Privacy Policy
This Privacy Policy (the “Policy”) describes what data is processed by the Tirify App mobile application and web panel (the “App”, the “Service”, “we”), for what purposes, who it is shared with, and how you can control it, including deleting your account.
Data controller. The Service is operated by the Tirify team. For any questions about the processing of personal data, or to exercise your rights, contact support@tirify.com — this is the single point of contact for privacy matters.
1. What Tirify App is
Tirify App is an administration tool for game servers (Rust). The App is intended for owners and staff of game projects (administrators, moderators) and lets them manage servers, moderate players, configure automoderation and notifications, run RCON commands, and view statistics. The App is not intended for end players and is not a public service for a general audience.
2. Data we collect
We collect only the data required for the Service to work.
2.1. Account data
- Email address — for sign-up, sign-in, account recovery, and service notifications.
- Password — stored solely as an irreversible cryptographic hash; we have no access to your password in plain text.
- Two-factor authentication (2FA) data — if enabled: the 2FA secret and hashes of backup codes.
- Staff profile — display name, avatar (if you uploaded one), role, and access permissions (RBAC) within a project.
2.2. Technical and session data
- Session and refresh tokens — to keep you signed in, along with the session creation and last-activity times, so you can see and revoke your devices.
- IP address — processed server-side when the API is accessed (security, abuse prevention, diagnostics).
- Device push token (Firebase Cloud Messaging) — an identifier used to deliver push notifications on Android, iOS, and the web version. It is sent to our server after sign-in and revoked on sign-out.
- Technical logs — records of errors and requests used to keep the Service running and secure.
2.3. Biometrics
If you enable biometric sign-in (Face ID / Touch ID / fingerprint), the check is performed locally on your device by the operating system. We do not receive, store, or share biometric data — the App only receives a “success / failure” result, which unlocks a locally stored session.
2.4. Analytics and error monitoring
- Usage analytics (web version only). In the browser version we use Google Analytics for Firebase to understand which sections of the panel are used. Anonymized events are collected: app instance identifier, browser and device type, and approximate region (determined by Google from the IP address). Analytics is not included in the iOS and Android mobile builds.
- Error monitoring. Crashes and unhandled exceptions are sent to a Sentry monitoring system hosted on our own infrastructure (the tirify.com domain) — this data is not sent to a third-party service. HTTP request and response bodies are not sent to monitoring: tokens and personal data pass through the API, and they have no place in an error tracker. Monitoring is enabled only in production builds.
2.5. What we do NOT collect
- We do not request or use advertising identifiers (IDFA / GAID) and do not show ads.
- We do not sell personal data to third parties.
- We do not request location permission and do not collect precise device location data.
- We have no access to your camera, microphone, contacts, or calendar.
3. Player data processed through the panel
As a moderation tool, Tirify App displays and processes data about players on connected game servers. This data belongs to the respective game project, and the project operator acts as its controller; Tirify App processes it on behalf of the project administrator for moderation purposes. Such data may include:
- Steam identifiers (SteamID), nicknames, and public avatars of players;
- players’ IP addresses and the results of proxy/VPN checks on them;
- moderation records: bans, kicks, mutes, warnings, reports;
- in-game chat messages, screenshots, and anti-cheat events.
A player’s country is determined using a local offline IP-to-country database on our server: the player’s IP address is not sent anywhere for this. Access to IP addresses and other sensitive fields in the panel is additionally restricted by a separate permission in the role model — not every project staff member can see them, only those who have been granted that permission.
This data is used solely for moderation and ensuring fair play on the servers and is not used for advertising purposes.
4. Purposes and legal bases for processing
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation, sign-in, security | email, password (hash), 2FA, session tokens, IP | Performance of a contract / legitimate interest |
| Delivering push notifications | device push token | Consent (notification permission) |
| Moderation features | player data (see §3) | Legitimate interest of the project operator |
| Diagnostics, stability, abuse prevention | technical logs, error reports, IP | Legitimate interest |
| Web version usage analytics | anonymized interface events | Legitimate interest |
5. Device permissions
- Internet / network — to exchange data with our server and detect connection status.
- Notifications (push) — to deliver event alerts. Can be turned off in your device settings or in the “Account” section.
- Biometrics — to unlock the session locally (see §2.3). Can be turned off.
- Photo access — requested only when you choose an image for your avatar yourself. The selected file is uploaded to our server; the App gets no access to the rest of your gallery.
6. Sharing with third parties
We share data only with infrastructure providers required for the App to work, and only to the minimum extent necessary:
| Recipient | What is shared | Purpose |
|---|---|---|
| Google — Firebase Cloud Messaging | device push token, notification content | Push delivery on Android, iOS (via APNs), and the web version |
| Google — Analytics for Firebase | anonymized interface events, device and browser type, IP address (used by Google to determine approximate region) | Web version usage statistics |
| proxycheck.io | player IP address | Proxy/VPN check for moderation |
| Valve — avatars.steamstatic.com | browser request for an avatar image | Displaying player avatars |
| flagcdn.com | browser request for a flag image | Displaying country flags |
Images from external CDNs (Steam, flagcdn) are loaded directly by the browser, so, as with any website that shows external images, these services can see your device’s IP address. No account data is shared in the process.
Error monitoring runs on our own Sentry installation and is not part of this list — the data does not leave our infrastructure (see §2.4).
We may also disclose data where required by law (in response to a lawful request from competent authorities) or to protect the rights, safety, and integrity of the Service.
7. Data retention
- Account data is kept while the account is active and is deleted at your request (see §8).
- The push token is kept while the device is registered and is revoked on sign-out.
- Technical logs and error reports are kept for up to 90 days, after which they are deleted or anonymized.
- Player moderation data is kept according to the settings of the respective game project.
8. Deleting your account and data
You can delete your Tirify App account and the personal data associated with it at any time in one of two ways:
- In the App: “Account” section → “Danger zone” block → “Delete account” button. You will need to confirm the action with your password.
- By email: send a request to support@tirify.com from the address linked to your account.
Deletion in the App takes effect immediately: we anonymize your email and display name, erase your password hash and avatar, delete your 2FA secret and backup codes, and revoke all active sessions on all devices. The account cannot be restored afterwards. Requests sent by email are processed within 30 days.
Certain records (for example, security logs) may be retained for the period stated in §7, or longer where expressly required by law; such data is kept to a minimum and then deleted.
Player data processed within a project is deleted upon request to the administrator of the respective game project.
Step-by-step instructions and the full list of data that gets deleted are on a separate page: “Account deletion” (in Russian).
9. Security
- Data in transit is protected with HTTPS/TLS encryption.
- Passwords are stored only as irreversible hashes.
- Refresh tokens are single-use: any attempt to reuse an already-spent token forcibly terminates the entire session chain.
- Access to features is governed by a role model (RBAC); two-factor authentication is supported.
- Staff actions in the panel are recorded in the project’s audit log.
- We apply organizational and technical measures to protect against unauthorized access.
No method of data transmission or storage is completely secure; we strive to use commercially reasonable safeguards but cannot guarantee absolute security.
10. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your data, as well as to withdraw consent and object to processing. To exercise these rights, contact support@tirify.com. You also have the right to lodge a complaint with a data protection supervisory authority.
11. Changes to this Policy
We may update this Policy. In the event of material changes, we will update the date at the top of the document and, where appropriate, notify you in the App or by email. Continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.
12. Contact
For questions about privacy and data processing:
- Email: support@tirify.com
- Website: https://tirify.app
This is a translation of the Russian version of the Policy. In case of any discrepancy, the Russian version prevails.