Privacy Policy
WoleSSH (“WoleSSH”, “the app”, “we”, “us”, or “our”) is a cross-platform SSH client for desktop and mobile. This Privacy Policy explains what information the app accesses, how it is used, stored, and shared, and the choices you have.
WoleSSH is local-first: your connections, keys, and settings are stored on your own device. We do not run analytics, advertising, or user-tracking services. Cloud features (Sign in with Google, Google Drive backup, custom backup server, connection sharing) are optional and only run when you explicitly enable them.
If you do not agree with this policy, please do not use the app.
1. Who we are and how to contact us
WoleSSH is operated by Muhammad Hendrik Eka Saputra (“the Developer”).
- Contact email: cs.extools@gmail.com
- Website: https://wolessh.dev
For any privacy question, data access request, or data deletion request, email us at the address above.
2. Summary of what we collect
| Category | Collected? | Where it is stored |
|---|---|---|
| Google account info (ID, email, name, profile picture) | Only if you Sign in with Google | On your device (encrypted). Not on our servers. |
| Google OAuth tokens (access + refresh token) | Only if you Sign in with Google | On your device (encrypted at rest). |
| SSH connection details, SSH keys, notes, snippets, command history, app settings | Created by you inside the app | On your device (encrypted at rest). |
| Encrypted backup files | Only if you enable backup/sync | Your Google Drive and/or your own custom server. |
| Device sharing token (connection sharing feature) | Only if you use connection sharing | A salted hash is stored by our sharing service. |
| Analytics / advertising / tracking data | No | — |
3. Information we access and collect
3.1 Google user data (only when you use “Sign in with Google”)
When you choose to sign in with Google, we request the following OAuth scopes:
openid,email,profile— to authenticate you and obtain your Google account ID, email address, display name, and profile picture. This is used to identify your account inside the app and to name your backup file.https://www.googleapis.com/auth/drive.file— a per-file Google Drive scope. It grants the app access only to the specific backup file that WoleSSH itself creates in your Google Drive. WoleSSH cannot see, read, or modify any other files in your Google Drive.
Google returns short-lived access tokens and (with your consent) a refresh token. These tokens are stored encrypted at rest on your device and are never sent to the Developer’s own servers.
3.2 Data you create in the app
The following data is created and controlled entirely by you and stored locally on your device:
- SSH connection metadata: name, host, port, username, optional description, and an optional saved password (only if you choose to save it).
- SSH keys managed in the Keychain: private keys, public keys, certificates, and optional key passphrases.
- Per-connection notes, command snippets, and command history.
- Detected server OS labels (used for display icons).
- App settings: theme, fonts, notification preference, and an optional sharing alias.
3.3 Connection sharing (optional)
If you use the connection-sharing feature, WoleSSH generates a random per-device token to identify your install to our sharing service. Only a salted hash of this token is stored server-side — never the token itself. Shared connection payloads are encrypted before transmission.
3.4 Information we do NOT collect
We do not collect analytics, usage telemetry, advertising identifiers, location data, or behavioral tracking data. We do not build user profiles for advertising.
4. How we use information
We use the information described above solely to:
- Authenticate you via Sign in with Google and display your account identity inside the app.
- Create, update, read, and delete your own encrypted backup file in your Google Drive (or on your own custom backup server).
- Provide the app’s core features: connecting to your SSH servers, managing your keys, and — if enabled — backing up, syncing, restoring, and sharing your data.
We do not use your data for advertising, and we do not sell your data.
5. Google user data and Limited Use disclosure
WoleSSH’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request the minimum scopes needed for the features you enable.
- Google user data is used only to provide and improve the user-facing features described in this policy (authentication and backup of your own data to your own Drive).
- We do not transfer Google user data to third parties except as necessary to provide these features, to comply with applicable law, or as part of a merger/acquisition with the same protections.
- We do not use Google user data for advertising.
- We do not allow humans to read your Google user data unless: (a) you give explicit consent for a specific case (e.g. troubleshooting a support request), (b) it is necessary for security (e.g. investigating abuse), (c) it is required by law, or (d) the data has been aggregated and anonymized.
6. How your data is stored and secured
- Local-first: Your connections, keys, and settings live on your device.
- Encryption at rest: Sensitive local data — including OAuth tokens and the local vault — is encrypted at rest using a device key derived with Argon2id.
- Encrypted backups: Backup files are encrypted with AES-256-GCM on your device before they are uploaded anywhere.
- In transit: All network requests to Google and to backup endpoints use HTTPS/TLS.
- Tokens: Google OAuth tokens are stored encrypted on your device and are not transmitted to the Developer’s servers.
No method of storage or transmission is 100% secure. You are responsible for keeping your device, screen lock, and private keys protected.
7. Data sharing and disclosure
We do not sell your personal information. Your data may reach the following destinations only when you enable the corresponding feature:
- Google Drive — to store your own encrypted backup file (via the
drive.filescope). This stays within your Google account. - Your custom backup server — if you configure a custom backup endpoint, your encrypted backup is sent to the server you specify. You are responsible for that server.
- The WoleSSH sharing service — if you use connection sharing, a salted hash of your device token and encrypted shared payloads are processed to deliver shared connections.
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of users and the public.
8. Data retention and deletion
- Local data: You can delete all local data at any time from within the app (“Clear all local data”).
- Google Drive backup: You can delete your backup from within the app, or directly from your Google Drive. WoleSSH also offers an option to delete the cloud backup on uninstall.
- Revoking Google access: You can revoke WoleSSH’s access to your Google account at any time at https://myaccount.google.com/permissions. Revoking access invalidates the stored tokens.
- Custom server data: Data stored on your own backup server is managed by you.
- Deletion requests: To request deletion of any data we may hold (e.g. the sharing service hash), email cs.extools@gmail.com and we will process the request within a reasonable time.
9. Children’s privacy
WoleSSH is a technical tool intended for developers and system administrators and is not directed to children. We do not knowingly collect personal information from children under the age of 13 (or the minimum age required in your jurisdiction). If you believe a child has provided us information, contact us and we will delete it.
10. International users
WoleSSH may be used worldwide. Because it is local-first, your data primarily stays on your device. When you use Google Drive backup, your data is stored and processed according to Google’s infrastructure and policies. By using the app, you understand that any optional cloud data may be processed in the country where the relevant provider operates.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, through an in-app notice. Your continued use of the app after changes take effect constitutes acceptance of the revised policy.
12. Contact us
If you have questions about this Privacy Policy or your data, contact:
- Email: cs.extools@gmail.com
- Website: https://wolessh.dev