Privacy Policy
CoreNet Servers ("CoreNet Servers", "we", "us", or "our") builds and operates a range of software products and services, including websites, browser extensions, Discord bots, and mobile, desktop, and backend applications (collectively, the "Services"). This Privacy Policy explains what information we handle, why we handle it, how it is protected, how long it is kept, who it may be shared with, and the choices and rights you have. By installing or using a Service, you acknowledge the practices described here.
Contents
- Advanced BM RCON (Chrome extension)
- Discord bots & privileged intents
- Information we handle
- How we use information
- Legal bases for processing
- Third-party services
- How we share information
- International data transfers
- Local storage & cookies
- Data retention
- Security
- Your rights & choices
- Children's privacy
- Third-party links
- Changes to this policy
- Contact
Advanced BM RCON (Chrome extension)
Advanced BM RCON is a private browser extension that adds player information to BattleMetrics RCON pages to help approved Rust server administrators do their work. It is intended only for members of our administration team; access is restricted and verified at sign-in. This section describes exactly what the extension does with data, and the general sections that follow apply to it as well.
What the extension accesses and stores
- API tokens you enter — your BattleMetrics and Steam API tokens, together with your extension preferences (such as feature toggles and excluded ban lists), are stored locally in your browser using the Chrome storage API. These tokens are used directly from your browser to call the BattleMetrics and Steam APIs on your behalf. They are never transmitted to, or stored by, CoreNet Servers.
- Google account email (sign-in) — the extension uses Google sign-in solely to read your account's email address and confirm that you are on our approved-user allowlist. We receive only your verified email address — not your Google password, contacts, or wider profile. Your email is used only to grant or deny access to the tool and to keep a basic access log for security and accountability.
- Player and game-server data — when you open a player, the extension requests data such as player profiles, aliases, identifiers, IP addresses, ban records, linked accounts, and play statistics from the official BattleMetrics and Steam APIs, and displays it to you within the page. This data concerns game accounts (generally not you), and the processing happens in your browser to render the administration view.
- IP connection-type lookups — to help identify ban evasion, IP addresses associated with a player may be sent to our backend service (hosted on Cloudflare) for the sole purpose of classifying the connection type (for example, residential, VPN, or hosting) via proxycheck.io. The proxycheck.io key is held on our server and is never exposed in the extension. We do not build advertising or behavioural profiles from this data.
Permissions and why they are needed
- storage — to save your API tokens and preferences locally on your device.
- identity — to perform Google sign-in for access control.
- Host access — to the BattleMetrics and Steam APIs (to retrieve the player data you request) and to our own backend host (for sign-in verification and the IP connection-type lookup). The extension's interface runs only on BattleMetrics pages and does not monitor your browsing on other sites.
What the extension does not do
It does not sell or rent your data, does not serve advertising, does not use your data to build advertising or credit profiles, and does not collect your general web-browsing history.
Google API Limited Use
Advanced BM RCON's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use Google account information only to authenticate you and control access to the tool; we do not transfer or use it for serving advertisements, and we do not allow humans to read it except as necessary for security, to comply with applicable law, or where you have given consent.
Uninstalling the extension removes the tokens and preferences it stored on your device. To have your email address removed from the access allowlist and access logs, contact us using the details below.
Discord bots & privileged intents
We operate Discord bots that add moderation, administration, and community features to Discord servers ("guilds") that choose to add them. When a server owner or administrator invites one of our bots, the bot receives data from Discord according to the permissions and gateway intents it is authorised to use. This section explains what we access and why; the general sections that follow also apply.
Information a bot receives from Discord
- Server and channel data — the server (guild) ID, channel IDs, roles, and the bot's own configuration for that server.
- User and member data — user IDs, usernames and discriminators, nicknames, avatars, roles, and join dates for members who interact with the bot or whom a command concerns.
- Interactions and commands — the slash commands, buttons, and inputs you send to the bot, and the actions you ask it to perform.
- Moderation data — where a bot provides moderation features, records such as warnings, notes, mutes, kicks, or bans that a moderator creates through the bot.
Privileged gateway intents
Discord classes three gateway intents as "privileged." A bot only receives the data below when the corresponding intent is enabled for that bot, and we enable an intent only where a feature requires it:
- Server Members Intent — lets the bot receive the server's member list and member events (joins, leaves, role and nickname changes). We use it for features such as welcome/farewell messages, role management, member counts, and moderation. We do not use it to build profiles for advertising.
- Presence Intent — lets the bot see a member's presence (online status and the activity or game shown on their profile). Where enabled, we use it only for presence-dependent features (for example, status roles or activity displays). We do not log or retain your presence history beyond what a feature needs at the moment.
- Message Content Intent — lets the bot read the content of messages (rather than only metadata). Where enabled, we use it to process prefix commands and to provide features such as auto-moderation, keyword filtering, or logging that a server has configured. Message content is processed to deliver the requested feature; we do not sell it, use it for advertising, or read it beyond what those features require.
How long bot data is kept
Configuration and moderation records (such as a server's settings or a member's warning history) are retained while the bot is in your server so the features keep working, and are deleted on request or when the bot is removed from the server. Message content processed for a feature is used transiently and is not stored unless a feature you have enabled (such as a moderation or logging feature) specifically requires it, in which case it is kept only as long as that feature needs. Removing the bot from a server stops further data collection for that server.
What our Discord bots do not do
They do not sell or rent your data, do not serve advertising, do not use message content or presence to build advertising profiles, and do not share your data except with the providers needed to run the bot or as required by law.
Information we handle
Depending on the Service, we may handle the following categories of information:
- Account & identity information — such as your Discord user ID and username, Google account email address, or an account you create with us. Used to identify you, authenticate you, and control access to restricted tools.
- Authentication credentials — such as API tokens or keys you provide (for example, BattleMetrics or Steam API tokens), or sign-in tokens issued by providers such as Google. Where a Service lets you enter your own tokens, they are generally stored locally on your device or securely on our systems and used only to perform the actions you request.
- Usage and diagnostic data — such as the features you use, the actions or commands you run, timestamps, and error, access, or audit logs. Used to operate, secure, and improve the Services.
- Technical data — such as IP address, browser or client type and version, device and operating-system information, and similar metadata generated when you connect to a Service.
- Game-server and player data — some Services (for example, tools for Rust / BattleMetrics server administration) access third-party gaming data such as player profiles, identifiers, IP addresses, ban records, linked accounts, and play statistics via official APIs (for example, BattleMetrics and Steam). This data relates to game accounts and is processed to provide administration features.
- Content you submit — such as messages, notes, configuration, or files you provide to a Service.
We do not intentionally collect sensitive or special-category information (such as health, biometric, or precise-location data), and we ask that you do not submit it unless a Service specifically requests it.
How we use information
We use information to:
- provide, operate, and maintain the Services;
- authenticate users and control access to restricted or private tools;
- perform the actions you initiate and respond to your requests;
- secure the Services, detect and prevent abuse or unauthorised access, and keep audit and access logs;
- diagnose problems, monitor performance, and improve and develop the Services;
- communicate with you about the Services, including important notices; and
- comply with legal obligations and enforce our terms.
We do not sell your personal information, use it for advertising or ad targeting, or use it to determine creditworthiness or for lending purposes.
Legal bases for processing
Where the law (such as the UK/EU GDPR) requires a legal basis for processing personal data, we rely on one or more of the following, depending on the context:
- Performance of a contract — to provide a Service you have requested or agreed to use;
- Legitimate interests — to operate, secure, and improve our Services, prevent abuse, and administer our gaming communities, provided these interests are not overridden by your rights;
- Consent — where you have given it (for example, by choosing to enter your tokens or sign in); you may withdraw consent at any time; and
- Legal obligation — where processing is necessary to comply with applicable law.
Third-party services
Our Services rely on trusted third parties (sub-processors and providers) to function. Depending on the Service, these may include:
- Google — sign-in / identity verification;
- Discord — bot platform and user identity;
- BattleMetrics and Steam — game-data APIs;
- Cloudflare — hosting, backend/edge compute, and content delivery;
- proxycheck.io — IP connection-type classification;
- database and hosting providers we operate or contract with.
These providers process data only as needed to deliver the Services, under their own terms and privacy policies. We encourage you to review the privacy policies of any third-party platform (such as BattleMetrics, Steam, Discord, or Google) whose data or accounts you use with our Services.
How we share information
We do not sell or rent personal information. We may share information only:
- with the third-party services listed above, to operate the Services;
- where you direct us to (for example, by issuing an action through a Service);
- with other authorised administrators of the same gaming community, to the extent a Service is designed to support shared moderation and administration;
- in connection with a business transfer (such as a merger, acquisition, or reorganisation), subject to this policy; and
- to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and security of our users, the public, and our Services.
International data transfers
We and our providers may process and store information in countries other than the one in which you live. Where information is transferred across borders, we take steps to ensure it remains protected in line with this policy and applicable law, including relying on providers that offer appropriate safeguards for such transfers.
Local storage & cookies
Our browser extensions and apps use local device storage (such as the Chrome storage API or a browser's local storage) to keep your settings, tokens, and preferences on your own device so the Service can function. This data stays on your device until you remove it or uninstall the Service. Our website uses only the cookies or local storage strictly necessary for it to work and does not use third-party advertising or cross-site tracking cookies.
Data retention
We keep information only as long as needed to provide the Services and for legitimate operational, security, or legal purposes:
- Data stored locally by a Service (such as tokens or settings you enter into an extension or app) remains on your device until you remove it or uninstall the Service.
- Access and audit logs (such as which approved account signed in, and when) are kept for a limited period for security and accountability, then deleted or aggregated.
- Allowlist entries (such as an approved email address) are kept while your access is authorised and removed when access is revoked or on request.
Security
We take reasonable technical and organisational measures to protect information, including transmitting data over encrypted connections (HTTPS/TLS) and holding Service secrets (such as our own API keys) server-side, where they are not exposed to end users. Access to restricted tools is limited to approved accounts. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
Your rights & choices
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access — to know what personal information we hold about you;
- Correction — to have inaccurate information corrected;
- Deletion — to have personal information erased;
- Restriction or objection — to limit or object to certain processing;
- Portability — to receive certain information in a portable format; and
- Withdrawal of consent — where processing is based on consent.
You can also:
- stop using a Service at any time; uninstalling a browser extension or app removes locally stored data; and
- request that your email be removed from an access allowlist and logs by contacting us.
To exercise any of these rights, contact us using the details below. We will respond in accordance with applicable law, and we will not discriminate against you for exercising your rights. If you are in the UK/EU, you also have the right to lodge a complaint with your local data-protection authority.
Children's privacy
Our Services are not directed to children under the age required by local law to consent to processing (for example, 13 in many jurisdictions), and we do not knowingly collect their personal information. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to remove it.
Third-party links
Our Services and this website may link to third-party sites or services that we do not control. This policy does not apply to those third parties, and we are not responsible for their practices. Please review their privacy policies before providing them with information.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice within the relevant Service. Your continued use of a Service after an update takes effect constitutes acknowledgement of the revised policy.
Contact
Questions or requests about this Privacy Policy or your data: contact@corenetservers.com