-
Notifications
You must be signed in to change notification settings - Fork 0
Privacy
Flume collects nothing by default, and asks once whether it may collect anything at all.
This page is the whole answer. If something here is vague, that is a bug — open an issue.
Not with your consent, not without it, not in a diagnostics report, not in a log file that leaves your machine:
- What you download. No torrent names, file names, info hashes, or magnet links.
- Who you download it from. No tracker addresses, peer IP addresses, or DHT node addresses.
- Where you put it. No file paths, folder names, or drive names.
- Who you are. No account, no email address, no name, no machine identifier, no hardware serial, no MAC address, no IP address stored by the collector.
- What you type. No search terms, no settings values.
There is no free-text field anywhere in the wire format. Every value Flume can
send is one of a fixed list, enumerated below and enforced twice — once by the
Rust type in src-tauri/src/usage/mod.rs, and again by the collector, which
rejects any batch containing a field or value it does not recognise.
Settings → Privacy → Diagnostics report.
Builds a report about this install for you to paste into a bug report. It is shown on screen first, and you copy it yourself. Flume does not send it anywhere and has no way to.
It contains Flume's version, your OS and CPU type, whether the listen port bound, how many DHT nodes were found, how many torrents are in your library (the count, never the list), your settings described rather than quoted — the download folder appears as "exists, inside the home directory", a proxy as "configured (socks5)" — and the last 200 lines of the current session's log with paths, addresses, URLs, info hashes and torrent names removed.
If usage reporting is on, it also says what happened to the last batch — that it was accepted, that it was refused with a status code, or that it got no answer at all. That last one is reported as exactly that, without guessing: being offline, a DNS block, a certificate problem and a proxy in the way are not distinguishable from inside Flume, and claiming to know which would be a verdict the data cannot support.
One honest limitation. Redaction removes torrent names by matching them against the torrents currently in your library, so a log line naming a torrent you have already removed has nothing to match against. Flume no longer writes torrent names into its log at all, and the one line that used to is redacted by shape as well — but librqbit, the engine underneath, is not under the same discipline, and a name reaching the log by some other route would survive.
That is why the report is shown before it is copied rather than after: you are the only person who can recognise a name that got through. Read it before you paste it.
Settings → Privacy → Send anonymous usage counts.
Asked once during first run and off unless you turn it on. Declining is permanent; Flume does not ask again.
If you turn it on, Flume sends, at most once an hour and once when you quit:
| Field | Value |
|---|---|
installId |
A random UUID generated on your machine when you consented |
appVersion |
Flume's version, e.g. 1.0.0
|
os |
macos, windows or linux
|
arch |
x86_64 or aarch64
|
events |
The list below |
installId is random. It is not derived from your hardware, your network,
your username or anything else — it is a UUID with no relationship to you or
your machine, so it cannot be linked to you or correlated with any other
application. Turning the setting off deletes it, along with anything queued
and not yet sent. Turning the setting back on generates a new one.
Every event is timed to the hour, not the second.
| Event | Carries |
|---|---|
launched |
nothing |
sessionEnded |
how long Flume ran, as one of five ranges |
libraryCount |
how many torrents, as one of five ranges |
torrentPreviewed |
magnet or file
|
torrentAdded |
nothing |
torrentCompleted |
nothing |
torrentRemoved |
whether the files were deleted too |
libraryImported |
how many torrents came from another client, as a range |
settingChanged |
which setting, e.g. net.proxy — never what you set it to
|
operationFailed |
which class of error, e.g. metadataTimeout
|
Counts are ranges rather than exact numbers because a range is what anyone would graph, and "the install with 1,483 torrents" is one identifiable person.
The collector runs on Cloudflare Workers and writes to a D1 database. Its
source is in collector/ in this repository — the whole thing is about 250
lines and you can read it.
It stores exactly the fields listed above. It does not store your IP
address or your User-Agent; the code never reads either, and the database
schema has no column for them. Requests reach Cloudflare, which sees your IP
as any web server would, but nothing in Flume's control records it.
Counts are approximate. Delivery is at-least-once, so a response lost after a row was written means a handful of events are counted twice. Events are also discarded from your machine after three days if they cannot be sent, so a long time offline loses counts rather than accumulating them. For aggregate counters that is a better trade than the complexity of exact-once delivery, and overstating the precision would be worse than the imprecision.
Settings → Privacy → Send anonymous usage counts → off.
Immediately, with no restart: the install ID file and the queue of unsent events are both deleted from your machine. Data already received cannot be tied back to you — the ID is gone from your side and was never linked to you in the first place — so there is nothing to request the deletion of.
Whether or not you consent to usage counts, Flume connects to:
- Trackers listed in the torrents you add.
- Peers, directly or through your configured SOCKS5 proxy.
- The DHT, if enabled, which is how magnet links work at all.
- Your router, if UPnP is enabled, to request a port mapping.
That is the complete list. Flume has no update checker, no crash reporter, no analytics SDK, no font or asset fetching — the fonts are vendored, so the interface renders with no network at all — and no bundled search.
The interface itself cannot make network requests. Its Content Security Policy allows it to talk to the Rust backend and nothing else, so every connection above originates in Rust where it can be audited in one place.
Settings → Network → Only transfer while traffic leaves through a tunnel.
Off unless you turn it on. When it is on, Flume works out which network interface your traffic would actually leave by, and can hold all transfer while that is not a tunnel.
It sends nothing to do this. The check is two lookups against your own routing table plus, when something changes, a walk of your interface list. There is no "what is my IP" request to a web service — that would mean handing your address to a third party in order to tell you your address is protected.
What holding actually does. Flume does not pause your torrents; it does not start the torrent engine at all. So while transfer is held there is no session: no peer connections, no tracker announces, no DHT, no listening port. Your torrents are not modified, which is why the ones you paused yourself stay paused and the ones that were running come back running when a tunnel returns.
A drop takes effect immediately. Recovery waits about ten seconds of a steady tunnel before resuming, so a VPN reconnecting or a laptop waking does not make your library flap between states, re-announcing to every tracker each time.
What it cannot tell you. Flume can see which interface traffic leaves by and whether that interface looks like a tunnel. It cannot see where the tunnel goes, who runs it, or whether it is doing what you think:
- A PPPoE connection or a USB cellular modem looks exactly like a VPN tunnel from here — the same kind of point-to-point link with no hardware address. If your machine dials the connection itself rather than going through a router, the check may say "tunnel" about your ordinary internet connection.
- On Windows with OpenVPN, the adapter is named
Local Area Connectionand is indistinguishable from an Ethernet card through anything Flume can read. It will not be recognised as a tunnel, and transfer will be held even though you are protected. Pinning that interface in settings is the way through. - Pinning an interface means Flume accepts it because you said so, not because it agrees. The interface says so where it appears, and it never claims that traffic is tunnelled on the strength of your pin.
This is a check on your own machine, not a guarantee about the internet. It is the difference between "traffic leaves through utun6, which is a tunnel interface" and "you are anonymous", and Flume only ever claims the first.
The wire format is versioned (schema: 1). A change to what is collected
means a new schema version, a change to this page, and a change to the
consent text — in the same commit, because
src-tauri/tests/usage_contract.rs fails until the client and the collector
agree.
Flume — Apache-2.0. This wiki is generated from docs/ by wiki-sync.yml; edits made here are overwritten on the next sync, so change the source instead and it gets reviewed with the code. The same pages, laid out for reading, are at flume.adamgreenwell.com/docs.
Using Flume
Developing
- Development-Setup
- Architecture
- Design-System
- Torrent-Engine-Notes
- CI-CD-and-Releases
- Signing-and-Distribution
Project