Skip to content
Termoak
FeaturesPricingDownloads
Sign inCreate a free accountCreate account
FeaturesPricingDownloads
Sign inCreate a free account
Terms of UsePrivacy PolicyLegal notice

Privacy Policy

Version 1.0 · In effect since October 4, 2026

This policy explains what personal data Termoak processes, why, with whom it is shared and what rights you have. In short: we only use your data to provide the service, we do not sell it, and there is no advertising or tracking on Termoak.

1. Who is responsible for your data

The controller is Ohz Digital SL ("Ohz", "we"), tax ID (CIF) B56646771, García Salazar 2, 48003 Bilbao, Bizkaia, Spain. For anything about privacy or to exercise your rights, write to legal@termoak.com.

2. What this policy covers

It covers the website termoak.com, your Termoak account and the Termoak server that we run there, which the apps connect to when you sign in with that account. It does not cover:

  • the apps used without an account: your data then stays on your device and we do not receive it;
  • Termoak servers run by other people or companies (self-hosted): whoever runs them is responsible for the data on them;
  • the servers you connect to over SSH, nor the AI providers you use with your own API key, which have their own policies.

3. What data we process and why

Your account

  • Your email address, your name, your preferred language (used for emails and notifications), your plan and the date you created the account.
  • Your password, which we never store as such: we only keep an Argon2id hash of it.
  • If you turn on two-step verification, its secret (encrypted with the server's key) and your recovery codes (we only keep a hash of each).
  • That you accepted these terms and this policy, with their version and the date.

Your devices

  • For each device you sign in on: its name, its platform (for example, "Android" or "web"), when it signed in and when it was last used. The session tokens are only stored as hashes.
  • If you turn on notifications on a phone, its push token from Apple or Google.

What you sync

Your hosts, groups, identities, SSH keys, snippets, port forwards, known hosts and AI memories, so that you have them on all your devices.

  • Their secrets (passwords, private keys and passphrases) are stored encrypted with XChaCha20-Poly1305, with a master key that is kept on our server. They travel between your devices and the server inside an encrypted (TLS) connection.
  • This is not end-to-end encryption: our server can decrypt these secrets, and needs to in order to open the sessions on the server that you ask for and to run the AI tools on your hosts. The rest of the data (for example, the address and the user name of a host) is stored without that extra encryption.
  • Anything you mark as "This device only" never leaves your device: it is not synced and our server never sees it.
  • Revealing a secret through the API is recorded in the activity log.

Sessions on the server

  • When you open a session on the server, the SSH connection to your host runs on our server, so what you type and what the terminal shows go through it. While the session is open, we keep its recent output (scrollback) in memory so you can reconnect from any device.
  • We keep a record of each session: the host, its title, its status, when it started and ended and the error if it failed; and of who you shared it with, with what permission and until when.
  • Recordings are off by default. If you record a session, we store its output, and only if recording of keyboard input is turned on, also what is typed (it is off on termoak.com, because it can contain passwords).

Teams

The teams you create or belong to: their name, their members and roles, and the invitations (with the email address of the person invited).

AI

  • Your AI tasks: what you ask, the conversation, the actions of the AI and their results (which may include the output of your terminal and the contents of the files it reads on your hosts) and your approvals. You can delete each task.
  • A usage record for each request: the provider, the tokens used, the cost and whether it used your own key.
  • Your own API keys, encrypted with the server's key. They are never shown again, only their last 4 characters.

Activity log and security

  • An activity (audit) log of your account: sign-ins (with the IP address, the device and the platform), the creation of the account, the sessions you open and share, the commands run by the AI, the secrets revealed and changes to your security settings.
  • To block attempts to guess passwords, we count failed sign-ins per email address and per IP address, in memory, for 10 minutes.

Emails

We send you the emails the service needs: confirming your address, resetting your password, changing your email and invitations. We do not send you advertising.

When you write to us

If you write to us, we use your message and your email address to answer you.

4. Why we are allowed to (legal bases)

  • To provide the service you asked for (contract): your account, devices, sync, sessions, teams, AI, notifications and the emails of the service. Some of these features (notifications, recordings, AI, sharing) are only used when you turn them on.
  • Our legitimate interest in keeping the service and its users secure and preventing abuse: the activity log with IP addresses, the limits on failed sign-ins and the investigation of abuse. You can object to it (see section 8).
  • Legal obligations: for example, keeping the invoices of paid plans for the time tax law requires, or answering requests from the authorities made in accordance with the law.

5. Who we share it with

We do not sell your data or give it to anyone for advertising. We only use these providers, and only for what is described:

  • Hosting: the service runs on servers operated by Ohz in Spain (EU).
  • Brevo (EU) sends our emails: it receives your email address and the content of the email.
  • OpenAI provides Termoak AI (the AI credit of the Pro plan, when available, through Codex): it receives your requests and the terminal context the AI needs. This involves a transfer to the United States (see section 6).
  • The AI provider you choose: if you add your own API key (Anthropic, OpenAI, OpenRouter or OpenCode), your server AI requests, with the context they need, are sent to that provider on your instructions, under its terms and its privacy policy. In the desktop app's "This computer" mode, nothing goes through our servers.
  • Apple and Google, if you turn on notifications on a phone: they deliver them with the push token. By default the text of the notifications is generic and does not include commands or titles.
  • GitHub hosts the open-source code of Termoak and the files of its releases. If you visit our repositories on GitHub, GitHub's privacy policy applies.
  • The people you share with: when you share a session or join a team, the other people see your name and email and what you share with them.
  • Authorities, only when the law requires us to.

6. Transfers outside the EU

We keep your data in the EU. It only leaves it in these cases:

  • Termoak AI, with OpenAI in the United States: covered by the EU-US Data Privacy Framework and, where applicable, the standard contractual clauses of the European Commission.
  • The AI provider you choose with your own key, and Apple or Google for notifications, when they process data outside the EU: this happens because you use those services, under their terms.

7. How long we keep it

  • Your account data, what you sync, your sessions, recordings, teams, AI tasks and activity log: while your account exists. You can delete AI tasks, synced items and API keys yourself at any time.
  • When you delete your account (in your account settings: Account → Danger zone), we delete your synced data, your sessions and their history, your recordings, your AI tasks and usage, your API keys, your activity log and the teams where you were the only member. Your open sessions are closed.
  • Session tokens expire: the access token after 60 minutes and the refresh token after 90 days without use. Email links expire after 48 hours (confirming your address) or 1 hour (resetting your password).
  • Failed sign-in counters: 10 minutes, in memory.
  • Data that we must keep by law (for example, invoices of paid plans): for the period the law requires.

8. Your rights

You have the right to access your data, rectify it, erase it, restrict its processing, take it with you (portability) and object to processing based on our legitimate interest. Many things you can do yourself in the app (change your name or email, delete data or delete the account). For anything else, write to legal@termoak.com, preferably from the email address of your account so that we can check that it is you. We will answer within one month.

If you think we have not handled your data properly, you can file a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es. We would appreciate it if you told us first, so we can try to fix it.

9. Security

Connections are encrypted (TLS); passwords are stored as Argon2id hashes; secrets are encrypted at rest; tokens and codes are stored as hashes; you can use two-step verification; sign-in attempts are limited; and the website only loads code from our own server. The code is open source, so anyone can check how all this works.

10. No cookies, no tracking

The termoak.com website does not use cookies, analytics or advertising, and does not load anything from third parties. It only stores in your browser's local storage what it needs to work: your session (so that you stay signed in), your language and your theme (light or dark). This storage is strictly necessary for the service you ask for, so it does not need your consent and there is no cookie banner. It is deleted when you sign out (the session) or when you clear your browser's data.

11. Minimum age

Termoak is not intended for people under 16, who may not create an account.

12. Changes to this policy

If we change this policy, we will publish the new version here with its date and, if the changes are important, we will tell you in advance by email or on the website.

Termoak

The SSH client whose sessions never drop, for you and your team.

Product

  • Features
  • Pricing
  • Downloads

Account

  • Sign in
  • Create account
  • Recover password

Support

  • Support is disabled for now.

Legal

  • Terms of Use
  • Privacy Policy
  • Legal notice
© 2026 Ohz Digital SL · version 0.2.3 · Source code on GitHub