Telemetry data-handling statement
Last updated 2026-10-07.
Who operates it
The Gameplane project maintainers run the default provider at telemetry.gameplane.net. Reports go to https://telemetry.gameplane.net/ingest. Anyone can run their own provider; this statement covers only the project's.
What is sent
Two tiers, about once a day, only while an admin has left them on.
- Basic: exactly
version(Gameplane version),servers(number of GameServers),templates(number of GameTemplates). - Extended (adds only the following): a random install ID (a UUID generated on the install, not derived from the cluster, host, network or users); environment: Kubernetes minor version, a distribution category (k3s, rke2, k0s, eks, gke, aks, openshift, microk8s, minikube, kind, doks, talos or other), CPU architectures, and a node-count band (1, 2-3, 4-10, 11-50, 51+); game usage: a server count for each official catalog module plus one combined
customcount; feature adoption: wake-on-connect, relay tunnel types (frp, tailscale, playit), packet capture, backups, single sign-on, audit forwarding (each yes/no), a registered-cluster band (1, 2-3, 4-10, 11+), database kind (sqlite or postgres) and UI language; the install's public signing key and the time the report was sent. - Every extended value comes from a fixed set of categories or bands, or is a number, the install ID, the public key or the send time; anything else is sent as
other.
Signing and the install ID
Extended reports are signed (Ed25519) with a key derived from a random secret that never leaves the install combined with the install ID; the provider binds an ID to the first key that uses it, so nobody can report under another install's ID. Signing proves which key sent a report, not that the install is real; figures are approximate and self-reported. The ID is pseudonymous: it lets the provider tell that two reports came from the same install. An admin can reset it in Admin Settings, and it is deleted from the install when extended telemetry is turned off.
What is never collected
Server names, namespaces, hostnames, player counts or names, custom module names, free text, or any address or identifier of your cluster, network or users. The provider does not store raw reports and does not store source network addresses. The report format cannot hold any of these.
Requests to telemetry.gameplane.net pass through Cloudflare's proxy, which sees the connecting address to deliver the request and handles it under Cloudflare's own privacy policy. The receiver uses the address only in memory to rate-limit and never stores it.
What the provider stores
| Category | Contents |
|---|---|
| Daily aggregates | Counts per day by version, fleet-size band, and for extended reports counts by environment, game and feature category; never linked to an install ID |
| Activity records | A one-way keyed hash of the install ID, a fingerprint of the public key, first-seen and last-seen dates, last send time and last version; used for unique-install and new/lapsed counts |
| Total-reports counter | A single number only |
How long
| Data | Retention |
|---|---|
| Daily aggregates | 24 months (730 days), deleted by an hourly sweep |
| Activity records | 90 days after the install's last report |
| Total-reports counter | Kept indefinitely |
| Source addresses | Memory only, never written to disk |
Abuse protection
Reports are strictly validated (one JSON object, size cap 16 KiB, fixed-set values); per-source daily limit; proof-of-work on submission whose cost is zero under normal traffic and grows only with the request rate (installs refuse challenges above 26 bits); the dashboard is private (token of at least 32 characters, never public). Someone can still send fabricated reports, so figures are approximate.
Public summary
https://telemetry.gameplane.net/v1/summary returns exactly five numbers: asOf date, reports on the latest day, reports in 30 days, total reports, and active installs in 30 days. Nothing else is public; the detailed dashboard is private to the maintainers.
How to opt out
- At first login: A notice appears before any report is sent, showing both tiers and the destination. Admin Settings > Telemetry then shows separate basic and extended switches (turning basic off turns extended off).
- At install time: Set
--set api.telemetry.enabled=falseto hard-disable telemetry whatever the switches say, with no notice shown. - Custom provider: Set
api.telemetry.endpoint=https://your-host/ingestto send to your own provider instead and never also to the project's. - Existing installs that never saved a choice stay off after upgrading.
See the docs on platform settings, telemetry, and build info, the Helm values reference, and air-gapped installation.
Questions and requests
Open an issue on GitHub; the maintainers operate the provider.