Data handling, in plain language

Privacy Policy

Termind is local-first. You choose which services to connect and whether to share diagnostic data.

EffectiveOctober 3, 2026Version2.1
01

Overview

We do not sell personal information, show advertising, use cross-app tracking, or include third-party behavioral analytics SDKs in the app. No Termind account is required.

Termind is a client application. When you use AI, search, iCloud, Tailscale, speech, or remote connections, the relevant service provider processes what it receives under its own terms. Termind does not place a hosted proxy between you and those providers.

02

Data stored on your device

To provide its features, Termind stores the following information on your device:

  • Vault metadata such as host names, addresses, ports, usernames, groups, tags, identity labels, public-key fingerprints, Known Hosts entries, snippets, and port-forwarding rules.
  • Tailscale group configuration, this device’s Tailnet profile, and cached peer information such as device names, addresses, public SSH host keys, online status, and key-expiry information. Private node state is stored separately in Keychain, as described in the Tailscale section.
  • Connection history, including the host, connection type and times, together with the name or model used to identify the device where the connection was made.
  • AI provider and model configuration, role assignments, the last selected model, MCP client configuration and tool policies, skill text and enabled state, Web Search preferences, terminal themes and integration options, and Connections preferences such as SSH Max Sessions and file-transfer concurrency. Enabling settings sync also stores these settings in your private iCloud database.
  • Conversations, messages, agent tool calls and results, security-review records, command history, workspace state, and app settings.
  • Context attachments you import and per-conversation scratch files until you delete the related conversation.

This data is not automatically sent to the Termind developer. The operating system, device backups, or other software you install may access or back up local files according to their own settings.

03

iCloud & Keychain

Vault sync

When “iCloud Sync” is on and “Vault” is selected, Vault data, connection history, and the device names or models used to identify where connections were made are stored in the private iCloud database for your Apple ID. Device information is used only to distinguish connection-history sources across your devices. It is transferred only through your private iCloud database; the Termind developer does not receive or collect it. Apple processes synced data under its terms.

Tailscale group configuration can sync with Vault. Tailnet sign-in and the discovered peer cache stay on the current device; see Tailscale data handling.

Metrics sync

“Metrics” is selected by default. When iCloud Sync is on, monitored host identifiers, pause state, disk and network-interface selections, and card order sync through CloudKit. Host addresses and credentials remain managed separately by Vault and Keychain; live samples, metric history, authentication state, and menu-bar preferences do not sync. A configuration is retained but hidden when its host is unavailable on the current device.

Settings sync

iCloud sync is a Pro feature with one main switch and checkboxes for the data to sync. Vault, Metrics, and Settings are all selected by default. When the main switch is on and “Settings” is selected, provider and endpoint settings, model lists and custom parameters, role assignments, the last selected model, MCP client configuration and tool policies, complete skill text and enabled state, Web Search preferences, terminal preferences, and Connections preferences sync through CloudKit to your Apple account’s private iCloud database. Connections preferences include SSH Max Sessions and file-transfer concurrency. Configuration includes complete custom terminal configuration text and custom MCP header names and values; use the dedicated credential fields for secrets.

Settings sync excludes conversations, messages, tool execution history, runtime or connection state, global approval mode, and the enabled state, port, exposed-tool settings, and access token of Termind’s built-in MCP server. That token is stored only in the Data Protection Keychain on the current Mac. Enabling sync does not automatically connect to MCP servers or execute tools. Apple processes synced data; Termind does not operate a backend that receives this configuration.

Passwords and private keys

Passwords, software SSH private keys, AI API keys, and MCP credentials are stored in Apple’s Data Protection Keychain, not in the Vault database. You can choose whether to save a software SSH key’s passphrase with its private key in Keychain; if you do not, Termind asks for it when connecting. Storage options for passwords and SSH keys include:

  • iCloud: the Keychain item may sync across your devices through iCloud Keychain.
  • This Device: the item is marked for this device only and does not sync.
  • Secure Enclave: the private key is non-exportable and does not sync to other devices.

For a compatible FIDO2 hardware key, the Vault stores a credential reference and public key, which may sync with Vault data. The private key stays on the hardware key and is needed to authenticate even if its reference syncs.

When you first enable settings sync, existing AI API keys and remote MCP client bearer tokens migrate from local Keychain storage to iCloud Keychain; configuration records contain only references to these credentials. Failed migrations retain the local copy and can be retried. The built-in MCP server token is excluded; copies synchronized by older releases are moved to and verified in the local Keychain before being removed from iCloud Keychain. Credentials that have never been enabled for sync remain local. Turning off settings sync leaves migrated AI and remote MCP credentials managed by iCloud Keychain, where subsequent changes may still sync. Your Apple account and system settings determine whether iCloud Keychain is enabled, which devices receive items, and how Apple protects them. Configuration and credentials may reach another device at different times.

04

Purchases and subscriptions

Termind uses Apple StoreKit to verify the annual Pro subscription, introductory free trial, lifetime purchase, restored purchases, revocations, renewal state, and Family Sharing access. Apple processes purchase-account, transaction, and payment information under its policies. Termind does not receive your complete payment details.

RevenueCat provides our purchase validation, entitlement synchronization, and paywall service. Its SDK sends a randomly generated anonymous app user ID, purchase and subscription records, and app/device environment information needed to provide these services. Restoring the same Apple purchase can associate your anonymous IDs across devices. We do not send RevenueCat your host credentials, terminal content, conversations, AI API keys, or payment-card details, and automatic device-identifier collection is disabled.

Free-trial eligibility, duration, and subscription expiration are based on the store's product and purchase records. Termind does not use device fingerprinting or operate its own license server.

RevenueCat Privacy Policy

05

AI providers and MCP

AI features are optional and use a bring-your-own-key model. You may configure any endpoint that speaks the Chat Completions, Responses, Messages, or generateContent protocol. When you use AI, Termind sends the data needed for the request directly to the selected endpoint, which may include:

  • your prompts, conversation history, selected images, and attachments;
  • current session context, such as host and remote-system information and working directory;
  • tool names, arguments, results, and command output or file contents you authorize the agent to read;
  • the API key or access token used to authenticate the request.

Private-key material is not sent to the model as chat context. Termind resolves credentials locally to establish SSH connections. Review the privacy policy, retention controls, and enterprise terms of your selected AI provider. The operator of a custom endpoint is responsible for that endpoint.

If you add a remote MCP server, Termind exchanges requests, tool arguments, and results according to the tools that server exposes. The data shared depends on the server you enable and tools you invoke. On Mac only, Termind’s built-in MCP server listens on the local loopback interface by default; if you change how it is exposed, you are responsible for securing access.

07

SSH, SFTP, web fetches, and remote actions

When you connect to a host, Termind sends the information required to establish the connection to that host and any proxy or jump host you configure. Passwords are used for authentication inside the encrypted SSH session. SSH private keys remain on the current device and are used to sign locally. Target systems may log IP addresses, usernames, times, commands, file transfers, and other activity according to their own configuration.

When you or the agent fetches a web page, Termind directly visits the specified HTTP(S) address, including private-network addresses. The destination generally receives your IP address, URL, user agent, and standard network-request information. Depending on the tool call, bounded Markdown or original HTML may be sent to your selected AI provider as context. Termind cannot control the destination’s logging or privacy practices.

08

Tailscale

Sign-in and device information

Tailscale is optional. When you sign in from a Vault group, Termind registers an embedded node with Tailscale or the control service you configure. Browser sign-in is handled by that service and its identity provider. If you use an Auth Key, it is sent to the selected control service to authorize the node; it is not included in synced group configuration.

The control service receives information needed to authenticate the node and coordinate connections, including the device name you configure, operating system, Tailscale version, IP addresses, node identifiers, and public keys. It supplies the peer information Termind uses to show devices and verify Tailscale SSH host keys. Tailnet administrators can see device and connection information according to their permissions and logging settings.

Traffic, relays, and exit nodes

Traffic between Tailscale nodes is encrypted with WireGuard. Connections may be direct or pass through a peer relay or DERP relay, which forwards encrypted traffic without decrypting its contents. The services involved can process connection metadata such as IP addresses, connection times, and traffic volume; Tailscale may also process diagnostic and connection logs under its own policy. This processing is separate from Termind’s optional Crashlytics reporting.

If you select an Exit Node, traffic routed through it is handled by its operator, who may see destinations and any contents not protected by application-layer encryption. SSH and SFTP remain encrypted to the target server. DNS resolvers may process the names queried according to your network configuration. Termind’s embedded connection does not turn on a system-wide VPN or route other apps’ traffic.

Local storage and iCloud

Private node state, including the keys used to maintain the Tailnet identity, is stored in Apple Keychain items marked for this device only, with Keychain synchronization disabled. The app stores the local profile reference and discovered peer cache on this device. These are not included in Termind’s iCloud sync, so another device must sign in separately.

With Vault sync enabled, the group’s control-service URL, Tailnet DNS suffix, selected Exit Node identifier, and saved host preferences can sync through your private iCloud database. Host preferences include usernames, tags, colors, detected distribution, character encoding, initial SFTP path, shell-integration choice, startup-snippet reference, and environment variables. Do not put secrets in these configuration fields.

Tailscale’s processing and retention are governed by its Privacy Policy. If you use a custom control service, its operator’s policy also applies. Data retained by a Tailnet administrator, identity provider, relay, DNS resolver, or Exit Node operator is subject to that party’s policies.

Tailscale Privacy Policy

09

Camera attachments and speech transcription

Camera attachments on iPhone and iPad

Termind accesses the camera only after you choose Camera in the Assistant and grant permission. A photo remains in the conversation draft until you send it; when sent, it is handled as described in the AI section. Mac does not expose this camera attachment flow.

Speech transcription

Termind captures audio only after you press the transcription button and grant microphone and Speech Recognition permissions. Transcription uses Apple Speech. Depending on operating-system settings, language, and device capabilities, Apple may process audio on-device or on its servers. Termind stops the active recording after completion, cancellation, or failure. Transcribed text enters your chat draft and, if sent, is handled as described in the AI section.

10

Diagnostics

Termind asks for your choice before enabling Google Firebase Crashlytics. If you agree, diagnostic data is sent to Google to help us diagnose and fix problems. This includes crash stack traces, relevant application state, app and operating-system versions, device information, and diagnostic installation identifiers. Termind does not attach terminal output, chat content, passwords, private keys, or a user account ID.

Your choice is stored only on this device and does not sync through iCloud. You can decline without losing app features, or change your choice in Settings > App > Diagnostics. Turning sharing off blocks future uploads; it does not withdraw data already sent or stop an upload already authorized. Restarting Termind stops local crash recording. If you opt back in, pending diagnostic data from before consent was restored is discarded.

Google processes this diagnostic data under the Firebase data-processing terms. For Firebase's data handling and retention information, see Firebase Privacy and Security.

11

This website

This website sets no analytics cookies, uses no advertising technology, and contains no contact form. It stores only your selected site language in local browser storage; that preference is not transmitted to Termind. The hosting provider may still process standard server logs—such as IP address, request time, path, and user agent—to deliver the site, prevent abuse, and maintain security, subject to the hosting provider’s policy.

12

Retention, deletion, and your controls

  • You can turn off the main iCloud Sync switch or deselect Vault, Metrics, or Settings to pause the corresponding configuration transfers. You can also disable Web Search, speech permissions, and other optional features. Pausing sync does not erase existing cloud data or stop iCloud Keychain sync for migrated AI credentials.
  • You can delete hosts, monitored items, credential references, conversations, and other content in the app. When the corresponding sync is enabled, Vault, Metrics, and settings deletions propagate to iCloud; deletions made while paused or offline propagate after sync resumes. The protocol retains necessary deletion markers to prevent deleted content from returning, so deletion does not immediately erase all sync metadata.
  • Uninstalling the app may not automatically delete data in Keychain or iCloud. Delete relevant credentials, Vault data, and settings in the app before uninstalling, or use Apple’s system settings to manage iCloud and Keychain.
  • To remove a Tailnet sign-in from this device, log out in the group editor and save the change. Termind removes the local profile reference and peer cache, closes the node, and schedules its private Keychain state and supporting files for deletion, retrying if cleanup fails. Group configuration and synced preferences are separate; delete the group if you also want to remove them. Local logout does not erase provider or administrator logs or revoke a reusable Auth Key. Manage device removal and key revocation through the control service.
  • Data retained by AI or search providers, Apple, Tailscale or a custom control service, or remote hosts must be managed through those providers. The Termind developer cannot delete data from those services on your behalf.

Termind is not directed to children under 13, and we do not knowingly collect children’s personal information.

13

Changes and contact

If the product’s data practices materially change, we will update the version and effective date on this page and provide notice in the app where appropriate.

For privacy questions, email privacy-termind@akinokaede.com. For product and technical support questions, email support-termind@akinokaede.com. For business inquiries, email termind@akinokaede.com. Do not include passwords, private keys, API keys, complete host addresses, unredacted logs, or other unnecessary sensitive information.