SSH Toolbox
Privacy Policy
In short
- SSH Toolbox does not collect any data. We have no servers that the app sends information to.
- There is no account, no analytics, no advertising, no tracking and no third-party SDK in the app.
- Everything you enter stays on your device. Passwords and private keys are kept in the system's secure storage.
- The app connects only to the SSH servers you add, and nowhere else.
1. About this policy
This policy describes how the SSH Toolbox app for iPhone, iPad and Android (“the app”) handles information. The app is made by Redshift (“we”, “us”). It applies to every version of the app distributed through the Apple App Store and Google Play.
2. Information we collect
None. We do not collect, receive, store, share or sell any personal or usage information. In particular, the app does not:
- require or offer an account or sign-up;
- include analytics, crash reporting, advertising or tracking software, or any other third-party SDK;
- read advertising identifiers or other device identifiers, your location, contacts, photos, camera or microphone;
- send anything about you or your use of the app to us or anyone else.
3. Information stored on your device
To work, the app saves what you enter locally on your device. None of it is sent to us.
| What | Where it is kept |
|---|---|
| Connections: name, host, port, username, tags, colour, jump host, terminal settings and the command to run after connecting | The app's private database |
| Key details: name, type, fingerprint, comment, public key | The app's private database |
| Private keys, key passphrases, and passwords you choose to save | Secure storage (see below) |
| Snippets and variables | The app's private database; variables marked secret go to secure storage |
| Host keys of servers you trust (fingerprints) | The app's private database |
| Preferences: appearance and terminal text size | The app's preferences on the device |
Secure storage means the iOS Keychain, with items available only while the device is unlocked and only on this device, or on Android, values encrypted with a key held in the Android Keystore that never leaves the device. Secrets are never written to the database, to files or to logs.
A password is saved only if you ask the app to remember it, and only after the server has accepted it. A saved password that the server rejects is removed.
4. Network connections
The app connects only to the SSH servers you add, including any jump hosts you set up, using the SSH protocol, which encrypts the connection. Your credentials, commands, terminal output and files travel directly between your device and those servers. We are not part of that connection and cannot see any of it.
Those servers are run by you or by whoever administers them, and what they do with the data you send them is up to their operators. The app checks every server's host key: you confirm a new server's fingerprint, and a key that changes stops the connection.
The app makes no other network connections.
5. Files
- Downloads from a server are saved on your device: on iOS in the app's folder in the Files app, on Android in Downloads/SSH Toolbox.
- Uploads send only the file you pick, or share into the app, to the server and folder you choose.
- Sharing a server file to another app makes a temporary copy on your device, which the app deletes afterwards.
- Importing a key reads only the file you choose.
6. Permissions
- Android: Internet access, to connect to your servers, and vibration, for the terminal bell. The app asks for no other permissions. Downloads are saved without storage permission.
- iOS: the app needs no special permissions. If you connect to a server on your local network, iOS may ask whether the app may reach devices on it. This is used only for that connection.
7. Backups and moving to a new device
Passwords, private keys, passphrases and secret variables are never included in device backups or transfers to a new device. Other app data, such as connections, key details, snippets and preferences, may be included in your device's own backup (iCloud or Google) if backups are turned on. Those backups are provided by Apple or Google under their privacy policies, and we have no access to them. After restoring, you will need to enter passwords and import private keys again.
8. Keeping and deleting your data
Your data stays on your device until you delete it. You can delete connections, keys, snippets and variables in the app. In Settings you can forget trusted servers and remove all saved passwords. Uninstalling the app removes its data from the device.
On iOS, the system may keep Keychain items after an app is deleted. To be sure your secrets are gone, delete your keys and remove saved passwords in the app before uninstalling it.
Because we hold no data about you, there is nothing for us to access, correct, export or delete on request.
9. Children
The app is a tool for managing servers and is not directed at children. It collects no information from anyone, including children.
10. Your rights
Privacy laws such as the GDPR and the CCPA give you rights over personal data that a company processes. We do not process personal data through the app, so those rights have nothing to act on. You keep full control of the data on your device. If you have a question or a concern, contact us and we will answer.
11. Changes to this policy
If the way the app handles information changes, we will update this page and its effective date before the change reaches the app. Changes that affect you significantly will also be noted in the app's release notes.
12. Contact
Questions about this policy: support@redshift.team. You can also visit SSH Toolbox Support.