Effective 29 July 2026 · Private alpha
Privacy Policy
This Policy explains what STNL HQ processes, why it is processed, how it is protected and the choices available to users and other people whose public gaming identifiers may be included.
1. Controller and contact
The data controller is STNL HQ, an independent service currently operated from France. Privacy requests may be sent to drascaoo@gmail.com.
You may also lodge a complaint with the French data-protection authority, the CNIL, or the supervisory authority of your habitual residence in the European Economic Area.
2. Data we process
Account and organization data
- email address, display name and password verifier;
- organization membership, role and hosted-session status;
- authentication-session and security-audit records.
Connected-service data
- Discord server ID and name, channel and role identifiers, interaction data and messages required to perform requested bot functions;
- Rust+ server address, paired SteamID64, pairing token, server responses, team information, map information, events, devices and team-chat commands;
- optional Steam Web API and BattleMetrics credentials and the public profile or server-presence information returned by those services;
- user-created commands, alerts, watchlists, market watches, farming timers and other Sentinel configuration.
Technical data
The server necessarily receives IP addresses, timestamps, request paths, error information and security events when the service is accessed. STNL HQ does not add advertising trackers, behavioral analytics or product telemetry.
3. Purposes and legal bases
- Performance of the service: authenticate users, host isolated sessions, operate requested Rust+ and Discord features, save configuration and provide support.
- Legitimate interests: secure the service, prevent abuse, diagnose failures and provide user-requested monitoring of public gaming identifiers, balanced against the rights of affected people.
- Consent or user authorization: connect optional third-party integrations and permissions that the user can revoke.
- Legal obligations: respond to lawful requests and retain information where required by applicable law.
STNL HQ does not sell personal data and does not use it for targeted advertising.
4. Discord OAuth and secrets
Discord OAuth sends the user to Discord to choose a server and approve bot permissions. STNL HQ receives the selected server identity and verifies that the central Sentinel bot joined it. The temporary Discord user access token used during installation is discarded after verification and is not stored in the hosted session.
Rust+ pairing tokens, optional API credentials and other designated secrets are encrypted at rest. Secret values are not intentionally displayed in the console, application logs or public configuration summaries.
5. Recipients and infrastructure
Access is limited to the user’s authorized organization members and the operator where necessary for security, maintenance or support. The private-alpha infrastructure is currently hosted on a dedicated Scaleway server in France.
When a user enables an integration, relevant data is exchanged with that provider to perform the requested function:
- Discord for OAuth, commands, channels and notifications;
- Facepunch/Rust Companion and Steam for Rust+ functionality;
- BattleMetrics only when its optional integration is enabled.
These providers process data under their own privacy policies and may operate outside the European Economic Area. STNL HQ does not disclose configuration or secrets to unrelated third parties.
6. Retention
- Browser authentication sessions expire after eight hours.
- OAuth anti-forgery state expires after ten minutes. Temporary Discord user authorization tokens are discarded after the installation check.
- Account, organization and hosted-session configuration is kept while the account or session remains active and is deleted within 30 days after a verified deletion request, unless legal retention is required.
- Operational and security logs are normally retained for no more than 90 days. Security-audit records may be retained for up to 12 months where necessary to investigate abuse or protect the service.
- Backups, when enabled, are overwritten or deleted on a rolling cycle of no more than 30 additional days.
Data may be retained longer where necessary to establish, exercise or defend legal claims or comply with a binding legal obligation.
7. Cookies
STNL HQ uses only strictly necessary security cookies: an HTTP-only session cookie for authentication and a short-lived HTTP-only state cookie during Discord OAuth. They are marked Secure and are not used for advertising or cross-site tracking.
8. Security
Measures include encryption of designated secrets using authenticated encryption, organization-level isolation, restricted server binding, HTTPS, least-privilege service accounts, protected cookies and access-controlled configuration. No system can provide absolute security. Confirmed incidents will be handled in accordance with applicable notification obligations.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal data, and may object to processing based on legitimate interests. You may withdraw consent or disconnect an optional integration at any time without affecting earlier lawful processing.
Send requests to drascaoo@gmail.com. We may request reasonable proof of identity and authority over the relevant account, Discord server or gaming identifier.
10. Public player identifiers
Optional tracking or player-review tools may store SteamID64 values, profile names, public-profile information and observed server presence supplied by the user or an enabled provider. These tools are intended for user-requested gaming context, not legal findings or automated punishment. A person may request correction, objection or deletion by providing the relevant identifier and sufficient information to locate the record.
11. Changes
This Policy may change as Sentinel moves beyond private alpha or adds providers. Material changes will be dated and, where appropriate, notified in the service before taking effect.