LiveSSH Privacy Policy
Effective date: (set before publication) Last updated: 2026-08-02
Draft for legal review. This describes the implemented product and production architecture, but it is not legal advice and has not been reviewed by counsel. Confirm the Korean PIPA and international-transfer disclosures, store declarations, processor agreements, and effective date before launch.
LiveSSH is published by XIUSoft ("we", "us"). Contact: contact@xiu.kr.
1. Product summary
LiveSSH Local works without an account. It stores SSH-related data on your device and connects directly to servers you choose. LiveSSH Cloud is optional; if you create a Cloud account, it provides end-to-end encrypted synchronization.
We do not run advertising or behavioral analytics. Optional privacy-safe crash reporting is off by default. You may review each report before sending it or explicitly enable automatic reports. We do not receive SSH passwords, private keys, private-key passphrases, terminal contents, command history, local-shell contents, or transferred file contents.
2. Data stored on your device
| Data | Purpose |
|---|---|
| Connection profiles, groups, notes, tags, jump-host settings, and local key paths | Connect to servers without re-entering settings |
| Preferences, trusted SSH host-key fingerprints, and workspace state | Security checks and workspace restoration |
| Local diagnostic logs and pending privacy-safe crash reports, bounded and rotated by the app | Troubleshooting on your device and letting you review or discard a report before sending |
| Remembered passwords or passphrases, only when you request it | Convenient authentication |
| Cloud refresh token, vault key, recovery material, and device identity | Sign-in and end-to-end encrypted synchronization |
Secrets are stored using the operating system's protected store, such as Windows DPAPI, Apple Keychain, or Linux Secret Service. Cloud vault keys are generated on a client device. XIUSoft does not receive the plaintext vault key or recovery key.
Uninstalling LiveSSH may not remove every file or operating-system secret. Use the app's deletion controls or remove its application-data and secret-store entries if you want to erase local data.
3. Data processed by LiveSSH Cloud
Cloud is optional. When you use it, we process:
| Category | Examples and purpose |
|---|---|
| Account | Email address, internal user UUID, confirmation/reset status, password hash, and security timestamps for authentication |
| Encrypted sync | Encrypted profile and portable-preference records, nonces, revisions, deletion markers, and wrapped vault keys |
| Device enrollment | Device name, platform, public encryption key, creation/last-seen time, and revocation state |
| Subscription | RevenueCat/store customer identifier, product and store, entitlement status, transaction or event identifiers, and relevant start/expiry/event timestamps |
| Service security | IP address, request time, route, status, user agent, and server error details in access/security logs |
| Support email | Sender/recipient addresses and the message content you send to us |
| Optional crash diagnostics | A random per-report UUID, occurrence time, app/core version, platform, OS version, locale, exception type (not its message), allow-listed package/Dart stack frames, consent mode, and a server-derived crash fingerprint |
The plaintext fields intentionally excluded from Cloud sync include passwords, private keys, passphrases, local key paths, terminal output, command history, local-shell configuration, and transferred file contents. Connection-profile fields selected for sync are encrypted on your device before upload.
Crash reports never include an account or device identifier, email address, profile, host, username, port, local path, terminal or command content, file content, application log, or raw exception message. Public-proxy access logging is disabled for the crash endpoint, and the source IP is neither forwarded nor stored with a report. Nginx uses it transiently in memory only to enforce a per-IP request limit. Internal service security/error logs remain subject to the general log retention below but do not contain the crash request body.
We process account and encrypted sync data to provide the Cloud service you request; subscription data to provide and administer paid access; security logs for abuse prevention, reliability, and legal security interests; and support messages to answer your request and meet applicable obligations.
4. Network connections and permissions
LiveSSH connects directly to SSH, SFTP, or Telnet servers that you specify. The operator of each server processes that connection under its own policies. Telnet is unencrypted; anything sent over Telnet may be visible in transit.
LiveSSH also connects to livessh.xiu.kr when you use Cloud or choose to send a
crash report, to Apple or Google store services for in-app subscriptions, and
to RevenueCat for subscription management. Platform stores or operating-system
update services may independently check for app updates.
Android uses internet access. Apple platforms may request local-network and file-access capabilities needed for server discovery/connection and user-chosen file operations. Desktop platforms use ordinary network, file, process, and secret-store access needed for SSH and local shell features.
5. Service providers and international transfers
We use the following providers. Data is transferred over encrypted connections when the related feature is used.
| Recipient / location | Data and purpose | Timing and retention |
|---|---|---|
| Oracle Cloud Infrastructure, Japan Central (Osaka) | Hosts our self-managed Supabase authentication, database, Edge Functions, backups, web endpoint, and optional anonymous crash reports | During Cloud use or crash-report submission; retained as described below |
| RevenueCat, Inc. / AWS in the United States | Pseudonymous user UUID and store purchase/subscription data for entitlement management | On purchase, restore, subscription events, and account deletion; customer deletion is requested when the LiveSSH Cloud account is deleted, subject to provider/legal retention |
| Apple App Store / Google Play | Store account, transaction, device/store, and subscription information governed by the applicable store | When you use store billing; retained under the store's terms and legal obligations |
| Google Workspace, potentially in countries where Google and its subprocessors operate | Email address and transactional/support email content | When email is sent; retained only as needed for delivery, support, security, or legal obligations |
RevenueCat states that customer data is stored in AWS data centers in the United States. Its current privacy and data-processing terms are available at revenuecat.com/privacy and revenuecat.com/dpa. Oracle lists Osaka as its Japan Central region at Oracle Cloud Regions.
Payment-card details are entered into and processed by the applicable store or payment provider; XIUSoft does not receive full payment-card details.
6. Retention and deletion
- Account and active Cloud records are kept while the account exists.
- When a trial or subscription ends, synchronization stops. The encrypted vault remains downloadable for 30 days, then the scheduled purge removes it.
- Production database backups are retained for up to 7 days. Data deleted from the live database may remain in a protected backup until that backup expires; it is not restored except for disaster recovery.
- Web access/error logs are rotated daily and retained for up to 14 days, unless a longer period is required to investigate abuse or meet a legal obligation.
- Submitted anonymous crash reports are retained for no longer than 30 days. Pending reports remain only on your device until sent or discarded; the app bounds the queue and does not upload them unless you choose reviewed or automatic submission.
- Support correspondence and legally required transaction/tax records are kept only as long as reasonably necessary for the request or applicable law.
You can permanently delete your LiveSSH Cloud account in the app or at
https://livessh.xiu.kr/account/delete.
This removes the account and associated live Cloud data and requests deletion of
the linked RevenueCat customer when that integration is configured. Deleting an
account does not cancel an Apple App Store or Google Play subscription; cancel
store billing separately to prevent future charges. Account deletion does not
delete local profiles on your devices.
7. Security
We use TLS in transit, row-level database authorization, server-side entitlement enforcement, least-privilege service credentials, encrypted backups, and client-side authenticated encryption for synchronized profile data. No system is completely secure. Keep your recovery key in a trusted password manager; we cannot recover it for you.
8. Your choices and rights
You may use Local without a Cloud account, decline to sync, export/restore Cloud data during the permitted period, keep automatic crash reporting disabled, review or discard pending reports, correct your account email through available account controls or support, and delete the Cloud account. Submitted reports are intentionally not linked to an account, so we cannot locate one by account or email; the server deletes them automatically after 30 days. Depending on your location, you may also request access, correction, portability, restriction, or information about processing. Contact contact@xiu.kr. We may need to verify your identity before completing a request.
9. Children
LiveSSH is a developer tool and is not directed to children under 14. Do not create a Cloud account if applicable law requires parental consent that has not been obtained.
10. Changes
We will update this policy before materially changing data practices. Material changes will be identified in the app, release notes, website, or account email as appropriate. The date above identifies the latest revision.
11. Contact
XIUSoft — contact@xiu.kr