# privacy policy
Privacy without
a control plane.
Shepherd SSH does not operate an account service, analytics service, advertising service, or remote server for your SSH data. Your configured servers remain under your control.
Short version: We do not collect personal data through Shepherd SSH. The app stores connection profiles on your device, keeps credentials in Apple Keychain, and connects directly to servers you choose. Optional iCloud sync uses your private Apple account.
1. Scope
This Privacy Policy explains how Shepherd SSH handles information when you use the iOS app. “We,” “us,” and “our” refer to the independent developer of Shepherd SSH. Shepherd SSH is an independent companion for the official Herdr runtime and does not change the privacy practices of servers, networks, Apple services, or third-party tools you choose to use.
2. Information we collect
We do not collect personal information through a developer-operated backend. Shepherd SSH does not include advertising SDKs, behavioral analytics, third-party tracking, or a Shepherd SSH account system. We do not receive your server addresses, usernames, passwords, private keys, terminal contents, prompts, Apple ID, or payment card information.
If you contact us by email, we receive the email address, message, and any information you choose to include. We use that information to respond to support, refund, purchase-restoration, or privacy requests. This communication happens outside the app and is not used for advertising or profiling.
3. Information stored on your device
To provide its core features, the app stores information you enter or create, including:
- server display names, SSH hosts, ports, usernames, session names, and optional executable paths;
- pinned SSH host-key fingerprints used to detect unexpected host changes;
- app preferences, including terminal shortcut configuration and iCloud sync state;
- photos you explicitly select for upload to a configured server; and
- SSH passwords, private keys, and private-key passphrases stored using Apple Keychain.
Server profile metadata is stored in the app's local storage. Production credentials are stored with Apple Keychain and are configured to be accessible only while the device is unlocked.
4. Direct SSH connections
When you connect, Shepherd SSH sends authentication material, commands, terminal input, prompts, selected photo attachments, and other requested session traffic directly to the SSH server address you configured. This transfer is necessary to provide the connection you requested. We do not proxy, receive, or store that traffic. Uploaded photos may remain in a temporary directory on that server until you or the server removes them. The operator of the destination server and network may have separate logging or privacy practices.
5. Optional iCloud sync
Shepherd SSH can optionally synchronize saved server profiles across devices at no charge. This feature is off by default and only activates after you turn it on. Profile metadata is stored with Apple's iCloud key-value storage, while passwords, private keys, and passphrases use synchronizable iCloud Keychain items.
The synchronized data is associated with your Apple iCloud account and is not sent to a developer-operated server. Apple processes iCloud data under its own terms and privacy policy. Turning sync off stops future synchronization on that device but does not automatically delete copies already present in iCloud or on your other devices.
6. App Store purchases
Shepherd Pro is offered as a non-consumable in-app purchase through Apple's StoreKit. Apple handles purchase authentication, payment, offer-code redemption, and purchase restoration. The app reads the verified entitlement needed to unlock Pro features. We do not receive your Apple ID password or payment card information. Apple's services are governed by Apple's privacy policy.
7. Notifications and diagnostics
Agent-status notifications and Live Activity state are generated locally on your device. Shepherd SSH does not send their content through a developer-operated push server. If you independently choose to share diagnostics with Apple, Apple may provide aggregated or crash information according to your device settings and Apple's policies; the app does not include a separate third-party crash-reporting SDK.
8. Retention and deletion
Local profile information remains until you remove a saved server, reset the relevant setting, or delete the app. Removing a server also removes its local Keychain credential. Apple Keychain items may persist after app deletion according to operating-system behavior. When iCloud sync is enabled, removing a synchronized server also requests deletion of its synchronized profile and credential. Data retained by Apple services is subject to your iCloud settings and Apple's retention practices. Photo copies uploaded to a configured server remain subject to that server's storage and deletion practices. Support emails are retained only as long as reasonably needed to respond, keep necessary records, and meet legal obligations.
10. Security
Shepherd SSH uses SSH for network transport, Apple Keychain for credentials, and pinned host-key fingerprints to warn about unexpected server identity changes. No method of storage or transmission can be guaranteed absolutely secure. You are responsible for protecting your device, SSH server, private network, Apple account, and authentication material.
11. Changes to this policy
We may update this policy when app behavior, platform requirements, or legal obligations change. The effective date at the top of this page will be updated when material changes are published.
12. Contact
Apple processes App Store refunds. For refund help, purchase restoration, privacy requests, or any other inquiry, email contact@kotoro.click.