Privacy Policy for Attach

Effective date: 2026-07-20  ·  Last updated: 2026-08-12

Attach (“the app”) is an SSH tunnel and tmux terminal client for Android, published by Nimona (“we”, “us”). This policy explains what the app does and does not do with your information. The credentials and connections you set up stay on your device, and the app has no user accounts and no analytics or behavioural tracking.

What leaves your device, and only these: banner ads (Google AdMob) request an advertising ID, and crash reports (Firebase Crashlytics) are sent unless you turn them off. Both are described below, and both are under your control. Nothing about your servers, credentials, or terminal sessions is ever sent anywhere.

1. Information the app handles

Data you enter (stays on your device)

To connect to your servers, you enter connection details: host names/addresses, ports, usernames, and authentication material (SSH passwords and/or private keys). This information is:

Your SSH traffic

When you connect, the app communicates directly with the servers you configure. That traffic — including anything shown in the terminal — flows only between your device and those servers. We never see it, receive it, or store it off your device.

Crash and diagnostic data — opt-out

To help us find and fix stability problems, the app sends crash reports to Google Firebase Crashlytics. This is on by default and you can turn it off at any time in Settings → Debugging → “Send crash reports”. When enabled, a crash report may include:

Crash reports never contain your passwords, private keys, known_hosts entries, terminal contents, server names, host addresses, or usernames. The app enforces this on-device (sensitive values are structurally prevented from reaching a crash report) before anything is sent.

Advertising

The app shows banner ads supplied by Google AdMob on the session list and the server list. There are no ads in the terminal.

To show an ad, the Google Mobile Ads SDK sends Google your device’s advertising ID along with device and network information (device model, OS version, coarse network type, approximate location as inferred from your IP address). We never send your connection details, credentials, or anything from your terminal sessions to it — see section 2.

2. What we do NOT collect

Attach has no user accounts and does not collect, store, or transmit: your identity, email, contacts, precise location, usage/behavioral analytics, or the contents of your sessions. Your connection names, host names, usernames, passwords and private keys are never sent anywhere, to us or to any third party — not in a crash report, and not in an ad request.

3. Third-party services

Both are governed by Google’s Privacy Policy; Firebase additionally by the Firebase terms, and advertising by Google’s advertising privacy terms.

The app contains no other third-party SDKs, analytics, or advertising libraries.

4. Data retention

5. Your choices and controls

6. Security

Secrets (passwords and private keys) are encrypted at rest using the Android Keystore, and the app is designed so that secrets are never written to logs or crash reports. No security measure is perfect, but we aim to keep your credentials on your device and under your control.

7. Children’s privacy

Attach is a general-purpose developer tool and is not directed to children under 13, and we do not knowingly collect any information from children.

8. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected by an updated “Last updated” date, and the current version is always available at this URL.

9. Contact

Questions about this policy or your data? Contact us at shangchieh.l@gmail.com.