About Projects Blog Contact

SSHdroid

Android app by nulltolife · com.nulltolife.sshdroid

Privacy policy

What the SSHdroid app keeps on your phone, the only places it ever connects to, and why each Android permission is asked for.

Last updated

On this page · 10 sections

The short version

Nothing you keep in the app ever reaches the developer.

SSHdroid is an SSH terminal for Android published by nulltolife. This policy explains what the app does with your data.

What the app stores, and where

Everything below stays on your device. None of it is sent to the developer or to any third party.

  • Hosts you save: label, address, port, username, authentication method, which key to use, jump host, keep-alive interval, host key checking setting, whether it reconnects on its own, and port forwarding rules. Stored in the app's private storage.
  • Snippets you save: each one's name, the command, whether it is offered on every host or one, and whether it presses Enter or asks first. Stored in the app's private storage.
  • Command history: the commands you run in a session are kept in memory while it is open, for the quick panel's History tab. A line is only kept once the server has echoed it back, so a password typed at a prompt is not. The history is never written to storage and is gone when the session closes.
  • Pinned host keys: for each server you connect to, its address, key type and SHA-256 fingerprint, used to warn you if a server's key changes. Stored in the app's private storage.
  • Private keys you import: the key file's contents, encrypted with a key held in the Android Keystore. Alongside it, in the app's private storage: the key's file name, its type, the date you imported it and whether it has a passphrase. The file picker also leaves a copy of the key file in the app's cache (see below).
  • Passwords and key passphrases are asked for each time you connect, used only for that connection and never written to storage.
  • Your preferences: whether the app has already asked for notification permission, the terminal palette and text size, the key bar's rows, whether holding and dragging moves the cursor, which quick panel tab you used last, and whether the app lock is on and how long it waits.
  • Files you transfer: a file you upload goes from your phone to the server you are connected to. A file you download goes to the place you pick in Android's save picker; while it downloads, a temporary copy sits in the app's private cache and is deleted when the transfer ends.
  • Copies left by the file picker: when you pick a private key to import or files to upload, the file picker SSHdroid uses copies each file into the app's private cache and reads it from there. These copies are not deleted when the import or upload finishes, or when you delete the key in the app. They stay until Android clears the cache to free space, you clear it yourself (below), or you uninstall SSHdroid. A key's copy is the file exactly as you picked it, so a key without a passphrase is not encrypted there. Other apps cannot read the cache, and it is not included in backups.
  • Saved scrollback: if you choose Save scrollback, the session's text goes to the file you create in Android's save picker. A temporary copy in the app's private cache is deleted as soon as it has been copied.

Network connections

only the servers you add

Your SSH servers

SSHdroid connects to the SSH servers you configure, either directly or through a jump host you configure. What you type in a terminal session goes to the server you connected to and is governed by that server's operator. With broadcast input on, what you type also goes to every other open session you picked for it, each governed by its own server's operator. Which sessions are side by side or broadcasting is kept in memory and never stored.

at launch, and on the Pro page

Google Play

The only other traffic is with Google Play, for the Pro subscription: at launch the app asks Play whether your Google account holds it, and it asks Play for the price and any free trial when you open the Pro page. That goes through the Google Play app on your device.

SSHdroid sends nothing about your hosts, keys or sessions to Google Play or anyone else. It has no analytics, advertising, crash reporting, accounts or servers of its own.

SSHdroid Pro

SSHdroid Pro is an optional yearly subscription made through Google Play. It adds two terminal features, side by side and broadcast input; everything else in the app stays free, and nothing about host key checks or sign-in is ever part of it.

Google Play processes the payment and any free trial under Google's own privacy policy, and gives the developer the order records it gives every developer. SSHdroid stores nothing about the subscription on your device: it asks Play each time it starts. You manage or cancel it in Google Play, which the Pro page links to.

Backups

If Android Auto Backup is on for your Google account, Android may include your saved hosts, snippets, pinned host keys and preferences in that backup, and the list of keys you imported (each one's file name, type, import date and whether it has a passphrase). The private keys themselves are deliberately excluded and have to be imported again on a new device.

Can be in the backup

  • Saved hosts and snippets
  • Pinned host keys
  • Preferences
  • The list of keys you imported

Never in the backup

  • The private keys themselves
  • Passwords and key passphrases
  • The file picker's cached copies

These backups are handled by Google under your account and are not accessible to the developer.

Permissions

Internet and network state
To open the SSH connections you start.
Foreground service and notifications
To keep an open SSH session connected while SSHdroid is in the background, with a notification that shows which session is open and lets you disconnect it. The service runs only while a session is open. Declining notifications hides the notification; the session still stays connected.
Google Play billing
To offer the Pro subscription.
Biometric only with app lock
Along with, on Android 8 and older, the legacy fingerprint permission that comes with it. Used only if you turn the app lock on, to ask for the phone's own fingerprint, PIN or pattern before SSHdroid opens. Android checks it; the app is told yes or no and nothing else. No fingerprint or PIN data reaches SSHdroid, and none is stored.

The app requests no other permissions. Private keys and files to upload are opened through Android's system file picker, which grants access only to the files you choose, and downloads are saved through its save picker, which grants access only to the file you create.

Deleting your data

  • Delete hosts, snippets, keys and pinned host keys inside the app, or uninstall it to remove everything it stored on the device.
  • To remove the copies the file picker left in the cache without uninstalling, open SSHdroid's page in Android's Settings, then Storage & cache, and tap Clear cache.

Children

SSHdroid is a technical tool and is not directed at children.

Changes

Changes to this policy will be published at this address with a new date at the top.

Contact

Questions about this policy or your data?

sshdroid@nulltolife.com