Termex
Privacy Policy
Last updated: 3 July 2026 Controller: MAGRATHEAN UK LTD. Company number: 16955343 Registered office: 16 Caledonian Court, West Street, Watford, England, WD17 1RY Privacy contact: [email protected] Security contact: [email protected] This Privacy Policy explains how MAGRATHEAN UK LTD. (“Magrathean”, “we”, “us”, or “our”) processes personal data in connection with Termex, our website, App Store administration, support, security, subscriptions, communications, and related product operations. Termex is an iOS and iPadOS SSH client for terminal work, tmux continuity, SFTP transfer, port forwarding, SOCKS proxying, jump hosts, shell integration, snippets, diagnostics, archive import/export, Tailnet Import, and related local server-profile functionality. The important point is that Termex is designed primarily as a client-side app. Termex connects directly from your device to the SSH hosts, SFTP servers, jump hosts, proxy targets, local network services, Tailscale API, DNS resolvers, Apple services, and other endpoints that you configure or choose. Magrathean does not operate a relay for your SSH sessions, terminal content, transferred files, credentials, private keys, passphrases, known-host store, or infrastructure.
Contents
Scope Controller and data-protection roles Data processed locally by Termex Secrets and sensitive operational data Optional Apple-only sync Data Magrathean does not normally receive from the app Network communication Local network discovery SFTP transfers, remote files, and file data Diagnostics, support bundles, logs, and transcripts Tailnet Import and Tailscale API SSHFP Check and DNS-over-HTTPS StoreKit and subscription state Website cookies, analytics, and similar technologies App analytics, advertising, tracking, and crash reports App permissions and platform surfaces Lawful bases Sharing and recipients International transfers Retention
Scope
This Policy applies to personal data that Magrathean processes as controller for:
- the Termex website and legal pages;
- App Store administration and subscription support;
- customer support and security communications;
- product administration;
- voluntary diagnostics or support material you send to us;
- business, legal, tax, accounting, and compliance records;
- direct communications with Magrathean.
This Policy also explains local app processing, Apple/iCloud sync, StoreKit, Tailscale API use, Cloudflare DNS-over-HTTPS use, diagnostics, exports, and other product behaviour, even where Magrathean does not receive the data.
Controller and data-protection roles
MAGRATHEAN UK LTD., a company registered in England and Wales with company number 16955343 and registered office at 16 Caledonian Court, West Street, Watford, England, WD17 1RY, is the controller for personal data that Magrathean processes for the Termex website, App Store administration, support, security, customer communications, and business operations.
For data on servers, accounts, files, networks, customer systems, employer systems, tailnets, or infrastructure that you connect to or import, the relevant controller is usually you, your employer, your customer, the server owner, the hosting provider, the network operator, the account owner, or another third party. Magrathean is not normally a processor for that data merely because you use Termex locally on your device.
Apple, Tailscale, Cloudflare, remote-host providers, hosting providers, network operators, DNS resolvers, VPN providers, email providers, app-store providers, and support tools may be separate controllers or providers for their own processing.
If a separate written data-processing agreement signed by Magrathean says that Magrathean acts as a processor for a specific customer or enterprise service, that written agreement controls for that processing.
Data processed locally by Termex
Termex may process and store the following categories of data locally on your device:
- server profiles, labels, hostnames, IP addresses, ports, usernames, aliases, folders, tags, workspaces, route state, and preferences;
- SSH config imports and selected metadata from imported configuration;
- proxy settings, jump-host settings, proxy chains, port-forwarding rules, SOCKS/dynamic-forwarding settings, and agent-forwarding configuration;
- authentication mode, credential references, password references, key references, certificate references, passphrase prompts, unlock state, and passphrase-cache settings;
- SSH passwords, private keys, passphrases, public keys, certificates, certificate metadata, Secure Enclave key references, security-key or hardware-signing metadata where supported, and related key records;
- known-host entries, host-key fingerprints, public host keys, trust decisions, trust prompts, SSHFP settings, and trust events;
- terminal session metadata, connection state, tmux session names, tmux working-directory settings, current-directory state from shell integration, persistent-session state, reconnection state, route/restore state, active session counts, and Live Activity state;
- terminal settings, terminal type, text encoding, mouse reporting, option-as-meta setting, clipboard-writing setting, keepalive settings, connection timeouts, bell setting, idle timeout, rendering backend, font settings, and theme settings;
- snippets, startup commands, startup snippet commands, startup environment variable names and values, command-palette entries, recent command metadata, and automation state;
- SFTP and remote-file-browser data, including filenames, source and destination paths, file sizes, transfer progress, transfer state, verification results, SHA-256 status, resumable progress, cached folder metadata, and recent transfer history;
- diagnostics, connection reports, structured SSH errors, local app logs, session events, terminal transcripts or excerpts where generated locally, and support archive content if you create it;
- encrypted archive export/import files and related migration material if you create them;
- Tailnet Import configuration, tailnet identifier, imported device metadata, SSH username for imported devices, and optional Tailscale API token if you choose to remember it;
- onboarding state, demo mode, subscription entitlement cache, settings, local network permission state, and local logs.
Secrets are intended to be stored in Keychain-backed storage or platform-protected stores. Syncable metadata is kept separate from device-local secrets where the app architecture allows.
Secrets and sensitive operational data
Termex may process high-risk security material, including SSH passwords, private keys, passphrases, API tokens, certificates, known-host records, hostnames, usernames, jump-host routes, server paths, snippets, commands, environment variables, terminal output, diagnostics, and file-transfer metadata.
You should treat this material as sensitive. Do not put secrets, customer data, regulated data, private keys, passwords, passphrases, API tokens, or confidential business information into names, labels, comments, snippets, startup commands, environment variables, hostnames, file paths, diagnostics, screenshots, transcripts, or support messages unless you are authorised and understand where that data may be stored, synced, exported, or shared.
Optional Apple-only sync
Termex may offer a local-only mode and an optional Apple/iCloud sync mode.
If Apple-only sync is enabled, Apple/iCloud may sync selected metadata linked to your Apple ID. This may include:
- server names, hostnames or IP addresses, ports, usernames, aliases, folders, workspaces, and preferences;
- jump-host references, proxy references, proxy chains, port-forward rules, SOCKS/dynamic-forwarding settings, and agent-forwarding settings;
- persistent tmux settings, working directories, startup commands, selected startup snippet commands, terminal settings, transport type, connection settings, and environment variable names and values;
- key metadata, public key material, key type, key fingerprints, comments, certificate references, and key record identifiers;
- certificate metadata, public certificate/key material, certificate fingerprints, comments, principals, validity dates, signer metadata, and certificate record identifiers;
- snippets, snippet names, snippet commands, insert/send mode, sort order, and creation dates;
- workspace names and server references.
Passwords, private keys, passphrases, known-host material, transfer records, session logs, and private terminal transcripts are intended to remain device-local unless a feature explicitly says otherwise or you export, share, back up, or sync them through another service.
Apple processes iCloud and Apple platform data under Apple’s own terms and privacy notices. Magrathean does not control Apple’s iCloud account handling, Apple ID security, Apple backups, Apple device sync, family sharing, or Apple retention.
Data Magrathean does not normally receive from the app
Magrathean does not normally receive, collect, or operate server-side storage for your:
- SSH credentials;
- private keys;
- passphrases;
- terminal content;
- remote files;
- transferred files;
- known-host stores;
- server lists;
- hostnames;
- usernames;
- session logs;
- transfer history;
- diagnostics;
- transcripts;
- Tailnet device records;
- Tailscale API tokens;
- local network discovery results;
- app settings;
- snippets;
- startup commands;
- environment variables.
Magrathean receives this kind of material only if you deliberately send it to us, for example by email, support request, security report, diagnostics bundle, screenshot, screen recording, crash report forwarding, issue tracker, cloud link, or another support channel.
Apple, Tailscale, Cloudflare, remote hosts, network operators, DNS resolvers, VPN providers, ISPs, mobile carriers, employers, customers, and other endpoints you choose may process related data as described in this Policy and in their own terms.
We do not sell personal data.
Network communication
Depending on the features you use, Termex may connect directly from your device to:
- SSH hosts, jump hosts, bastion hosts, SFTP servers, forwarded destinations, SOCKS destinations, and proxy targets you configure;
- local network services where you use local connection or discovery features;
- Apple services for App Store distribution, StoreKit subscriptions, restore purchases, transaction updates, updates, iCloud sync when enabled, Live Activities and notifications where handled by the platform, Apple diagnostics where enabled by the operating system, and platform operation;
- Tailscale API where you use Tailnet Import;
- Cloudflare DNS-over-HTTPS, or another configured resolver, where you enable SSHFP Check;
- Magrathean websites when you open legal, support, release-note, product, or documentation links;
- support channels only when you deliberately contact us or send material.
Servers, network operators, hosting providers, Apple, Tailscale, Cloudflare, DNS resolvers, mobile carriers, VPN providers, ISPs, employers, customers, and other endpoints may process IP addresses, hostnames, request metadata, timing metadata, connection metadata, and account data under their own terms.
Magrathean does not receive your session or server metadata unless you send it to us.
Local network discovery
Where Termex offers or uses local connection discovery, the app may process local IP addresses, hostnames, service names, Bonjour records, ports, and related local network metadata visible to your device.
Magrathean does not receive local discovery results unless you deliberately include them in diagnostics, screenshots, support messages, transcripts, or other material you send to us.
Local network permission prompts are controlled by Apple’s operating system.
SFTP transfers, remote files, and file data
SFTP transfers occur over the SSH connection you initiate. Termex may process file names, paths, sizes, timestamps, transfer progress, remote directory listings, local paths, verification results, hash status, resumable progress, and local transfer records.
Magrathean does not receive transferred files, remote file contents, local file contents, or remote directory listings unless you deliberately send them to us.
You are responsible for the confidentiality, integrity, encryption, backup, destination permissions, and legal basis for files you transfer or browse.
Diagnostics, support bundles, logs, and transcripts
Termex can generate diagnostics and support or migration archives locally. These may include server metadata, connection errors, configuration details, connection reports, session events, local logs, terminal transcripts or excerpts, transfer metadata, app version, build number, system version, device model, and other operational details.
Termex may attempt to redact common secrets such as private keys, authorisation headers, cookies, API keys, tokens, passwords, passphrases, and secrets. Redaction is not guaranteed.
Nothing leaves your device through Magrathean support unless you deliberately share it. If you share diagnostics, transcripts, screenshots, screen recordings, archives, or logs with Magrathean or another recipient, that recipient may process the material you send.
Before sharing, review and redact diagnostics. Do not send secrets, private keys, passwords, passphrases, API tokens, customer data, regulated data, server files, proprietary code, or unnecessary personal data unless we have agreed a secure route and you are authorised to disclose it.
Tailnet Import and Tailscale API
If you use Tailnet Import, Termex sends your tailnet identifier and API token directly from your device to the Tailscale API to fetch device records.
The Tailscale API response may include device IDs, node IDs, names, hostnames, addresses, users, operating system/client version, authorisation state, connection-blocking status, and related device metadata.
Termex uses this information to display import candidates and create local server profiles for selected devices. Magrathean does not receive the token, request, response, or imported records unless you send them to us.
If you enable “Remember token”, Termex may store the Tailscale API token in Keychain-backed storage or another platform-protected secure store on your device. If you do not enable “Remember token”, Termex uses the token for the request and should not deliberately retain it, although the operating system, network stack, Tailscale, or device state may process it transiently.
Tailscale is a separate provider and may process your API request, token, IP address, account data, tailnet data, and device metadata under its own terms and privacy notice.
SSHFP Check and DNS-over-HTTPS
If SSHFP Check is enabled, Termex may query the configured host name as an SSHFP DNS query using DNS-over-HTTPS through Cloudflare’s resolver by default unless a build, setting, or later version uses another resolver.
Cloudflare or another resolver may receive the queried hostname, your IP address, request metadata, and response metadata. This is used to help validate SSH host keys. Magrathean does not receive the query or response unless you send diagnostics or support material to us.
SSHFP Check is optional unless a future build or policy states otherwise.
StoreKit and subscription state
Termex may use Apple StoreKit to load subscription products, show pricing, initiate purchases, restore purchases, check current entitlements, check trial status, listen for transaction updates, verify transactions, cache entitlement status locally, and unlock paid features.
Apple manages App Store billing and may process Apple ID, purchase, tax, region, payment, refund, subscription, device, and fraud-prevention data under Apple’s terms and privacy notices. Magrathean does not receive your full payment-card details from Apple.
Magrathean may receive limited App Store administration, sales, proceeds, subscription, refund, territory, campaign, crash, analytics, or financial information from Apple through Apple developer tools, depending on Apple’s reporting and your Apple settings. This information is used for product administration, accounting, support, fraud prevention, and legal compliance.
UK 2026 data-law update: recognised legitimate interests, complaints and local-first boundaries
This notice is drafted for the UK GDPR, the Data Protection Act 2018 and PECR as amended by the Data (Use and Access) Act 2025 where those laws apply.
For ordinary website operation, support, app administration, analytics, B2B outreach, service delivery, account administration and security logging, we rely on the lawful bases stated elsewhere in this notice. We may rely on the UK GDPR recognised legitimate interests basis only where the relevant statutory condition is available, such as prevention or detection of crime, safeguarding, emergency response, national or public security, or disclosure to an organisation or public authority that needs the information for a public task. We do not rely on recognised legitimate interests for routine commercial marketing, ordinary app analytics, cross-site advertising, retargeting or general prospecting.
Termex is local-first for SSH profiles, terminal sessions, known hosts, SFTP history, snippets, keys, passphrases, local transcripts and connection state. Magrathean normally cannot search, delete or export data stored on your device or remote hosts unless you send it to us or give us access under a separate written support arrangement.
If a support request, bug report, screenshot, export, diagnostic bundle or legal request contains secrets, tokens, keys, passwords, private footage, raw tenant exports, special-category data, children’s data, criminal-offence data or other high-risk material, we may reject, delete, quarantine, return or restrict that material unless a secure written handling process has been agreed. Sending material to Magrathean does not make Magrathean responsible for data we did not request and cannot reasonably inspect before receipt.
Cookie and storage-technology implementation note
Where a Magrathean website or product page uses cookies, local storage, tracking pixels, scripts, tags, link decoration, device/browser signals or similar storage/access technologies, those technologies should be read in three groups:
- strictly necessary, security, anti-abuse, load-balancing, rate-limiting, form-protection and fraud-prevention technologies;
- low-risk analytics or measurement technologies where an applicable UK PECR exception is available and the use is not for advertising, cross-site tracking or user-level profiling;
- advertising, remarketing, cross-site tracking, tag-based conversion measurement, fingerprinting, behavioural profiling or similar technologies, if enabled.
The operational position remains that the relevant websites may run cookies, analytics, measurement, attribution and similar technologies by default without a consent banner, as described in this notice. You can block or delete cookies and similar technologies through browser, device, DNS, content-blocking or network controls. This notice describes the processing; the live cookie/tag configuration should be kept aligned with this notice and with any product-specific statement.
Website cookies, analytics, and similar technologies
This website uses cookies and similar technologies — including first- and third-party analytics, measurement, and tracking tools such as Google Analytics — to understand how the site is used, measure traffic and campaigns, improve content, and protect the site. These technologies are active by default when you visit the site. We do not display a cookie consent banner and we do not ask you to opt in before analytics run.
Acceptance. By accessing, browsing, or continuing to use this website, you accept the use of the cookies, analytics, measurement, attribution, and tracking technologies described in this section, and you acknowledge that they are active by default from your first visit without a consent banner. If you do not accept this, use the browser-level controls described in this section or stop using the website. This acceptance operates alongside — and does not replace — the lawful basis stated in this section, and you may object to our legitimate-interests processing at any time.
We may process: pages viewed, events and interactions, referring source, UTM and ad-click identifiers (such as gclid, gbraid, wbraid, and msclkid), approximate location derived from your IP address, and device, browser, and operating-system information, together with similar usage data.
Lawful basis. For website analytics, measurement, and attribution we rely on our legitimate interests (Article 6(1)(f) UK GDPR) in understanding and improving how our website and campaigns perform and in keeping the site secure. We do not sell personal data, and we do not use this data to make decisions producing legal or similarly significant effects about you.
Your controls. Because we do not operate a consent banner, you control these technologies yourself. You can:
- block or delete cookies in your browser settings;
- install the Google Analytics opt-out browser add-on (
tools.google.com/dlpage/gaoptout); - use privacy or content-blocking extensions; or
- object to our legitimate-interests processing by emailing [email protected].
We do not currently respond to browser Do-Not-Track signals. Blocking cookies may limit some features but will not stop you reading the site.
App-local storage used to provide Termex features is described elsewhere in this Policy. This website disclosure does not change how the Termex app itself handles data: the app remains local-first and does not use third-party analytics, advertising, or tracking SDKs, as set out below.
App analytics, advertising, tracking, and crash reports
This section is about the Termex app. Website analytics and tracking are described separately above under “Website cookies, analytics, and similar technologies”.
The Termex app does not use third-party advertising SDKs, behavioural advertising, data-broker tracking, cross-app tracking, or tracking for advertising purposes.
Termex does not request Apple’s App Tracking Transparency permission because it is not intended to track your activity across other companies’ apps or websites for advertising or data-broker purposes.
Termex does not intentionally integrate third-party analytics or crash-reporting services unless this Policy is updated to identify them. Apple may provide crash reports, performance metrics, App Store analytics, or diagnostic information to Magrathean through Apple developer tools if your Apple settings and Apple’s terms permit it. Those reports are controlled by Apple and should not include your SSH credentials, private keys, passphrases, terminal content, or transferred files unless such data is unexpectedly captured by the operating system or included in material you send.
App permissions and platform surfaces
Depending on features used, Termex may request or use Apple platform permissions or capabilities such as:
- local network access for nearby/local SSH hosts and local discovery;
- file picker or document access for importing keys, certificates, SSH config, uploading files, downloading files, and exporting diagnostics or transcripts;
- iCloud/CloudKit if Apple-only sync is enabled;
- Keychain or platform secure storage for secrets;
- notifications, Live Activities, widgets, or Shortcuts where available and enabled;
- background execution for limited session, transfer, or cleanup behaviour permitted by Apple;
- clipboard access where terminal clipboard-writing features are enabled.
Permission prompts and platform controls are handled by Apple’s operating system. You can manage many permissions in device settings.
Lawful bases
For personal data Magrathean processes as controller, we rely on the following lawful bases under the UK GDPR and, where applicable, EU GDPR.
| Processing | Examples | Lawful basis |
|---|---|---|
| Providing requested app functionality and support | Responding to support requests, handling product queries, administering subscriptions, troubleshooting | Contract, or steps before contract |
| Product administration and security | Security reports, abuse prevention, vulnerability handling, logs for website security, fraud prevention | Legitimate interests |
| Website analytics, measurement, and attribution | Google Analytics and similar cookies/tracking technologies that run by default on this website to measure traffic and campaigns and improve and secure the site | Legitimate interests (Article 6(1)(f) UK GDPR) |
| Business records | Accounting, tax, company records, App Store proceeds, contracts, legal correspondence | Legal obligation and legitimate interests |
| Communications | Service messages, support replies, security notices, product notices | Contract and legitimate interests |
| Optional marketing, if used | Mailing list or promotional email | Consent or soft opt-in where legally available |
| Legal claims and compliance | Handling disputes, enforcing terms, responding to lawful requests | Legal obligation and legitimate interests |
| Local app processing | Data processed on your device to provide Termex features | Usually not received by Magrathean; where Magrathean is controller, contract and legitimate interests |
| Voluntary diagnostics | Diagnostics you choose to send to Magrathean | Consent for sending, then contract/legitimate interests for support and security |
Where data belongs to your employer, customer, server owner, network operator, or another third party, you are responsible for ensuring you have a lawful basis and authority to process it using Termex.
Sharing and recipients
We do not sell personal data and do not use app data for advertising.
We may share or process personal data with the following categories of recipients where necessary:
- Apple for App Store distribution, StoreKit subscriptions, iCloud, TestFlight, crash reporting, App Store administration, developer tools, and platform operation;
- Tailscale where you use Tailnet Import;
- Cloudflare or another DNS-over-HTTPS resolver where SSHFP Check is enabled;
- hosting, domain, DNS, email, security, monitoring, issue-tracking, support, backup, legal, accounting, tax, payment-administration, and business-operation providers;
- professional advisers, insurers, auditors, banks, and corporate-service providers;
- public authorities, courts, regulators, law enforcement, or third parties where required by law or necessary to protect rights, security, or safety;
- acquirers, successors, or counterparties in a merger, acquisition, financing, reorganisation, sale of assets, or change of control, subject to appropriate confidentiality and legal controls.
Server data, credentials, diagnostics, transcripts, transfer details, screenshots, and support bundles are shared with Magrathean only if you deliberately send them.
International transfers
We primarily operate from the United Kingdom. Apple, Tailscale, Cloudflare, hosting providers, email providers, support providers, security providers, accounting providers, and other service providers may process personal data outside the UK or EEA.
Where required, we use appropriate safeguards such as adequacy regulations, adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement, the UK Addendum, processor terms, or other lawful transfer mechanisms.
Connections you initiate to servers, networks, jump hosts, proxies, forwarded destinations, Tailscale, DNS resolvers, or other endpoints occur directly from your device to those destinations and are governed by those providers or operators.
You can contact us for more information about the safeguards used for a relevant international transfer and, where applicable, how to obtain a copy of those safeguards.
Retention
Local app data remains on your device until you clear it, delete server profiles, delete keys, clear known hosts, clear transfer history, clear diagnostics, delete archives, uninstall the app, disable sync where applicable, or the operating system removes it.
Apple StoreKit, iCloud, Apple ID, App Store, TestFlight, crash, and developer records are handled by Apple under Apple’s terms and retention practices.
Tailscale API records are handled by Tailscale under Tailscale’s terms and retention practices. Cloudflare DNS-over-HTTPS records are handled by Cloudflare under Cloudflare’s terms and retention practices.
For records Magrathean controls, we use the following retention criteria:
| Record type | Typical retention |
|---|---|
| Support emails and customer communications | Up to 24 months after the issue is closed, unless needed longer for legal, security, abuse-prevention, or audit reasons |
| Voluntary diagnostics and support bundles | Normally deleted within 30 days after the support issue is resolved, and in any event within 90 days, unless needed for a security incident, dispute, or legal claim |
| Security reports and vulnerability correspondence | As long as needed to investigate, remediate, document, defend, and prevent recurrence; normally up to 6 years for significant reports |
| Website security logs | As short as reasonably practical for security and abuse prevention, normally no more than 12 months unless needed for investigation |
| App Store, subscription, accounting, tax, company, and financial records | Normally up to 6 years, or longer if required by law |
| Legal claims and disputes | As long as needed for the claim, limitation period, settlement, enforcement, or legal hold |
| Marketing consent records, if used | Until consent is withdrawn, then retained as necessary to evidence suppression or withdrawal |
We delete, anonymise, or aggregate records when they are no longer needed.
Security
Termex is designed around local SSH, direct SFTP over SSH, Keychain-backed secrets, device-local credential storage, known-host enforcement, strict trust prompts, optional SSHFP verification, optional Apple-only sync for selected metadata, and local diagnostics/export controls.
However, no method of storage, transmission, remote access, cryptography, app sandboxing, platform security, sync, or support handling is completely secure.
You remain responsible for securing:
- your device and device passcode;
- Apple ID and iCloud account;
- device backups;
- SSH servers, user accounts, file permissions, and host keys;
- passwords, private keys, passphrases, certificates, security keys, API tokens, and agent-forwarding boundaries;
- Tailscale accounts and API tokens;
- support bundles, diagnostics, screenshots, screen recordings, archives, transcripts, and exports;
- networks, VPNs, proxies, jump hosts, DNS, and remote destinations.
If you believe you have found a vulnerability in Termex, contact [email protected].
Children and minors
Termex is not directed to children under 16, or under the minimum digital-consent age in their country if different. Termex is not intended for the Apple Kids category.
We do not knowingly collect personal data from children through the app. Minors should use Termex only with parent or guardian involvement and only for systems they are authorised to access.
If you believe a child has sent personal data to Magrathean, contact us and we will take appropriate steps.
EU representative and EEA users
If you are in the European Economic Area, you may contact us at [email protected]. If EU law requires us to appoint an EU representative for Termex, we will list the representative’s name, address, and contact details in this section.
You may also complain to the supervisory authority in your EEA Member State.
Data Protection Officer
We have not appointed a statutory Data Protection Officer because we do not currently consider the statutory appointment criteria to be met. You can contact [email protected] about privacy matters.
If this changes, we will update this Policy.
Automated decision-making and profiling
Termex does not make solely automated decisions about you that produce legal effects or similarly significant effects.
Subscription entitlement checks, transaction verification, connection diagnostics, trust prompts, transfer warnings, local ranking, command-palette behaviour, operational warnings, and security messages are used to provide app functionality and remain subject to user review.
Termex does not profile you for advertising.
Your choices and controls
You can control many kinds of Termex data directly on your device:
- delete server profiles;
- delete imported keys and certificates;
- clear saved passphrases where stored;
- clear known hosts;
- clear transfer history;
- clear local diagnostics;
- delete generated diagnostics bundles;
- delete transcript exports;
- delete encrypted archives;
- disable or change Apple-only sync;
- clear or avoid remembering Tailnet API tokens;
- manage local network, iCloud, notification, file, and other permissions in Apple settings;
- cancel subscriptions through Apple;
- uninstall the app.
Deleting the app may not delete data already synced through Apple/iCloud, backed up through Apple, sent to support, shared with third parties, stored by Tailscale, logged by Cloudflare, or retained by remote servers. Manage those services through the relevant provider.
Your data-protection rights
Under the UK GDPR, Data Protection Act 2018, and where applicable EU GDPR, you may have rights to:
- access personal data we hold about you;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data where the right applies;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority.
To exercise rights against personal data Magrathean controls, contact [email protected]. We may need information to verify the request.
Magrathean usually cannot access or delete data that is only on your device, in your iCloud account, on your remote servers, in your Tailscale account, in Cloudflare resolver logs, in Apple systems, or held by your employer, customer, server owner, network operator, hosting provider, or another third-party controller. You should direct requests about that data to the relevant controller or use the controls in the relevant service.
You have the right to object to processing based on our legitimate interests. We will stop that processing unless we can show compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is needed for legal claims.
Complaints and rights-request handling
You may complain to Magrathean first by emailing [email protected]. Please include enough information for us to identify the product, website, account, support thread, submission, export, device-local issue or customer engagement involved. Do not include passwords, private keys, bearer tokens, recovery codes or unnecessary raw personal data in the first message.
Where UK data-protection law requires complaint handling, we will acknowledge a data-protection complaint within 30 days and respond without undue delay. A complaint is separate from a UK GDPR rights request, but we may treat the same message as both where it asks us to exercise a data-protection right.
For rights requests, we normally respond without undue delay and within one month of receipt, or within one month of receiving information reasonably needed to confirm your identity or clarify the request. Where the law permits it, we may extend the response period by up to two further months for complex or multiple requests. Searches for access requests will be reasonable and proportionate. For local-first product data, we can usually act only on data Magrathean actually controls or has received.
You may also complain to the UK Information Commissioner’s Office (ICO): https://ico.org.uk/make-a-complaint/. We would prefer the chance to address the issue first, but you are not required to contact us before contacting the ICO.
If EU GDPR applies to your use, you may also complain to a supervisory authority in the EU Member State where you live, where you work or where you believe an infringement occurred.
Changes
We may update this Policy to reflect product changes, legal changes, provider changes, App Store changes, security changes, or operational changes.
The “Last updated” date shows when the current version took effect. Material changes may be notified through the app, website, App Store listing, release notes, customer channel, or another appropriate route.
Contact
Privacy questions: [email protected] Security reports: [email protected]
MAGRATHEAN UK LTD. Company No. 16955343 16 Caledonian Court West Street Watford England WD17 1RY