SSHoo is designed with privacy as a core principle. This Privacy Policy explains how SSHoo ("we", "our", or "the app") collects, stores, uses, and safeguards information when you use our Android SSH client application.
Information We Collect
SSHoo collects the minimum information needed to provide SSH, terminal, tunneling, AI chat, and subscription features. Most information is stored locally on your device and is never transmitted to our servers unless explicitly stated below.
- Connection data: SSH host addresses, ports, usernames, jump hosts, and connection preferences you configure
- Authentication material: SSH passwords, private keys, and key passphrases you choose to save locally
- Host fingerprints: SSH server fingerprints for known host verification
- Session data: Terminal tabs, optional terminal session recordings, saved commands, aliases, and autocomplete data
- Tunnel configurations: Port forwarding settings and related connection metadata
- App preferences: Theme, font, SSH defaults, AI agent selection, analytics preference, and behavior settings
- Optional Tailscale data: Your Tailscale API key if you enable Tailscale device discovery
- Subscription data: Google Play purchase tokens and anonymous premium subscription status used only for receipt validation
- Voice input (optional): If you use voice input, your speech is transcribed entirely on your device using Android's on-device speech recognition. Audio is not recorded, stored, or sent off your device by SSHoo, and is not transmitted to any third party
- Usage, crash, and performance data: Basic usage analytics, crash reports, and performance metrics. These are enabled by default and can be turned off at any time in app settings
We do not collect terminal output, file contents transferred through SFTP, SSH credentials stored on your device, or data from your remote servers.
Data Storage
All sensitive data is stored locally on your device. SSHoo does not operate a cloud sync service for your hosts, credentials, terminal sessions, or files.
- Credentials: SSH passwords, private keys, key passphrases, and Tailscale API keys are encrypted locally using Google Tink authenticated encryption (AES-256-GCM), with the encryption key held in the Android Keystore (hardware-backed where available)
- Local app data: Hosts, known hosts, tunnels, commands, aliases, sessions, recordings, and preferences are stored in local app storage; sensitive preferences use encrypted DataStore
- Private keys: Private keys remain on your device and are never transmitted to our servers
- Session recordings: Optional terminal recordings are stored in local encrypted storage and can be deleted at any time
- Backups: Stored credentials are excluded from Android cloud backups and device transfers to reduce exposure
- External transmission: Data is sent outside the device only for analytics and crash/performance reporting (on by default, can be disabled), subscription validation, direct Tailscale API use, Google Play Billing, Claude sign-in if you use it, or AI services you choose to use
You can delete stored credentials and local records from within SSHoo, by clearing app data in Android settings, or by uninstalling the app.
Voice Features
SSHoo offers optional voice input and spoken responses. Both run entirely on your device:
- Voice input: Speech is transcribed using Android's on-device speech recognition. Your audio is processed locally and is not sent to Google or any other third party. If your device does not have an on-device speech model available, voice input is shown as unavailable rather than falling back to a cloud service
- Spoken responses: Text-to-speech is generated on your device using a neural voice model. The voice model files are downloaded once over the network from a public software repository (GitHub) and then run locally; your text and audio are never uploaded for synthesis
Third-Party Services
SSHoo integrates with the following third-party services. Use of these services is subject to their respective privacy policies:
Firebase (Google)
SSHoo uses Firebase services provided by Google. These are enabled by default and can be turned off at any time in the app settings:
- Firebase Analytics: Collects anonymized usage data (such as screens viewed and features used) to help us improve the app
- Firebase Crashlytics: Collects crash reports and diagnostic data to help us identify and fix bugs
- Firebase Performance: Monitors app performance metrics
Analytics, crash reporting, and performance monitoring are on by default. You can disable any of them at any time in the app settings; when a feature is disabled, no further data is sent to the corresponding Firebase service.
Google Play Billing
For premium subscriptions, we use Google Play Billing. Payment information is handled entirely by Google and we do not have access to your payment card details.
Subscription validation (our Appwrite backend)
We use our own Appwrite backend to validate premium subscription receipts. When you make a purchase, the app sends your Google Play purchase token to this backend, which stores the purchase token, order ID, product ID, and purchase time against an anonymous, app-generated identifier. We do not receive or store your name, email address, or Google account, and we have no access to your payment details.
Tailscale (Optional)
If you choose to use Tailscale integration, you provide your own Tailscale API key. This key is encrypted locally and used by the app to query the Tailscale API for your device list. The API key is never transmitted to our servers; it remains on your device and communicates directly with Tailscale's API. You can revoke the API key at any time from your Tailscale admin console.
AI Services (Claude, Codex)
SSHoo can integrate with AI assistants such as Claude or Codex running on your remote servers. Chat messages are transmitted over your SSH connection to the remote host, not through our servers. The AI tools on your remote host may in turn send your prompts to their provider (for example Anthropic or OpenAI); that provider's terms and privacy policies apply to those interactions. We do not process or store your AI conversations.
If you choose to sign in to Claude from within SSHoo, the app connects directly to Anthropic (claude.com and platform.claude.com) to complete sign-in and to obtain and refresh access tokens. Those tokens are stored locally on your device.
Data Sharing
We do not sell, trade, or share your personal information with third parties. Your SSH credentials, private keys, terminal sessions, remote server data, and SFTP file contents remain on your device or on the remote hosts you connect to.
Limited data may be sent to third-party services only when needed for the features you use: Firebase for analytics, crash reporting, and performance monitoring (on by default, can be disabled); Google Play and our Appwrite backend for subscription validation; Tailscale for optional device discovery; Anthropic if you sign in to Claude in the app; and AI providers reached through your remote host when you use AI chat features.
Data Security
We implement appropriate security measures to protect your data:
- SSH credentials and API keys are encrypted at rest using Google Tink authenticated encryption (AES-256-GCM), with keys held in the Android Keystore where available
- Private keys are encrypted locally and are not accessible to our servers
- SSH connections use standard SSH encryption protocols
- Known host fingerprints help verify server identity
- Stored credentials are excluded from Android cloud backups and device-to-device transfers
- No data is synced to cloud services without your explicit action
Your Rights
You have control over the information stored by SSHoo:
- Delete stored hosts, keys, tunnels, sessions, commands, aliases, and recordings at any time
- Disable analytics, crash reporting, and performance monitoring in app settings
- Clear all SSHoo app data through Android settings
- Uninstall the app to remove local app storage from your device
- Revoke optional Tailscale API keys from your Tailscale admin console
- Manage or cancel premium subscriptions through Google Play
- Export configuration for backup purposes where the app provides export features
- Request deletion of the subscription-validation records associated with your purchases by emailing [email protected]
Analytics data collected by Firebase when enabled is subject to Google's data retention policies.
Children's Privacy
SSHoo is not intended for use by children under the age of 13, or the minimum age required to consent to data processing in your jurisdiction. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page, and we will update the Effective Date at the top. Continued use of SSHoo after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or our data practices, please contact us by email: