TERMOSH
Termosh Privacy Policy
Termosh is a client for services you configure. It does not create a Termosh cloud account or operate a terminal, mail, or AI relay. It does not include advertising or analytics SDKs, sell personal data, or track you across apps or websites. Data leaves your device only when you use a feature that connects to a destination described below, when you contact support, or through Apple and Expo notification services.
Data stored on this device
- Termosh may store connection profile metadata (host name or IP address, port, and username), preferences, snippets, recent sessions, limited terminal context and receipts, chat threads, timers and notification identifiers, up to 30 web-history entries, AI, mail, and voice settings, and managed chat images in app storage.
- Passwords, private keys, mail account settings and app passwords, and AI API keys are intended to be kept in platform secure storage. The operating system separately stores calendar events and scheduled local notifications.
- The Termosh developer does not automatically receive data that remains only on your device.
SSH, SFTP, files, and photos
- Commands and terminal input and output are transmitted directly over SSH to the host you choose. Termosh does not operate a public terminal relay.
- Files and photos that you select, capture, or edit are uploaded directly by SFTP to your chosen host when you request it. That host and any remote agent you run there may retain or process the content, including through providers configured on the host.
- The Termosh developer cannot access your host or uploads unless you deliberately choose a host operated by the developer or send the content to support.
Remote notifications
- When remote notifications are enabled and permission is granted, Termosh asks Expo Push Service for an Expo push token. Expo receives information needed to create and maintain the token, including an installation identifier, the native Apple push token, app and project identifiers, and normal network information such as your IP address. A copy of the Expo token is stored on your chosen SSH host.
- A watcher on that host sends the token, notification title and body, and a remote session identifier through Expo Push Service and Apple Push Notification service (APNs) for delivery.
- Expo states that notification contents are kept transiently in memory and queues until delivery; token-related records may persist. Disabling remote notifications asks the configured host to remove its token copy. Expo and Apple handle their records under their own privacy policies.
- Mail account addresses, app passwords, and server settings are stored in secure storage. Termosh connects directly over encrypted IMAP and SMTP to the mail provider you configure; it does not proxy messages through a Termosh server.
- Your mail provider receives authentication data, message headers and bodies, recipients, and messages you send, and may retain them under your account and its privacy policy.
- If you choose to extract a calendar event with AI, Termosh first shows the destination and asks for confirmation, then sends the subject and the first 4,000 characters of the body to your configured AI provider. No event is added until you review and confirm it.
User-configured AI and remote agents
- When you invoke AI features, prompts and the context you select—such as terminal output, project context, or the confirmed mail excerpt—are sent directly to the AI endpoint you configured. API keys are sent to that endpoint for authentication.
- The selected provider may retain or use requests and responses under its terms. Local endpoints such as Ollama or LM Studio may keep processing on a device or network you control.
- Agents running on your SSH host may send prompts, files, photos, or terminal context to providers configured on that host. Their processing and retention are controlled by your host and provider settings, not by a Termosh-hosted AI service.
Calendar and ICS
- With permission, Termosh reads events from and writes confirmed events to the calendars on your device. Calendar data is not automatically sent to a Termosh server or AI provider.
- A selected ICS file is parsed on the device. When you enter an iCalendar URL, Termosh fetches it directly over HTTPS without browser credentials; that server receives the request and normal network information such as your IP address. Imported events are written only after review and confirmation.
- The confirmed mail-to-AI action described above is the only built-in path that sends mail content for calendar extraction.
Web browsing and history
- The in-app browser connects directly to websites. Termosh stores up to 30 visited URLs in app storage and does not automatically send that history to the Termosh developer.
- Websites and the search provider you use may receive URLs or queries, your IP address, cookies, and other ordinary web data under their own policies.
- A page annotation (URL, selected text, and element details) is sent to your chosen SSH host or remote agent only when you explicitly submit it.
Speech recognition
- In device speech-recognition mode, audio or transcripts may be processed by Apple’s speech service. The Termosh developer does not receive Apple’s service data; the resulting transcript is returned to the app.
- In custom-endpoint mode, the recorded audio file and selected language are sent directly to the endpoint you configured; its operator may retain them under its policy.
- A transcript is used as a local draft. It is sent to your chosen SSH host, remote agent, or AI provider only if you submit it to that feature.
Retention, deletion, support, and contact
- Local data remains until you delete it with available in-app controls or remove the app. Delete saved profiles, mail accounts, and API keys in the app before uninstalling; items in iOS secure storage may persist or be restored after reinstalling.
- Removing Termosh does not delete calendar events, remote files or logs, mail or AI-provider data, or records held by Expo or APNs. Delete those items with the relevant server or service. Termosh does not set retention periods for services you choose.
- If you email support or file a public GitHub issue, the email provider or GitHub may retain your address, message, and diagnostics you include. Do not include passwords, private keys, API keys, or sensitive mail or terminal content. Support data is used to answer your request and protect the service.
- Termosh has no advertising or analytics SDKs, does not sell personal data, and does not track you across apps or websites. Privacy contact: [email protected]. Last updated: July 30, 2026.