Privacy notice
Kelrik Terminal is built so that we know as little about you as possible. This page explains what the Kelrik service stores, what it can't read, and how to remove it.
What we store
- Your email address, so you can sign in.
- A hash of your auth key. Your password never leaves your device. The device derives an auth key from it with Argon2id and HKDF, and the server stores only an Argon2 hash of that key.
- Your encrypted vault: hosts, groups, keys, passwords, snippets, tunnels and settings, encrypted on your device with XChaCha20-Poly1305 before upload. We can't decrypt it.
- Signed-in devices: a name such as "Mac" or "Safari", the platform, and when it was last active, so you can see and sign out your devices.
- Subscription state (plan, trial end, renewal date) once paid plans launch, and the payment provider's reference. We never see card numbers.
- Web gateway records: when you use SSH in the web app, the gateway records which host and port you connected to, when, and whether it worked, for abuse prevention. The content of your sessions is not recorded.
Integrations
Integrations are optional. If you use them:
- Destinations (Slack, Teams and Discord webhook URLs, Telegram bot tokens, ntfy topics and tokens, your webhook addresses) are stored encrypted with a server key, because Kelrik needs them to deliver. They are never shown to anyone but you.
- Messages sent to your notify keys pass through Kelrik's server to reach those services, so they aren't end-to-end encrypted. We keep only a delivery log of titles, times and results (your last 200 messages), never the message text.
- Notify keys are stored encrypted, looked up by a keyed hash, and can be replaced or deleted at any time.
- Integration data is deleted with your account. If your Pro access ends and you don't come back, it's removed after 90 days.
What we don't do
- No analytics, trackers or advertising, in the apps or on this site.
- The desktop and mobile apps connect directly to your servers. Those sessions don't pass through Kelrik.
- We don't sell or share your data.
Your browser
This site keeps your session token and vault key in your browser's sessionStorage, which is cleared when you close the tab. It remembers your light or dark choice in localStorage. There are no cookies.
Your password can't be reset
Because your password encrypts your vault, nobody can reset it for you. You can change it while you still know it; the vault key is then re-encrypted on your device. If you forget it, the copies of your vault on your own devices stay usable, but the account can't be recovered.
Deleting your data
Delete your account any time from your account page. Your account, encrypted vault, devices, integrations and subscription records are deleted from the server immediately. Copies on your own devices stay until you remove the app.