Privacy Policy

Last updated: 2026-09-29

1. Who we are

Panelra ("Panelra", "we", "us") is a platform for managing Rust game servers, currently offered free of charge as an open beta. This policy explains what personal data we handle when you visit panelra.io, use the dashboard at app.panelra.io, or run the Panelra agent on your server, and what rights you have.

For questions about this policy or your data, email [email protected].

2. Our two roles: controller and processor

Your account data (who you are, your team, your usage of the platform): we decide how and why it is processed, so we are the controller.

Your players' data (people who join the game servers you manage with Panelra): you decide which servers to connect and what to do with that information, so you are the controller and we are your processor. We only process it to provide the service to you and on your instructions. You are responsible for telling your players how their data is handled and for having a legal basis to do so. If a player contacts us about their data, we will refer them to you and help you respond.

3. What we collect

  • Account data: your email address, display name, and either a hashed password (we never store it in plain text) or, if you sign in with Google, your Google account identifier, email, and name as provided by Google.
  • Team data: team names, members, roles, and pending invitations (including the email addresses of people you invite).
  • Host data from the agent: for each server you connect: its IP address, hostname, operating system details, and resource metrics such as CPU, memory, and disk usage.
  • Game-server configuration and activity: server settings, installed plugins and their configs, wipe and backup schedules, backups you create, console output, and a history of actions taken through the dashboard (audit log).
  • Player data (processed on your behalf): players' in-game names, Steam IDs, IP addresses and approximate location derived from them (country/city), connection sessions, gameplay statistics such as kills and deaths, in-game reports, bans, and notes your team adds.
  • Technical data: standard server logs when you use our website or API (IP address, request path, timestamp, user agent), used for security and debugging.

We do not collect payment details: the service is currently free.

4. Why we use it, and our legal basis

  • To provide the service: creating your account, signing you in, running your servers, and showing you their data. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • To send service emails: email verification, password resets, team invitations, and important notices about your account. Legal basis: contract, and our legitimate interest in operating the service (Art. 6(1)(f)).
  • To keep the platform secure and working: preventing abuse, detecting unauthorized access, and fixing bugs. Legal basis: legitimate interest (Art. 6(1)(f)).
  • To meet legal obligations: where the law requires us to keep or disclose information. Legal basis: legal obligation (Art. 6(1)(c)).

We do not sell personal data, do not use it for advertising, and do not use your or your players' data to profile you for marketing.

5. Service providers we use

We rely on a small number of providers to run Panelra. Each only receives the data it needs for its task.

  • Hetzner Online GmbH: server hosting. Our application, database, and backups run on servers located in Germany.
  • Cloudflare, Inc.: DNS, CDN, and network protection for our websites, and R2 object storage for backups. Traffic to our sites passes through Cloudflare.
  • Resend: delivery of transactional emails (your email address and the message content).
  • Google: only if you choose "Sign in with Google", to authenticate you.
  • IP geolocation services (ipapi.co, ip-api.com): player IP addresses are looked up to show an approximate country/city in your dashboard.
  • Steam Web API (Valve): player Steam IDs are looked up to show public Steam profile information such as names, avatars, profile visibility, account creation date, Steam level, Rust playtime (only when the player's game details are public), and VAC, game, community and trade ban status. When your team asks for it on a player's page, we also count how many of that player's Steam friends have VAC or game bans; we store only these counts, never the friends' IDs or names. This data is cached (ban status for about an hour, profile data and friend counts for about a day) and is shown to your team as information only: Panelra never bans or kicks anyone based on it.
  • Grafana and Loki: used for monitoring and logs, but self-hosted on our own Hetzner servers; no data is sent to Grafana Labs.

Some of these providers are based in, or may access data from, countries outside the EU/EEA (for example the United States). Where that happens, transfers rely on the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

6. How long we keep it

  • Account and team data: for as long as your account exists. When you delete your account, it is removed from our live database.
  • Server console logs: kept in monthly batches and deleted after about 6 months.
  • Application and infrastructure logs (Loki): deleted after 14 days.
  • Game-server backups: kept according to the retention you configure per server, or until you delete them or the server.
  • Database backups: kept for 30 days, then deleted. Data you delete may remain in these backups until they expire.
  • Player data: kept on your behalf for as long as the related server remains in your account, or until you delete it.
  • Cached Steam data: refreshed while the player keeps joining servers on Panelra, and deleted within about an hour once no server in Panelra lists that player anymore.

7. Your rights

If you are in the EU/EEA or UK (and in many other places), you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict or object to certain processing, including processing based on legitimate interest;
  • receive your data in a portable, machine-readable format;
  • lodge a complaint with a data protection authority, in particular the one where you live or work.

Deleting your account: you can delete your account yourself at any time from your account settings in the dashboard. For anything else, email [email protected] and we will respond within 30 days.

Players of servers managed with Panelra should contact the server's owner first, since the owner controls that data.

8. Cookies and local storage

We do not use advertising or analytics trackers, and this website loads no third-party analytics scripts.

We only use what is strictly necessary: the dashboard keeps your sign-in session in your browser's storage so you stay logged in, and both sites remember your light/dark theme preference in local storage. Because these are essential for the service or simply remember a choice you made, no consent banner is needed.

9. Security

All traffic to Panelra and between the agent and the platform is encrypted in transit (HTTPS/WSS). Passwords are hashed, agents authenticate with unique tokens, and access to team data is limited by team membership and role. No system is perfectly secure, but if we become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.

10. Children

Panelra is a tool for server administrators and is not directed at children under 16. We do not knowingly collect account data from them.

11. Changes to this policy

We may update this policy as the service evolves (for example when the open beta ends). We will change the "Last updated" date above and, for significant changes, notify you by email or in the dashboard before they take effect.

12. Contact

Questions, requests, or concerns about privacy: [email protected].