Privacy Policy — XConnect for iOS

Last updated: 14 September 2026

XConnect is an SSH, Telnet, SFTP and remote desktop (RDP) client for iPhone, with an AI assistant, a script library and optional end-to-end encrypted sync. This policy explains what the iOS app keeps on your device, what reaches our servers and why, and how to delete it.

This policy covers the iOS app. The desktop apps are described in the desktop Privacy Policy. Use of the iOS app is governed by the iOS Terms of Use.

1. What stays on your iPhone

Your connections, groups, jump hosts, scripts, SSH key details, AI settings (provider and model) and app preferences are stored in a database inside the app's private sandbox, protected by iOS Data Protection. Secrets are kept separately in the iOS Keychain, never in that database: connection passwords, private keys, jump host passwords, your AI provider API key, and your sign-in session.

2. Your servers and sessions

The app connects your iPhone directly to the servers you configure. Terminal input and output, remote desktop images, keystrokes and transferred files travel between your device and your server. They do not pass through our servers, and we do not record sessions.

3. What reaches our servers

DataWhenWhy
Install identifier — a random ID the app creates and keeps in the Keychain. It is not your advertising identifier and is not derived from your device's hardware. When the app checks your plan and limits (also in offline mode), when you sign in, and when you sync To apply free-tier limits, keep sign-in sessions per device, and tell your devices apart in sync
Email address and account ID; for Sign in with Apple, Google or GitHub also the account identifier and email address that provider shares with us. Your Google name and profile picture are shown only inside the app and are not stored on our servers. When you create an account or sign in To create and identify your account
Password — stored only as a salted hash When you register or sign in with email and password To verify sign-in
Encrypted sync records, with their record type, ID, modification time and the install identifier of the device that sent them Only when you use cloud sync (Pro) To deliver your data to your other devices
Subscription status: plan, status, renewal or expiry date, store and transaction identifiers When you subscribe, renew, cancel or restore purchases To unlock Pro on your account on every device
Failed sign-in attempts (by email) and registration attempts (by IP address) When you sign in or register To protect accounts from password guessing and abuse
Announcement requests When the app loads announcements To show service notices; if you are signed in, to remember which ones you have read

Like any online service, our hosting provider processes your IP address and basic request information to deliver these requests and protect the service. We do not use it to profile you.

Cloud sync is end-to-end encrypted

Before anything is synced, the app encrypts it on your iPhone (AES-256-GCM) with a key derived on the device from your password (PBKDF2). The key never leaves your devices, so our servers store only ciphertext and cannot read your connections, passwords, keys, scripts or notes. The server can see only the metadata listed in the table above. Because we never hold the key, we cannot recover synced data if you lose your password. On iOS, cloud sync is available when you sign in with email and password.

4. The AI assistant

The AI assistant uses your own API key with the provider you choose — for example OpenAI, Anthropic, DeepSeek, Moonshot, Alibaba Cloud, Zhipu, SiliconFlow, a local Ollama server, or another compatible endpoint. The key is stored in your Keychain and sent only to that provider.

When you use the assistant, your request is sent directly from your iPhone to that provider, together with the context it needs: depending on the task, recent terminal output, the output of commands it runs at your request, and details of the server you are connected to. We are not in that path and never see it. The provider handles that data under its own privacy policy. Do not use the assistant on output you would not share with that provider.

5. Purchases

Subscriptions are purchased through Apple. We never receive your payment card or billing details. We use RevenueCat to validate App Store purchases and tell our servers about your subscription status. RevenueCat receives your XConnect account ID, your App Store purchase and transaction information, and the technical device and app information its SDK needs to do this; see RevenueCat's privacy policy.

6. What we do not do

7. Service providers

We rely on a small number of providers, each receiving only what its function needs:

8. Retention and deletion

9. Children

XConnect is a tool for developers and system administrators. It is not directed at children, and we do not knowingly collect personal data from children under 13, or the minimum age required in your country.

10. Your rights

Depending on where you live (for example under the GDPR or the CCPA), you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. Contact us and we will respond within the time the law requires. You can also complain to your local data protection authority. Because synced data is end-to-end encrypted, it can only be read from a device holding your key.

11. International transfers

Our servers run on Cloudflare's global network, so your data may be processed outside your country. Where required, transfers rely on appropriate safeguards such as standard contractual clauses. Synced data remains end-to-end encrypted wherever it is stored.

12. Changes to this policy

If we change this policy materially, we will update the date above and let you know in the app before the change takes effect.

13. Contact

Questions, requests or a data protection concern: [email protected]