Privacy policy
Last Updated: December 6, 2025
1. Introduction
This Privacy Policy describes how SSH Assistant (“we,” “us,” or “our”) collects, uses, and protects your information when you use our desktop application and website services. We are committed to protecting your privacy and ensuring the security of your personal information.
Key Privacy Principles:
- We collect only the information necessary to provide our services
- Your API credentials and server data remain on your local device
- We do not sell, rent, or share your personal information with third parties for marketing
- You have control over your data and can request deletion at any time
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (required for account creation and communication)
- Name (for account personalization and support)
- Password (encrypted and stored securely)
- Purchase history (for license management and support)
2.2 Payment Information
For software purchases
- Payment processing is handled by Stripe (our payment processor)
- We do not store credit card numbers, CVV codes, or full payment details
- We receive only transaction confirmations and receipt information
- Stripe’s privacy policy governs payment data handling: https://stripe.com/privacy
2.3 Usage Analytics
We collect anonymous usage data through AnalyticsWP plugin:
- Websie performance metrics (loading times, response rates)
- General usage patterns (session duration, feature adoption)
Account-Linked Analytics:
- Purchase attribution (linking purchases to existing accounts for license management)
- User journey tracking (understanding the path from trial to purchase)
What This Means:
- We can identify if someone with an existing account makes a purchase
- This helps us provide proper license management and prevent duplicate accounts
- We analyze how registered users interact with different website features
- All data is used solely for product improvement and customer service
Data Protection:
- Account-linked data is encrypted and access-controlled
- Analytics data is retained for up to 2 years
- You can opt-out of detailed analytics while maintaining basic functionality
- Purchase attribution cannot be disabled as it’s required for license management
No External Sharing:
- Analytics data is never sold or shared with third parties
- Data is used only internally for product development and support
- Aggregated, anonymized insights may be used for general product marketing
2.4 Information We Do NOT Collect
SSH Assistant does not collect:
- Any credentials, passwords, or server login information
- Server hostnames, IP addresses, or connection details
- File contents, directory structures, or server data
- Commands executed on your servers
- Personal files or website content
- Browsing history or other personal activities
- Any other credentials
3. Local Data Storage
3.1 What is Stored Locally
Software stores the following data on your device:
- API credentials and server configurations (encrypted locally)
- Command history (stored locally, never transmitted)
- Application settings and preferences
3.2 No Cloud Synchronization
- Your API credentials and configurations are never synchronized to our services
- Each installation maintains its own local data
- We cannot access or recover your API credentials if lost
4. How We Use Your Information
4.1 Primary Uses
We use collected information to:
- Provide software access through account authentication
- Process payments and manage software licenses
- Deliver customer support and respond to inquiries
- Send important updates about software releases and security patches
- Improve the software based on usage analytics and feedback
4.2 Communication
We may contact you for:
- Account-related communications (password resets, security alerts)
- Software updates and new feature announcements
- Customer support responses and follow-ups
- Payment confirmations and license information
4.3 Legal Requirements
We may use or disclose information when required by law, including:
- Compliance with legal processes or court orders
- Protection of our rights and property
- Investigation of potential violations of our Terms of Service
- Prevention of fraud or security threats
5. Third-Party Services
5.1 Stripe Payment Processing
Purpose: Secure payment processing for software purchases
Data Shared: Name, email, payment amount, transaction details
Privacy Policy: https://stripe.com/privacy
Data Handling: Stripe maintains PCI DSS compliance for payment security
5.2 AnalyticsWP Plugin
Purpose: Understanding software usage patterns for improvements
Data Collected: Usage statistics, feature adoption, error reports
Personal Information: Purchase attribution (linking purchases to existing accounts for license management) and User journey tracking (understanding the path to purchase)
Opt-out: Available through application settings
5.3 YouTube Integration
Purpose: Providing help videos and tutorials
Data Sharing: Only when you choose to watch embedded videos
Privacy Policy: https://policies.google.com/privacy
Control: Videos are embedded only when requested by user
5.4 Google Fonts (Local)
Purpose: Typography and user interface design
Data Sharing: None – fonts are loaded locally from our servers
Privacy: No data is shared with Google as fonts are self-hosted
6. Data Retention
6.1 Account Data
- Account information is retained while your account is active
- Purchase records are kept for tax and legal compliance (typically 7 years)
- Support communications are retained for service improvement
6.2 Analytics Data
- Usage analytics are retained for up to 2 years for trend analysis
- Error reports are kept for 1 year for software improvement
6.3 Data Deletion
- You can request deletion of your data by:
- Deleting your account through the user dashboard
- Contacting our support team with a deletion request
- Using data export tools to download your information first
7. Data Security
7.1 Security Measures
We implement industry-standard security practices:
Encryption in transit using TLS/SSL for all communications
Encrypted password storage using bcrypt hashing
Secure servers with regular security updates and monitoring
Access controls limiting employee access to personal data
Regular security audits and vulnerability assessments
7.2 Local Security
SSH Assistant implements local security measures:
Encrypted credential storage on your device
Secure memory handling for sensitive operations
No credential transmission except direct SSH connections
User-controlled data clearing capabilities
7.3 Incident Response
In case of a security incident:
- Affected users will be notified within 72 hours
- Steps to protect your data will be clearly communicated
- Incidents will be investigated and addressed promptly
- Lessons learned will be applied to prevent future incidents
8. Your Privacy Rights
8.1 Access Rights
You have the right to:
Access your personal data we have collected
Update or correct inaccurate information
Download your data in a portable format
Delete your account and associated data
8.2 Communication Preferences
You can control communications by:
Updating email preferences in your account settings
Unsubscribing from marketing emails (account security emails will continue)
Opting out of usage analytics through application settings
8.3 Regional Privacy Rights
European Union (GDPR):
Right to access, rectify, erase, and port your data
Right to restrict or object to data processing
Right to lodge complaints with supervisory authorities
Legal basis for processing: contract performance and legitimate interests
California (CCPA):
Right to know what personal information is collected
Right to delete personal information
Right to opt-out of sale of personal information (we don’t sell data)
Right to non-discrimination for exercising privacy rights
Other Jurisdictions: We comply with applicable privacy laws in all jurisdictions where we operate.
9. Children’s Privacy
SSH Assistant is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:
- Standard contractual clauses for transfers outside the EU
- Adequacy decisions where available
- Other approved transfer mechanisms as required by applicable law
11. Changes to This Privacy Policy
11.1 Policy Updates
We may update this Privacy Policy to reflect:
Changes in our data practices
New features or services
Legal or regulatory requirements
Industry best practices
11.2 Notification of Changes
When we make material changes:
- Email notification will be sent to account holders
- In-app notifications will alert active users
- Website posting of the updated policy
- Continued use constitutes acceptance of changes
11.3 Previous Versions
Previous versions of this Privacy Policy are available upon request for your reference.
12. Contact Information
For questions about this Privacy Policy or our data practices:
Email: info@ssh-assistant.com
Response Time: We aim to respond within 2 business days
Effective Date: This Privacy Policy is effective as of the date listed at the top of this document.
Contact Us: If you have any questions about this Privacy Policy or our privacy practices, please contact us using the information provided above. We value your privacy and are committed to addressing your concerns promptly and transparently.
Your Consent: By using SSH Assistant and our services, you consent to the collection and use of your information as described in this Privacy Policy.