Privacy Policy

Overview

exec terminal ("the App") is an SSH, Mosh, and local terminal client for iOS and iPadOS with optional local and cloud AI assistance, Sign in with Apple, and auto-renewable subscriptions. This policy explains what data is stored, processed, and disclosed when you use the App.

The developer operates the Exec Cloud account, subscription, and AI gateway service. The App and gateway do not use third-party advertising analytics, do not sell personal data, and do not perform advertising or cross-app tracking.

Data Stored on Your Device

The App can store the following information locally:

Exec Cloud access and refresh tokens are stored in the iOS Keychain. The current release does not accept third-party cloud AI API keys, and it removes obsolete AI-provider Keychain entries from earlier versions without removing SSH credentials.

Exec Cloud Account and Subscription Data

Sign in with Apple is required only for Exec Cloud. The gateway stores a User ID consisting of Apple's stable subject identifier, an internal account identifier, a stable App Account Token, an encrypted Apple refresh token when Apple supplies one, and cryptographic hashes of app sessions. The App does not request your Apple name or email address.

For purchase and subscription verification, the gateway stores App Store transaction and original transaction identifiers, product identifier, environment, entitlement status, signed and expiration dates, renewal or billing-retry state, revocation state, and the App Account Token used to bind the purchase to your account.

The gateway also stores Product Interaction and service-usage metadata needed for authentication security, idempotency, abuse prevention, quota enforcement, and fair-use limits. This includes counters, reset dates, keyed request fingerprints, reservation identifiers, and token-unit totals, but not the text of your prompts or responses.

Exec Cloud AI and User Content

When you choose Exec Cloud, the prompts you submit and the model response are processed in real time by the gateway and its AI processing provider, CometAPI. This Other User Content is not stored in the gateway database and is excluded from application logs. CometAPI handles the content and related technical data it receives under its Privacy Policy and Terms of Service.

Include terminal context is off by default. When you turn it on, a bounded portion of recent terminal output plus the server or host and executed command can be added to an Exec Cloud or user-configured Ollama request. Automatic output analysis is available only while terminal context is enabled.

Agent mode requires terminal context. Agent reasoning can request terminal or file tools, but tools and dangerous-command confirmations execute on your device. Only bounded prompts, tool descriptions, and tool results needed for the task are sent to Exec Cloud or your local Ollama endpoint. Apple Intelligence and on-device GGUF chat stay on the device.

Other Network Connections

The privacy and retention practices of your SSH/Mosh server, Ollama operator, Apple, CometAPI, and model-download host apply to data they receive.

Voice Input

Voice input is optional and requires microphone permission. Apple Speech is used only when on-device recognition is available, and Whisper transcription runs locally with a downloaded model. Recorded audio is not sent to a remote speech-recognition service by the App.

Retention and Account Deletion

Account records, session records, entitlement records, and App Store transaction records are retained while your Exec Cloud account exists and are deleted when you use Delete Account in the App. If Apple token revocation is temporarily unavailable, an encrypted token without your Apple subject or account ID can remain in a retry queue for up to seven days.

To prevent repeated free allowances and enforce same-day Pro fair-use limits after deletion and reauthorization, the gateway retains a keyed, non-reversible hash derived from the Apple subject. It retains only lifetime free-use counters and current-UTC-day Pro counters with that hash; it does not retain the Apple subject, account ID, prompts, terminal content, tool data, or model responses in that aggregate. Stale Pro counters are cleared after the UTC day changes, while lifetime free counters remain for fraud prevention.

Deleting your Exec Cloud account does not cancel an Apple subscription. Use Manage Subscription before or after deletion if you want to cancel renewal. Apple controls its own purchase records and retention.

Data Control and Device Credentials

You can edit or delete saved servers, remove command snippets, clear AI or agent history, sign out, restore or manage purchases, and delete your Exec Cloud account inside the App. Deleting a saved server also removes the credentials associated with that server.

Deleting the App removes data in its local container, but iOS Keychain items may persist after uninstall. Remove saved server credentials and sign out before uninstalling if you want those local credentials removed. Data already sent to a server or user-configured Ollama endpoint is controlled by that service and its policies.

Data Sharing, Selling, and Tracking

The developer uses Apple for authentication and purchase processing and CometAPI as a service provider for Exec Cloud AI processing. No advertising or cross-app tracking is performed. The developer does not sell or rent personal data.

Device Permissions

The App may request Local Network access, Face ID or Touch ID, Microphone access, and Speech Recognition access for the features you choose to enable.

Children's Privacy

The App is not directed to children under 13, and the developer does not knowingly collect personal information from children through the App.

Changes to This Policy

This policy may be updated as the App changes. The date at the top identifies the latest version.

Support

For privacy questions, support requests, or deletion-related questions, visit exec terminal Support. Do not include API keys, passwords, private keys, host details, terminal output, tokens, or other sensitive information in a support request.