Skip to content
RustMapCDN

Privacy.

Last updated 19 September 2026

RustMapCDN hosts Rust map files. It keeps as little about you as it can: enough to know who you are when you log in, and enough to show your team its maps. There are no ads, no advertising cookies and no tracking scripts.

What we store

When you log in

Logging in uses Discord's identify permission, which gives us your Discord user ID, username and avatar. Nothing else: not your email address, not your servers, not your messages. We store those three things so your team can see who is in an organisation.

Two cookies are involved. A session cookie holds a random token and keeps you logged in for seven days. A short-lived cookie during login protects against a cross-site attack and lasts ten minutes. Both are marked HttpOnly and Secure, and neither is used to follow you anywhere.

When you upload a map

We store the map file, its original filename, the name you give it, its size, when it was uploaded and when it expires, which organisation it belongs to and which account uploaded it. Organisation names, logos, invite links and API keys are stored too. API keys are only ever kept as a hash, so the key itself cannot be read back out of the database.

When someone downloads a map

We count downloads: a daily total for the site, and a daily total for each map. Those counts are what the usage figures and the reliability tracker on the home page are built from. We do not store who downloaded a map, and no IP addresses go into our database.

Who else is involved

  • Cloudflare runs the site, the database and the file storage, and delivers every download. As part of that it processes network data, including IP addresses, and keeps short-term logs to deliver and protect the service.
  • Discord handles the login itself. We never see your Discord password.

We do not sell data, and we do not share it with anyone else.

Anyone with a link can download the map

That is the point of the service: your server passes the link to every player who joins. Map links are hard to guess, and we ask search engines not to index them, but treat a map link as public. Do not upload anything you would not want downloaded.

How long things are kept

  • Maps are served for 90 days from upload. After that the link stops working and the file may be removed.
  • Deleted organisations can be restored for 30 days. After that they and their maps are deleted for good.
  • Sessions expire after seven days, and logging out ends them immediately.
  • Download counts are daily totals with nothing personal in them, and are kept as a record of usage.
  • Your account stays until you ask us to remove it.

Your choices

You can delete an organisation and its maps yourself, from its Settings page. You can revoke API keys and invite links at any time. To see what we hold about you, correct it, or have your account deleted, message us on Discord at @chronicallywhatever and we will sort it out.

Changes

If this page changes, the date at the top changes with it.