Privacy
What we collect
The short version: your hosts, keys and passwords never leave your device unless you turn on sync, and even then we only ever hold ciphertext.
Your vault
Hosts, identities, private keys, passwords, snippets and known-host pins are stored encrypted on your own machine, under a key derived from your master password. We do not have that password and cannot derive it.
If you enable sync, the encrypted records are copied to our servers so your other devices can pull them. The encryption happens before anything is sent. A server operator — including us — sees record sizes and timestamps, not contents.
What we do not collect
We do not collect the contents of your terminal sessions, the addresses of the servers you connect to, your usernames, or your keys. There is no keystroke logging and no session recording unless you turn on session logs, which are stored under the same encryption as everything else.
Diagnostics
Crash reports and usage analytics are off by default. If you turn them on, reports carry the app version, the operating system, and a stack trace — never a hostname, a username or anything from a session.
Account data
An account exists only if you create one for sync. It holds an email address, a password verifier (not the password), your public keys, and your subscription state. Delete the account and all of it goes with it.
Contact
Questions about any of this go to privacy@termiyo.com.