luSSH — Privacy Policy
Last updated: 8 September 2026
luSSH is an SSH client for Windows, published by Luacua. This policy explains
what the app does with data. The short version is that your servers, keys and
passwords never reach us — but the app does make one small request to a server
we run, and this policy explains exactly what that request contains.
We never see your SSH credentials, your servers, or anything you type
in a terminal. There is no account and no sign-in. SSH connections go
directly from your computer to the servers you choose; we are not in the path
and could not read them if we wanted to.
What stays on your computer
- Passwords and key passphrases — saved, only if you ask, in
the Windows Credential Manager, the operating system's own
credential store. They are never sent anywhere by luSSH.
- SSH private keys — read from the files you point at
(normally in
%USERPROFILE%\.ssh\). They are used to
authenticate and are never copied, uploaded or transmitted.
- Session profiles — host names, user names, ports, folder
layout and preferences, in
%APPDATA%\com.tbop02.lussh\profiles.json.
- Host keys — luSSH reads and writes the standard
known_hosts file in %USERPROFILE%\.ssh\, the same
file other SSH tools use.
- Terminal output and transferred files — these exist only
on your computer and on the servers you connect to.
The one request luSSH makes to us
luSSH contacts a single host that we run — lussh-slot.luacua.com —
to check for updates and security advisories, and to find out whether a sponsor
message should be shown in the sidebar. It is the only host the app is permitted
to contact; this is enforced by the app's content security policy, not merely by
convention.
- When. Once each time luSSH starts, and then at most once
every six hours while it keeps running.
- What we send. Nothing about you. The request carries no
cookies, no identifiers, no account, no query string and no custom headers.
Every copy of luSSH sends a byte-for-byte identical request, which is
deliberate: it means the request cannot distinguish one installation from
another.
- What we unavoidably see. Because it is an ordinary HTTPS
request, our host (served by Cloudflare) sees your IP address
and the time of the request, as any web server would. We do not use this to
build a profile, and we do not join it to anything else.
- What comes back. A small signed file saying whether an
update or advisory exists and whether the sponsor slot is on. It is verified
with a cryptographic signature before the app acts on it.
This check cannot currently be switched off. We say so plainly
rather than leaving you to discover it. It is also how a security advisory would
reach you, since luSSH has no automatic updater of its own. You can, of course,
block the host at your firewall; luSSH is designed so that a failed or blocked
request simply means nothing is shown.
Sponsorship
luSSH may show a small sponsor image at the bottom of the sidebar, always
labelled as such. At the time of writing it is switched off.
- No personal information is sent to any advertiser. We do
not use an advertising network's script or tag. The app does not run
advertiser code at all — it displays a single image served from our own
host and nothing else.
- There is no interest-based advertising, no advertising
identifier, no profiling and no tracking pixels. Because we send advertisers
nothing about you, there is nothing to opt out of.
- If you click a sponsor message, the link opens in your normal web browser.
From that point the destination site's own privacy policy applies.
What luSSH stores in its own window
The app keeps three small values in local browser-style storage inside its own
window: a counter used to reject out-of-date configuration, a note of the last
check, and a random number between 0 and 999 used to stage a gradual rollout.
The random number is never transmitted — it is compared against a
threshold on your own machine.
No analytics, no telemetry, no crash reporting
luSSH contains no analytics library, no usage tracking and no crash reporter.
We do not know how many sessions you open, which servers you use, or whether the
app crashed.
Children
luSSH is a developer tool and is not directed at children.
Your choices
- Saved passwords and passphrases can be removed from within the app, or from
the Windows Credential Manager directly.
- Deleting
%APPDATA%\com.tbop02.lussh\ removes your profiles and
preferences.
- Uninstalling luSSH stops the update check. Blocking
lussh-slot.luacua.com at your firewall also stops it, at the
cost of not receiving security advisories.
Changes to this policy
If luSSH begins collecting or transmitting anything not described here, this
page will be updated before that version is released, and the date at the top
will change.
Contact
Questions about this policy: tbop02@gmail.com