Direct SSH stays direct.
Ordinary SSH credentials, terminal input, and terminal output do not pass through AFK infrastructure.
Privacy at AFK
Ordinary SSH credentials, terminal input, and terminal output do not pass through AFK infrastructure.
Saved passwords and private keys use platform-protected storage on your device.
Only a prompt you choose to submit is sent to the AFK AI service and its model provider.
01 / Scope
Thaker Innovations Pvt. Ltd. (“Thaker Innovations,” “we,” “us,” or “our”) develops AFK. This policy covers the AFK mobile applications, the optional AFK-operated AI command service, and getafk.dev.
It does not govern infrastructure you configure AFK to reach, including SSH servers, jump hosts, HTTP proxies, or other services controlled by you or a third party. Their operators determine how information on those systems is handled.
02 / Data AFK handles
AFK stores information needed to provide its features in the application’s private storage. Depending on what you use, this can include host labels, hostnames or IP addresses, usernames, ports, proxy and jump-host configuration, known-host fingerprints, recent-connection and recoverable-session metadata, snippets, appearance and keyboard settings, and security preferences.
Passwords, private keys, passphrases, and proxy credentials are stored using Apple Keychain on iOS or Keystore-backed encrypted storage on Android. AFK may use Face ID, Touch ID, or Android biometrics to control local access when you enable a related feature. AFK receives the success or failure of that device authentication—not your biometric data.
When you connect, AFK sends connection details, authentication material, terminal input, and terminal output directly between your device and the SSH server, proxy, or jump host you configured. AFK does not operate an SSH relay and does not receive that traffic through ordinary SSH use.
Clipboard content and imported files are accessed only when you invoke the relevant paste, copy, or document-picker action. AFK processes them on the device or sends them to the destination you direct; they are not automatically uploaded to AFK.
If you enable recoverable sessions, AFK communicates with the independently published AFK-CLI on your configured server through the same verified SSH connection. Remote process state, PTY data, and recent-output buffers remain on that server and travel over direct SSH when you attach. AFK infrastructure does not host or relay those sessions.
If you ask AFK to install or update AFK-CLI, the app downloads the supported release artifact from GitHub, verifies its expected size and SHA-256 digest, keeps the verified artifact in app-private storage, and transfers it to your server over SSH. GitHub may receive standard network request information for that download.
03 / Optional AI
Where available, AFK’s AI command feature is optional. Nothing is sent merely because you opened a terminal or typed into the shell. When you explicitly submit an AI prompt, AFK sends the following over HTTPS:
AWS infrastructure also processes standard network and request metadata, such as the source IP address, timestamp, request path, and response status, to deliver and protect the optional AI service.
AFK does not automatically attach terminal history, terminal output, SSH credentials, host configuration, or clipboard content to an AI request. Do not place secrets or sensitive personal information in a prompt. If you choose to include such information, it will be processed as part of that request.
The AFK service sends the prompt and request identifier to OpenAI to generate the command. The provider request disables provider-side response storage where supported, but OpenAI may independently process request data under its applicable terms and privacy policy. Generated commands are returned for review and are not automatically executed.
The installation identifier is generated randomly and stored in non-synchronizing Keychain storage on iOS or an encrypted no-backup file protected by Android Keystore. AFK converts it to a keyed pseudonymous value before persistent quota storage. It is not an advertising identifier and is not linked to an AFK user account.
04 / Diagnostics
AFK keeps bounded diagnostic records in private application storage to troubleshoot rendering and connection lifecycle issues. iOS records app version, operating-system version, general device model, screen geometry, renderer events, and payload-free SSH event identifiers. Android records timestamped, payload-free SSH event identifiers.
These diagnostic logs are designed to exclude terminal bytes, commands, hostnames, credentials, and key material. On Android, the log is limited to 10 MB and entries older than three days are pruned. On iOS, the current log rotates at approximately 10 MB, one previous log may be retained, and files whose last modification was more than three days ago are removed. An active iOS log can therefore contain individual events older than three days until it rotates. AFK does not automatically upload diagnostics. A diagnostic file leaves your device only when you choose Export diagnostics and then choose a destination in the operating system’s share sheet. Review it before sharing.
06 / Retention and deletion
AFK does not currently provide end-user accounts, so there is no AFK account to delete. To request deletion of information you submitted to us or information associated with the optional AI service, email the privacy contact below. We may need information from your device, such as the installation identifier, to locate a pseudonymous record, and some records may be retained where required for security or legal compliance.
07 / Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of personal information, or to receive a portable copy. Contact us to make a request. We may verify the request and may decline or limit it where permitted by law. You may also complain to your local data-protection authority.
08 / Security
AFK uses platform secure storage for secrets, app-private storage for non-secret data, host-key verification for SSH connections, HTTPS for the optional AI service, keyed pseudonymization for quota identifiers, encryption at rest for backend quota storage, access controls, request limits, and short retention periods. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
09 / Children
AFK is a professional SSH tool and is not directed to children under 13 or the minimum age required by local law. We do not knowingly collect personal information from a child without legally required consent. If you believe a child provided information to us, contact us so we can investigate and delete it where required.
10 / Changes and contact
We may update this policy when AFK’s features, providers, or legal obligations change. We will post the revised policy at this URL and update the effective date. If a change materially affects how we handle information, we will provide additional notice where required.
Thaker Innovations Pvt. Ltd.