XConnect is a server connection manager and terminal: SSH, Telnet, RDP and SFTP, with an AI assistant, a script library and encrypted sync. It is built local-first. Everything that matters works with no account at all, and the data you do choose to sync is encrypted on your device before it leaves it — we cannot read it.
By default, everything. Connections, groups, scripts, jump hosts and settings live in an encrypted database inside the app's own sandbox. Passwords and private keys are never written to that database: they are stored in the operating system's secure storage (Keychain on iOS, Keystore on Android) and never leave the device in plaintext.
Anything you mark “this device only” is excluded from sync entirely, whatever else you have enabled.
| Data | When | Why |
|---|---|---|
| Email address, display name, account identifier | Only if you create an XConnect account or sign in with Apple, Google or GitHub | To identify the account your data syncs to |
| Encrypted sync payloads (connections, groups, scripts, keys) | Only if you turn on cloud sync | To hand the same records to your other devices |
| Purchase and subscription status | Only if you buy Pro | To unlock Pro on your other devices and to restore purchases |
| App version and platform | On update checks and announcement fetches | To tell you a newer version exists |
Sync payloads are encrypted on your device with a key derived from your credentials. The server stores ciphertext and has no way to decrypt it. That also means a lost password can mean lost synced data — we cannot recover it for you.
You can point sync at your own server instead of ours. In that case nothing reaches XConnect's infrastructure at all.
XConnect connects your device directly to the servers you configure. Terminal output, remote desktop frames, transferred files and keystrokes travel between your device and your server. They do not pass through us. There is no relay, no gateway, and no session recording on our side.
The AI features are bring-your-own-key: you choose the provider (OpenAI, Anthropic, DeepSeek, a local Ollama, or any compatible endpoint) and supply your own API key, which is stored in your device's secure storage and sent only to that provider.
When you ask the assistant to do something, the request — and, depending on the task, recent terminal output and details of the server you are connected to — is sent to the provider you selected, so it can answer. We are not in that path and never see it. That data is then handled under your chosen provider's privacy policy, not ours. If terminal output is sensitive, do not invoke the assistant on it.
We use a small number of processors strictly to run the service: Cloudflare (hosting and delivery), and RevenueCat together with Apple and Google (purchases and subscription status). They receive only what their function requires.
Account data and encrypted sync payloads are kept while your account exists. You can delete your account from inside the app — Profile → Delete account — or by writing to us. Deletion removes your account and the synced data attached to it. Records kept on your device, including anything marked “this device only”, are yours to remove by deleting them in the app or uninstalling it.
XConnect is a tool for system administrators and developers. It is not directed at children, and we do not knowingly collect data from anyone under 13 (or the equivalent minimum age in your country).
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. Write to us and we will act on it. Because sync data is end-to-end encrypted, an export of it is only meaningful from a device holding your key.
Our infrastructure runs on Cloudflare's global network, so data may be processed outside your country. Sync payloads are encrypted end-to-end wherever they are stored.
If this policy changes materially we will update the date above and surface a notice in the app before the change takes effect.
Questions, requests, or a data-protection concern: [email protected].