Skip to content

Privacy

github-actions[bot] edited this page Sep 1, 2026 · 4 revisions

Privacy

Flume collects nothing by default, and asks once whether it may collect anything at all.

This page is the whole answer. If something here is vague, that is a bug — open an issue.

What Flume never collects

Not with your consent, not without it, not in a diagnostics report, not in a log file that leaves your machine:

  • What you download. No torrent names, file names, info hashes, or magnet links.
  • Who you download it from. No tracker addresses, peer IP addresses, or DHT node addresses.
  • Where you put it. No file paths, folder names, or drive names.
  • Who you are. No account, no email address, no name, no machine identifier, no hardware serial, no MAC address, no IP address stored by the collector.
  • What you type. No search terms, no settings values.

There is no free-text field anywhere in the wire format. Every value Flume can send is one of a fixed list, enumerated below and enforced twice — once by the Rust type in src-tauri/src/usage/mod.rs, and again by the collector, which rejects any batch containing a field or value it does not recognise.

The two features

Diagnostics report — nothing is sent

Settings → Privacy → Diagnostics report.

Builds a report about this install for you to paste into a bug report. It is shown on screen first, and you copy it yourself. Flume does not send it anywhere and has no way to.

It contains Flume's version, your OS and CPU type, whether the listen port bound, how many DHT nodes were found, how many torrents are in your library (the count, never the list), your settings described rather than quoted — the download folder appears as "exists, inside the home directory", a proxy as "configured (socks5)" — and the last 200 lines of the current session's log with paths, addresses, URLs, info hashes and torrent names removed.

If usage reporting is on, it also says what happened to the last batch — that it was accepted, that it was refused with a status code, or that it got no answer at all. That last one is reported as exactly that, without guessing: being offline, a DNS block, a certificate problem and a proxy in the way are not distinguishable from inside Flume, and claiming to know which would be a verdict the data cannot support.

One honest limitation. Redaction removes torrent names by matching them against the torrents currently in your library, so a log line naming a torrent you have already removed has nothing to match against. Flume no longer writes torrent names into its log at all, and the one line that used to is redacted by shape as well — but librqbit, the engine underneath, is not under the same discipline, and a name reaching the log by some other route would survive.

That is why the report is shown before it is copied rather than after: you are the only person who can recognise a name that got through. Read it before you paste it.

Usage counts — opt-in, off unless you say yes

Settings → Privacy → Send anonymous usage counts.

Asked once during first run and off unless you turn it on. Declining is permanent; Flume does not ask again.

If you turn it on, Flume sends, at most once an hour and once when you quit:

Field Value
installId A random UUID generated on your machine when you consented
appVersion Flume's version, e.g. 1.0.0
os macos, windows or linux
arch x86_64 or aarch64
events The list below

installId is random. It is not derived from your hardware, your network, your username or anything else — it is a UUID with no relationship to you or your machine, so it cannot be linked to you or correlated with any other application. Turning the setting off deletes it, along with anything queued and not yet sent. Turning the setting back on generates a new one.

Every event is timed to the hour, not the second.

Event Carries
launched nothing
sessionEnded how long Flume ran, as one of five ranges
libraryCount how many torrents, as one of five ranges
torrentPreviewed magnet or file
torrentAdded nothing
torrentCompleted nothing
torrentRemoved whether the files were deleted too
libraryImported how many torrents came from another client, as a range
settingChanged which setting, e.g. net.proxynever what you set it to
operationFailed which class of error, e.g. metadataTimeout

Counts are ranges rather than exact numbers because a range is what anyone would graph, and "the install with 1,483 torrents" is one identifiable person.

What the collector stores

The collector runs on Cloudflare Workers and writes to a D1 database. Its source is in collector/ in this repository — the whole thing is about 250 lines and you can read it.

It stores exactly the fields listed above. It does not store your IP address or your User-Agent; the code never reads either, and the database schema has no column for them. Requests reach Cloudflare, which sees your IP as any web server would, but nothing in Flume's control records it.

Counts are approximate. Delivery is at-least-once, so a response lost after a row was written means a handful of events are counted twice. Events are also discarded from your machine after three days if they cannot be sent, so a long time offline loses counts rather than accumulating them. For aggregate counters that is a better trade than the complexity of exact-once delivery, and overstating the precision would be worse than the imprecision.

Turning it off

Settings → Privacy → Send anonymous usage counts → off.

Immediately, with no restart: the install ID file and the queue of unsent events are both deleted from your machine. Data already received cannot be tied back to you — the ID is gone from your side and was never linked to you in the first place — so there is nothing to request the deletion of.

Network connections Flume makes

Whether or not you consent to usage counts, Flume connects to:

  • Trackers listed in the torrents you add.
  • Peers, directly or through your configured SOCKS5 proxy.
  • The DHT, if enabled, which is how magnet links work at all.
  • Your router, if UPnP is enabled, to request a port mapping.

That is the complete list. Flume has no update checker, no crash reporter, no analytics SDK, no font or asset fetching — the fonts are vendored, so the interface renders with no network at all — and no bundled search.

The interface itself cannot make network requests. Its Content Security Policy allows it to talk to the Rust backend and nothing else, so every connection above originates in Rust where it can be audited in one place.

The tunnel check — what it can and cannot tell you

Settings → Network → Only transfer while traffic leaves through a tunnel.

Off unless you turn it on. When it is on, Flume works out which network interface your traffic would actually leave by, and can hold all transfer while that is not a tunnel.

It sends nothing to do this. The check is two lookups against your own routing table plus, when something changes, a walk of your interface list. There is no "what is my IP" request to a web service — that would mean handing your address to a third party in order to tell you your address is protected.

What holding actually does. Flume does not pause your torrents; it does not start the torrent engine at all. So while transfer is held there is no session: no peer connections, no tracker announces, no DHT, no listening port. Your torrents are not modified, which is why the ones you paused yourself stay paused and the ones that were running come back running when a tunnel returns.

A drop takes effect immediately. Recovery waits about ten seconds of a steady tunnel before resuming, so a VPN reconnecting or a laptop waking does not make your library flap between states, re-announcing to every tracker each time.

What it cannot tell you. Flume can see which interface traffic leaves by and whether that interface looks like a tunnel. It cannot see where the tunnel goes, who runs it, or whether it is doing what you think:

  • A PPPoE connection or a USB cellular modem looks exactly like a VPN tunnel from here — the same kind of point-to-point link with no hardware address. If your machine dials the connection itself rather than going through a router, the check may say "tunnel" about your ordinary internet connection.
  • On Windows with OpenVPN, the adapter is named Local Area Connection and is indistinguishable from an Ethernet card through anything Flume can read. It will not be recognised as a tunnel, and transfer will be held even though you are protected. Pinning that interface in settings is the way through.
  • Pinning an interface means Flume accepts it because you said so, not because it agrees. The interface says so where it appears, and it never claims that traffic is tunnelled on the strength of your pin.

This is a check on your own machine, not a guarantee about the internet. It is the difference between "traffic leaves through utun6, which is a tunnel interface" and "you are anonymous", and Flume only ever claims the first.

Changes to this page

The wire format is versioned (schema: 1). A change to what is collected means a new schema version, a change to this page, and a change to the consent text — in the same commit, because src-tauri/tests/usage_contract.rs fails until the client and the collector agree.

Clone this wiki locally