Who operates Sherpa
Sherpa is developed and operated by Francesco Primerano. For privacy questions or requests, email fprimeconsulting@gmail.com.
Information stored on your device
To provide its terminal and connection features, Sherpa stores or processes:
- Connection settings: machine names, hostnames or IP addresses, SSH ports, usernames, server modes, executable paths, and recorded server host keys.
- Credentials: saved private keys, key passphrases, and machine passwords in Apple's Keychain using device-only accessibility. Key names, types, fingerprints, and machine associations are stored separately as app settings.
- Workspace information: selected sessions, tabs, panes, text sizes, and cached metadata such as workspace labels, paths, and agent status.
- Terminal and diagnostic information: screen output and local scrollback held in memory during use, plus connection progress and diagnostic messages that may contain server addresses or usernames.
Sherpa does not automatically upload this information to the developer. It does not provide its own cloud synchronization. Operating-system backup and device-management features may handle app data according to your Apple and device settings; this policy does not control those services.
Information sent to your chosen servers
Sherpa opens SSH connections to the hosts you configure. Those hosts receive the information needed for the connection, including your network address, SSH username, authentication exchanges, commands, terminal input, and sizing or session-control requests. Password authentication sends the password to the selected server inside the encrypted SSH connection. Private-key authentication uses signatures; Sherpa does not send the private key or its passphrase to the server or developer.
Herdr and tmux modes also exchange session and workspace information with the selected remote backend. Your server, its administrators, and any programs you run there may retain logs or send information to other services. If you run a coding agent, that agent's provider and server configuration govern its handling of prompts and project data. Sherpa does not itself supply an AI service.
SSH encrypts connection traffic. Sherpa's current host-key acceptance behavior is described on the support page. No security measure eliminates every risk.
The app may use local-network access, read a key file you select through the file picker, or read clipboard content when you choose to paste. Links opened from terminal content are handed to your browser; the destination's privacy policy then applies.
Information you send to support
If you email us, we receive your email address, message, and any attachments or diagnostics you choose to include. We use that information to respond, investigate reported issues, and maintain support records. Please do not send passwords, private keys, or passphrases.
Support email is handled through the developer's Gmail address. Email providers process correspondence under their own terms and privacy policies. We may disclose information where reasonably necessary to comply with law, protect legal rights, or respond to a security incident. We do not sell personal information or use support correspondence for targeted advertising.
Website visits
This website is static. Its code does not set cookies, use browser storage, load third-party analytics, or include advertising trackers or externally hosted fonts. There is no account system or contact form; contact links open your email application.
Serving a webpage requires the hosting infrastructure to process a visitor's IP address and request information. The VPS and hosting software may record access or error logs containing timestamps, requested URLs, browser details, and network addresses for operation, troubleshooting, and security. This technical website traffic is separate from your SSH connections and terminal content.
Apple services and purchases
Apple handles App Store downloads, payments, and purchase records. We do not receive your payment-card details. Apple may provide sales reports or diagnostic information according to its services and your settings. If you use TestFlight, Apple also handles beta feedback and diagnostics. See Apple's privacy policy.
The app does not embed third-party advertising or analytics SDKs and does not track you across other apps or websites.
Retention and deletion
App data: connection and key records remain on your device until you remove them. Use Machines to disconnect and remove connections, then Keys to remove unused shared keys. You must reassign or remove machines using a key before that key can be deleted. Removing a machine does not remove its shared key.
Uninstalling normally removes the app's container, but Keychain entries may survive app removal. Delete credentials in the app before uninstalling if you want to remove them. Device backups are managed through your operating-system settings. We cannot remotely retrieve or delete local Keychain items or app data.
Remote data: deleting local settings or uninstalling Sherpa does not delete remote files, persistent sessions, server logs, or information held by services you use through the terminal. Manage those with the server or service operator.
Support and website records: we retain them as needed to respond to requests, resolve issues, operate and protect the service, and meet applicable legal obligations. You can request deletion of support correspondence by emailing us; some records may need to be retained where the law permits or requires it.
Your choices and rights
You choose which servers to connect to, what to type or paste, and what to share with support. You can revoke local-network permissions in device settings and manage your saved connections and keys in the app.
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing of, or obtain a copy of personal information we hold. Contact fprimeconsulting@gmail.com to make a request. We may need to verify that a request comes from the person concerned. You may also have the right to complain to your local data-protection authority.
Hosting, email, and Apple services may process information in countries other than your own. Their handling of that information is also subject to their terms and applicable law. Sherpa is a developer utility; we do not knowingly collect personal information from children. Please contact us if you believe such information was sent to us.
Updates and contact
We may update this policy as the product or its services change. The effective date at the top identifies the current version. Material changes will be described here and, where appropriate, through an app update or other notice.
Francesco Primerano — Sherpa Terminal Manager
fprimeconsulting@gmail.com