Skip to main content

Privacy policy

Last updated

1. Who processes your data

The data controller is NETMESAFE, a French société par actions simplifiée with share capital of 500 €, registered with the Paris trade and companies register under number 945 026 953 (SIRET 945 026 953 00014), with its registered office at 30 boulevard de Sébastopol, 75004 Paris, France. NETMESAFE publishes the SSHive app and the sshive.app website.

For any question about your data, or to exercise the rights described below, write to contact@netmesafe.com. It is the same address as support: there is no separate department to reach. There is no data protection officer: the company is not required to appoint one and has not appointed one.

2. The app collects nothing

SSHive asks for no account: no sign-up, no login, no profile held by us. The app sends no telemetry, no crash reports, no usage statistics and no advertising identifier, and it never asks for your location. Apple’s own privacy label on the App Store listing reads “Data Not Collected”: that is Apple’s statement, not only ours.

The only network connections the app opens are the ones you ask it to open: your own hosts over SSH, SFTP, FTP, FTPS, RDP, VNC or Telnet, and on a Mac a device on a serial port, which crosses no network at all. FTP, FTPS, Telnet and the serial port are macOS only; on iPhone and iPad the app speaks SSH, SFTP, RDP and VNC. To that add, if you set up the AI assistant, the provider whose key you entered, contacted straight from your machine. No NETMESAFE server sits on that path, because none exists. The MCP server, when you turn it on, listens on 127.0.0.1 only and never leaves your machine.

3. What stays on your device

Your connection profiles (hosts, ports, usernames, settings, folders and snippets) are written to the application support directory, on your device.

Your passwords and passphrases are stored in the Apple Keychain. We will not write that they “are never stored”: they are. What matters is where, and under what protection. The entry is created as a device-only item, which excludes it from iCloud backups, and when biometric protection is on it is macOS or iOS that requires Face ID or Touch ID before releasing it. We hold no database of our own, and we have no way to read that Keychain.

One honest caveat: if you turn on iCloud sync (a Pro feature, off by default, running through your own private CloudKit database), a saved password can be mirrored into your iCloud Keychain. That is what sync is for, but it is worth knowing before you enable it.

You erase all of it yourself: delete the profiles concerned, or uninstall the app and its support files.

4. The website

The site measures its audience with Umami, software NETMESAFE installed on its own server, in France, at stats.netmesafe.com. Nothing goes to a third party: no Google Analytics, no Meta pixel, no ad network. The site loads no third-party asset: the fonts are served from the site itself. It does load one script, the measurement tag, and that tag comes from stats.netmesafe.com, another machine, run by NETMESAFE itself, not another company.

No cookie is set and nothing is written to your device, and that holds for the session recording described below as well: it is assembled in the browser’s memory and sent, but never left on your machine. What makes a consent banner compulsory is reading or writing information on your device, and neither happens here, which is why there is no banner. It is worth being exact about how far that argument reaches: it answers the question about storage. The recording described below is still a heavier kind of processing than counting pages; it rests on legitimate interest rather than on your consent, and what it owes you in return is a plain description (it follows) and a way to refuse it, set out in “Your rights”. The script also honours Do Not Track: if your browser sends it, neither the visit nor the session is recorded.

What is recorded for a visit: the address of the page and its title, the page or search engine that brought you here, the browser, the operating system, the device type, the screen resolution, the language your browser asks pages in, the country, and a non-reversible same-day hash whose only job is to avoid counting one visit twice. The screen size and the language go with every pageview: Umami’s dashboard has a Screens report and a Languages report, and that is where they come from.

A few events are added to that. They record what is done with a page, not who does it: which page was viewed, how far down it was read, which call to action was clicked, whether the product demonstration on the page was interacted with, whether a configuration snippet was copied, and clicks on links that lead off the site. Each one reports the address of the page it happened on and, where that is worth anything, the language version you were reading and which block the button sat in (the hero, the pricing table, the closing call). Reading depth is taken once when the page opens, then again each time you pass a quarter, a half, three quarters or the whole height of the page, and it reports the threshold reached. A page shorter than your window counts as read in full the moment it opens, without your scrolling at all. What is described here is what is measured rather than a number of events, because the detail changes as the site does; what does not change is the nature of what is recorded: an action on a page, never a person.

Since 22 September 2026 the site also records sessions and builds heatmaps, with the same Umami and on the same server. A recording is exactly what the word says it is: a replay of what happened on the page (where the pointer moved, what was clicked, how far it was scrolled, and the changes the page itself made), kept as a reconstruction of the page rather than as a picture of it, and watched back afterwards like a short film. Nothing outside the page is seen: not your other tabs, not your screen, not your camera, not your microphone. The heatmaps are that same material added up across visits: where clicks land on a page, and how far down the page people get. Every session is recorded, and a recording stops by itself after five minutes.

One protection deserves to be stated as what it is rather than as a reassuring phrase: every form field is masked at the moment of capture, in your browser, before anything is sent. What you type is therefore neither transmitted nor stored; the replay shows that a field was filled, never what was put in it. A recording carries no name, no email address and no account, and is attached to no identity. We will not call it anonymous even so: the replay of one visit is far more detailed than a line in a count, and that is precisely why it is described here. It is kept for the same 14 months as the rest of the statistics, and deleted with them.

What is not recorded: no name, no email address, no account, and no identifier that would follow you from one site to another or from one day to the next.

The legal basis is legitimate interest, under article 6(1)(f) GDPR: knowing which pages are read, whether visitors find the download link, and where a page loses them. That basis has to be weighed rather than declared, and the session recording is what makes the weighing real: cookieless measurement that identifies nobody, deliberately narrowed (form fields masked before they leave the browser, five minutes at most per recording, 14 months at most in the database, no identifier that would follow you from one site to another), and set against an objection anyone can make at once. If you would rather not be recorded at all, “Your rights” says how to stop it in one step. No profile is built, and this data is neither sold nor shared.

5. The web server’s logs

Separate from the statistics, the nginx server in front of the site keeps an access log, and its configuration passes your IP address on to the application behind it. One line is written per request, in nginx’s standard format: the address it came from, the date and time, the page asked for, the response code, the size, the page that linked to it and the browser’s identification string. An IP address is personal data, so this belongs here even though nobody reads those lines on an ordinary day.

They exist for two reasons. The first is ours: they are what separates a real outage from a crawler, what shows an attack while it is happening, and what lets us answer a question about abuse afterwards (legitimate interest, article 6(1)(f) GDPR). The second is not ours to decide: article 6-II of the French LCEN requires the publisher of a site to hold the data that identifies whoever contributed content to it, and a publisher who logged nothing would have nothing to produce (legal obligation, article 6(1)(c)).

How long: these logs rotate by size, not by date. Docker keeps at most three 512 MB files for the web server (about 1.5 GB of lines) and overwrites the oldest beyond that. At this site’s traffic that comes to several months, but the exact span depends on how many visits there are rather than on the calendar, and we would rather give you the real rule than a number of days that would not be true. These lines are never joined to the statistics, and nothing in them is used to build a profile.

6. How long data is kept

We keep none of the app’s data: it is on your device and stays there for as long as you keep it.

The website statistics (the counts, the events, the session recordings and the heatmaps built from them) stay on our server for 14 months and are then deleted by a job that runs every week: long enough to compare a month against the same month a year earlier, short of the two years of history nobody here needs. The period sits inside what the CNIL accepts for audience measurement. If you want to know what the database holds today, or ask for it to be erased sooner, write to contact@netmesafe.com and the answer will be specific.

The web server’s access logs are on their own rotation, by size rather than by date: the section above says exactly how much is kept and why the span is measured in gigabytes instead of days.

Email you send us stays in the mailbox while the matter is open and is deleted once it is settled, unless it concerns a purchase or a claim that could still come back.

7. Your rights

The GDPR gives you a right of access, rectification, erasure, restriction of processing, objection and portability. Restriction is the one people know least: you can ask us to keep data but stop using it while a disagreement about its accuracy, or about our legitimate interest, is being settled. To exercise any of them, write to contact@netmesafe.com. We usually answer within a few days, and within a month at the latest.

French law adds one more: you can leave directives about what happens to your data after your death (general ones, lodged with a certified digital trustee, or specific ones sent to us) and name someone to carry them out. We will follow them.

One honest point about the website statistics: they are attached to no identity. So in most cases we have no way of finding “your” rows among the others, which is also what makes them so unintrusive. What you can do right now, without writing to us, is object: turn on Do Not Track in your browser, or block stats.netmesafe.com, and nothing is recorded at all.

If an answer does not satisfy you, you can complain to the authority that supervises us, which is the French one because the company is French: Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr. If you live elsewhere in the European Union, you may just as well go to the supervisory authority of the country you live in, which will take it up with the CNIL for you.

8. Who else is involved

The main processor is OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France, www.ovhcloud.com. OVH hosts the website, the analytics server and the server logs, and nothing else runs on it. The second is the provider of our mailbox, further down.

Apple sits in a different position, and it is worth naming it correctly. Apple distributes the apps and sells SSHive Pro: the download, the in-app purchase, the receipt and any refund are Apple’s operations. On that, Apple is not our processor: it is the seller, and the data attached to your purchase falls under Apple’s own privacy policy, at apple.com/legal/privacy. We receive neither your name, nor your address, nor your payment method.

No other provider takes part in running the site itself. If you write to us, your message lands in our mailbox, hosted for us by a mail provider that is, on that one point, a processor as well. It is Microsoft: our mail is hosted on Microsoft 365, whose contracting entity for the European Union is Microsoft Ireland Operations Limited. That is the only point at which Microsoft is involved: neither the site, nor the statistics, nor the server logs go through it.

What we do with that correspondence is answer it: support questions, licence and purchase problems, bug reports and the requests covered by “Your rights” above all arrive in the same mailbox. The legal basis is our legitimate interest in replying to the people who write to us (article 6(1)(f) GDPR); where the message concerns a purchase, it is the performance of that contract (article 6(1)(b)). How long it is kept is in “How long data is kept”.

9. Transfers outside the EU

The website, its statistics and the server logs are hosted on an OVH server located in France. For that part, nothing leaves the European Union.

The purchase, though, is an Apple transaction made on the App Store. What Apple does with it, including any transfer to its own infrastructure, is governed by Apple’s privacy policy and not by ours. We would rather say that than claim to control a chain we do not control.

10. Changes to this policy

The date at the top of this page is the date of its last revision: 22 September 2026. Any substantive change is published here with a new date; the previous version stays available on request at contact@netmesafe.com. We do not have your email address and so cannot notify anyone: this page is the record.

What the 22 September 2026 revision changed: it added the section about the website, the section about the server logs, a retention period of 14 months for the statistics, and, to the list of rights, restriction of processing and post-mortem directives. It also describes the session recording and the heatmaps switched on the same day, what the masking protects (the contents of form fields, masked in the browser before anything is sent) and what it does not, and it says exactly what the absence of a consent banner means. The previous version, dated 17 March 2026, stated that the site used no audience measurement at all. That was true when it was written and stopped being true when Umami went up on our server.