Last updated: 20 August 2026
Terminal Spike is an Android SSH terminal app developed by Jiyu Yan. It can also connect through Mosh when the optional, separately installed Terminal Spike Mosh extension is available.
Terminal Spike is local-first. The developer does not collect, receive, sell, or share personal data through the app. The app has no user account, analytics, advertising, automatic crash reporting, cloud-sync service, or developer-operated backend.
Data the App Handles
To provide its terminal features, Terminal Spike handles data that you enter or create, including:
- connection profiles, such as a display name, hostname or IP address, port, username, and connection preferences;
- trusted host keys and fingerprints used to verify remote servers;
- authentication data, such as an imported private key or a password that you explicitly choose to save;
- terminal input, output, local terminal history, snippets, themes, keyboard layouts, settings, and imported fonts; and
- backup files that you explicitly create or restore using Android's document picker.
This data is processed on your device to provide features you request. It is not transmitted to Jiyu Yan or to a Terminal Spike service.
Remote Connections
When you start a session, Terminal Spike connects directly from your device to the SSH or Mosh server address you provide. The app sends the connection and authentication data needed to establish that session, along with terminal input you choose to send. It receives terminal output from that server.
The operator of the remote server and the networks used to reach it may process connection information and terminal activity under their own policies. You are responsible for choosing and trusting the servers to which you connect.
If you use Mosh, the main app exchanges only the session data needed to run the connection with the separately installed, verified Terminal Spike Mosh extension on your device. Mosh starts through SSH and then uses its encrypted UDP transport.
Local Storage and Security
Profiles, trusted-host records, settings, snippets, and other app data are stored in app-private storage. Imported private keys and passwords you explicitly choose to save are encrypted using keys protected by Android Keystore. Private-key passphrases are not saved.
SSH sessions use encryption provided by the SSH protocol. Android cloud backup and device-transfer backup are disabled for Terminal Spike data.
You can choose to export a portable backup through Android's document picker. A backup can contain connection details, credentials, private keys, snippets, settings, themes, and imported fonts. Exported backup files are not protected by a separate Terminal Spike passphrase, so you should store and share them carefully. The selected Android document provider handles the file under its own privacy and security terms.
Clipboard and Notifications
Terminal Spike can place terminal text on the Android clipboard when you request it. A remote OSC 52 clipboard request is disabled or requires confirmation according to your setting. Clipboard content is managed by Android and may be visible to other software as allowed by the operating system.
The app can show a foreground-service notification while a user-started terminal session remains active. Notification content is privacy-reduced by default, and you can deny notification permission or change the related setting.
Permissions
Terminal Spike may use these Android permissions:
- Internet and network state to connect to the remote server you select and respond to network changes;
- Foreground service, notifications, and wake lock to keep a user-started remote session active and show its status; and
- Biometric authentication to let Android verify your identity for the optional app lock. Terminal Spike does not receive or store biometric data.
Data Sharing
The developer does not sell or share app data with advertisers, analytics providers, data brokers, or other companies. Data is sent only as necessary for actions you initiate—for example, to a remote server you choose, an Android document provider you select for a backup, or the optional on-device Mosh extension.
Retention and Deletion
Local data remains on your device until you delete individual items, reset Terminal Spike's local data, clear the app's storage in Android settings, or uninstall the app. Because the developer does not receive app data, there is no developer-held account or cloud record to delete.
Exported backup files are controlled by you and the storage provider you selected. Deleting or uninstalling Terminal Spike does not delete those external files; delete them through that provider when they are no longer needed.
Children's Privacy
Terminal Spike is a general-purpose developer and systems tool. It is not directed to children, and the developer does not knowingly collect personal information from children.
Changes to This Policy
This policy may be updated when Terminal Spike's features or data practices change. The date at the top identifies the latest version.
Contact
For privacy questions about Terminal Spike, contact Jiyu Yan at yn.jiyu@gmail.com.