Privacy policy
What Ark Manager sends off your PC, when, and how to turn it off.
Short version: the app checks /latest.json for updates,
and new installs have the learn-relay ON (shape-only
lessons). You can turn the relay off in Settings any time.
1. Update check
On launch (and once every 24h while running) Ark Manager fetches
https://arcmanager.autoflexx.net.au/latest.json.
This is a static JSON file giving the current version and SHA-256 of
/latest.zip. The request is a normal HTTPS GET; the only
information it reveals is your IP address and User-Agent, which the
hosting droplet records in nginx access logs for 30 days and then
rotates out.
If you don't want this request to go at all, you can set the environment
variable ARK_MANAGER_SKIP_UPDATE_CHECK=1 before launching,
or block arcmanager.autoflexx.net.au at your firewall. Ark
Manager still runs; the update badge just never appears.
2. Learn relay (ON by default, you can turn it off)
Ark Manager has a switch at Settings → Flex Learning Relay.
New installs leave it ON. Untick the checkbox to stop.
While it is on, once a week Ark Manager posts a small log to
/learn/report on this site.
What the lesson log CAN contain
- The topic of what Flex (or another AI calling the local API) tried to do, e.g.
"ini-edit","plugin-stage","addon-install". - The outcome:
"ok","dry-run","refused", or"error". - A short, generic action label like
"edit game ini (2 keys)"or"ask (medium)". Length bucket only - never prompt text, never INI values. - For an INI edit: the names of the keys that were edited (e.g.
["XPMultiplier", "TamingSpeedMultiplier"]), nothing about the values. - For an add-on install: the kind of add-on (
"plugin","preset", etc.), nothing identifying. - A rotatable, salted hex install ID (not reversible to your identity, and you can rotate it anytime).
- The Ark Manager version number.
- A timestamp.
What the lesson log CANNOT contain, by design
- INI contents (values, lines, full files)
- Plugin DLL bytes or filenames
- ARK server save files
- Player names, Steam IDs, admin passwords, RCON passwords
- Server passwords, session names, or server labels
- Any filesystem path, UNC share, or hostname
- Discord webhooks, Twilio/SMTP tokens, or any secret
- The text of prompts you type into Flex
- Anything from your other apps (AutoFlexx or otherwise)
The scrubber enforcing this list lives in learn_relay.py
in your install. It uses an allowlist of generic key names and a
blocklist of substrings like password, steamid,
path, file, name, admin,
session_name. If a lesson accidentally gets built with a
hostile key, that key is dropped before it reaches the queue, let alone
the network.
%LOCALAPPDATA%\..\<install>\learn_queue.jsonl
in Notepad before uploading. The Settings panel has an
Open queue file button that does exactly this. If a line
in there looks like it shouldn't go, the Clear queue
button deletes everything unsent.
3. Rotation and revocation
You can press Rotate install id in Settings at any time. Future lessons look like they came from a fresh install. Already uploaded lessons stay with the old ID on the vhost.
I can also push an install ID onto the revocation list at
/learn/revocation.json. If your ID shows up there, Ark
Manager refuses to upload any further lessons on the next launch. This
exists so a compromised install cannot keep spamming the relay.
4. Hosting
This site runs on a VPS in Sydney, Australia (DigitalOcean). The
arcmanager.autoflexx.net.au vhost is isolated from any
other service on that droplet:
- Dedicated non-login system user
flex-droplet, no sudo, no shell. - Dedicated data directories
/var/lib/flex-publishand/var/lib/flex-learn; the service literally cannot write anywhere else (ProtectSystem=strict,ReadWritePaths=). - Separate nginx access/error logs so troubleshooting Ark Manager never means reading an unrelated app's logs.
- Monthly retention of nginx logs is 30 days.
5. Ads
If this page or the download page shows an ad, it is served by a third-party ad network (Google AdSense or similar). Ad networks set their own cookies and may track your browsing. If you don't want them, use an ad blocker; Ark Manager itself does not depend on them and will never show ads inside the app without a visible toggle.
6. Contact
Email privacy@autoflexx.net.au for anything on this page. If you'd like your install ID revoked (because the PC is sold, lost, etc.), include the first 8 characters of the ID. The full ID isn't needed and I'd rather not have it.
7. Changes
This document is versioned in the public repo. Any material change
gets its own release note and a bump of the schema version in
learn_relay.py; Ark Manager won't upload under a
schema the server doesn't recognise, so you can't be silently
enrolled into something new.