SSHHIP Privacy Policy

Local-first by design.

SSHHIP connects to hosts that you configure. It has no SSHHIP backend, no account system, no analytics, no tracking, and no ads.

Summary

SSHHIP does not collect data from you.

Your saved hosts, command snippets, and preferences stay on your device by default.

If you enable saved-host iCloud sync, SSHHIP syncs saved-host metadata through the private CloudKit database in your own Apple iCloud account.

Some hosts can use Automatic authentication without saving a password or private key.

Passwords and imported private keys that you choose to save are stored in the iOS Keychain and are used only to connect to hosts that you configure.

Secure Enclave private keys are non-exportable; SSHHIP stores only their persistent key references in the iOS Keychain and their public keys with saved host metadata.

SSHHIP does not send your credentials, terminal contents, host list, or usage activity to SSHHIP or to any SSHHIP server.

If you use Send Image, the selected image goes to the host you are connected to, not to SSHHIP.

Diagnostics recording is metadata-only and stays on your device.

SSHHIP can save a diagnostics capture when you choose Capture Now or Capture Diagnostics, or when its enabled foreground UI-freeze watchdog confirms a stall. You can turn automatic capture off in Settings. Exports happen only when you choose Share through the iOS share sheet.

Captures do not include terminal content, host or account details, commands, paths, credentials, keys, tokens, audio, or transcript text.

Information stored on your device

SSHHIP stores the information needed to make the app work on your device:

Imported credentials and Secure Enclave key references are stored with the iOS Keychain.

Secure Enclave private keys remain non-exportable in the hardware.

They are not stored in a SSHHIP cloud vault because SSHHIP does not have a cloud vault.

Deleting a saved host is designed to remove the imported credentials and key references associated with that host from the Keychain.

Network connections

SSHHIP makes network connections to hosts that you configure or explicitly choose to connect to, to Apple's systems for App Store purchases, to Apple's on-device speech model service when iOS needs that model, and to Apple's CloudKit service only if you enable saved-host iCloud sync.

Terminal traffic, SSH authentication, and configured multiplexer commands go between your device and your configured host.

SSHHIP does not proxy those sessions through a SSHHIP server.

Your terminal input and terminal output may contain personal or sensitive information because they are the contents of your own shell sessions.

SSHHIP displays that content in the app so you can use your terminal.

SSHHIP does not collect or transmit that content to SSHHIP.

Image handoff

If you use Send Image, SSHHIP reads the copied image from the iOS pasteboard when one is present.

If no copied image is present, SSHHIP uses Apple's photo picker so you can choose an image.

SSHHIP uploads that selected image directly to the host you are connected to over the active SSH/SFTP connection and inserts the remote file path into your terminal input line.

SSHHIP does not press Return for you.

SSHHIP does not send selected images to SSHHIP or to any SSHHIP server.

The uploaded file is stored on the host you chose, in a hidden .sshhip-uploads directory under that account's home directory.

You can manage or delete those files on your host.

Voice input

If you use SSHHIP voice input, the app requests microphone and speech recognition permission from iOS.

SSHHIP uses on-device transcription for this feature.

On iOS 26, starting voice input may ask iOS to download Apple's on-device speech model if it is not already installed.

That model download is managed by iOS; SSHHIP still keeps voice audio and transcripts on device.

The final transcript is normalized for terminal use and typed into the live terminal input line without automatically pressing Return.

SSHHIP does not collect voice recordings or transcripts.

If you choose to send the typed transcript in the terminal, it is sent to the host you are connected to, just like text you type manually.

Purchases

SSHHIP uses Apple's in-app purchase system for the one-time lifetime unlock.

Apple processes the purchase through the App Store.

SSHHIP does not receive your payment card information.

SSHHIP may store local entitlement state on your device so the app can know whether the lifetime unlock is active.

Apple's handling of App Store purchase information is governed by Apple's privacy policy and App Store terms.

Analytics, tracking, and advertising

SSHHIP does not include analytics SDKs.

SSHHIP does not track you across apps or websites.

SSHHIP does not show ads.

SSHHIP does not sell data.

SSHHIP does not share your data with data brokers or advertising networks.

Accounts and cloud sync

SSHHIP does not require a SSHHIP account.

SSHHIP does not upload your host list or credentials to a SSHHIP service.

Saved-host iCloud sync is optional and defaults off.

When you enable it, SSHHIP uses only the private CloudKit database in your own Apple iCloud account.

SSHHIP does not use a CloudKit public database, CloudKit shared database, SSHHIP backend, shared account, or app-run sync server.

The synced host metadata includes display name, hostname, port, username, authentication method, theme, transport, optional multiplexer startup behavior, Secure Enclave public key, and sync metadata used to merge edits and deletes.

Passwords, imported private keys, passphrases, Secure Enclave private-key references, command snippets, trusted host keys, terminal contents, image bytes, and diagnostics captures are not synced through CloudKit.

If iCloud is signed out or unavailable, sync silently stops and local hosts continue working on that device.

Diagnostics

SSHHIP does not add its own telemetry or crash reporting service.

SSHHIP keeps a bounded in-memory record of fixed diagnostic events for the current launch.

When you choose Capture Now in Settings or Capture Diagnostics in a session menu, SSHHIP saves a metadata-only capture in protected app storage on your device. The enabled foreground UI-freeze watchdog can also save a capture after it confirms a stall; you can turn that automatic capture off in Settings.

A capture can include app and device state, connection lifecycle, configured and active transport, typed fallback and probe-cache decisions, terminal dimensions and readiness, byte and chunk counters, and fixed CommandDial and voice-capture metadata such as state names, counts, and timings.

Captures never include terminal input, terminal output, scrollback, visible terminal text, host names or addresses, usernames, endpoints, session names, startup commands, remote paths, credentials, private keys, tokens, image data, voice recordings, or transcript text.

SSHHIP keeps the newest 7 captures for no more than 14 days and within a 25 MB total limit, whichever limit is reached first.

Automatic diagnostics captures are limited to 3 in 24 hours.

You can delete one capture or clear all captures in Settings.

Every saved capture is scrubbed and validated before it is stored, then rebuilt and validated again before sharing.

SSHHIP never uploads diagnostics and the diagnostics feature contains no network request path.

An export happens only after you choose Share, using the iOS share sheet, where you decide whether to save the file or send it somewhere.

Apple may provide developers with App Store or system diagnostic information depending on your device settings and Apple's policies.

SSHHIP does not use that information to track you.

Children's privacy

SSHHIP is a developer tool and is not directed to children.

SSHHIP does not knowingly collect personal information from children.

Changes to this policy

If SSHHIP's privacy practices change, this policy will be updated before those changes are reflected in the app listing.

The updated policy will keep the same public URL when possible.

Contact

For support, use the SSHHIP support page at https://kunchenguid.github.io/sshhip/appstore/support/.