Privacy at AFK

Privacy
Policy.

This policy explains how Thaker Innovations Pvt. Ltd. handles information through the AFK applications for iOS and Android, the optional AFK AI command service, and the AFK website.

Effective
July 28, 2026
Contact
afk@thakerinnovations.com
01

Direct SSH stays direct.

Ordinary SSH credentials, terminal input, and terminal output do not pass through AFK infrastructure.

02

Secrets stay local.

Saved passwords and private keys use platform-protected storage on your device.

03

AI is explicit and optional.

Only a prompt you choose to submit is sent to the AFK AI service and its model provider.

01 / Scope

Who this policy covers

Thaker Innovations Pvt. Ltd. (“Thaker Innovations,” “we,” “us,” or “our”) develops AFK. This policy covers the AFK mobile applications, the optional AFK-operated AI command service, and getafk.dev.

It does not govern infrastructure you configure AFK to reach, including SSH servers, jump hosts, HTTP proxies, or other services controlled by you or a third party. Their operators determine how information on those systems is handled.

02 / Data AFK handles

On your device and on systems you choose

Saved connection and application data

AFK stores information needed to provide its features in the application’s private storage. Depending on what you use, this can include host labels, hostnames or IP addresses, usernames, ports, proxy and jump-host configuration, known-host fingerprints, recent-connection and recoverable-session metadata, snippets, appearance and keyboard settings, and security preferences.

Passwords, private keys, passphrases, and proxy credentials are stored using Apple Keychain on iOS or Keystore-backed encrypted storage on Android. AFK may use Face ID, Touch ID, or Android biometrics to control local access when you enable a related feature. AFK receives the success or failure of that device authentication—not your biometric data.

Direct SSH and related connections

When you connect, AFK sends connection details, authentication material, terminal input, and terminal output directly between your device and the SSH server, proxy, or jump host you configured. AFK does not operate an SSH relay and does not receive that traffic through ordinary SSH use.

Clipboard content and imported files are accessed only when you invoke the relevant paste, copy, or document-picker action. AFK processes them on the device or sends them to the destination you direct; they are not automatically uploaded to AFK.

Optional AFK-CLI

If you enable recoverable sessions, AFK communicates with the independently published AFK-CLI on your configured server through the same verified SSH connection. Remote process state, PTY data, and recent-output buffers remain on that server and travel over direct SSH when you attach. AFK infrastructure does not host or relay those sessions.

If you ask AFK to install or update AFK-CLI, the app downloads the supported release artifact from GitHub, verifies its expected size and SHA-256 digest, keeps the verified artifact in app-private storage, and transfers it to your server over SSH. GitHub may receive standard network request information for that download.

03 / Optional AI

Data sent when you request a command

Where available, AFK’s AI command feature is optional. Nothing is sent merely because you opened a terminal or typed into the shell. When you explicitly submit an AI prompt, AFK sends the following over HTTPS:

  • the prompt you entered;
  • a random installation identifier used for quota management;
  • a random request identifier used to safely correlate and retry that request; and
  • the generated command and quota result returned to your device.

AWS infrastructure also processes standard network and request metadata, such as the source IP address, timestamp, request path, and response status, to deliver and protect the optional AI service.

AFK does not automatically attach terminal history, terminal output, SSH credentials, host configuration, or clipboard content to an AI request. Do not place secrets or sensitive personal information in a prompt. If you choose to include such information, it will be processed as part of that request.

The AFK service sends the prompt and request identifier to OpenAI to generate the command. The provider request disables provider-side response storage where supported, but OpenAI may independently process request data under its applicable terms and privacy policy. Generated commands are returned for review and are not automatically executed.

The installation identifier is generated randomly and stored in non-synchronizing Keychain storage on iOS or an encrypted no-backup file protected by Android Keystore. AFK converts it to a keyed pseudonymous value before persistent quota storage. It is not an advertising identifier and is not linked to an AFK user account.

04 / Diagnostics

Local by default; shared by you

AFK keeps bounded diagnostic records in private application storage to troubleshoot rendering and connection lifecycle issues. iOS records app version, operating-system version, general device model, screen geometry, renderer events, and payload-free SSH event identifiers. Android records timestamped, payload-free SSH event identifiers.

These diagnostic logs are designed to exclude terminal bytes, commands, hostnames, credentials, and key material. On Android, the log is limited to 10 MB and entries older than three days are pruned. On iOS, the current log rotates at approximately 10 MB, one previous log may be retained, and files whose last modification was more than three days ago are removed. An active iOS log can therefore contain individual events older than three days until it rotates. AFK does not automatically upload diagnostics. A diagnostic file leaves your device only when you choose Export diagnostics and then choose a destination in the operating system’s share sheet. Review it before sharing.

05 / Sharing and providers

When information leaves your device

We do not sell personal information. AFK contains no advertising SDK and does not use data for cross-app tracking or targeted advertising.

RecipientPurpose and data
Infrastructure you configureSSH servers, jump hosts, and proxies receive the connection and terminal data needed to perform the connection you requested.
Amazon Web ServicesHosts the optional AI service, pseudonymous quota counters, security controls, and operational logs, and processes standard network and request metadata for delivery and abuse prevention.
OpenAIProcesses prompts and request identifiers submitted through the optional AI command feature to generate a command.
GitHubHosts AFK-CLI release artifacts. AFK contacts GitHub only when it needs to download a supported artifact for an install or update you requested.
CloudflareProvides website hosting, DNS, delivery, and security and may process standard request data such as IP address, browser information, requested URL, and timestamp.
Apple and GoogleDistribute AFK and provide operating-system services. Their handling of store, device, and payment information is governed by their policies.

We may also disclose information when reasonably necessary to comply with law, protect users or our services, investigate abuse, or complete a corporate transaction with appropriate notice and protections. Service providers are required to handle data for the stated purpose and with protections consistent with this policy and applicable law.

Website data

We do not place advertising or analytics cookies on the AFK website. Cloudflare may process standard network and security information needed to deliver and protect the site.

06 / Retention and deletion

How long data is kept

  • Local AFK data: kept until you delete the relevant host, credential, record, or app data. The operating system normally removes sandboxed app files when AFK is uninstalled; secure-storage items may persist according to Apple or Google platform behavior.
  • Local diagnostics: Android prunes entries older than three days and caps its log at 10 MB. iOS rotates each log at approximately 10 MB, keeps at most one previous log, and removes files that have not been modified for more than three days; an active file may contain older individual events.
  • AI retry cache: a keyed request token and the generated outcome may remain in process memory for up to five minutes to coalesce retries.
  • AI quota counters: pseudonymous monthly keys and call counts are scheduled for automatic deletion 90 days after the applicable quota month closes.
  • AI operational logs: request identifiers, status, and redacted error information may be retained for up to 30 days. Prompts and generated commands are not written to AFK application logs.
  • Support messages: information you voluntarily send is kept only as long as reasonably needed to respond, maintain support records, protect the service, or meet legal obligations.

AFK does not currently provide end-user accounts, so there is no AFK account to delete. To request deletion of information you submitted to us or information associated with the optional AI service, email the privacy contact below. We may need information from your device, such as the installation identifier, to locate a pseudonymous record, and some records may be retained where required for security or legal compliance.

07 / Your choices and rights

You control when data is used

  • Use ordinary SSH without using the optional AI service.
  • Do not submit an AI prompt, or cancel before submitting it.
  • Disable AFK-CLI per host and remove it from infrastructure you control.
  • Delete saved hosts, credentials, known-host records, and other app data using AFK’s controls.
  • Decline to export or share diagnostic files.
  • Control biometric access, clipboard, background activity, and other platform capabilities through AFK and operating-system settings where available.

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of personal information, or to receive a portable copy. Contact us to make a request. We may verify the request and may decline or limit it where permitted by law. You may also complain to your local data-protection authority.

08 / Security

How AFK protects information

AFK uses platform secure storage for secrets, app-private storage for non-secret data, host-key verification for SSH connections, HTTPS for the optional AI service, keyed pseudonymization for quota identifiers, encryption at rest for backend quota storage, access controls, request limits, and short retention periods. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

09 / Children

Not directed to children

AFK is a professional SSH tool and is not directed to children under 13 or the minimum age required by local law. We do not knowingly collect personal information from a child without legally required consent. If you believe a child provided information to us, contact us so we can investigate and delete it where required.

10 / Changes and contact

Questions or requests

We may update this policy when AFK’s features, providers, or legal obligations change. We will post the revised policy at this URL and update the effective date. If a change materially affects how we handle information, we will provide additional notice where required.

Thaker Innovations Pvt. Ltd.
Privacy contact: afk@thakerinnovations.com
Product: AFK for iOS and Android
Website: getafk.dev