TELEMETRY

Telemetry data-handling statement

Last updated 2026-10-07.

Who operates it

The Gameplane project maintainers run the default provider at telemetry.gameplane.net. Reports go to https://telemetry.gameplane.net/ingest. Anyone can run their own provider; this statement covers only the project's.

What is sent

Two tiers, about once a day, only while an admin has left them on.

  • Basic: exactly version (Gameplane version), servers (number of GameServers), templates (number of GameTemplates).
  • Extended (adds only the following): a random install ID (a UUID generated on the install, not derived from the cluster, host, network or users); environment: Kubernetes minor version, a distribution category (k3s, rke2, k0s, eks, gke, aks, openshift, microk8s, minikube, kind, doks, talos or other), CPU architectures, and a node-count band (1, 2-3, 4-10, 11-50, 51+); game usage: a server count for each official catalog module plus one combined custom count; feature adoption: wake-on-connect, relay tunnel types (frp, tailscale, playit), packet capture, backups, single sign-on, audit forwarding (each yes/no), a registered-cluster band (1, 2-3, 4-10, 11+), database kind (sqlite or postgres) and UI language; the install's public signing key and the time the report was sent.
  • Every extended value comes from a fixed set of categories or bands, or is a number, the install ID, the public key or the send time; anything else is sent as other.

Signing and the install ID

Extended reports are signed (Ed25519) with a key derived from a random secret that never leaves the install combined with the install ID; the provider binds an ID to the first key that uses it, so nobody can report under another install's ID. Signing proves which key sent a report, not that the install is real; figures are approximate and self-reported. The ID is pseudonymous: it lets the provider tell that two reports came from the same install. An admin can reset it in Admin Settings, and it is deleted from the install when extended telemetry is turned off.

What is never collected

Server names, namespaces, hostnames, player counts or names, custom module names, free text, or any address or identifier of your cluster, network or users. The provider does not store raw reports and does not store source network addresses. The report format cannot hold any of these.

Requests to telemetry.gameplane.net pass through Cloudflare's proxy, which sees the connecting address to deliver the request and handles it under Cloudflare's own privacy policy. The receiver uses the address only in memory to rate-limit and never stores it.

What the provider stores

CategoryContents
Daily aggregatesCounts per day by version, fleet-size band, and for extended reports counts by environment, game and feature category; never linked to an install ID
Activity recordsA one-way keyed hash of the install ID, a fingerprint of the public key, first-seen and last-seen dates, last send time and last version; used for unique-install and new/lapsed counts
Total-reports counterA single number only

How long

DataRetention
Daily aggregates24 months (730 days), deleted by an hourly sweep
Activity records90 days after the install's last report
Total-reports counterKept indefinitely
Source addressesMemory only, never written to disk

Abuse protection

Reports are strictly validated (one JSON object, size cap 16 KiB, fixed-set values); per-source daily limit; proof-of-work on submission whose cost is zero under normal traffic and grows only with the request rate (installs refuse challenges above 26 bits); the dashboard is private (token of at least 32 characters, never public). Someone can still send fabricated reports, so figures are approximate.

Public summary

https://telemetry.gameplane.net/v1/summary returns exactly five numbers: asOf date, reports on the latest day, reports in 30 days, total reports, and active installs in 30 days. Nothing else is public; the detailed dashboard is private to the maintainers.

How to opt out

  • At first login: A notice appears before any report is sent, showing both tiers and the destination. Admin Settings > Telemetry then shows separate basic and extended switches (turning basic off turns extended off).
  • At install time: Set --set api.telemetry.enabled=false to hard-disable telemetry whatever the switches say, with no notice shown.
  • Custom provider: Set api.telemetry.endpoint=https://your-host/ingest to send to your own provider instead and never also to the project's.
  • Existing installs that never saved a choice stay off after upgrading.

See the docs on platform settings, telemetry, and build info, the Helm values reference, and air-gapped installation.

Questions and requests

Open an issue on GitHub; the maintainers operate the provider.