Skip to content

Privacy and Crash Reports

22Pizzas edited this page Oct 3, 2026 · 2 revisions

Rostrum makes two kinds of network request, and only if you allow them: it can send a crash report after a crash, and it checks once a day for a new version. Nothing else in Rostrum touches the network, apart from talking to OBS's WebSocket server on your own computer. Rostrum never listens for connections from the network; its remote control works over D-Bus, which is local to your desktop session.

You choose both during first-time setup and can change them later in Settings → Privacy and Settings → Updates. The full technical description is docs/privacy.md.

Does my copy have crash reports?

Only official builds can send crash reports. They are built with Rostrum's own crash reporting settings, and no official builds have been published yet.

A copy you build yourself from source has no crash reporting at all. In that case:

  • First-time setup's step is called Updates instead of Privacy and Updates.
  • Settings has no Privacy group.
  • Nothing about crashes leaves your computer. A crash still adds a backtrace to the log file, which you can attach to an issue yourself.

Crash reports (official builds)

Reports go to Sentry, a crash reporting service, in its US region.

Your choices

Setting What happens after a crash
Ask after a crash (default) The next time Rostrum starts, it asks whether to send the report: "Rostrum Quit Unexpectedly". Show the Report shows exactly what would be sent. Choose Send Report or Don't Send.
Send automatically The report goes out quietly the next time Rostrum starts. You can also pick this by ticking "Send reports without asking from now on" in the dialog.
Never send Crashes are not recorded, and waiting reports are deleted.

Nothing is sent at the moment of the crash. The report is kept on disk and handled at the next start, according to your setting.

What a report contains

Included Never included
Where in Rostrum's code it crashed, and the libraries on the way there Your name, user name, files or folders
Rostrum's version, build and how it was installed App, device and scene names
Linux distribution, kernel, CPU type, desktop and session type Logs, audio, or anything you type or say
Qt, KDE Frameworks, PipeWire and WirePlumber versions Tracking IDs or accounts

Rostrum builds the report by copying a fixed list of fields and dropping everything else, including any fields a future version of the crash library might add. Memory addresses are kept because Sentry needs them to find the line of code; they change every time Rostrum starts, so they say nothing about you and cannot link two reports. No memory contents are captured.

Rostrum also tells Sentry not to store your IP address as your user address and not to look up a location from it. Sentry still sees the IP address every upload comes from, as with any web request.

See for yourself: Settings → Privacy → What a crash report contains shows a complete example report built from your computer. During setup, the same example is behind See an Example Report.

Where reports are kept

Waiting reports are stored in ~/.local/state/rostrum/crashes/, readable only by you. At most 10 are kept, and none older than 30 days. If there are unsent reports, Settings → Privacy offers to review them.

Update checks

Setting Default Meaning
Check for updates On Once a day, Rostrum asks the release feed for the newest version number. Nothing about you is sent.
Install updates automatically On Download and install new versions by itself. This only applies to the AppImage.

The first check runs 20 seconds after Rostrum starts, then at most once a day while it runs. It is a plain request for the release feed, with Rostrum's version in the User-Agent and no cookies. Settings → Updates → Check now checks straight away, and the switch's description names the host it asks.

The feed is https://getrostrum.dev/releases/latest.json. That address redirects to the latest.json file attached to the newest release on GitHub, so a check talks to getrostrum.dev and then GitHub. AppImage downloads come from GitHub.

No release has been published yet. Until the first one is, the feed has nothing to serve, so checks fail quietly and Settings → Updates says "Could not check". Nothing else happens.

What happens when a new version is out depends on how Rostrum was installed:

Installed as What Rostrum does
Built from source A banner says the new version is out and to pull and rebuild, with What's New and Skip This Version.
Distribution package A banner says to update from your software center or package manager. Rostrum never installs updates itself.
AppImage Downloads the new AppImage, checks it against the release checksum, replaces the file, and offers Restart Now. With automatic install off, a banner offers Install instead. If Rostrum cannot write to the AppImage's folder, it only tells you.
Flatpak Rostrum does not check. Flatpak keeps it up to date.

Only the source build exists today. AppImage builds are planned for each release, and self-update applies to them once they are published; see Installation. Pre-release versions are never offered, and Skip This Version hides a version for good.

OBS

The OBS integration talks to OBS's WebSocket server on 127.0.0.1 only. Rostrum reads the port and password from OBS's own settings on your computer; they are not sent anywhere else. It is used in two ways:

  • Set Up OBS and Undo OBS Changes, when you press them. These are the only requests that change OBS.
  • Follow OBS while it runs (Settings → OBS, on by default). While OBS runs with its WebSocket server on, Rostrum stays connected and only reads: whether OBS is streaming or recording and for how long, the scene on program, and the scene list. That drives the LIVE and REC badges, go-live warnings and scene mapping. Nothing is stored apart from the scene mapping you choose. When OBS is not running, no connection is attempted. Turn the switch off and Rostrum connects only while the OBS page is open.

See OBS Setup.

Command line and D-Bus

The rostrum command and the dev.getrostrum.Rostrum1 D-Bus interface only work inside your own desktop session. Nothing listens on the network. See Command Line and D-Bus.

Questions

Email hello@getrostrum.dev. If you find something personal getting into a crash report, treat it as a security problem and report it to security@getrostrum.dev; see the security policy.

Clone this wiki locally