Data handling, in plain language

Privacy Policy

Termind is a local-first macOS app. We do not operate Termind accounts or a hosted AI service. Data leaves your Mac only when a feature you choose needs Apple, your selected AI or search service, or a server you connect to.

EffectiveAugust 27, 2026Version1.0
01

Overview

We do not sell personal information, show advertising, use cross-app tracking, or include third-party behavioral analytics SDKs in the app. No Termind account is required.

Termind is a client application. When you use AI, search, iCloud, speech, or remote connections, the relevant service provider processes what it receives under its own terms. Termind does not place a hosted proxy between you and those providers.

02

Data stored on your Mac

To provide its features, Termind stores the following information on your Mac:

  • Vault metadata such as host names, addresses, ports, usernames, groups, tags, identity labels, public-key fingerprints, Known Hosts entries, snippets, and port-forwarding rules.
  • Conversations, messages, agent tool calls and results, security-review records, command history, workspace state, and app settings.
  • Context attachments you import and per-conversation scratch files until you delete the related conversation.

This data is not automatically sent to the Termind developer. macOS, local backup tools, or other software you install may access or back up local files according to their own settings.

03

iCloud & Keychain

Vault sync

When “Sync Vault with iCloud” is enabled, hosts, host groups, identity metadata, public-key metadata, Known Hosts entries, snippets, and port-forwarding rules are stored through CloudKit in the private iCloud database for your Apple ID. Apple processes this data; Termind has no separate backend service that reads it.

Passwords and private keys

Passwords, SSH private keys, AI API keys, search API keys, and MCP credentials are stored in Apple’s Data Protection Keychain, not in the Vault database. For passwords and software SSH private keys, you can choose:

  • iCloud: the Keychain item may sync across your devices through iCloud Keychain.
  • This Mac: the item is marked for this device only and does not sync.
  • Secure Enclave: the private key is non-exportable and does not sync to other devices.

AI, Web Search, and MCP credentials are currently stored on this Mac only. Whether iCloud Keychain is enabled, which devices receive synced items, and how Apple protects the data are governed by your Apple ID and system settings.

04

AI providers and MCP

AI features are optional and use a bring-your-own-key model. You may configure OpenAI, Anthropic, Google, or a custom protocol-compatible endpoint. When you use AI, Termind sends the data needed for the request directly to the selected endpoint, which may include:

  • your prompts, conversation history, selected images, and attachments;
  • current session context, such as host and remote-system information and working directory;
  • tool names, arguments, results, and command output or file contents you authorize the agent to read;
  • the API key or access token used to authenticate the request.

Private-key material is not sent to the model as chat context. Termind resolves credentials locally to establish SSH connections. Review the privacy policy, retention controls, and enterprise terms of your selected AI provider. The operator of a custom endpoint is responsible for that endpoint.

If you add a remote MCP server, Termind exchanges requests, tool arguments, and results according to the tools that server exposes. The data shared depends on the server you enable and tools you invoke. Termind’s built-in MCP server listens on the local loopback interface by default; if you change how it is exposed, you are responsible for securing access.

06

SSH, SFTP, web fetches, and remote actions

When you connect to a host, Termind sends the information required to establish the connection to that host and any proxy or jump host you configure. Passwords are used for authentication inside the encrypted SSH session. SSH private keys remain on your Mac and are used to sign locally. Target systems may log IP addresses, usernames, times, commands, file transfers, and other activity according to their own configuration.

When you or the agent fetches a web page, the destination receives the request, generally including your IP address, URL, request headers, and user-agent information. Termind applies local checks and authorization to restricted network destinations, but cannot control the destination’s logging or privacy practices.

07

Speech transcription

Termind captures audio only after you press the transcription button and grant microphone and Speech Recognition permissions. Transcription uses Apple Speech. Depending on your macOS settings, language, and device capabilities, Apple may process audio on-device or on its servers. Termind stops the active recording after completion, cancellation, or failure. Transcribed text enters your chat draft and, if sent, is handled as described in the AI section.

08

This website

This website currently sets no analytics cookies, uses no advertising technology, and contains no contact form. The hosting provider may still process standard server logs—such as IP address, request time, path, and user agent—to deliver the site, prevent abuse, and maintain security, subject to the hosting provider’s policy.

09

Retention, deletion, and your controls

  • You can disable Web Search, Vault iCloud sync, speech permissions, and other optional features.
  • You can delete hosts, credential references, conversations, and other content in the app. When sync is enabled, Vault deletions sync to iCloud.
  • Uninstalling the app may not automatically delete data in Keychain or iCloud. Delete relevant credentials and Vault data in the app before uninstalling, or use Apple’s system settings to manage iCloud and Keychain.
  • Data retained by AI or search providers, Apple, or remote hosts must be managed through those providers. The Termind developer cannot delete data from those services on your behalf.

Termind is not directed to children under 13, and we do not knowingly collect children’s personal information.

10

Changes and contact

If the product’s data practices materially change, we will update the version and effective date on this page and provide notice in the app where appropriate.

For privacy questions, email [email protected]. For product and technical support questions, email [email protected]. For business inquiries, email [email protected]. Do not include passwords, private keys, API keys, complete host addresses, unredacted logs, or other unnecessary sensitive information.