Skip to content

No signal from the server

Legal

Privacy policy

Last updated: 9 October 2026

Required details are still missing in the configuration: LEGAL_HOSTING_PROVIDER

Note: This English version is a courtesy translation. Only the German version is legally binding.

This privacy policy explains, in accordance with Art. 13 and 14 GDPR, which personal data we process on the website https://dieselrust.com, for what purpose, on what legal basis and for how long. It also covers the data that our Rust game server transmits to the website.

Key points at a glance

  • We do not use any analytics or tracking tools, advertising or social media plugins.
  • Fonts are hosted on our own server. We do not use Google Fonts.
  • Images from the shop (Tebex) and Steam profile pictures are fetched by our server and delivered from our own domain. Your browser does not connect to these providers.
  • Discord is only included as a plain link, not as a widget.
  • External media such as YouTube videos or Twitch streams are currently not embedded. If they are added later, they only load once you consent.
  • The website does not store IP addresses in its database. We only store e-mail addresses if you write to us via the contact form.

1. Controller

The controller responsible for data processing is:

For questions about data protection or to exercise your rights, an informal e-mail to the address above is sufficient. Further details can be found in the imprint.

2. Hosting and server logs

The website runs on a server administered by ourselves (root server) provided by [LEGAL_HOSTING_PROVIDER fehlt] (hosting provider). The hosting provider processes data only on our behalf and according to our instructions (Art. 28 GDPR). In front of the application, the Caddy web server acts as a reverse proxy and establishes the encrypted connection (HTTPS). The certificate for this comes from Let's Encrypt; no visitor data is transmitted to Let's Encrypt in the process.

To deliver a page to you, the web server has to process your IP address. Typically, the date and time of the request, the requested address, the status code, the amount of data transferred, the previously visited page (referrer) and information about your browser and operating system are processed as well.

  • Purpose: delivering the website, stability and security, for example to fend off attacks and to analyse errors.
  • Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.
  • Retention: The application does not store IP addresses in its database, and our reverse proxy does not keep access logs. The application and the reverse proxy only write error and operating messages to log files (server logs); in individual cases these may contain technical details of a request. We delete these logs after 7 days at the latest.

3. Cookies and local storage

Without your consent, we only store what is strictly necessary on your device: the session cookie after you sign in, the language you have chosen, a check value during the Steam sign-in, the basket reference in the shop and your decision in the privacy settings. Only if you use the respective function, this also includes streamer mode being turned on and – for team members in the admin panel – the command history of the server console. No consent is required for this (Section 25(2) no. 2 TDDDG). The related processing of personal data is based on Art. 6(1)(b) GDPR (sign-in and basket) and Art. 6(1)(f) GDPR (language choice, protection of the sign-in process, storing your settings).

Names, purposes and storage periods are listed under Cookies & local storage.

4. External media (only with consent)

Currently, no third-party content is embedded on the website; even with your consent, the website does not load any external media at the moment. The following rules apply as soon as we embed such content, for example YouTube videos or Twitch streams. We will add new providers to the table beforehand. Such content only loads once you agree: either for all external media in the privacy settings or individually via the placeholder on the content ("Load content"). Until then, your browser does not connect to the provider.

As soon as external content loads, your browser transmits your IP address and technical information about your device to the provider. The provider may also use cookies or similar technologies and use the data for its own purposes; we have no influence on this.

Planned service Provider Privacy information
YouTube Google Ireland Limited, Dublin, Ireland policies.google.com/privacy
Twitch Twitch Interactive, Inc., San Francisco, USA legal.twitch.com
  • Legal basis: your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG).
  • Transfer to the USA: Data may be transferred to the USA. For Google LLC, the European Commission's adequacy decision on the EU-US Data Privacy Framework applies (Art. 45 GDPR). For providers without such a certification, the USA does not offer a level of data protection comparable to the EU: US authorities may access the data, and your legal remedies are limited. In that case the transfer is based on your explicit consent (Art. 49(1)(a) GDPR).
  • Withdrawal: You can withdraw your consent at any time with effect for the future via the "Privacy settings" link in the footer of every page. The lawfulness of processing carried out before the withdrawal remains unaffected.

5. Steam sign-in and website account

Signing in is voluntary. You can use the public areas of the website without an account; for your website account and for purchases in the shop we need your SteamID.

To sign in, we redirect you to Steam (OpenID 2.0). There you sign in directly with Valve Corporation; we never learn your password. Steam then only confirms your SteamID (SteamID64) to us, which is the public identifier of your Steam account. If a Steam Web API key is configured, our server also retrieves your public display name and profile picture from the Steam Web API.

We store your SteamID, your display name, the address of your profile picture and the times your account was created and you last signed in. Sessions are stored only as a SHA-256 hash of the session token together with its expiry time; the token itself is kept only in your browser.

So that your browser does not have to connect to Steam, our server fetches profile pictures itself and keeps them in a cache on our server; after 24 hours, a picture is renewed the next time it is requested, and it is deleted at the latest after 30 days without a request. If you delete your account, we also delete your cached profile picture.

  • Purpose: providing your account, signing in and recognising you, linking you to your game account on our server.
  • Legal basis: Art. 6(1)(b) GDPR (providing the account you requested) and Art. 6(1)(f) GDPR (security of the sign-in and protection against misuse).
  • Retention: We keep account data until you delete your account; accounts without a sign-in for 730 days are deleted automatically. A session ends after 30 days or when you sign out; expired sessions are deleted automatically.
  • Steam (Valve): Valve Corporation, P.O. Box 1688, Bellevue, WA 98009, USA, is itself responsible for the sign-in on Steam's pages; the Steam privacy policy applies. When our server retrieves your name and profile picture via the Steam Web API, it transmits your SteamID to Valve in the USA. Valve states that it is certified under the EU-US Data Privacy Framework. Insofar as this certification exists, the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR).

6. Data from the game server

Our Rust game server continuously transmits data to the website over an encrypted and signed connection. The data is generated on our game server when you play there; the game server is therefore the source of this data.

We process:

  • Server status: e.g. player count, queue, map and wipe dates. The player count history is stored without reference to individual persons.
  • Player data: player name, SteamID, clan and team, rank (e.g. VIP), online status, first and last visit, play time, kills, deaths and other game statistics for leaderboards.
  • Public "Live radio" feed: messages from the game such as bounties, auctions, events, clan wars, lottery, trades and wipe and restart notices. These may contain player names.
  • Staff-only messages: e.g. admin log, punishments, reports by players about other players, anti-cheat alerts, raid logs and raid alarms, territory messages, kit usage, join and leave messages, daily reports as well as signs and clan banners designed by players in the game (text or image together with the name or SteamID of the person who created them). Only the server team can see these messages. The website does not take over chat messages (including team and clan chat) as messages; they may, however, appear in the live console (see section 7).

Publicly visible are the server status (without names), leaderboards with player names and values, and the Live radio feed. Only the server team can see by name who is currently online. Players who use streamer mode in the game are not shown by name in public on the website.

  • Purpose: transparency for the community (server status, leaderboards, Live radio) as well as moderation and game integrity (staff-only messages).
  • Legal basis: Art. 6(1)(f) GDPR. Our legitimate interests are a transparent community and fair gameplay in which rule violations can be detected and sanctioned.
  • Retention: Live radio messages are deleted after 30 days, staff-only messages after 90 days and the player count history after 14 days. Player data and statistics are deleted once a player has not been on the server for 365 days.
  • Objection: You can object to being shown publicly at any time (Art. 21 GDPR) with an informal e-mail to support@dieselrust.com stating your player name or SteamID. We will then no longer show you by name in public on the website.

7. Admin panel for the server team

The server team also manages the game server through an admin panel on the website. Team members sign in via Steam like everyone else. The website takes their roles and permissions from the game server (staff list with SteamID, name, role and permissions); each team member only sees the areas they are authorised for.

Every action in the admin panel, such as a kick, ban or mute, crediting items or Radcoins, assigning ranks or sending a message to a player, is logged with the time, type of action, target (e.g. the SteamID of the player concerned), details such as reason or amount, result and the SteamID of the acting team member (audit log). Commands to the game server and their results, for example an inventory lookup, are also kept briefly in a queue. In addition, the team can see the game server's ban list (SteamID, name, reason, period and who issued the ban).

Server owners can also view the game server's live console in the admin panel and enter commands there. The console lines may contain player names, SteamIDs, chat messages and game events; IP addresses are already masked by the game server. The game server only sends console lines while someone has the console open. The website keeps at most the last 2,000 lines in memory and does not store them in the database; they expire when the website or the game server restarts.

  • Purpose: managing the game server, accountability for team actions and protection against misuse of team permissions.
  • Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is an orderly and accountable operation of the server.
  • Retention: Audit log entries are deleted after 365 days, queued commands after 14 days. The ban list and staff list are continuously synchronised with the game server; entries lifted or removed there also disappear from the website with the next synchronisation.

8. Shop (Tebex)

Our shop is integrated via the interface of the provider Tebex. The seller and your contractual partner for purchases is Tebex Limited (London, United Kingdom), which acts as reseller (merchant of record). Payment is handled exclusively by Tebex and its payment service providers; we do not receive your payment details. Tebex is itself responsible for the data processing during payment. The Tebex privacy policy and the Tebex terms apply.

When you add packages to your basket and proceed to checkout, our server transmits the selected packages, your SteamID and your IP address to Tebex. Tebex requires the IP address so that the basket is attributed to you as the buyer; we do not store it. After the purchase, Tebex sends us a purchase notification. Of this, we only store the transaction ID, packages, amount, currency, status and SteamID. We do not store payment details or your e-mail address. Images of the shop packages are fetched from Tebex by our server and delivered from our own domain.

  • Purpose: processing your purchase, crediting the purchased items to your game account, handling enquiries and keeping proof of purchases.
  • Legal basis: Art. 6(1)(b) GDPR (performance of the purchase and provision of the purchased items in the game); where statutory retention obligations apply, Art. 6(1)(c) GDPR.
  • Retention: Purchase notifications are deleted after 1095 days (regular limitation period for enquiries and proof), immediately if you delete your website account. Statutory retention obligations remain unaffected.
  • Transfer to the United Kingdom: An adequacy decision of the European Commission applies to the United Kingdom (Art. 45 GDPR). It was renewed in December 2025 and is valid until 27 December 2031.

9. Contact by e-mail and contact form

If you send us an e-mail or use the contact form, we process your e-mail address, your name (if provided), the chosen category, the subject, the content of your message and – if provided or signed in – your Steam name or SteamID in order to handle your request.

Form requests are stored in the website database so that the server team can handle them in the admin panel. If set up, we additionally forward them by e-mail to our support mailbox (via our e-mail provider). An optional notice to the team on Discord only contains the request number and category, no content and no personal data. To prevent abuse, we briefly check in memory how many requests come from an IP address; we do not store the IP address in the database.

If you report another player or illegal content (category "Report a player") or submit a ban appeal, we also process the information you provide about other persons, such as their player name or SteamID, and compare it with the game server's data. We do not disclose who made a report to the reported person unless we are legally obliged to do so.

  • Legal basis: Art. 6(1)(b) GDPR if your request concerns your account or a purchase; Art. 6(1)(c) GDPR for requests about your data protection rights and for notices of illegal content (Art. 16 DSA); otherwise Art. 6(1)(f) GDPR (answering enquiries, enforcing the server rules).
  • Cancellation and withdrawal: On the page “Cancel & withdraw” you can cancel subscriptions and withdraw from purchases. We store your name, e-mail address, optionally your SteamID, the contract details and your note, confirm receipt by e-mail and forward the declaration to Tebex Limited (seller) for execution. The legal basis is Art. 6(1)(b) and (c) GDPR (contract handling, statutory cancellation and withdrawal function).
  • Retention: Form requests are deleted automatically 180 days after receipt (cancellations and withdrawals after 1095 days), e-mails as soon as we no longer need them to handle your request – in each case unless statutory retention obligations apply.

10. Discord and external links

You can reach our Discord server via a plain invite link. We do not embed a Discord widget, so no data is sent to Discord when you visit our website. Only when you follow the link do you leave our website. From then on, the Discord privacy policy applies; for users in the European Economic Area, Discord Netherlands BV is responsible. The same applies to other links to external websites.

11. Retention periods at a glance

Data Retention
Error and operating logs (server logs) no longer than 7 days
Cached Steam profile pictures renewed after 24 hours on the next request; deleted after 30 days without a request and together with the website account
Website account (SteamID, name, profile picture, timestamps) until the account is deleted, at the latest 730 days after the last sign-in
Sessions 30 days or until you sign out
Public Live radio feed 30 days
Staff-only messages 90 days
Player count history (no personal reference) 14 days
Admin panel audit log 365 days
Admin panel command queue 14 days
Admin panel live console in memory only, at most 2,000 lines, until the next restart
Player data and statistics 365 days after the last visit to the server
Purchase notifications from Tebex 1095 days or until the website account is deleted
Contact form 180 days after receipt
Cancellations and withdrawals (form “Cancel & withdraw”) 1095 days after receipt (proof towards Tebex and you, Art. 6(1)(c) and (f) GDPR)
E-mails to us until your request has been dealt with, unless a retention obligation applies
Privacy decision, streamer mode, console command history (in your browser) until you change it or clear the website data in your browser

12. Your rights

You have the following rights towards us:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR, see below)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

You can do much of this yourself: under My account you can view the data stored for your website account, download it as a JSON file and delete your account. Data managed by the game server (e.g. bans, statistics or Radcoins) is not included. Please send requests about such data by e-mail to support@dieselrust.com.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. A list of the data protection supervisory authorities in Germany is provided by the Federal Commissioner for Data Protection and Freedom of Information.

13. Right to object

Where we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

We comply with an objection to the public display of your player data by no longer showing you by name in public on the website. An informal e-mail to support@dieselrust.com is sufficient.

14. Children and young people

In Germany, Rust is rated for ages 16 and up (USK 16). We do not knowingly collect data from children under 16 on the basis of consent. If you are under 16, you may only enable external media with the consent of your parents or legal guardians (Art. 8 GDPR). For purchases in the shop, the age rules in the shop terms apply.

15. Obligation to provide data and automated decisions

You are not obliged to provide us with any data. However, without the technically necessary connection data we cannot deliver the website to you, and without signing in with Steam you cannot create an account or buy anything in the shop. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on the website. Anti-cheat alerts from the game server do not automatically lead to measures on the website either: they are shown to the server team, and bans via the admin panel are triggered by a team member after their own review.

16. Data security

The connection between your browser and the website is encrypted with TLS (HTTPS). Session tokens are stored only as a SHA-256 hash. The session cookie cannot be read by scripts in the browser and is only sent over encrypted connections. The connection between the game server and the website is encrypted and signed with a shared key. Access in the admin panel is restricted by a permission system and logged.

17. Changes to this privacy policy

We update this policy when the website, our processes or the legal situation change. The version published on this page applies.

By default this website only uses strictly necessary storage. Third-party content (e.g. videos) only loads once you allow it here or directly on the content.

More in the privacy policy