Privacy Policy
Last updated: 1 October 2026
This Privacy Policy explains how the publisher of Herdcats (“we,” “us,” or “Publisher”) handles information in connection with the Herdcats iPhone app, related websites (including herdcats.dev), and associated documentation or demos (together, the “Service”).
Contact: hello@enchantinglabs.com.
Herdcats is designed so that your SSH sessions, source code, terminal output, and agent activity stay between your iPhone and machines you control. We do not operate a relay, backend, or cloud daemon for those sessions.
1. Summary
- No analytics SDKs, advertising trackers, or usage telemetry from us
- SSH traffic goes to your host (or a network path you choose, such as Tailscale)
- Credentials and host-key pins you save live in the on-device iOS Keychain
- Optional drafts and command history can be stored locally on your device
- Optional dictation uses Apple’s Speech frameworks (and may involve Apple)
- Optional photo attachments are sent to your remote machine over SSH
- App Store purchases are processed by Apple
2. Information We Do Not Collect
We do not run analytics, crash-reporting, advertising, or telemetry SDKs in the app. We do not receive your SSH passwords, private keys, pane output, source code, worktrees, or agent transcripts on our servers, because those servers are not in the path of your SSH connection.
If you contact us by email, we receive whatever you choose to include in that message so we can respond.
3. Information on Your Device
Depending on how you use the app, the following may be stored locally on your iPhone:
- Credentials. Passwords or unencrypted OpenSSH ed25519 private keys you choose to remember, stored in the iOS Keychain with device-only protection (WhenUnlockedThisDeviceOnly). They are sent only to hosts you connect to, during SSH authentication.
- Connection profile. Recent connection details (such as host, port, and username) and approved SSH host-key fingerprints, stored in Keychain and checked on later connects, including automatic reconnect.
- App preferences. Settings such as onboarding state and Pane Data & Privacy choices (for example whether to preserve drafts and command history), typically via ordinary app preferences / UserDefaults.
- Drafts and history. When Preserve Drafts and Command History is enabled (default), unsent drafts and sent-message history keyed by connection and pane may be stored locally. Turning the setting off or clearing saved data erases that local material; it does not clear remote panes.
- In-session UI state. Temporary in-memory state needed to run the app (for example connection phase, queues, or debug latency samples in non-production builds). Debug diagnostics are not present in production builds and do not record keystrokes, output, or credentials.
4. SSH, Your Machine & Agents
When you connect, the app opens an encrypted SSH session (using the Citadel library) to a host you specify. Pane output, diffs, agent activity, and commands you send travel on that session. We do not host or store that content.
If you use a VPN or mesh network you choose (for example Tailscale), that provider may carry encrypted traffic under its own terms. Keep SSH off the public internet where appropriate; Tailscale is the recommended way to reach your machine.
Photo attachments you select are processed on device (including downscaling and stripping EXIF where implemented) and uploaded over SSH to a cache path on your remote machine (for example under ~/.cache/herdcats/attachments). The app does not automatically delete those remote files.
5. Microphone & Dictation
Optional Voice / dictation uses the microphone and Apple’s Speech frameworks. The app requests microphone and speech-recognition permission when you use that feature. Recognized text can be placed into an editable Compose draft for your review; it is not auto-sent.
Speech recognition is provided by Apple. Depending on your device settings and Apple’s systems, audio or transcripts may be processed by Apple under Apple’s privacy policy. We do not operate a separate speech cloud for Herdcats.
6. Purchases
If you buy a one-time unlock or start a trial through the Apple App Store, payment and subscription/trial state are handled by Apple. We do not receive or store your full payment card details. Apple’s privacy policy applies to those transactions.
7. Website
Our website may be hosted on infrastructure operated by third parties (for example Cloudflare Pages). Standard web server or CDN logs (such as IP address, user agent, and requested URL) may be collected by those hosts as part of delivering the site. The marketing site is separate from your SSH sessions in the app.
8. How We Use Information
Where information reaches us at all (primarily email support), we use it to:
- Respond to support or legal requests
- Improve documentation and the Service based on what you tell us
- Comply with law and enforce our Terms
On-device data is used only to provide the features you enable (connect, remember hosts, preserve drafts, dictate, attach photos, and restore purchases via Apple).
9. Sharing
We do not sell your personal information. We do not share SSH session content with third parties because we do not receive it. Categories of third parties that may process data in connection with the Service include:
- Apple (App Store / StoreKit, and Speech if you use dictation)
- Website hosting / CDN providers for herdcats.dev
- Networks and hosts you configure (your SSH server, Tailscale, Herdr, AI agent tools)
10. Retention & Deletion
Local credentials, host-key pins, drafts, and preferences remain on your device until you delete them in the app, clear app data, or uninstall the app (subject to iOS behavior). Email you send us is retained as long as needed to handle your request and meet legal obligations. Remote attachments and pane data on your machine are under your control.
11. Security
We design the app to fail closed on host-key changes, keep remembered secrets in the Keychain, and avoid logging credentials. No method of transmission or storage is perfectly secure. You remain responsible for device lock, key hygiene, and the security of machines you connect to.
12. Children
The Service is a developer tool and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information by email, contact us and we will delete it.
13. International Users
We are oriented around Singapore for the Publisher’s operations and for the Terms of Service. If you use the Service from elsewhere, you are responsible for compliance with local law. Because SSH content stays on your path to your machine, cross-border transfer of that content is determined by where you and your hosts are, not by a Publisher-operated processing pipeline.
14. Your Choices & Rights
You can:
- Decline to remember credentials, or remove saved connections and secrets in the app
- Turn off or clear local drafts and command history in Settings → Pane Data & Privacy
- Deny microphone or speech permission in iOS Settings (dictation will not work)
- Avoid selecting photos if you do not want attachments on your remote host
- Uninstall the app
- Email us to access, correct, or delete personal information we hold (typically email correspondence)
Depending on where you live, you may have additional rights under applicable privacy law. Contact us to exercise them. You may also have rights regarding data held by Apple or by operators of machines and networks you use; those requests go to those parties.
15. Changes
We may update this Privacy Policy from time to time. We will post the updated policy with a revised “Last updated” date. Material changes may also be noted in the app or on the website. Continued use after the effective date means you accept the updated policy.
16. Related Terms
Use of the Service is also subject to our Terms of Service.