Information stored on your device

Saved data includes server profiles, credentials, private keys, host identities, jump hosts, tunnel rules, session snapshots, login history, file paths, folder-access grants and app settings. Android also stores VPN/proxy configurations and their secrets. iOS secrets use Keychain. Android encrypts inventory with a Keystore-backed key, but can save it in plain text if encryption is unavailable; WireGuard, Shadowsocks and OpenVPN profile storage requires encryption. Android cloud backup is disabled. Optional debug logs are stored locally.

Information sent over the network

SSH authentication goes to your configured servers and jump hosts after their identity checks. Terminal, SFTP, VNC and forwarded traffic goes to the endpoints you choose. Plugin catalogs and downloads contact their configured sources. Android VPN/proxy profiles can send other apps' traffic and DNS through your SSH, WireGuard, Shadowsocks or OpenVPN servers, according to the selected routes. This traffic is not sent to Mobile SSH analytics or cloud storage.

File transfer and storage access

File transfer uses folders and files you select, without broad storage permission. Android retains access to the folder you grant. iOS can use the app's folder or remember a folder chosen in Files, and imports documents, photos and shared files through system interfaces. A selected file provider may store data in its own cloud service. Opening or sharing a file sends it to the app or destination you choose.

Logs and troubleshooting

Login attempts are recorded locally as you connect. Debug recording is optional: Android's recorder warns that terminal diagnostics include every key you type, including passwords, and exports an archive. iOS debug logs record connection addresses, failures, reconnects, network changes and tmux diagnostics. Review logs before sharing them; they can reveal server details and, on Android, typed secrets.

Usage analytics

When enabled, Mobile SSH sends Aptabase feature interactions (including VPN/proxy use and terminal multiplexer type), connection diagnostics, app/OS versions, device model, language and a temporary session ID over HTTPS to improve the app. Aptabase processes the request IP address and User-Agent to derive country/region and a daily pseudonymous identifier; it does not store the original IP address or User-Agent with analytics. Events exclude browsing traffic, DNS queries, server addresses, usernames, credentials, commands and file contents. Android builds with the analytics consent prompt require opt-in; older Android builds and iOS enable analytics by default. All features work without analytics. Settings can stop collection; previously queued events may still be delivered on iOS. Android consent is device-local and is not restored from backups. See Aptabase's data processing agreement.

Backups you export

Full backups include inventory and app settings, plus VPN/proxy profiles on Android. A passphrase encrypts the file; without one, it contains passwords and private keys in plain text. You choose where it is saved or shared. SSH host trust, active sessions and system folder grants are excluded. Import previews show which sections and security preferences will be applied.

VPN routing on Android

Device VPN routing requires Android's consent and continues until stopped or ended by the system. Only one device VPN can run at a time; a local SOCKS proxy can coexist with another VPN. SSH routing carries TCP and DNS, while other UDP assigned to SSH is blocked. Stopping, switching or terminating the app ends the old VPN's protection; Mobile SSH does not provide always-on or lockdown guarantees.

Permissions

Security responsibilities

Protect your device and exported backups. Compare unknown SSH fingerprints through a trusted channel: disable Android's automatic acceptance of new identities if you want to approve first use; iOS asks by default. Investigate changed-key failures before replacing a saved identity. Secure screen blocks screenshots and recording on Android; iOS hides the app-switcher preview and recording/mirroring, but cannot block manual screenshots.

Contact

Support contact: mobile.ssh.info@gmail.com.