Conchshell has no accounts, no sign-in and no analytics. This page describes every case in which anything leaves your machine.
Last updated 3 August 2026
Your servers, hostnames, usernames, passwords, private keys and file transfers. Credentials are decrypted inside the application at the moment a connection opens and go straight to the server you are connecting to. They are never sent anywhere else, and there is no command in the application that returns a stored credential to the interface.
The application connects to the servers you configure, and to nothing else on your behalf. Those servers see what any SSH, SFTP, FTP or RDP server sees.
The application asks conchshell.app whether a newer version exists. That request carries the current version, your operating system and its architecture — the same information any download would reveal. The web server keeps ordinary access logs, which include IP addresses, for a short period for operational reasons. Update checks can be turned off in the settings.
The application collects none. No usage tracking, no crash reporting, no identifiers, nothing sent anywhere on your behalf. The website is different: with your consent it runs Google Analytics and Yandex Metrica to count visits. Nothing loads until you agree, and declining loads nothing at all.
Static pages. Before you answer the consent banner there are no third-party requests and no analytics cookies. The server keeps standard access logs, which include IP addresses. See the cookie page for what runs if you accept.
Open an issue on GitHub.