// Security & privacy

What Termax knows about you – and what it doesn't.

Termax holds the keys to your servers. So here is, in plain words, which data reaches us, which never does – and where the exceptions are.

As of September 2026 · details in the privacy policy (German)


// Transparency

What our server sees – and what it never does

Without an account it sees none of this: your connections then stay on your device only. With an account, Termax syncs a vault that only your devices can open.

What the server sees (with an account)

  • Your email address – for signing in and account emails.
  • A sign-in value derived from your password – your password itself never leaves your device.
  • Your vault as encrypted data blocks, plus how many entries there are, what kind they are (connection, folder, snippet) and when they last changed.
  • Your subscription status if you use Premium. Payment data stays with Stripe, not with us.
  • Server logs with IP address and time of requests, to fend off attacks. They are deleted automatically; the retention periods are in the privacy policy.

What the server never sees

  • Your server list – names, addresses, ports and user names.
  • Passwords, SSH keys and passphrases of your servers.
  • Your snippets and saved commands.
  • Your account password and the key to your vault.
  • What you type and see in the terminal – in the Windows and Android apps, Termax connects directly to your server.

This isn't just a promise, it follows from how Termax is built: the vault is encrypted on your device before it is uploaded, and the key to it is derived from your password only. That is why "Forgot password" can give you back your account, but not your vault – for that you need your recovery key. Whoever got access to our server would only find encrypted blocks.


// Said openly

Two exceptions you should know about

You only use either of them if you explicitly choose to.

The browser terminal

A browser can't open an SSH connection. In the web app, our gateway on our server in Germany does it for you: for the duration of the connection it receives the server address, user name and password or key, and the terminal session passes through it. All of that stays in memory only and is neither stored nor logged. If you don't want that, use the Windows or Android app – there is no detour through us.

Dictation (Premium)

When you click the microphone, the recording goes to our dictation service and from there to Groq in the USA for recognition (covered by the EU Standard Contractual Clauses). You see the recognized text before you insert it. Neither the recording nor the text is stored; we only count the minutes used. Without your click, Termax never touches the microphone.


// How we secure Termax

How we protect your credentials

End-to-end encrypted

The vault is encrypted with AES-256-GCM, its key derived from your password with Argon2id. Windows and Android use exactly the same scheme, so a vault created on your PC opens on your phone.

Protected on the device

Saved credentials and your sign-in are encrypted on the device – with Windows data protection (DPAPI) or the Android Keystore. On Android, none of it moves along when you switch phones or into cloud backups.

Host key verification

Termax remembers your server's key on the first connection. If it changes later, the connection is refused and you see the new fingerprint – protection against impostor servers.

Servers in Germany

Account, sync, web app, gateway and statistics run on our own server in the IONOS data center in Germany. No advertising or tracking services; the website counts visits without cookies. The only exception: for the browser terminal without an account, Cloudflare Turnstile checks that a human is in front of the screen.

Tested on every change

Every code change runs through automated tests, including the encryption. On top of that we review the apps and servers for vulnerabilities ourselves on a regular basis, most recently in September 2026, and ship fixes through the update function.


// Who is behind it

A person, not a data company

Termax is developed and run by Mark Tietz in Waltenhofen in the Bavarian Allgäu, Germany. Termax earns its money with the optional Premium subscription, not with your data. The core features are free and work without an account.

Questions about security or privacy are answered directly: support@termax.app or via the contact form. Provider details are in the imprint, what we do with which data in the privacy policy. What changed recently is listed in the release notes.