Privacy Policy
We built SSHush for people who care about what's running on their servers. It follows that we should be straight with you about what we collect and why.
Last updated: April 2026
// what we collect
SSHush collects the minimum necessary to provide the service.
- Your iCloud identity. SSHush uses your iCloud account as your identity - there are no separate user accounts. When you enable alerts, your CloudKit user record ID is sent to our backend as a stable identifier. We never see your Apple ID or email address.
- Your server details. When you enable alerts, your server's host, port, and username are sent to our backend so we can poll it. Your SSH credentials are never sent to us - they stay in your device's Keychain.
- A monitoring SSH key. When you enable alerts, SSHush generates a dedicated ed25519 keypair. The private key is stored encrypted in our database and used only to poll your server for metrics. It has no shell access - it is locked to a single read-only command.
- Your APNs device token. Required to deliver push notifications to your device. We store this against your iCloud identity and use it for nothing else.
- Alert history. Records of alerts that have fired and cleared, stored for 30 days then automatically deleted.
// what we don't collect
- Your SSH password or private key - these never leave your device
- Your Apple ID or email address
- Your name or any other personal details
- Analytics, tracking, or advertising data of any kind
- Your server's metrics data - we poll it, evaluate it against your rules, and discard it
// where your data is stored
Server records sync via Apple's CloudKit infrastructure. Alert rules and notification history are stored in a multi-region database hosted by CockroachDB, with nodes in the United States, the Netherlands, and Singapore.
Our monitoring backend runs on DigitalOcean droplets in the same three regions.
// third parties
We use the following third-party services:
- Apple CloudKit - server record sync and user identity
- Apple Push Notification service (APNs) - push notification delivery
- CockroachDB - database hosting
- DigitalOcean - compute infrastructure
- Cloudflare - DNS and website delivery
We do not sell your data to anyone. We do not share it with anyone beyond the services listed above, and only to the extent necessary to operate SSHush.
// deleting your data
Delete a server in the app and its alert rules and history are deleted from our backend immediately. Delete all servers and there is nothing left on our side.
If you want confirmation or have a specific request, contact us and we will sort it out.
// contact
Questions about privacy? Get in touch. We're two people - you'll get a real answer.