-
Notifications
You must be signed in to change notification settings - Fork 0
Privacy
Flume collects nothing by default, and asks once whether it may collect anything at all.
This page is the whole answer. If something here is vague, that is a bug — open an issue.
Not with your consent, not without it, not in a diagnostics report, not in a log file that leaves your machine:
- What you download. No torrent names, file names, info hashes, or magnet links.
- Who you download it from. No tracker addresses, peer IP addresses, or DHT node addresses.
- Where you put it. No file paths, folder names, or drive names.
- Who you are. No account, no email address, no name, no machine identifier, no hardware serial, no MAC address, no IP address stored by the collector.
- What you type. No search terms, no settings values.
There is no free-text field anywhere in the wire format. Every value Flume can
send is one of a fixed list, enumerated below and enforced twice — once by the
Rust type in src-tauri/src/usage/mod.rs, and again by the collector, which
rejects any batch containing a field or value it does not recognise.
Settings → Privacy → Diagnostics report.
Builds a report about this install for you to paste into a bug report. It is shown on screen first, and you copy it yourself. Flume does not send it anywhere and has no way to.
It contains Flume's version, your OS and CPU type, whether the listen port bound, how many DHT nodes were found, how many torrents are in your library (the count, never the list), your settings described rather than quoted — the download folder appears as "exists, inside the home directory", a proxy as "configured (socks5)" — and the last 200 lines of the current session's log with paths, addresses, URLs, info hashes and torrent names removed.
If usage reporting is on, it also says what happened to the last batch — that it was accepted, that it was refused with a status code, or that it got no answer at all. That last one is reported as exactly that, without guessing: being offline, a DNS block, a certificate problem and a proxy in the way are not distinguishable from inside Flume, and claiming to know which would be a verdict the data cannot support.
One honest limitation. Redaction removes torrent names by matching them against the torrents currently in your library, so a log line naming a torrent you have already removed has nothing to match against. Flume no longer writes torrent names into its log at all, and the one line that used to is redacted by shape as well — but librqbit, the engine underneath, is not under the same discipline, and a name reaching the log by some other route would survive.
That is why the report is shown before it is copied rather than after: you are the only person who can recognise a name that got through. Read it before you paste it.
Settings → Privacy → Send anonymous usage counts.
Asked once during first run and off unless you turn it on. Declining is permanent; Flume does not ask again.
If you turn it on, Flume sends, at most once an hour and once when you quit:
| Field | Value |
|---|---|
installId |
A random UUID generated on your machine when you consented |
appVersion |
Flume's version, e.g. 1.0.0
|
os |
macos, windows or linux
|
arch |
x86_64 or aarch64
|
events |
The list below |
installId is random. It is not derived from your hardware, your network,
your username or anything else — it is a UUID with no relationship to you or
your machine, so it cannot be linked to you or correlated with any other
application. Turning the setting off deletes it, along with anything queued
and not yet sent. Turning the setting back on generates a new one.
Every event is timed to the hour, not the second.
| Event | Carries |
|---|---|
launched |
nothing |
sessionEnded |
how long Flume ran, as one of five ranges |
libraryCount |
how many torrents, as one of five ranges |
torrentPreviewed |
magnet or file
|
torrentAdded |
nothing |
torrentCompleted |
nothing |
torrentRemoved |
whether the files were deleted too |
libraryImported |
how many torrents came from another client, as a range |
settingChanged |
which setting, e.g. net.proxy — never what you set it to
|
operationFailed |
which class of error, e.g. metadataTimeout
|
Counts are ranges rather than exact numbers because a range is what anyone would graph, and "the install with 1,483 torrents" is one identifiable person.
The collector runs on Cloudflare Workers and writes to a D1 database. Its
source is in collector/ in this repository — the whole thing is about 250
lines and you can read it.
It stores exactly the fields listed above. It does not store your IP
address or your User-Agent; the code never reads either, and the database
schema has no column for them. Requests reach Cloudflare, which sees your IP
as any web server would, but nothing in Flume's control records it.
Counts are approximate. Delivery is at-least-once, so a response lost after a row was written means a handful of events are counted twice. Events are also discarded from your machine after three days if they cannot be sent, so a long time offline loses counts rather than accumulating them. For aggregate counters that is a better trade than the complexity of exact-once delivery, and overstating the precision would be worse than the imprecision.
Settings → Privacy → Send anonymous usage counts → off.
Immediately, with no restart: the install ID file and the queue of unsent events are both deleted from your machine. Data already received cannot be tied back to you — the ID is gone from your side and was never linked to you in the first place — so there is nothing to request the deletion of.
Whether or not you consent to usage counts, Flume connects to:
- Trackers listed in the torrents you add.
- Peers, directly or through your configured SOCKS5 proxy.
- The DHT, if enabled, which is how magnet links work at all.
- Your router, if UPnP is enabled, to request a port mapping.
That is the complete list. Flume has no update checker, no crash reporter, no analytics SDK, no font or asset fetching — the fonts are vendored, so the interface renders with no network at all — and no bundled search.
The interface itself cannot make network requests. Its Content Security Policy allows it to talk to the Rust backend and nothing else, so every connection above originates in Rust where it can be audited in one place.
The wire format is versioned (schema: 1). A change to what is collected
means a new schema version, a change to this page, and a change to the
consent text — in the same commit, because
src-tauri/tests/usage_contract.rs fails until the client and the collector
agree.
Flume — Apache-2.0. This wiki is generated from docs/ by wiki-sync.yml; edits made here are overwritten on the next sync, so change the source instead and it gets reviewed with the code. The same pages, laid out for reading, are at flume.adamgreenwell.com/docs.
Using Flume
Developing
- Development-Setup
- Architecture
- Design-System
- Torrent-Engine-Notes
- CI-CD-and-Releases
- Signing-and-Distribution
Project