Muxly

Privacy Policy

Effective date: August 9, 2026

Overview

Muxly is an SSH client for iOS provided by Whale shark s. r. o. ("we", "us", "our"), which is the controller of the personal data we process. This policy explains what information we process, why we process it, how it is shared and retained, and your choices and rights.

The short version: Muxly does not require a Muxly account and does not use personal data for advertising or tracking. Your host configurations, SSH credentials, commands, and terminal traffic are not sent to us. We process limited information to provide optional terminal-bell notifications and support features, protect our services, and diagnose and improve the app. Some crash and diagnostic information may be sent automatically, as described below.

Data stored on your device

Muxly stores host configurations, SSH credentials, server host-key fingerprints, and app settings primarily on your device using iOS storage and security features. Certain information needed for terminal-bell notifications may be synchronized by Apple if you enable iCloud Keychain.

None of your host configurations, SSH credentials, commands, or terminal traffic is transmitted to us. We have no servers that receive or store that data.

SSH connections

SSH connections go directly from your device to the servers you configure, encrypted with the SSH protocol. Your traffic is never routed through Muxly-operated infrastructure. We never see your servers, credentials, commands, or terminal content. If you connect to hosts on your local network, iOS may ask for local-network permission; that access is used solely to reach the hosts you configure.

Voice dictation

If you use voice dictation to type into the terminal, speech recognition runs on-device using Apple's speech frameworks. Your audio and transcripts are not sent to us.

Terminal bell notifications (optional)

Muxly can deliver a push notification when a terminal bell rings in one of your remote tmux sessions. This feature is off until you enable it.

When enabled, Muxly processes pseudonymous registration and routing identifiers, a device notification token, encrypted notification content, and limited technical and network information. We use this information only to provide and secure notifications, manage registrations, prevent abuse, and operate the service. The notification service does not receive your SSH credentials, commands, or terminal traffic.

Notification details, such as server, session, and window context, are end-to-end encrypted between your remote tmux session and your device. Muxly's relay, Cloudflare, and Apple process encrypted content and delivery information but cannot decrypt those details.

We use Cloudflare to host and protect the notification service and Apple to deliver notifications.

Diagnostics, feedback, and bug reports

Muxly may automatically process limited crash and diagnostic data, including app and device information, interactions with app features, performance data, and information about errors or failures. We use this information to provide, secure, maintain, support, and improve Muxly. Diagnostic information generated by Muxly is designed to exclude SSH credentials, commands, terminal content, and raw persistent identifiers.

Feedback and bug reports may include text, screenshots, and diagnostic information that you choose to provide. User-provided content leaves your device only when you submit it. Depending on what you provide, a report may identify you and is not considered anonymous.

Muxly may process limited technical data and pseudonymous identifiers to provide and secure these features, verify eligibility, prevent abuse, and apply service limits. We do not link these identifiers to you or use report or diagnostic data for advertising or tracking.

We use Cloudflare to transmit, protect, and store reports and related technical and network information. Reports are encrypted in transit and at rest but are not end-to-end encrypted. Muxly and its service providers may access report contents only as necessary to provide support, operate and protect the service, and diagnose or improve Muxly.

To ask about privacy or request deletion, contact us at the address below. Because Muxly has no user accounts and reports are not associated with an account, we may be unable to locate a particular report unless you provide enough information to identify it. We will delete a report when it can be located and deletion is feasible, subject to applicable provider retention and legal obligations.

Purchases

Muxly purchases and subscriptions are processed entirely by Apple through the App Store. We do not receive your payment details, billing address, or Apple Account identity. Entitlement checks happen on-device through Apple's StoreKit framework.

The muxly.sh website

This website is static and sets no cookies. It is served through Cloudflare, whose infrastructure processes basic technical information (IP address, user agent, request time) to deliver the site and protect it from abuse. Cloudflare also provides cookie-less, aggregate visit metrics for this site (Cloudflare Web Analytics), which does not use client-side identifiers or track you across sites.

Service providers and international transfers

We use Apple and Cloudflare as described above. Where service providers process personal data on our behalf, they are required to use it only to provide the relevant services and to protect it consistently with this policy and applicable law. They may process data in countries other than your own. Where required, we rely on an applicable adequacy decision or contractual safeguards. Contact us for information about the safeguards relevant to your data.

Legal bases (GDPR)

Where the GDPR applies, we process personal data as needed to provide services you request and for our legitimate interests in operating and securing our services, preventing abuse, diagnosing and improving stability, responding to support requests, and understanding aggregate website use. We rely on consent where we specifically ask for it. iOS permissions are separate platform controls that you can change in iOS settings; granting one does not by itself constitute consent for unrelated server-side processing.

Retention

Unless otherwise stated, we retain personal data only for as long as reasonably necessary for the purposes described in this policy and to comply with applicable legal obligations, resolve disputes, and enforce our agreements.

Notification registrations are retained while needed to provide the feature, and inactive registrations expire automatically. Feedback, bug, crash, and diagnostic reports are normally retained for no longer than 90 days. Limited backup, security, and provider records may remain for longer under applicable retention schedules or legal obligations. Support emails are kept only as long as needed to handle your request and meet legal obligations.

Data in the app's local storage is generally removed when you uninstall the app. Items stored in the iOS Keychain or synchronized through iCloud Keychain may persist according to your settings and Apple's platform behavior.

Your choices

Bell notifications are optional and can be disabled at any time. Feedback, bug reports, and support emails are also optional, and user-provided content is sent only when you choose to submit it. Crash and diagnostic data may be processed automatically as described above. We do not use personal data for tracking or profiling or for solely automated decisions that produce legal or similarly significant effects.

Your rights

You may contact us to request access, correction, deletion, restriction, portability, or to object to processing of personal data we control, and to withdraw consent where processing is based on consent. If you are in the EU/EEA, you also have the right to lodge a complaint with a supervisory authority — in Slovakia, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR).

Children

Muxly is not directed at children and we do not knowingly collect personal data from children.

Changes

We may update this policy as the app evolves. Material changes will be reflected on this page with an updated effective date.

Contact

Whale shark s. r. o.
Karpatské námestie 7770/10A
831 06 Bratislava - Rača
Slovakia

Email: support@muxly.sh

Company ID: IČO 57 713 251