Privacy
Privacy Policy
Mobile SSH is designed as a local SSH client for Android and iOS. It does not require a Mobile SSH account and does not provide a Mobile SSH cloud sync service.
Information stored on your device
If you choose to save app data, Mobile SSH stores it locally on the device. Secrets are kept in the system Keychain on iOS; on Android they are encrypted with a key held in the Android Keystore that cannot be exported off the device, and the app opts out of Android cloud backup. This may include saved server profiles, usernames, ports, passwords, private keys, key passphrases, port-forwarding rules, recent sessions, login attempt history, file-transfer paths, file-sort preferences, tmux session snapshots and reattach hints, app settings, and debug logs when debug recording is enabled.
Information sent over the network
Mobile SSH sends SSH authentication data only to servers that you configure and connect to. Terminal input/output, SFTP file contents, and local port-forwarded traffic are exchanged with the servers and remote endpoints you choose. Mobile SSH does not send this data to a Mobile SSH analytics, advertising, telemetry, or cloud sync service.
File transfer and storage access
The file transfer feature browses local phone storage and remote SFTP directories so you can upload and download files. Mobile SSH does not ask Android for broad storage permission: you pick one folder with the system folder picker and the app can read and write only inside it. On iOS, local files and photos are reached through the system document and photo pickers.
Logs and troubleshooting
Login history and optional debug logs are stored locally for troubleshooting, and both are off or empty until you turn them on. Android's debug recorder captures terminal events, SSH data sizes, touch input diagnostics, resize events, and tunnel lifecycle events — it warns you before it starts that this includes every key you type, passwords included, and it writes an archive to your Downloads folder. iOS records a different, narrower log: the addresses it dialled and why each failed, reconnects and backoff, dropped connections, network changes, and tmux commands with their errors. Review any debug log or archive before sharing it with support or another person.
Anonymous usage analytics
To understand how the app is used and improve it, Mobile SSH sends anonymous usage analytics to Aptabase, a privacy-focused analytics provider acting on our behalf. This is limited to anonymous events (such as app launches and which features are used) together with your app version, operating-system version, device model, and language. It uses a random session identifier that resets regularly and is not tied to you or your device. It never includes your SSH servers, hostnames, usernames, passwords, keys, commands, or file contents. Data is sent over an encrypted (HTTPS) connection. Analytics is on by default. On Android you can turn it off at any time in Settings, and when off nothing is sent; the iOS app does not offer that switch yet, so on iOS these anonymous events are sent for as long as the app is installed. We intend to add the iOS switch — until then this page states the position as it actually is.
Permissions
- Internet: required to connect to SSH servers.
- Wake lock and Wi-Fi lock: used on Android to keep active SSH sessions alive while the device sleeps.
- Foreground service and notifications: used on Android for active connection handling in the background; on iOS, notifications are used for agent alerts.
- File access: granted per folder through the system picker on Android, and through the system document and photo pickers on iOS. Mobile SSH does not request blanket storage permission on either platform.
Security responsibilities
Protect your device with a strong screen lock if you save credentials or private keys. Only connect to servers you trust. The current implementation uses local app storage (and the iOS Keychain) rather than a separate encrypted cloud vault. An optional Secure screen setting adds protection when secrets are on screen: on Android it blocks screenshots and screen recording and hides the app from the recents view; on iOS it blanks the app-switcher preview and blocks screen recording and mirroring (a manual screenshot cannot be blocked on iOS).
Contact
Support contact: mobile.ssh.info@gmail.com.