Skip to content
ArionAC Dashboard

Server operations

Data and privacy

Understand optional ArionAC telemetry, local logging, account inactivity, third-party webhooks and player data handling.

Local operation and optional telemetry

ArionAC can operate without a dashboard account. Telemetry is disabled by default. Local violation storage, logs and explicitly enabled diagnostic recordings remain on your server unless you share them or enable an external feature.

When enabled, dashboard telemetry sends the server identity, version/platform, metrics, player diagnostics, detections, check status and action receipts to the configured HTTPS endpoint. Connection codes authenticate the intended workspace. Keep them private and only connect servers you administer.

As server operator, tell players what data your configured features process. The public website’s privacy policy describes the website service; it does not replace your own server’s privacy information.

Account and dashboard retention

All accounts, including Admin and Staff, expire after 30 days without dashboard use. Telemetry does not keep an account active. Owner expiration removes owned server/network links and their dependent telemetry, and invalidates connection codes.

Dashboard cleanup removes old metrics after 7 days and inactive player/detection records after 30 days, in bounded batches. A player’s stored frame history is bounded. Cleanup depends on service calls or scheduled maintenance rather than a browser staying open.

The dashboard is not a permanent evidence archive. Server logs, your violation database, operational backups and hosting-provider logs have their own retention rules. Maintain only the records you need and restrict access.

Discord alerts and release announcements

discord:
  ENABLED: false
  WEBHOOK-URL: ""
  SEND-ALERTS: true
  MIN-ALERT-VL: 5
  SEND-PUNISHMENTS: true

Plugin webhooks are optional and separate from the externally hosted support/release bot. Enabling a webhook sends configured alert or punishment content to Discord. The webhook URL is a secret. Limit channel access and disclose this processing as appropriate.

Release announcements are published through the separate bot as text embeds. The bot does not require Attach Files for release messages. Neither this documentation nor the public landing page provides a download endpoint.

Optional AntiVPN

AntiVPN is disabled by default because a lookup sends joining players’ IP addresses to a third-party provider. IP_API uses plain HTTP on its free tier; PROXYCHECK uses HTTPS and needs a key. Choose a provider deliberately and inform players before enabling this feature.

Key under antivpnDefaultPurpose
ENABLEDfalseEnable third-party IP checks.
PROVIDERIP_APIIP_API or PROXYCHECK.
API-KEYemptyProvider key where required.
BLOCK-PROXY / BLOCK-HOSTINGtrue / falseBlock confirmed VPN/proxy/Tor or optionally hosting ranges. Hosting classification can include legitimate cloud/mobile use.
CACHE-MINUTES / LOOKUPS-PER-MINUTE360 / 40Result cache lifetime and lookup budget.
EXEMPT-PLAYERS / EXEMPT-ADDRESSESempty listsConfigured exclusions from lookups.
KICK-MESSAGEVPNs and proxies are not allowed on this server.Operator-configured provider rejection message.

Provider errors, unreadable responses, timeouts and exhausted lookup budgets admit the player rather than treating an outage as a ban. A backend behind a proxy may only see the proxy address; use the supported proxy integration where appropriate instead of treating that as the joining player’s IP.

Protect operational data

Keep production database credentials, connection codes, bridge secrets, webhook URLs, bot tokens and API tokens out of public repositories, screenshots and browser code. A private repository is not a reason to commit live credentials.

Use HTTPS, restricted database users and separate protected backups. Website database configuration belongs outside the public document root. Avoid attaching raw player or ticket archives to support messages when a small redacted diagnostic excerpt is sufficient.