Privacy Policy
At VANTA//SSH, we believe that your server infrastructure, credentials, and command history are strictly your business. Our application is built from the ground up on a "local-only, zero-cloud" philosophy.
1. Data Collection & Analytics
We collect absolutely nothing.
VANTA//SSH does not include any telemetry, analytics, crash reporting SDKs, or tracking code. We do not know when you open the app, how you use it, or what errors you encounter.
2. Cloud Synchronization
There is no cloud sync.
Your data never leaves your device. All host configurations, SSH keys (generated or imported), known hosts, port forwards, VPN tunnel profiles, and snippets are stored securely in local Android storage (Room Database and DataStore). We do not operate any servers to sync your data.
The optional backup feature exports your vault to a single passphrase-encrypted file (AES-256-GCM) that you move yourself over any offline transport you choose. We never see it, and hardware-backed keys sealed in the Android Keystore are intentionally never exported.
3. SSH Keys & Credentials
Your cryptographic keys and passwords are handled entirely on-device:
- Keys are generated locally using device APIs.
- Passphrase encryption occurs locally.
- Authentication data is only transmitted directly to the remote servers you explicitly connect to via standard SSH protocols.
4. Network Access & Foreground Services
The application requests network permissions solely to establish SSH and SFTP connections to the hosts you configure. To ensure these connections are not interrupted when the application is in the background, VANTA//SSH utilizes a Foreground Service (Data Sync). This service is active only during an open session and is clearly indicated to the user via a persistent notification.
5. VPN Tunnels (WireGuard & IKEv2/IPsec)
VANTA//SSH can establish a WireGuard or IKEv2/IPsec VPN tunnel using Android's system VPN service. Tunnels are built entirely from the profiles you enter on-device and connect directly to the VPN endpoints you specify. We do not operate any VPN servers, and no traffic is ever routed through us. A tunnel is active only while you turn it on, and Android displays its standard VPN indicator whenever it is running.
6. App Lock & Biometrics
You can optionally lock VANTA//SSH behind your device biometrics (fingerprint or face) or screen credential. This uses Android's system BiometricPrompt: your biometric data is held and verified entirely by the operating system's secure hardware and is never read by, shared with, or accessible to the app. VANTA//SSH only receives a yes/no result confirming that the system authenticated you.
7. Storage Permissions
VANTA//SSH utilizes the Android Storage Access Framework (SAF) for SFTP downloads and key imports. This means the app only has access to the specific files and directories you manually select through the system picker. We do not request broad file storage permissions.
8. Data Retention & Deletion
Since all data is stored locally on your device and not on our servers, we do not retain any of your personal information. You can delete all application data at any time by uninstalling the application or clearing the application cache/data in your Android System Settings.
9. Contact Information
For any questions regarding this Privacy Policy or our data practices, you may contact us at: JbTecWiz@outlook.com
10. Changes to this Policy
Because we do not collect user data or email addresses, we cannot notify you of policy changes. However, our core philosophy of "zero cloud" is immutable. Any updates to this policy will be reflected on this page.