Son güncelleme: 10 Ağustos 2026
Rackmate, Proxmox VE ve Proxmox Backup Server sunucularını yönetmek için kullanılan bir mobil uygulamadır. Bu belge uygulamanın hangi verilere dokunduğunu ve nereye gönderdiğini anlatır.
Rackmate'in sunucusu yoktur. Uygulama yalnızca sizin girdiğiniz Proxmox sunucularına bağlanır. Geliştiriciye veya üçüncü taraflara hiçbir veri gönderilmez.
Aşağıdakilerin tamamı yalnızca cihazınızda durur:
| Veri | Nerede | Neden |
|---|---|---|
| Sunucu profilleri (ad, adres, port, kullanıcı adı) | Cihaz depolaması | Bağlantı kurmak için |
| API token secret'ları, parolalar, SSH özel anahtarları | İşletim sisteminin güvenli deposu (Android Keystore / iOS Keychain) | Kimlik doğrulaması için |
| TLS sertifika parmak izleri | Cihaz depolaması | İlk bağlantıda sabitlenir; sonraki bağlantılarda sunucunun aynı sunucu olduğunu doğrulamak için |
| Sunucu ölçümlerinin önbelleği (CPU, bellek, disk, makine listesi) | Cihaz depolaması | Çevrimdışıyken son bilinen durumu gösterebilmek için |
| Tanılama günlüğü | Cihaz belleği (uygulama kapanınca silinir) | Sorun bildirirken paylaşabilmeniz için |
Bu verilerin hiçbiri cihazdan çıkmaz. Uygulamayı kaldırdığınızda hepsi silinir.
Rackmate, sunucu verileriniz için yalnızca sizin yapılandırdığınız sunucu adreslerine istek yapar. Gönderilen şey, Proxmox API'sinin gerektirdiği kimlik bilgileri ve komutlardır; alıcı sizin sunucunuzdur.
Bağlantı HTTPS üzerinden kurulur. Sertifika ilk bağlantıda sabitlenir; sonraki bir bağlantıda sertifika değişirse bağlantı kesilir ve "yine de bağlan" seçeneği sunulmaz.
İki özellik, sizin sunucunuz dışındaki adreslere bağlanır:
| Adres | Ne zaman | Ne gönderilir |
|---|---|---|
api.github.com, raw.githubusercontent.com | Community Scripts kataloğunu açtığınızda | Hiçbir kişisel veri gönderilmez; katalog dosyaları anonim olarak indirilir. Sunucunuzun adresi ya da kimlik bilgileriniz bu isteklere dâhil edilmez. |
cdn.jsdelivr.net (selfh.st simge seti) | Katalogdaki uygulama simgeleri gösterilirken | Yalnızca simge dosyası istenir. |
Bu isteklerde oturum çerezi, token ya da sunucu bilgisi taşınmaz; ayrı ve kimlik bilgisi eklemeyen bir HTTP istemcisi kullanılır. Katalog ekranını hiç açmazsanız bu adreslere hiç bağlanılmaz.
Rackmate Pro satın alımları Google Play üzerinden yapılır. Ödeme bilgileri Google tarafından işlenir; uygulama kart numarasını, adınızı ya da fatura bilgilerinizi görmez ve saklamaz. Uygulamanın cihazda tuttuğu tek şey "ücretli sürüm etkin mi" bilgisidir.
Google'ın satın alma sürecinde topladığı veriler Google'ın gizlilik politikasına tabidir.
Uygulama içindeki tanılama günlüğü sorun ararken işe yarar ve dilerseniz
paylaşabilirsiniz. Günlüğe yazılmadan önce token'lar, parolalar, oturum
biletleri, Authorization başlıkları ve UUID benzeri değerler
maskelenir. Yine de paylaşmadan önce içeriğini okumanız önerilir; sunucu adları
ve makine adları günlükte görünür.
| İzin | Neden |
|---|---|
INTERNET | Sunucunuza bağlanmak için |
ACCESS_NETWORK_STATE | Bağlanmadan önce ağ durumunu görmek için |
USE_BIOMETRIC | Uygulama kilidini açmak için (isteğe bağlı özellik) |
POST_NOTIFICATIONS | Sunucu uyarılarını bildirmek için (isteğe bağlı özellik) |
RECEIVE_BOOT_COMPLETED | Arka plan izlemenin cihaz yeniden başladıktan sonra da sürmesi için |
Biyometrik doğrulama işletim sistemi tarafından yapılır; uygulama parmak izi veya yüz verisine erişmez, yalnızca "doğrulandı" sonucunu alır.
Uygulama sunucu yöneticilerine yöneliktir ve çocuklara yönelik değildir.
Bu politika değişirse bu sayfanın üstündeki tarih güncellenir.
Sorularınız için: ismplat@gmail.com
Last updated: 10 August 2026
Rackmate is a mobile app for managing Proxmox VE and Proxmox Backup Server. This document describes what data the app touches and where it sends it.
Rackmate has no servers. The app connects only to the Proxmox servers you configure. No data is sent to the developer or to any third party.
All of the following stays on your device only:
| Data | Where | Why |
|---|---|---|
| Server profiles (name, address, port, username) | Device storage | To establish connections |
| API token secrets, passwords, SSH private keys | OS secure storage (Android Keystore / iOS Keychain) | For authentication |
| TLS certificate fingerprints | Device storage | Pinned on first connection to verify the server on later connections |
| Cached server metrics (CPU, memory, disk, guest lists) | Device storage | To show last known state while offline |
| Diagnostics log | Device memory (cleared when the app exits) | So you can share it when reporting a problem |
None of it leaves the device. Uninstalling the app deletes all of it.
For your server data, Rackmate makes requests only to the server addresses you configure. What is transmitted is the credentials and commands the Proxmox API requires; the recipient is your own server.
Connections use HTTPS. The certificate is pinned on first connection; if it changes on a later connection the connection is refused, with no "connect anyway" option.
Two features reach hosts other than your own server:
| Host | When | What is sent |
|---|---|---|
api.github.com, raw.githubusercontent.com | When you open the Community Scripts catalogue | No personal data. Catalogue files are downloaded anonymously; your server address and credentials are not included in these requests. |
cdn.jsdelivr.net (selfh.st icon set) | When catalogue app icons are displayed | Only the icon file is requested. |
These requests carry no session cookie, token or server information; a separate HTTP client that attaches no credentials is used. If you never open the catalogue screen, these hosts are never contacted.
Rackmate Pro purchases are made through Google Play. Payment details are processed by Google; the app never sees or stores your card number, name or billing information. The only thing stored on the device is whether the paid version is active.
Data Google collects during the purchase is subject to Google's privacy policy.
The in-app diagnostics log helps when troubleshooting and can be shared at
your choice. Tokens, passwords, session tickets, Authorization
headers and UUID-like values are masked before being written. Even so, read it
before sharing: server names and guest names are visible in it.
| Permission | Why |
|---|---|
INTERNET | To reach your server |
ACCESS_NETWORK_STATE | To check network status before connecting |
USE_BIOMETRIC | To unlock the app lock (optional feature) |
POST_NOTIFICATIONS | To deliver server alerts (optional feature) |
RECEIVE_BOOT_COMPLETED | So background monitoring survives a reboot |
Biometric verification is performed by the operating system; the app never accesses fingerprint or face data, only the "verified" result.
The app targets server administrators and is not directed at children.
If this policy changes, the date at the top of this page is updated.