Privacy
Local-first by design.
SSHHIP connects to hosts that you configure. It has no SSHHIP backend, no account system, no analytics SDK, no tracking, and no ads inside the app.
Summary
SSHHIP the app does not collect data from you for SSHHIP.
Your saved hosts, command snippets, command-menu pins, and preferences stay on your device by default.
If you enable saved-host iCloud sync, SSHHIP syncs saved-host metadata through the private CloudKit database in your own Apple iCloud account.
Passwords and imported private keys that you choose to save are stored in the iOS Keychain.
An optional Security setting, off by default, can require Face ID, Touch ID, or the device passcode before stored SSH keys, passphrases, and passwords are released. The gate is enforced by Keychain access control, with the device credential as fallback, so biometric lockout cannot strand credentials.
Secure Enclave private keys are non-exportable; SSHHIP stores only their persistent key references in the iOS Keychain and their public keys with saved host metadata.
SSHHIP does not send your credentials, terminal contents, host list, or usage activity to SSHHIP or to any SSHHIP server.
If you use Send Image, the selected image goes to the host you are connected to, not to SSHHIP.
Diagnostics recording is metadata-only and stays on your device until you choose Share.
Information stored on your device
- Saved host details and optional multiplexer startup behavior
- Credentials you choose to save, plus Secure Enclave key references
- Trusted host-key records you approve
- Command snippets and pinned commands
- App preferences, trial-start, and purchase entitlement state
- Optional local sync metadata when iCloud host-metadata sync is enabled
- Diagnostics captures you create or that the optional freeze watchdog saves
Network connections (app)
The app connects to hosts you configure, to Apple for App Store purchases, to Apple's on-device speech model service when iOS needs that model, and to Apple's CloudKit service only if you enable saved-host iCloud sync. The optional Scan Network action in Find Nearby also briefly probes other devices on your local network that you have not configured, only to discover candidate SSH hosts; the scan results stay on your device and are not sent to SSHHIP or any third-party server. If a saved host has fallback endpoints, a connection attempt may contact each of those addresses in the order you configured until one is reachable. Terminal traffic is not proxied through a SSHHIP server.
Image handoff
Send Image uploads the selected image over the active SSH/SFTP connection into a hidden
.sshhip-uploads directory on that host and inserts the remote path. SSHHIP does not press Return and
does not send the image to SSHHIP.
Voice input
Voice uses on-device transcription only. On iOS 26, starting voice input may ask iOS to download Apple's on-device speech model. SSHHIP does not collect recordings or transcripts.
Purchases
Apple processes the one-time lifetime unlock through the App Store. SSHHIP does not receive payment card information.
Analytics, tracking, and advertising (app)
SSHHIP does not include analytics SDKs, does not track you across apps or websites, does not show ads, and does not sell data.
Accounts and cloud sync
No SSHHIP account. Optional saved-host iCloud sync defaults off and uses only your private CloudKit database. Passwords, private keys, passphrases, Secure Enclave private-key references, snippets, pins, trusted host keys, terminal contents, image bytes, and diagnostics captures are not synced through CloudKit.
Diagnostics
Metadata-only captures can include app/device state, connection lifecycle, transport decisions, terminal dimensions, counters, and fixed CommandDial/voice metadata. Captures never include terminal content, host details, credentials, paths, audio, or transcripts. Exports happen only when you choose Share. There is no automatic upload path.
This website
The marketing site at https://sshhip.com is static and is served by Cloudflare. Every page
loads a cookieless Umami script from
https://a.kunchenguid.com/script.js, a collector operated by SSHHIP's author. Umami records page
views and named click events on App Store / Get SSHHIP CTAs (event name store_click): the page
URL, referrer, and coarse browser, operating system, device, and country signals. It does not set cookies,
does not fingerprint visitors, and does not track people across other sites.
Cloudflare may also inject its Cloudflare Web Analytics beacon at the zone edge. That beacon is not present in this source tree. Cloudflare states that Web Analytics is cookieless, does not fingerprint visitors, and does not track people across sites; it measures page loads, referrers, and coarse browser, device, and country signals. Cloudflare processes that data as our analytics provider under its own privacy policy.
The site's Content Security Policy permits the Umami collector, the Cloudflare beacon script host, and nothing else third-party.
Beyond those collectors the site sets no cookies, has no advertising or marketing pixels, no session recording, no cross-site trackers, and no SSHHIP-operated account or cloud vault. Nothing you type into a page is sent anywhere - the host readiness check runs entirely in your shell on your own machine, with no upload path.
Any further collector would be disclosed here before it goes live.
App Store purchases still go through Apple. External links (for example the App Store or competitor primary sources) are third-party sites with their own policies.
Children's privacy
SSHHIP is a developer tool and is not directed to children.
Contact
Support: sshhip.com/support · sshhip@kunchenguid.com
Last updated: August 25, 2026.