• Home
  • Features
  • Trust
  • Pricing
  • Discord
  • About Us

Legal — Privacy Policy

Privacy Policy

Privacy and Data Processing Notice

Last updated2026-02-24

Quick Summary

What we collect: Gameplay telemetry, behavioral signals, and account authentication data necessary for detection and observability.

How we use it: To detect suspicious activity, improve system accuracy, and provide operational insight to organizations.

On this page

  1. 1Introduction
  2. 2Information We Collect
  3. 3How We Collect Information
  4. 4How We Use Your Information
  5. 5Automated Decision-Making
  6. 6Data Sharing and Disclosure
  7. 7Data Storage and Security
  8. 8Data Retention
  9. 9Your Privacy Rights
  10. 10Public Game Data Considerations
  11. 11Cookies and Tracking Technologies
  12. 12Use by Minors
  13. 13International Data Transfers
  14. 14Third-Party Services
  15. 15Changes to This Privacy Policy
  16. 16Contact Us
Section 1

Introduction

Galium is a detection and intelligence platform designed to assist organizations in maintaining competitive integrity and operational oversight across Rust servers. This Privacy Policy explains what information we collect, how we use it, how we protect it, and what rights you may have regarding your personal information. This Policy complies with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). This policy applies to users of the Galium service, including website visitors, organization administrators, server operators, players whose in-game activity is processed through server-side integrations, Discord integration users, and API consumers (where available). By using Galium, you agree to the collection and use of information in accordance with this Privacy Policy. If you have questions or concerns about our privacy practices, please contact us at hello@cybersynthetics.com.
Section 2

Information We Collect

We collect several types of information to provide, secure, and improve our Service: Account Information: • Steam ID and Steam profile information (username, avatar) when you authenticate via Steam • Discord ID and Discord profile information (username, avatar, discriminator) when you authenticate via Discord • Organization and server configurations you create through our control panel • Subscription and payment status (payment processing handled by third-party providers) Server and Integration Data: • Server name, IP address, and port • Integration health, configuration settings, and operational metadata Telemetry, Integrity, and Detection Data: • Gameplay telemetry generated from in-game activity on servers where Galium is installed • Behavioral event streams and derived behavioral indicators used for integrity analysis • System integrity signals intended to identify tampering, abuse, or suspicious interaction with the Service and its integrations • Detection signals and risk scores generated by our detection and analysis systems • Automation event logs (including configured notifications, workflow actions, and system events) • Enforcement action logs (if applicable, when organizations configure enforcement or moderation actions) Technical Information: • IP address and browser information (for website access) • API access logs and request patterns • Error logs and performance metrics • Device information and operating system details We do NOT collect: • Email addresses (unless voluntarily provided for support) • Physical addresses or phone numbers • Payment card details (handled by third-party payment processors) • Private messages or chat logs • Voice communications or recordings
Section 3

How We Collect Information

Information is collected through various methods: Server-Side Integrations: Our server-side integrations collect telemetry, behavioral event signals, and integrity-related operational data from Rust servers where Galium is installed and enabled. Website and Control Panel: When you visit our website or use the control panel, we collect standard web analytics data and authentication information through Steam/Discord OAuth. Discord Integrations: When you interact with Galium’s Discord integrations (where available), we collect Discord user information and command/workflow usage data to provide integration functionality and improve our services. REST API: API usage generates access logs including timestamps, endpoints accessed, and response codes. API authentication tokens are stored securely. Third-Party Integrations: We may receive data from Steam's Web API, Discord's API, and optionally from Battlemetrics when you enable such integrations.
Section 4

How We Use Your Information

We use the collected information for the following purposes: Service Operation and Delivery: • Ingest and process telemetry and integrity signals to provide detection intelligence and observability • Provide dashboards, case workflows, audit trails, and operational reporting for organizations • Power notifications and integrations (including Discord integrations) based on organization configuration • Provide REST API access (where available) subject to access controls and rate limits • Manage multi-server and multi-organization deployments and configurations Detection, Risk Modeling, and Security: • Detect suspicious, anomalous, or abusive behavior patterns across servers and time windows • Perform risk modeling and scoring using telemetry-derived indicators • Monitor platform security, prevent abuse, and protect the integrity of the Service Automation Workflows: • Execute automation workflows configured by organizations (including alerts, routing, and optional enforcement actions) • Maintain automation event logs for auditability and operational analysis Service Improvement and Research: • Analyze usage patterns to improve features and user experience • Identify and fix bugs, errors, and performance issues • Refine detection quality and reduce false positives/false negatives • Train and improve our detection systems and machine learning models (where used) using gameplay telemetry, behavioral signals, and derived indicators Communication: • Send important service announcements and updates • Notify about subscription status, billing, and renewals • Respond to support requests and technical issues • Provide important security notifications • Share major feature releases (opt-in only for marketing) Analytics and Research: • Generate aggregate statistics about platform usage and detection performance • Understand behavioral and integrity trends at an aggregate level • Create anonymized datasets for research and detection refinement purposes Legal and Compliance: • Comply with legal obligations and regulatory requirements • Enforce our Terms of Service and Acceptable Use Policy • Protect against fraudulent, unauthorized, or illegal activity • Respond to law enforcement requests when legally required We do NOT use your data for: • Selling or renting to third parties for marketing purposes • Targeted advertising based on gameplay behavior • Profiling for purposes outside integrity monitoring, observability, and Service security.
Section 5

Automated Decision-Making

Galium may generate automated risk signals, flags, or classifications based on gameplay telemetry and behavioral analysis. These outputs are intended to support integrity monitoring and operational oversight. Unless explicitly configured by an organization, Galium does not independently impose enforcement outcomes. Final enforcement actions (including moderation decisions) are determined by the server operator or organization and may involve human review and additional context. Where automation features are enabled, organizations may configure thresholds, routing, and automated actions. Galium maintains audit logs to support accountability and operational review.
Section 6

Data Sharing and Disclosure

Galium respects your privacy and the security of our detection systems. We share data only in limited circumstances: With Your Consent: We will share data with third parties when you explicitly authorize such sharing, such as when you enable integrations with external services. With Organizations You Interact With: Galium is operated by organizations and server operators. Where applicable, we provide telemetry, integrity signals, detection outputs, case workflow data, and audit logs to authorized organization administrators to support integrity monitoring and operational oversight on their servers. Service Providers: We work with trusted third-party service providers who assist in operating our Service: • Cloud infrastructure providers (hosting and data storage) • Payment processors (subscription billing - they never share payment details with us) • Content delivery networks (CDNs for fast global access) • Analytics tools (aggregate usage statistics) These providers have access only to necessary information and are contractually obligated to maintain confidentiality and security. Integrity Protection and Investigations: We may disclose information as reasonably necessary to: • Investigate cheating, abuse, fraud, or violations of our Terms of Service • Protect the integrity and security of the Service and its integrations • Coordinate with affected organizations when investigating integrity incidents Legal Requirements: We may disclose information when required by law, such as: • In response to court orders, subpoenas, or legal processes • To enforce our Terms of Service or protect rights and property • To investigate potential violations or fraudulent activity • To protect the safety of our users or the public • To cooperate with legal authorities and law enforcement where legally required or appropriate Business Transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity, subject to the same privacy protections. Aggregate and Anonymized Data: We may share aggregate, non-identifiable statistical data about platform usage, integrity trends, and detection performance for research, partnerships, or public reports. We do NOT: • Sell or rent personal information to third parties • Share data with advertisers or marketing companies • Share API tokens or authentication credentials
Section 7

Data Storage and Security

We take data security seriously and implement industry-standard measures to protect your information: Technical Security Measures: • Encrypted data transmission using SSL/TLS protocols • Secure storage with encryption at rest for sensitive data • Regular security audits and vulnerability assessments • Access controls limiting employee access to necessary data only • API authentication using secure token-based systems • Regular automated backups with secure offsite storage Infrastructure Security: • Hosted on reputable cloud infrastructure providers • Network security with firewalls and intrusion detection • DDoS protection and traffic monitoring • Regular software updates and security patches • Isolated environments for testing and production Organizational Security: • Security training for all team members with data access • Strict confidentiality agreements with employees and contractors • Incident response procedures for potential breaches • Regular review and update of security policies Detection System Safeguards: • Restricted access to detection systems, risk models, and sensitive integrity datasets on a need-to-know basis • Internal segmentation of sensitive detection data and operational environments to reduce exposure • Measures intended to reduce reverse engineering, adversarial probing, and unauthorized access to detection methodologies Data Location: Your data is stored and processed in secure data centers located in the United Arab Emirates and the United States. All data transfers are protected under equivalent security and data protection standards, and we apply the same safeguards to all storage locations. Global CDNs may be used to enhance performance, but no sensitive data is stored in those systems. Despite our security measures, no method of electronic storage or internet transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials. If any data incident occurs, we will act in accordance with applicable UAE data protection obligations.
Section 8

Data Retention

We retain data for as long as necessary to provide our Service and comply with legal obligations: Active Data: • Account information and configurations are retained while your account is active • Telemetry, integrity signals, detection outputs, and audit logs are retained as necessary to provide integrity monitoring, investigations, and operational reporting • Detection signals may be retained longer to support integrity analysis, trend analysis, dispute handling, and detection refinement • API access logs are retained for approximately 90 days for security purposes • Server configurations are retained while your subscription is active Aggregated and Anonymized Data: • Aggregated detection datasets may be retained indefinitely in anonymized form for research and detection refinement Inactive Accounts: • Free accounts may be deleted after extended periods of inactivity • Paid accounts are retained for a reasonable period after subscription ends • Archived data may be permanently deleted after account closure, subject to legal, security, and integrity-related retention requirements
Section 9

Your Privacy Rights

Users may contact us at hello@cybersynthetics.com to request access to, or correction of, authentication-related information (Steam/Discord) and account-level data. We will consider requests in accordance with applicable UAE PDPL requirements. For security and integrity reasons, access requests do not include disclosure of proprietary detection methodologies, risk models, scoring logic, thresholds, rules, or other details that could reasonably enable evasion, reverse engineering, or compromise of the Service. We may provide high-level categories of data processed and the account-related information we maintain without exposing sensitive system security details.
Section 10

Public Game Data Considerations

Certain gameplay data processed by Galium may originate from publicly accessible in-game activity and public platform APIs (such as Steam profile information). This may include identifiers that are visible in-game and chosen by players themselves. Where applicable under the UAE PDPL, such publicly accessible data may be subject to limited rights of erasure. We review privacy requests on a case-by-case basis and will respond in accordance with applicable law, while balancing requests against the need to protect platform security, prevent fraud and abuse, and preserve the integrity of investigations and audit trails. Where appropriate, we may anonymize or de-identify certain records rather than delete them outright, particularly where retention is necessary for security, integrity monitoring, or legal compliance.
Section 11

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website and Service: Essential Cookies: • Session management and authentication cookies • Security tokens for protected resources • User preference settings (theme, language) • CSRF protection tokens These cookies are necessary for the Service to function and cannot be disabled. Functional Cookies: • Remember your login status • Save your control panel settings and preferences • Store your selected organization/server context • Cache API responses for performance Analytics Cookies: • Track page views and user journeys • Monitor feature usage and engagement • Identify errors and performance issues • Generate aggregate usage statistics We do NOT use: • Third-party advertising cookies • Cross-site tracking cookies • Social media tracking pixels (beyond basic OAuth) • Behavioral profiling cookies for marketing Cookie Management: You can control cookies through your browser settings. Note that disabling essential cookies may limit Service functionality. Most browsers allow you to: • View and delete cookies • Block third-party cookies • Set cookie expiration preferences • Receive notifications when cookies are set Local Storage: We use browser local storage for caching data, storing preferences, and improving performance. This data is stored locally on your device and can be cleared through browser settings. Third-Party Services: Some integrated third-party services (Steam, Discord) may set their own cookies when you authenticate. Refer to their respective privacy policies for details.
Section 12

Use by Minors

Galium is designed for use with Rust, a game intended for players aged 17 and above. Our Service is not directed to or intended for children under 13 years of age. We do not knowingly collect or process any data relating to minors. Steam and Discord authentication providers both require users to meet their own age requirements, which we rely on to ensure compliance.
Section 13

International Data Transfers

We may store or process data on secure servers in the United Arab Emirates and the United States. All transfers meet UAE PDPL standards and include equivalent safeguards.
Section 14

Third-Party Services

Our Service integrates with several third-party platforms. Each has its own privacy policy: Steam (Valve Corporation): • Used for: Player authentication, profile information, and game data • Data shared: Steam ID, username, avatar • Privacy Policy: https://store.steampowered.com/privacy_agreement/ • Control: Managed through your Steam account privacy settings Discord (Discord Inc.): • Used for: Bot integration, user authentication, community features • Data shared: Discord ID, username, server membership • Privacy Policy: https://discord.com/privacy • Control: Managed through your organization profile Payment Processors: • Used for: Subscription billing and payment processing • Data shared: Billing information (not visible to Galium) • We work with PCI-DSS compliant processors • Refer to their respective privacy policies Cloud Infrastructure Providers: • Used for: Hosting, storage, and computing resources • Data shared: All data stored on our Service • Providers include major cloud platforms with enterprise-grade security • Subject to strict data processing agreements Content Delivery Networks (CDNs): • Used for: Fast global content delivery and DDoS protection • Data shared: IP address, requested resources • Temporary caching of public content only These integrations are necessary for Service functionality. By using Galium, you acknowledge that these third-party services will process your data according to their respective privacy policies. We carefully vet third-party providers for security and privacy practices, but we cannot control their policies or practices. We encourage you to review their privacy policies directly.
Section 15

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. Notification of Changes: When we make changes, we will: • Update the "Last Updated" date at the top of this page • Post a notice on our website and in the client portal • Send email notifications for significant changes (if you've provided an email) • Announce major changes in our Discord server What Constitutes a Material Change: • New types of personal data collected • Changes in how we share or disclose data • Changes in data retention periods • New purposes for processing data • Reduced privacy protections or rights Your Options: If you disagree with updated terms: • You may discontinue use of the Service • You may request data deletion before changes take effect • You may contact us to discuss concerns Continued Use: Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically. Historical Versions: Previous versions of this Privacy Policy are available upon request at hello@cybersynthetics.com for comparison and reference. We are committed to protecting your privacy and will never make changes that fundamentally undermine the privacy expectations established when you first started using our Service.
Section 16

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: Email: hello@cybersynthetics.com Discord: https://discord.gg/galium Website: https://galium.gg For privacy-related requests, please include your Steam ID or Discord ID and a description of your request. We aim to respond to all inquiries promptly. We take all privacy concerns seriously and will work diligently to address any issues you raise.

Questions about your privacy?

For privacy requests or questions regarding data processing, contact us using the options below.

Email Support Join Discord
© 2026 Galium - CyberSynthetics Solutions LLC
• Terms • Privacy • Discord