GETSSH Privacy Policy
Effective date: May 24, 2026
Last updated: September 11, 2026
This Privacy Policy explains how GETSSH handles information in connection with its official website, official desktop client, and related project services. The most important points are these: the GETSSH client is designed around local processing, does not require a cloud account, and does not upload your SSH credentials, private keys, or terminal session content to GETSSH. However, the website, update services, servers you connect to, and any analytics, AI, plugins, or third-party integrations you choose to enable may each process data as described below.
Please read this Policy before using GETSSH. If you use GETSSH on behalf of an organization, you should also ensure that the organization has the appropriate permissions and legal basis for the data it processes.
1. Who is responsible for your information
The GETSSH project and official website are maintained by Realmcloud Open Source Laboratory by RIESILING TECHNOLOGY LTD. For website and project data whose purposes and means of processing we determine, RIESILING TECHNOLOGY LTD. is the responsible party (also called a “controller” under some privacy laws).
- Official website: https://getssh.realmcloud.net
- Official repository and release channel: https://github.com/JiangchenShen/GETSSH
- Privacy contact: GitHub Issues
GitHub Issues are public by default. Do not include passwords, private keys, access tokens, server addresses, terminal output, or other sensitive information in an Issue. If your request involves sensitive information, first post a contact request that does not contain the sensitive details so that an appropriate communication method can be arranged.
2. Scope of this Policy
This Policy applies to:
- the official GETSSH website;
- official GETSSH builds made available through the official repository and its GitHub Releases page; and
- feedback, security reports, and support requests we handle through the official repository.
This Policy does not apply to third-party modified, compiled, or distributed builds of GETSSH, or to servers, AI model services, plugins, MCP services, or other third-party products you use. Third parties may change the code or follow different data practices. Review their policies and assess them independently.
If you use GETSSH to administer servers belonging to you or your organization, you or that organization will generally determine the purposes and means of processing data on those servers. The GETSSH project maintainer does not become the controller of that data merely by providing a local client.
3. Information processed through the website
3.1 Website delivery, security, and access logs
When you visit the website, your browser sends the website and its network or hosting infrastructure the request information needed to deliver the page. This may include your IP address, request time, requested URL, referring page, browser and device type, language, HTTP headers, and error or security logs.
This data is used to deliver the website, troubleshoot problems, prevent abuse, and maintain security. Where applicable law requires a legal basis, we process it to provide the service you request, comply with legal obligations, and pursue our legitimate interests in keeping the website secure and reliable. Logs are retained only for as long as needed for those purposes, dispute resolution, or legal obligations; specific technical retention periods may also depend on hosting configuration.
3.2 Essential local storage
The website uses browser localStorage to remember your cookie and analytics choices, including keys such as:
cookie-consentcookie-analyticscookie-marketing- equivalent legacy preference keys that may remain from earlier versions of the site
These values record only whether you have made a choice and the state of each category. They do not contain your name, email address, or GETSSH client credentials. They remain in your browser until you change your preferences, clear site data, or your browser removes them. Rejecting analytics does not prevent basic use of the website.
3.3 Analytics (only after you consent)
The website loads the following analytics services only after you actively consent to “Analytics & Statistics”:
| Service | Data that may be processed | Purpose | Local identifiers and duration |
|---|---|---|---|
| Google Analytics 4 (GA4) | Page URL, visit time, referrer, browser/device information, approximate region, and page-view or interaction events | Understand traffic, page performance, and usage trends | Usually uses first-party cookies such as _ga and _ga_<ID>; Google publishes a default maximum duration of 2 years, which may be refreshed by configuration or later visits |
| Vercel Web Analytics | Aggregated page, referrer, time, browser, device, operating-system, and approximate-region data | Produce website usage statistics | Vercel states that Web Analytics does not use cookies and distinguishes visitors using a request hash that expires daily |
We configure Google's ad storage, ad user data, and ad personalization signals as denied. The website does not currently use third-party advertising or cross-site behavioral advertising. The “marketing” preference key only records your choice and does not currently cause a marketing script to load.
You can withdraw consent at any time through the cookie button on the website. After withdrawal, the site will stop loading analytics components and will attempt to remove Google Analytics cookies accessible to the current domain. You can also clear cookies and local storage in your browser. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
Further processing and retention by analytics services are governed by our service configuration and the providers' policies. See Google Analytics data safeguards, the Google Privacy Policy, Vercel Web Analytics privacy and compliance, and the Vercel Privacy Notice.
3.4 Third-party fonts
To display the site's typefaces, the website requests font styles or files from Google Fonts (fonts.googleapis.com / fonts.gstatic.com) and Xiaomi's font service (font.sec.miui.com). These requests occur when the page loads and are not conditional on analytics consent. As with any network request, the relevant provider receives your IP address and request information sent by your browser. We do not obtain your name or GETSSH client data through these font requests.
We use these resources to present the website consistently and clearly and, where applicable, rely on our legitimate interests in site presentation and compatibility. The providers process request information under their own rules; see the Google Privacy Policy and Xiaomi Privacy Policy. You may block third-party fonts using browser or network controls, in which case the site will fall back to local system fonts.
3.5 External links and downloads
When you go to GitHub to view code, submit an Issue, or download an installer, your browser connects directly to GitHub. GitHub processes related visit, account, and content data under its General Privacy Statement. Other external links are likewise governed by the destination site's own privacy terms.
4. Information processed by the GETSSH client
4.1 Data stored locally
Depending on the features you use, the GETSSH client may process or store on your device:
- server aliases, hostnames or IP addresses, ports, usernames, proxies, and connection options;
- passwords, private keys, master passwords, and other authentication material;
- known-host fingerprints and trust records;
- application preferences, plugin configuration, and local workspace state;
- local connection audit records, such as connection and disconnection times, duration, and destination information; and
- files, logs, and other content that you choose to save or export.
This data is used to provide the connections, authentication, SFTP, settings, audit, and other local features you request. It is normally stored on your device rather than in a GETSSH-operated cloud. The protections applied depend on your operating system, client version, data type, and whether you enable vault or system secure-storage features. Protect your device, operating-system account, master password, private keys, and backups appropriately.
GETSSH does not require a cloud account. The official client currently has no mechanism that automatically uploads application telemetry, terminal content, or crash reports to GETSSH. We receive diagnostic information only when you choose to submit it through a GitHub Issue or another communication channel.
4.2 Terminal and file transfers
Traffic for SSH, SFTP, Telnet, or other connections travels between your device and the destination you specify. The GETSSH project maintainer does not provide a relay proxy and does not receive or inspect your terminal input, terminal output, command history, remote file contents, or authentication credentials.
The destination server, network operator, proxy service, or your organization may log connection metadata or session content according to its own configuration. Unencrypted protocols such as Telnet involve additional risks and should be used only when you understand and accept them.
4.3 Update checks
The official client may connect to the GitHub Releases API to check for new versions. This request exposes to GitHub the information normally required for a network request, such as your IP address, User-Agent, request time, and requested resource. GETSSH does not add SSH credentials or terminal content to the update request. GitHub processes this data under its General Privacy Statement.
4.4 Optional AI, MCP, plugins, and integrations
When you choose to configure an AI model provider, MCP service, plugin, proxy, or other integration, the client may send the data needed to complete your request to the service you selected. For example, this may include prompts, terminal context you select, diagnostic information, tool parameters, or data explicitly requested by a plugin.
These transfers depend on the features, permissions, and configuration you enable. The GETSSH project maintainer does not automatically receive this data merely by providing the connection capability. The relevant provider may independently decide how to log, use, and retain it. Before enabling a service, review its permissions, destination, retention settings, and privacy policy, and do not send passwords, private keys, access tokens, or other secrets unless strictly necessary and appropriate.
Third-party plugins may be able to read local data, access terminal context, or make network requests after receiving the relevant permissions. Install only plugins you trust, and review permissions and code provenance again after updates.
5. What we do not do
For processing controlled by the GETSSH project maintainer:
- We do not sell your personal information.
- We do not “share” personal information for cross-context behavioral advertising.
- We do not operate a GETSSH cloud account that centrally stores SSH passwords, private keys, or terminal sessions.
- We do not restrict basic website access merely because you reject optional analytics.
- We do not claim the ability to access, export, or delete client data that was never transmitted to us.
6. Who may receive information
We disclose information we actually hold only in the following circumstances:
- Service providers: vendors needed for hosting, content delivery, analytics, security, and project collaboration, such as hosting or network providers, Google, Vercel, and GitHub;
- Third parties you choose: when you actively use external links, plugins, AI, MCP, or other integrations;
- Legal and safety reasons: when reasonably necessary to comply with applicable law or valid legal process, or to protect the rights and safety of users, the public, the GETSSH project, or others; and
- Project or operational changes: if project maintenance or related assets are merged, transferred, or reorganized, where permitted by law and subject to appropriate safeguards.
7. International processing
The GETSSH website is available globally. Google, Vercel, GitHub, Xiaomi, and the servers or integration providers you select may process information outside your country or region. Data protection rules differ across jurisdictions. Those providers are responsible for applying the transfer mechanisms and safeguards required by their policies and applicable law.
Local client data does not automatically cross borders merely because you install or open GETSSH. Connecting to a server abroad or enabling a foreign third-party service will, however, create cross-border network communications that you initiate.
8. Retention and deletion
- Local client data: remains on your device until you delete it in the client, remove the relevant directory, or the operating system removes it. Uninstalling the application may not remove all user data. Back up anything you need before deletion.
- Website preferences: remain in browser storage until you change them or clear site data.
- Analytics data: is retained according to the relevant analytics service configuration and policy; the ability to associate it with an individual user may be limited.
- Access and security logs: are retained for as long as needed to operate and secure the service, troubleshoot problems, and meet legal obligations.
- Issues, feedback, and support content: may remain as part of the public project record until deleted by you or an authorized maintainer, or otherwise handled by GitHub under its policy.
Some information may be retained longer where required by law or necessary to resolve disputes, prevent abuse, or enforce agreements. When data is no longer needed, we delete it, anonymize it, or stop retaining the copies within our control.
9. Your choices and rights
Depending on where you live, you may have the right to:
- know about and access personal information we process;
- correct inaccurate information;
- request deletion or restriction, or object to certain processing;
- receive a portable copy where applicable;
- withdraw consent-based processing at any time;
- exercise applicable privacy rights without discrimination; and
- complain to your local data protection authority.
You can manage website analytics through the cookie preferences panel and local client data through client features or your operating system's file-management tools. We cannot access, export, correct, or delete data that remains only on your device and was never sent to us.
To exercise rights over data we actually hold, contact us through the channel listed in Section 1 and describe your request and the relevant interaction. To protect data, we may need to verify the requester's relationship to it. Some rights are subject to conditions and exceptions under applicable law.
10. Security
We use technical and organizational measures appropriate to the nature of the project to reduce the risk of unauthorized access, disclosure, alteration, or loss. These include limiting when website analytics can load, using encrypted transport, and providing local secure-storage and permission-isolation capabilities in the client.
No software, device, or network transmission can be guaranteed completely secure. Open-source code can be modified by third parties, and builds obtained outside the official channel may not provide the same protections. Verify the download source and release signatures or checksums where available, keep the client updated, and protect your devices and credentials.
11. Children
GETSSH is a tool for developers and system administrators and is not directed to children. We do not knowingly ask children below the age at which they can independently consent to data processing in their jurisdiction to provide personal information. Contact us if you believe a child has submitted personal information to us.
12. Changes to this Policy
We may update this Policy when features, data practices, or legal requirements change. The updated version will be published on the website and/or in the official repository, with a revised “Last updated” date at the top. If a change materially affects your rights or how we use information, we will provide more prominent notice where reasonably practical and request consent again where required by law.
13. Contact us
For questions about this Policy or GETSSH's data practices, or to make a privacy request, contact us through the official GitHub Issues page. Remember that Issues are public and must not contain secrets or sensitive personal information.