove it.
Your Rust+ token expires by itself after 14 days whatever you do.
Contact
Email support@rustconnect.net, or use the report button inside the app.