Firebrik Terminal ("the app") is an SSH terminal for your own Herdr session. This policy explains what the app does with information. In short: the developer receives nothing. The app talks to the servers you configure and, only if you sign in with Google to sync your server list, to your own Google Drive.
What the app stores on your device
- Saved servers: the name, host, port, username and start-up command you enter for each server, whether it connects when the app opens, when you last edited it, and when you deleted servers (so a deletion is not undone by syncing).
- SSH key: a key pair created in the Android KeyStore. The private key cannot be exported from the device's secure hardware.
- Pinned host keys: the SSH host key of each server you connected to, used to detect a changed server.
- Google account: if you sign in to sync, the email address of the account you chose, to show it and to ask Google for access to the synced copy, and that account's profile picture (its address, and a copy of the image so it shows offline), shown on the account card. The picture is downloaded from Google and never sent anywhere; signing out deletes it.
- Preferences: theme, terminal colours and text size.
This data stays on the device unless you sign in to sync (below). It is excluded from Android cloud
backups and device-to-device transfers, and it is deleted when you uninstall the app. Deleting a
server in the app removes its saved details; its pinned host key stays (other saved servers may use
the same host) until you use Forget pinned host key or uninstall the app. Two small markers are
kept so that syncing cannot undo what you did: for each deleted server, its internal id and when it
was deleted; for each forgotten host key, the server's address (host:port) and when it was
forgotten.
Optional: syncing your servers with your Google account
Signing in is optional; the app works fully without it. If you tap Sign in with Google, you
choose a Google account and allow the app to use its own hidden app-data folder in that account's
Google Drive (the drive.appdata permission: the app cannot see or change any of your other files).
- What is synced: your saved servers (name, host, port, username, start-up command, connect when the app opens, edit times), the pinned host keys (the servers' public keys) and the markers above (deleted server ids and forgotten host addresses, with their times). They are kept as one file in that hidden folder, so every device signed in to the same account shows the same servers.
- What is never synced: your SSH private key (it cannot leave the device), any password, and your preferences. Each device has its own key; the first time a device connects to a server that does not know it yet, the app offers to add that device's key.
- Who can read it: the file is stored by Google in your Google account, under Google's privacy policy and terms. It travels encrypted (HTTPS) between your device and Google. The developer has no server and no access to your Google account or to the file.
- Deleting it: Servers → Delete synced data deletes the file from your Drive and withdraws the app's access to your account; servers stay saved on each device. You can also remove the app's access at myaccount.google.com/permissions and its hidden data in Google Drive under Settings → Manage apps.
- Signing out on a device stops syncing there; its servers stay on it.
What the app sends, and to whom
- The app opens an encrypted SSH connection only to a server you configure, one server at a time: the one you choose in the app. Over it, it shows your terminal, reads your Herdr session's state (workspaces, tabs, panes, agent status and recent pane text) and sends the keys, answers and prompts you type or tap.
- If you use Install key or Add key, your SSH password is sent once, over SSH, to that same
server to add the device's public key to
~/.ssh/authorized_keys. The password is not stored. - If you signed in to sync, the synced file goes to and from your Google Drive over HTTPS, as above.
- Nothing is sent to the developer. The app contains no analytics, advertising, crash-reporting or tracking code.
Voice input
If you tap the microphone in the prompt composer, Android's speech-recognition service on your device (for example Google's) turns your speech into text and returns it to the app. That service's own privacy policy applies to the audio. The app receives only the resulting text, which it sends to the connected server only when you tap Send.
Notifications
Notifications about agents waiting for you show the agent's name, the workspace and the last lines of that agent's screen. They are created on the device from data received from the connected server. You can turn them off in Android's notification settings.
Permissions
| Permission | Why |
|---|---|
| Internet, network state | Connect to your SSH servers, reconnect when the network changes and, if you signed in, sync with your Google Drive. |
| Notifications | Tell you when an agent is waiting or finished. |
| Foreground service (connected device) | Keep the SSH connection to the server you chose open while the app is in the background, so notifications keep working. |
Children
The app is a developer tool and is not directed at children.
Changes
If this policy changes, the new version will be published at the same address with a new effective date.