Privacy Policy

Revision of 23 September 2026. There are no accounts. The website keeps a web server log with a shortened network address and, with your permission, counts visits. The application sends usage statistics every three hours under a permanent identifier of the installation, and that can be switched off. A copy with a licence key also downloads a list of revoked licences after each launch and then daily. Buying a licence stores an e-mail address and a licence number. Your servers, logins, passwords, keys and session contents are not collected and cannot be.

1. General provisions

1.1. This Privacy Policy (the “Policy”) governs how information passed by the User when using the Conchshell application and the conchshell.app website (the “Service”) is processed and protected.

1.2. By using the Service, the User confirms their agreement with this Policy. A User who does not agree must stop using the Service.

1.3. The Service is run by a private individual, not a company. Contact details for any question about this Policy are in section 8.

2. Information collected

2.1. There is no registration: the Service has no accounts, logins or passwords, so no account identifiers are collected.

2.2. The conchshell.app website, its update server and the statistics address t.conchshell.app keep web server logs: a shortened network address (IPv4 to /24, IPv6 to /56), the country as determined by Cloudflare, the address requested and the time of the request; the website and update server logs also keep the browser or client string and the referring page. For the statistics address, the address requested is the whole statistics request, so that log links the identifier described in 2.5 with the shortened network address and the country. Full addresses stopped being written to disk on 8 August 2026, and the records made before then have been removed. Addresses that clients put into their own request headers are not logged either.

2.3. The website also collects aggregate visit statistics through Google Analytics and Yandex Metrica. Where consent is required, these are enabled only after consent is given; declining does not affect how the website works. What exactly they set is described on the Cookie page.

2.4. Usage statistics. While it is running, the application sends a request to t.conchshell.app every three hours; the first one goes about a minute after the first launch. The request contains: a permanent identifier of the installation (see 2.5); the date of the first launch; the application version; the family and major version of the operating system; the architecture the build was made for; the interface language; whether a licence is active; how many connections are saved, in ranges (0, 1–5, 6–20, 21–100, over 100); whether a session has ever been opened; on the desktop, whether the Security tab of the settings has ever been opened and whether the Buy button has ever been pressed; the kind of the day’s most recent failed connection (authentication, timeout, server identity, other, or none); and, for SSH, SFTP, FTP, RDP, VNC and the local terminal, how many sessions were opened that day, in ranges (0, 1–2, 3–10, 11–50, over 50). Days are counted in UTC.

2.5. The identifier is derived from a random secret created on first launch, kept in the application’s data folder and never sent. It contains nothing about the User, the device or the network, but it stays the same for the life of the installation — across updates, and when statistics are switched off and on again. The statistics are therefore pseudonymous, not anonymous. The identifier changes only if the file holding the secret (telemetry.json in the application’s data folder) is deleted or damaged. The request contains no server addresses or names, logins, file names or error messages, and carries no browser string or cookies.

2.6. Statistics are on by default. They are switched off in the application’s settings, under Advanced (in version 2.16 and earlier the switch is labelled “Anonymous usage statistics”); after that no statistics requests are sent. The same place shows the exact request that would be sent.

2.7. When it starts, the desktop application fetches the number of the latest version from conchshell.app. The request carries no application version, platform or identifier; its client string names only the update component and its version. A new version is downloaded only when the User chooses to install it. At present the automatic check cannot be switched off; a switch for it is being added to the settings in the next version.

2.8. After an update, the application downloads the list of changes from conchshell.app to show what is new; if that fails, it tries again at the next launch until the list has been shown. The request is made by the application’s built-in browser and carries its browser string.

2.9. A copy with a licence key downloads a signed list of revoked licences from conchshell.app about a minute and a half after each launch, then every 24 hours while it runs, and once right after a key is entered. The request contains no key, licence number or identifier; it does not depend on the statistics setting and stops when the key is removed from the device. Entering a short licence code sends that code to conchshell.app to exchange it for a key.

2.10. Synchronisation does not pass through servers of the Administration: the encrypted vault is written to a folder the User chooses, or passed directly between the User’s own paired devices over the local network.

2.11. Buying a licence stores the User’s e-mail address and the identifier of the licence issued. Both are needed to issue the licence and to reissue it on request.

2.12. The Service does not ask the User for identity documents, photographs or other personal information beyond the minimum needed to operate.

2.13. The following are not collected and cannot be: the addresses and names of the User’s servers, logins, passwords, keys, session contents, the names and contents of transferred files, and connection history (only the counts in ranges described in 2.4 are sent). None of it is ever sent to the Administration; synchronisation moves it, in encrypted form, only between the User’s own devices and storage.

3. Use of information

3.1. The Service uses the information collected solely to: operate its functionality and deliver updates; issue, reissue and verify licences; contact the User, including for notifications and support; and analyse and improve the Service.

3.2. The information is not used for advertising and is not sold.

4. Disclosure to third parties

4.1. The Administration does not pass the data collected to third parties, except: where required by law; where necessary to meet obligations to the User; or where the User has given consent.

4.2. Payment is processed by a payment provider. Card details are handled by that provider and never reach the Administration.

4.3. The website's visit counters pass data to their providers, Google and Yandex, to the extent described on the Cookie page, and only where the User has allowed them.

4.4. The website, the update server and the statistics address are served through Cloudflare, which carries the network connection and therefore sees full network addresses.

4.5. Notices about downloads and installations reach the Administration through Telegram: for a download, the platform, version and country; for an installation, the system and its version, the architecture, the interface language, whether a licence is active, the application version and the country. Network addresses are not included. To tell repeated downloads apart, the notifier keeps the shortened addresses of downloads for 48 hours.

4.6. Licence e-mails are sent through SendPulse, which receives the buyer’s e-mail address and the message with the licence code.

5. Storage and protection

5.1. Data is kept for as long as the purpose of processing requires.

5.2. A web server log file has no time limit while it is open: it is closed when it reaches a set size, and a closed file is deleted at the first rotation after it has been closed for 30 days. At current traffic the statistics log fills in about a year.

5.3. Separately from the log, the statistics themselves are kept without network addresses or country, for the current calendar month and the three before it, and are then deleted.

5.4. Records of issued licences are kept while the licence is valid: without them a licence cannot be reissued.

5.5. The Administration takes reasonable measures to protect data but does not guarantee absolute security of information transmitted over the internet.

6. Disclaimer

6.1. The User understands and agrees that transmitting information over the internet always carries risk.

6.2. The Administration is not liable for loss, theft or disclosure of data caused by third parties or by the User themselves.

7. Changes to the Policy

7.1. The Administration may amend this Policy.

7.2. The current revision is always published on this page; its date is stated at the top of the document.

7.3. Continued use of the Service after a change means the User accepts the new revision.

8. Contact

8.1. For any question about this Policy: support@conchshell.app.

8.2. The same address is shown inside the application, under “About”, and in the footer of every page of the website.

Last updated: 2026-09-23