Privacy
Rostrum has no telemetry, no accounts and no usage tracking. It makes two kinds of network request, and only if you allow them: it sends a crash report after a crash, and it checks once a day for a new version. Both are chosen during first-time setup and can be changed later in Settings → Privacy and Settings → Updates. Nothing else in Rostrum touches the network, apart from OBS on your own computer.
This page is a summary. The full details, including the exact fields a crash report may contain, are in docs/privacy.md in the source repository.
Update checks
- On by default, once a day: the first check runs 20 seconds after Rostrum starts, then at most every 24 hours while it runs.
- It is a plain request for
https://getrostrum.dev/releases/latest.json, which redirects to the file attached to the latest release on GitHub. So the check talks to getrostrum.dev and GitHub. - The request carries Rostrum's version in its User-Agent and nothing else about you: no cookies, no ID. Like any request, the servers see the IP address it comes from.
- What happens next depends on how Rostrum was installed. A build from source shows a banner that links to what changed. Package installs are left to the package manager, and Flatpak installs do not check at all.
- Turn it off in Settings → Updates.
Crash reports
- Only official builds have crash reporting. A plain build from source has none, and the settings are hidden.
- The default is to ask: the next time Rostrum starts after a crash, it offers to send the report, and Show the Report shows exactly what would be sent. You can also choose to always send, or never.
- Reports go to Sentry (US region). Rostrum copies a fixed list of fields out of the crash: where it crashed, the signal, and the versions of Rostrum, the system, Qt, KDE Frameworks, PipeWire and WirePlumber. Everything else is dropped.
- No names, file paths, device names, host name or IDs. No memory contents are captured. Rostrum asks Sentry not to store your IP address or look up a location from it.
- There is no ping on launch, no session tracking and no breadcrumbs.
OBS
- Rostrum talks to OBS through obs-websocket on
127.0.0.1only. That traffic never leaves your computer. - Set Up OBS and Undo change OBS only when you press them.
- While OBS runs, Rostrum can follow it to show LIVE and REC badges, go-live warnings and scene mapping. It only reads, and stores nothing apart from the scene mapping you choose. You can turn this off in Settings → OBS.
No network listener
Rostrum opens no network ports. The rostrum command and the D-Bus interface on
your session bus are the only ways to control it from outside the window.
This website
getrostrum.dev is a set of static files hosted on Cloudflare Pages. It sets no cookies, runs no JavaScript, and has no analytics or trackers. Fonts, styles and images all come from this site; nothing is loaded from other servers. Cloudflare handles the requests to serve the pages.
Questions
Write to hello@getrostrum.dev. For security problems, write to security@getrostrum.dev.