Privacy Policy
Effective: beta period · Last updated: July 2026
Termalin ("we") is the desktop SSH client and cloud service at termal.in.
The short version
- Your hosts, keys, passwords and terminal recordings are end-to-end encrypted on your device. We store ciphertext we cannot read. Details: security page.
- We collect the minimum needed to run accounts and sync.
- We don't sell data, run ads, or embed third-party trackers.
What we store
- Account: email address, a password hash (Argon2 — we never store the password itself), optional display name, subscription tier, sign-up and sign-in timestamps.
- Encrypted content: your sync data and session recordings as encrypted blobs, plus a key-derivation salt (not a secret).
- Recording metadata: duration, size, and whether an AI agent acted in the session — used for lists and plan quotas. The host label and title are encrypted with your master password, like the recording itself.
- Devices: a device identifier and name per synced device.
- Payments: if you buy a plan or add balance, our payment processor (Creem, or NOWPayments for crypto) handles the transaction and receives your email and payment details — we never see or store card numbers. We keep your subscription tier and an account-credit ledger.
- Server logs: standard operational logs (IP address, request path, timestamps) kept briefly for security and debugging — e.g. rate-limiting sign-in attempts.
What we never have
- Your master password, or any key derived from it.
- The plaintext of your hosts, SSH keys, credentials, or recordings.
- Your keystrokes — recordings capture terminal output only.
How we use data
To provide the service: authentication, sync, storing recordings, enforcing plan limits, and sending emails — account emails (verification, password reset) and, if you buy a plan, payment emails (a receipt, and, if you begin a checkout but don't finish, a one-off reminder). Nothing else. We do not sell or share personal data with third parties except the infrastructure providers that host the service (server & email delivery) and our payment processors (Creem, NOWPayments), each bound by their own data-processing terms.
Retention & deletion
- Cloud recordings are kept per your plan's retention window, then deleted.
- Deleting your account (in the app or the web cabinet) permanently removes the account and everything stored server-side: sync data, recordings, devices, tokens. There is no soft-delete.
Cookies & local storage
The landing site sets no cookies and runs no analytics. The web cabinet keeps your session token in your browser's local storage; your master password is used only in the page's memory and never transmitted.
Your rights
You can access what we hold about you (it is what you see in the app and cabinet), correct it, export your recordings, or erase everything via account deletion. Questions or requests: [email protected].
Changes
We'll update this page as the service evolves and note material changes on the site.