Last updated: 2026-09-19

Privacy Policy

Overview

INFINIACT CO., LIMITED (hereinafter referred to as "we", "the Company", or "Infiniact") is a technology company registered in Hong Kong SAR. This Privacy Policy explains how we handle your personal information.

IATerm is a terminal emulator application, providing SSH/SFTP connections, serial communication, port forwarding, and other features. This policy applies to IATerm obtained through:

  • Apple App Store (hereinafter referred to as "App Store Version")
  • Direct download from IATerm website (hereinafter referred to as "Website Version")

Effective Date: September 19, 2026

Data Collection Statement: We use your data to provide and improve IATerm services. This policy explains what information we collect, how we use it, and your choices regarding this data.


1. Data Storage

IATerm follows a local-first architecture. Your data is primarily stored on your device, and we do not collect and store this data unless you manually activate sync.

1.1 Local Storage (Primary Mode)

Locally stored data:

  • SSH server addresses, ports, usernames, passwords, or login keys
  • Connection groups and tags
  • Port forwarding configurations
  • Terminal appearance settings (themes, fonts)
  • Serial port connection parameters (baud rate, data bits, etc.)
  • Recent server connection lists (for quick reconnection)
  • Connection timestamps

Encryption: The local database is encrypted end-to-end; encryption keys are stored in the system keychain.

1.2 Command Execution History (Requires Manual Activation)

When you manually activate command execution history saving in Settings:

  • Command execution content will be recorded
  • Terminal session input/output content will be recorded
  • History data is stored only in your local encrypted database
  • You can disable this feature or clear history at any time
  • After disabling, no new commands or session content will be recorded

1.3 iCloud Auto Backup (App Store Version only, requires manual activation)

Current status: iCloud Auto Backup is only available on the Apple App Store version. The Website Version does not currently offer cloud sync or backup.

Applies only when you manually enable iCloud Auto Backup in Settings on the App Store version:

Backup Data (if enabled)

  • Connection profiles (SSH hosts, ports, usernames, passwords)
  • SSH login keys
  • Workspace layouts and preferences
  • Theme and font settings
  • Port forwarding configurations

Backup Security Model

  • Client-side encryption: Data is encrypted on your device using your backup password before being uploaded to your iCloud private database
  • Zero knowledge: We cannot access your plaintext backup password and cannot decrypt your backup data
  • Storage location: Your Apple iCloud private database (your personal space); we do not operate a server for this data
  • Security note: Your backup password is the key protecting your backup data. Use a strong password and keep it secure.
  • Password loss: If you forget your backup password, backed-up data cannot be recovered.

2. Data Storage and Security

2.1 Local Storage Security

  • Local encryption: Your sensitive data (SSH keys, server passwords, connection configurations) is stored encrypted on your local device
  • Key management: Encryption keys are stored in the system keychain and are never uploaded

2.2 iCloud Auto Backup Security (App Store Version only, if enabled)

App Store Version only: The Website Version does not currently offer cloud sync or backup.

  • End-to-end encryption: Data is encrypted on your device before being uploaded to your iCloud private database
  • Double-layer protection: Local device key + your backup password
  • Zero knowledge: We cannot decrypt your backup data; your backup password never leaves your device
  • No server-side storage on our side: We do not store your backup data; backups reside only in your iCloud private database

2.3 Network Security

  • Transmission Encryption: All network communications use HTTPS/TLS encryption
  • SSH Connections: Use industry-standard SSH protocol encryption

3. Data Sharing

  • No Ad Tracking: We will not sell your personal information to third-party advertisers, nor will we integrate SDKs for ad tracking within the application.
  • Necessary Third-Party Service Providers: To provide our services, we share the minimum necessary information with the following categories of service providers:
    • Apple (App Store version only): processes payments, license verification, and iCloud backup storage
    • Stripe (Website Version only): processes orders and payments; we receive only the order number, payment status and your email address, never your full card details
    • Email delivery provider (Website Version only): delivers sign-in codes and license information (License Key, recovery code) to your inbox
    • Crash Reporting Providers: receive de-identified crash logs used to diagnose stability issues
    • Third-Party Login Providers (if you choose Google Sign-In in the website account center): complete account login authorization These providers are bound by their own privacy policies and process data only for the purposes of providing services to Infiniact.
  • Legal Compliance: In order to comply with legal and regulatory requirements, we may provide necessary information to relevant regulatory authorities.

4. Data Retention

  • Local Data: Fully under your control, can be deleted at any time
  • Crash Reports: Retained for no more than 90 days, used solely to improve product stability and security

Account data, backup data, and transaction retention periods are specified in each platform's section.


5. Cookies and Tracking Technologies

  • No Ad Tracking: We do not use cookies or similar technologies for ad tracking or cross-site tracking
  • Third-Party Websites: Our website may contain links to third-party websites, which have their own privacy policies that we recommend reviewing

Essential Cookies usage is specified in each platform's section.


6. Children's Privacy

IATerm is intended primarily for adult developer users. We do not knowingly collect personally identifiable information from minors under 18. If you are a parent or guardian and discover that your child has provided us with personal information, please contact contact@infiniact.com and we will take steps to delete that information.


7. Permissions Usage

IATerm requires the following system permissions to provide services:

7.1 Network Access Permissions

  • Purpose: Connect to SSH/SFTP servers and establish remote terminal sessions
  • Local Network: Access SSH servers and network devices on the LAN
  • Port Forwarding: Support SSH -L/-R/-D port forwarding
  • Data Transmission: All network connections use HTTPS/TLS encryption

7.2 USB Device Access

  • Purpose: Access USB-to-serial adapters to connect to embedded devices and microcontrollers
  • Data Content: Only read serial data streams, no access to other USB device content
  • User Control: Only used when user actively initiates a serial connection

7.3 System Keychain Access

  • Purpose: Securely store the encryption key for your local database
  • Encryption: Uses the system keychain's encryption mechanism
  • Data Isolation: Only IATerm can access its own keychain entries

Your SSH keys, server passwords, and other sensitive data are stored encrypted in the local database; the system keychain is used only to protect the database encryption key.

7.4 File System Access

  • Purpose: Read and write user-selected files (SSH key files, configuration files)
  • Access Scope: Limited to files explicitly selected by the user
  • Background Access: No background file scanning or access

8. Different Platforms and Versions

The general principles in this policy apply to all platforms and versions of IATerm. For platform or version-specific information (such as Apple App Store version or website direct version), please refer to the corresponding sections below.


9. Apple App Store Version Specifics

This section applies only to the IATerm version downloaded from the Apple App Store.

9.1 iCloud Auto Backup

If you enable iCloud Auto Backup, see Section 1.3 for the data included in the backup. Auto Backup is a one-way upload to your own iCloud private database; restore operations are user-initiated inside the app.

iCloud Auto Backup Security

  • Multi-Layer Security:
    1. Apple ID Protection: Access to iCloud data requires your Apple ID credentials
    2. Device Trust: Apple's two-factor authentication and trusted device mechanisms
    3. iCloud Private Database: Data is stored in your personal iCloud private space, inaccessible to others
    4. Backup Password Encryption: All data is end-to-end encrypted with your backup password before upload
  • Zero-Knowledge Architecture: Neither Infiniact nor Apple can decrypt your data; your backup password never leaves your device
  • Password Security: Your backup password is never transmitted or stored on any Infiniact server
  • Password Recovery: If you forget your backup password, backup data cannot be recovered; you can only reset the backup

You can disable backup or reset backup data at any time in Settings. Disabling backup does not affect data on your local device.

9.2 Data Collection & Usage

Information We Collect:

  • Application crash reports and performance data

Data Usage: We use the collected information to:

  • Provide, maintain, and improve our services
  • Send you service-related notifications and updates
  • Analyze service usage to optimize the user experience

Payment and account-related data for the App Store version is handled by Apple. Please refer to Apple's privacy policy for details.

9.3 Essential Cookies

This version uses essential cookies to maintain basic functionality:

  • Login State: Maintains your login status when visiting the website
  • Preferences: Remembers your language and interface preferences

These cookies are used only when you visit the IATerm website and are not used for tracking or advertising purposes.

9.4 Data Retention

  • Backup Data: Encrypted backup data stored in iCloud will be deleted when you reset the backup or delete iCloud data
  • Crash Reports: Retained for no more than 90 days, used solely to improve product stability and security

Transaction records and other data are managed by Apple. Please refer to Apple's privacy policy.

9.5 Device Identifier

To distinguish backup data sources across your multiple Apple devices, the App Store version of IATerm generates a random device identifier (UUID) on each device. This identifier:

  • Is completely random and contains no hardware, account, or personally identifiable information
  • Is stored only in your device's Keychain and your own iCloud private database
  • Is never transmitted to Infiniact or any third party
  • Is not used for advertising or cross-app tracking
  • Cannot be used to identify you personally

You can remove this identifier by uninstalling the app or clearing IATerm's iCloud data from System Settings.

9.6 Data Storage Location

All backup data for the App Store version is stored on Apple iCloud servers:

  • Storage Location: Apple's iCloud servers, with specific locations determined by Apple based on your account region
  • Data Control: Your backup data is stored only in your personal iCloud private space
  • Zero-Knowledge Architecture: Neither Infiniact nor Apple can decrypt your backup data
  • Legal Protection: Apple's data centers comply with local laws and regulations, providing legal protection for your data
  • Data Management: You can manage your iCloud data through your Apple ID, including deleting backup data

9.7 30-Day Free Trial

  • Local trial status stored in Keychain
  • Trial start time is first launch date
  • Trial status is not reported to any server
  • Full functionality during trial period

9.8 Payment Information

  • License verification completed through Apple StoreKit framework
  • No payment information collected (all payments handled by Apple)

9.9 License Authorization

  • Usage authorization verified through Apple's official authorization mechanism
  • Authorization status managed by Apple App Store
  • We do not collect your device identification information for authorization

9.10 Data Isolation

  • App Store version does not share data with the direct download version from our website
  • iCloud backup data can only be restored within the App Store version family
  • Uninstalling the App Store version does not affect the website version's data

9.11 Your Rights

User rights for the App Store version are governed by Apple's privacy policy:

  • Apple Privacy Policy: Please refer to Apple's Privacy Policy (https://www.apple.com/privacy/)
  • Data Management: You can manage data related to the App Store version through your Apple ID
  • Data Deletion: Delete IATerm's iCloud data through the iCloud management interface in System Settings
  • Account Management: Manage your Apple ID and related data through Apple's official channels

To learn how Apple handles your data, please contact Apple directly or visit Apple's Privacy Policy page.

9.12 Terminal Assistant (BYOK)

The App Store version includes a built-in Terminal Assistant as an opt-in feature, off by default. When enabled:

  • Data flow: Your input and any terminal content you choose to include as context are sent from your Mac directly to the model provider you configure (BYOK model). IATerm does not proxy, retain, or upload copies to our servers.
  • API key storage: The API key for your model provider is stored in the macOS Keychain on your device. It is never uploaded and is not synced through iCloud.
  • Responsibility allocation: The model provider you choose is an independent data controller. Their handling of your data is governed by that provider's own privacy policy and terms of service.
  • User control: You may enable or disable the Assistant at any time in Settings, delete any stored API key, and clear local conversation records at any time. When the Assistant is disabled, no further network requests are made to any model provider.

10. Website Direct Version Specifics

This section applies only to the IATerm version downloaded directly from the IATerm website.

10.1 Website and License Services

For the Website Version we provide:

  • Application Download: direct download of the IATerm application from the IATerm website
  • In-app sign-in and purchase: sign in inside the app with an email one-time code, and purchase a license on a Stripe-hosted checkout page
  • Website account center (infiniact.com): sign in with an email one-time code or Google to manage your account and purchase licenses
  • License service: a license service operated by us issues, verifies and manages your entitlement

When you use these services we collect the necessary data described in the subsections below.

10.2 Sign-In and Identity

  • When sign-in is required: In the Website Version both the free trial and paid features use your email address as your identity, so you sign in first. Licenses are tied to your email; sign in with the same email on a new machine to restore them.
  • Data minimization: The account retains only your email address as the primary identifier and contact method. We do not collect username, avatar, phone number, or other profile fields.

Sign-In Methods

  • Email one-time code (in-app): We send a 6-digit one-time code to your email; it is valid for 10 minutes and can be used once. No password is set, eliminating password-leak risk.
  • Google Sign-In (website account center only): We request only the email scope from Google (not the profile scope), so Google does not provide us with your name or avatar. We do not retain Google access or refresh tokens and cannot access your Google account on your behalf.

What We Retain After Authentication

  • Your email address (primary account identifier)
  • Your device identifier: a random UUID generated on your machine the first time the app starts (contains no hardware or personal information), plus a one-way hash of a hardware fingerprint (the original device information cannot be reverse-engineered)
  • An offline license token issued by the license service and stored on your device (used to verify your entitlement while offline; it contains the device identifier, license id and validity period, and no personal data beyond what is listed here)
  • If you use Google Sign-In: the internal user ID that Google assigns to you (Google sub, an opaque identifier containing no personal information)

Sign-In and License Logs (Security Audit)

For security and abuse detection, the license service records runtime metadata:

  • Time, result, requesting IP address and device-fingerprint hash of one-time code requests and verifications
  • Time, result and IP address of license operations (activation, renewal, claim, rebinding, device deactivation, purchase)

These logs are used to rate-limit code requests and detect bulk sign-ups and abnormal access. They are not used for profiling or marketing.

10.3 Data Collection & Usage

Information We Collect:

  • Email address: retained when you sign in (the only persistent personal identifier)
  • License data: license number and recovery code, license type, purchase order number, update-window end date, the random identifiers and fingerprint hashes of bound devices, and each device's last-seen time
  • One-time code records: email, code, requesting IP, device-fingerprint hash (codes expire after 10 minutes)
  • Audit logs: see "Sign-In and License Logs" in 10.2
  • Crash reports and performance data: de-identified, for product stability improvements

Data Usage: We use the collected information to:

  • Issue, verify and manage your entitlement (including device limits)
  • Process purchases and renewals, and deliver license information to you by email
  • Send you service-related notifications
  • Rate-limit code requests and detect abuse and abnormal access
  • Analyze service usage to optimize the user experience

10.4 Cookies

  • In the app: no cookies are used. Your signed-in state is held as a license token on your device.
  • Website account center: essential cookies maintain your login state and remember language and interface preferences; they are not used for tracking or advertising.

10.5 Data Retention

  • Account and license data: retained while your license is valid. After account deletion, we delete your personal information within 30 days. Please record your license numbers and recovery codes before deleting your account, as deletion may prevent licenses tied to that email from being verified online. To preserve licenses, contact contact@infiniact.com before deletion.
  • One-time code records and audit logs: retained for no more than 12 months, solely for security auditing and abuse detection
  • Crash reports: retained for no more than 90 days, used solely to improve product stability and security

10.6 Data Storage Location

The Website Version is local-first. Apart from the necessary account, license, audit and crash data, we do not store your connection configurations, terminal sessions, or other sensitive data on our servers.

  • Account and license data: stored on servers in Hong Kong
  • Legal Protection: Hong Kong has comprehensive data protection laws (Personal Data (Privacy) Ordinance - PDPO) to protect your data
  • Transmission Security: all data transmissions use HTTPS/TLS encryption

10.7 Backup and Sync

The Website Version does not provide cloud sync or iCloud backup (iCloud backup is exclusive to the App Store Version). The Website Version only offers encrypted export and import of local files: the export file is encrypted with a password you choose and is kept by you; it never passes through our servers.

10.8 Payment Information

  • Payments are completed by Stripe on its hosted checkout page; we never see or store your card details
  • We receive from Stripe: the order number, payment status, amount and your email address (used to tie the license to your account)
  • After a successful purchase, license information (License Key and recovery code) is emailed to you, and the device you are signed in on claims the license automatically
  • Stripe's handling of payment data is governed by the Stripe Privacy Policy

10.9 License Authorization and Devices

  • Licenses are tied to your email: sign in with the same email on any device to claim the license
  • Device identifier: devices are identified by a random UUID; the hardware fingerprint is hashed before upload and cannot be reverse-engineered
  • Offline token: the license service issues a signed offline token stored on your device so entitlement can be verified without a network connection; the token is renewed online periodically
  • Device limit: a license may be bound to at most 3 devices at the same time. You can deactivate this device inside the app to free a seat; if a device is lost, you can rebind using your recovery code (rebinding clears all devices on that license and rotates the recovery code)
  • Data transmitted during verification: the license token or license number, the device identifier, the fingerprint hash, and your IP address (for rate limiting and auditing)

10.10 Data Isolation

  • The Website Version does not share data with the App Store Version
  • You can install both versions simultaneously; their data are completely independent

10.11 AI Features

The Website Version provides AI-assisted features (BYOK — you configure your own model provider):

  • Data Processing: this tool acts only as a channel. Coding assistance and AI chat are processed by the model provider you choose and are subject to that provider's privacy policy.
  • Data Flow: input and output content is stored locally; during processing it is sent directly to the model provider you configured. Our servers do not collect, store or proxy this data.
  • API keys: stored in your device's system keychain and never uploaded.
  • Privacy Responsibility: use of AI services is subject to the respective provider's privacy policy.

10.12 Your Rights

Under the Hong Kong Personal Data (Privacy) Ordinance (PDPO), when using the Website Version you have the right to:

  • Access: request access to personal data we hold about you
  • Correction: request correction of inaccurate or incomplete personal data
  • Deletion: request deletion of your personal data (we will delete within 30 days after account deletion)
  • Object/Restrict Processing: request that we stop or restrict specific processing of your personal data
  • Data Portability: where technically feasible, obtain your personal data in a structured, commonly used format

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may have additional rights under the GDPR. If you are a California resident, you may have rights under the CCPA/CPRA (e.g., the right to know, delete, and opt out of the sale/sharing of personal information — note that we do not sell or share personal information). We will respond to your requests in accordance with applicable law.

Cross-Border Data Transfers

When you use the Website Version, your personal information may be transferred across borders to our servers in Hong Kong (the Company's registered jurisdiction). IATerm follows a "global service, regional compliance" model:

Recipient: INFINIACT CO., LIMITED (Hong Kong SAR), operating and controlling servers located in Hong Kong.

Data Transferred: email address; license data and device-binding records; one-time code and sign-in records (time, IP address, device-fingerprint hash); purchase order numbers; de-identified crash reports.

Purpose: account and license management, online license verification, purchase and renewal processing, security auditing.

Safeguards: HTTPS/TLS transport encryption; server-side encryption at rest; strict access control and audit logging.

Regional Notices:

  • Mainland China users (under the Personal Information Protection Law / PIPL): The Website Version involves cross-border transfer of personal data to Hong Kong. The in-app sign-in screen links to this Privacy Policy; by completing your first sign-in via email one-time code (or via Google in the website account center), you acknowledge and agree to the data processing and cross-border transfer described in this policy. You may withdraw consent at any time by deleting your account (see §10.5).

  • EEA / UK / Switzerland users (under GDPR / UK GDPR / Swiss FADP): Hong Kong is not covered by an EU adequacy decision. Cross-border transfers rely on the European Commission-approved Standard Contractual Clauses (SCCs) or an equivalent legal mechanism. You retain the full set of data subject rights under the GDPR (access, rectification, erasure, restriction, portability, objection, and complaint to your local supervisory authority).

  • California residents (under CCPA/CPRA): You have the right to know, delete, correct, and opt out of the sale or sharing of your personal information. IATerm does not sell or share personal information. For requests, contact us as described below.

  • Other regions: Local personal information protection laws apply. Contact us to exercise your rights.

Cross-border data flows through third-party services (Apple iCloud, Stripe, Google Sign-In) are governed by those providers' own privacy policies.

To exercise the rights described above, or to raise a privacy-related concern, please contact: contact@infiniact.com. We aim to respond within the timeframe required by applicable law.


11. Policy Updates

We may update this Privacy Policy from time to time. As IATerm features evolve and the scope of data processing changes, we may adjust the sections of this policy regarding data collection, use, and storage.

The updated policy will be posted on this page, and we will notify you of significant changes through in-service notifications or the contact information you provided during registration. Your continued use of our services constitutes acceptance of the updated Privacy Policy. We recommend that you review this policy periodically to stay informed of the latest content.


12. Contact Us

For privacy-related questions, data protection requests, or inquiries, please contact:

We will respond to your request as soon as possible and process it within the timeframe required by law.


Last updated: September 19, 2026