Gizlilik Politikası — Rackmate

Son güncelleme: 10 Ağustos 2026

Rackmate, Proxmox VE ve Proxmox Backup Server sunucularını yönetmek için kullanılan bir mobil uygulamadır. Bu belge uygulamanın hangi verilere dokunduğunu ve nereye gönderdiğini anlatır.

Kısa cevap

Rackmate'in sunucusu yoktur. Uygulama yalnızca sizin girdiğiniz Proxmox sunucularına bağlanır. Geliştiriciye veya üçüncü taraflara hiçbir veri gönderilmez.

Uygulamanın tuttuğu veriler

Aşağıdakilerin tamamı yalnızca cihazınızda durur:

VeriNeredeNeden
Sunucu profilleri (ad, adres, port, kullanıcı adı)Cihaz depolamasıBağlantı kurmak için
API token secret'ları, parolalar, SSH özel anahtarlarıİşletim sisteminin güvenli deposu (Android Keystore / iOS Keychain)Kimlik doğrulaması için
TLS sertifika parmak izleriCihaz depolamasıİlk bağlantıda sabitlenir; sonraki bağlantılarda sunucunun aynı sunucu olduğunu doğrulamak için
Sunucu ölçümlerinin önbelleği (CPU, bellek, disk, makine listesi)Cihaz depolamasıÇevrimdışıyken son bilinen durumu gösterebilmek için
Tanılama günlüğüCihaz belleği (uygulama kapanınca silinir)Sorun bildirirken paylaşabilmeniz için

Bu verilerin hiçbiri cihazdan çıkmaz. Uygulamayı kaldırdığınızda hepsi silinir.

Uygulamanın gönderdiği veriler

Rackmate, sunucu verileriniz için yalnızca sizin yapılandırdığınız sunucu adreslerine istek yapar. Gönderilen şey, Proxmox API'sinin gerektirdiği kimlik bilgileri ve komutlardır; alıcı sizin sunucunuzdur.

Bağlantı HTTPS üzerinden kurulur. Sertifika ilk bağlantıda sabitlenir; sonraki bir bağlantıda sertifika değişirse bağlantı kesilir ve "yine de bağlan" seçeneği sunulmaz.

Diğer adresler

İki özellik, sizin sunucunuz dışındaki adreslere bağlanır:

AdresNe zamanNe gönderilir
api.github.com, raw.githubusercontent.comCommunity Scripts kataloğunu açtığınızdaHiçbir kişisel veri gönderilmez; katalog dosyaları anonim olarak indirilir. Sunucunuzun adresi ya da kimlik bilgileriniz bu isteklere dâhil edilmez.
cdn.jsdelivr.net (selfh.st simge seti)Katalogdaki uygulama simgeleri gösterilirkenYalnızca simge dosyası istenir.

Bu isteklerde oturum çerezi, token ya da sunucu bilgisi taşınmaz; ayrı ve kimlik bilgisi eklemeyen bir HTTP istemcisi kullanılır. Katalog ekranını hiç açmazsanız bu adreslere hiç bağlanılmaz.

Satın almalar

Rackmate Pro satın alımları Google Play üzerinden yapılır. Ödeme bilgileri Google tarafından işlenir; uygulama kart numarasını, adınızı ya da fatura bilgilerinizi görmez ve saklamaz. Uygulamanın cihazda tuttuğu tek şey "ücretli sürüm etkin mi" bilgisidir.

Google'ın satın alma sürecinde topladığı veriler Google'ın gizlilik politikasına tabidir.

Uygulamanın yapmadıkları

Tanılama günlüğü

Uygulama içindeki tanılama günlüğü sorun ararken işe yarar ve dilerseniz paylaşabilirsiniz. Günlüğe yazılmadan önce token'lar, parolalar, oturum biletleri, Authorization başlıkları ve UUID benzeri değerler maskelenir. Yine de paylaşmadan önce içeriğini okumanız önerilir; sunucu adları ve makine adları günlükte görünür.

İzinler

İzinNeden
INTERNETSunucunuza bağlanmak için
ACCESS_NETWORK_STATEBağlanmadan önce ağ durumunu görmek için
USE_BIOMETRICUygulama kilidini açmak için (isteğe bağlı özellik)
POST_NOTIFICATIONSSunucu uyarılarını bildirmek için (isteğe bağlı özellik)
RECEIVE_BOOT_COMPLETEDArka plan izlemenin cihaz yeniden başladıktan sonra da sürmesi için

Biyometrik doğrulama işletim sistemi tarafından yapılır; uygulama parmak izi veya yüz verisine erişmez, yalnızca "doğrulandı" sonucunu alır.

Çocuklar

Uygulama sunucu yöneticilerine yöneliktir ve çocuklara yönelik değildir.

Değişiklikler

Bu politika değişirse bu sayfanın üstündeki tarih güncellenir.

İletişim

Sorularınız için: ismplat@gmail.com


Privacy Policy — Rackmate

Last updated: 10 August 2026

Rackmate is a mobile app for managing Proxmox VE and Proxmox Backup Server. This document describes what data the app touches and where it sends it.

Short answer

Rackmate has no servers. The app connects only to the Proxmox servers you configure. No data is sent to the developer or to any third party.

Data the app stores

All of the following stays on your device only:

DataWhereWhy
Server profiles (name, address, port, username)Device storageTo establish connections
API token secrets, passwords, SSH private keysOS secure storage (Android Keystore / iOS Keychain)For authentication
TLS certificate fingerprintsDevice storagePinned on first connection to verify the server on later connections
Cached server metrics (CPU, memory, disk, guest lists)Device storageTo show last known state while offline
Diagnostics logDevice memory (cleared when the app exits)So you can share it when reporting a problem

None of it leaves the device. Uninstalling the app deletes all of it.

Data the app transmits

For your server data, Rackmate makes requests only to the server addresses you configure. What is transmitted is the credentials and commands the Proxmox API requires; the recipient is your own server.

Connections use HTTPS. The certificate is pinned on first connection; if it changes on a later connection the connection is refused, with no "connect anyway" option.

Other hosts

Two features reach hosts other than your own server:

HostWhenWhat is sent
api.github.com, raw.githubusercontent.comWhen you open the Community Scripts catalogueNo personal data. Catalogue files are downloaded anonymously; your server address and credentials are not included in these requests.
cdn.jsdelivr.net (selfh.st icon set)When catalogue app icons are displayedOnly the icon file is requested.

These requests carry no session cookie, token or server information; a separate HTTP client that attaches no credentials is used. If you never open the catalogue screen, these hosts are never contacted.

Purchases

Rackmate Pro purchases are made through Google Play. Payment details are processed by Google; the app never sees or stores your card number, name or billing information. The only thing stored on the device is whether the paid version is active.

Data Google collects during the purchase is subject to Google's privacy policy.

What the app does not do

Diagnostics log

The in-app diagnostics log helps when troubleshooting and can be shared at your choice. Tokens, passwords, session tickets, Authorization headers and UUID-like values are masked before being written. Even so, read it before sharing: server names and guest names are visible in it.

Permissions

PermissionWhy
INTERNETTo reach your server
ACCESS_NETWORK_STATETo check network status before connecting
USE_BIOMETRICTo unlock the app lock (optional feature)
POST_NOTIFICATIONSTo deliver server alerts (optional feature)
RECEIVE_BOOT_COMPLETEDSo background monitoring survives a reboot

Biometric verification is performed by the operating system; the app never accesses fingerprint or face data, only the "verified" result.

Children

The app targets server administrators and is not directed at children.

Changes

If this policy changes, the date at the top of this page is updated.

Contact

ismplat@gmail.com