outrigger
❯ cat privacy.txt

Where your data goes.

Your data goes to the servers you connect to, and nowhere else, unless you configure the ✦ assist to use your own AI provider. The rest of this page is the detail.

Last updated 12 September 2026 · applies to Outrigger for iPhone, all versions

data flow
your iPhone
keys · hosts · snippets
scrollback · summaries
ssh
your servers
everything you type and everything they answer — traffic we never see
opt-in · your key
your AI provider · opt-in
only the output you ask about, straight to Anthropic, OpenAI, or your own endpoint — off by default
nothing, ever
us
no servers this app talks to · no account · no sync · no analytics SDK

What stays on the device

SSH keys, saved host passwords, and assist API keys are stored on this device only and never enter a backup. Host entries and snippets are stored in the app container under iOS file encryption. Terminal scrollback and ✦ assist summaries are kept in memory only, never written to disk, and are gone when the session ends. How keys are generated and encrypted is covered on the security page.

In its default mode, the ✦ assist runs entirely on device and scrollback is never uploaded anywhere. The opt-in cloud mode is covered below.

What leaves the device

SSH traffic to the hosts you configure, including your public key, as SSH requires. If you switch the ✦ assist to a cloud provider and add your own API key, the terminal output you ask about goes directly from your phone to the provider you chose: Anthropic, OpenAI, or a server of your own. It does not pass through us. The app makes no other network connections; you can verify this with a proxy or a packet capture.

Purchases go through the App Store. Apple handles the payment and tells the app a purchase happened; we never see your name, card, or email, only anonymous aggregate sales counts. There is no per-person data on our side.

Things we are asked about

no No analytics, no crash-reporting SDK, no attribution SDK, no A/B framework. Apple's own system diagnostics follow your iOS privacy settings and go to Apple, not us.
no No cookies on this website. No trackers, no third-party fonts, no embedded video.
no No data broker relationships and no ad networks.
yes iCloud device backup includes your host list and snippets if you have backup enabled; you can exclude the app in Settings. Keys, saved passwords, and API keys never enter any backup.

Deleting your data

Deleting the app destroys hosts, snippets, and settings with its container. Keychain entries can outlive an app deletion, but they remain sealed to this device and this app, unreadable by any other app and unusable without Face ID. To destroy your keys immediately, delete them in Settings › Identity keys before removing the app, and remove the matching public keys from your hosts' authorized_keys. There is no server-side account to close.

Changes and contact

If this policy changes, the change is described in the app's release notes. If a future version needs to talk to a server of ours, it will be opt-in and explained here before it ships.

Questions or corrections: support@outriggerssh.app.

© Paul Miller support@outriggerssh.app home docs privacy security EOF