Effective date: 5 October 2026
Shepherdr - Client for Herdr (“Shepherdr”, “the app”) is an app for Android and iOS (iPhone and iPad). It is published on Google Play by Imperial AI Limited and on the Apple App Store by Techarge Limited (each “we”, “us” for its store). This policy explains what the app does with your information.
Summary
- We (the developer) collect no data from you. The app has no accounts, no analytics, no advertising and no crash-reporting service.
- The app never contacts Imperial AI, Techarge or any server we operate.
- The app connects only to the SSH servers that you add yourself. If you choose to open a link shown in a terminal, it opens in another app such as your browser.
- Everything you enter is stored on your device only.
- The optional one-time purchase that unlocks more than one server is processed by Google Play (Android) or the Apple App Store (iOS). We do not receive your payment details.
What Shepherdr is
Shepherdr is an independent client for herdr (https://herdr.dev), a terminal workspace manager for AI coding agents that runs on your own servers. Shepherdr is not affiliated with or endorsed by herdr.dev. It connects to your servers over SSH so that you can see and use your herdr workspaces from your phone.
Data we collect
None. We do not receive, collect, log, share or sell any personal or usage data. The app does not talk to any server of ours, and it contains no third-party analytics, advertising, tracking or crash-reporting SDKs. Its dependencies are open-source libraries for SSH (dartssh2), the terminal display (xterm), state management (flutter_riverpod), secure storage (flutter_secure_storage), device authentication (local_auth), local settings storage (shared_preferences), identifier generation (uuid) and key cryptography (pinenacl), opening links in other apps (url_launcher), and in-app purchases (in_app_purchase, which uses Google Play Billing on Android and StoreKit on iOS). None of these sends data to the developer or to third parties.
Data stored on your device
The app stores the following on your device only:
- Server details you enter: display name, host name or IP address, port, user name and authentication method. These are kept in the app’s private storage (Android SharedPreferences, iOS UserDefaults).
- Trusted host keys: the SSH host-key fingerprints you have accepted, kept in the same private storage, so that the app can warn you if a server’s key changes.
- App settings: the default terminal font size and whether the app lock is enabled, plus a yes/no flag recording that the unlock was purchased (refreshed from Google Play or the App Store each time the app starts).
- Secrets: server passwords, SSH private keys and key passphrases. These are kept in Android’s encrypted storage (flutter_secure_storage, with a key held in the Android Keystore) or, on iOS, in the Keychain, not in plain text. Passwords and passphrases are saved only if you ask the app to remember them.
Android backup is disabled for the app, and it is excluded from cloud backup and device-to-device transfer, so this data is not copied off your device by Android backup. Because secrets are bound to the device’s Keystore, they are not restored on another device. On iOS, secrets are kept in the device Keychain and are not synchronised to iCloud Keychain by the app. By default they are stored as “this device only”: they are excluded from device backups and are never restored to another iPhone or iPad. If you turn on “Include secrets in device backups” in Settings, they are included in your encrypted device backup instead. Keychain items can remain on the device after the app is uninstalled until you remove them in the app or reset the device.
Terminal content that you view is shown on screen and held in memory while you use the app. The app does not write it to storage. When a connection fails, the app may write a short, sanitised error line (server name and failure reason, never passwords or keys) to the device log (Android logcat or the iOS system log), which stays on your device and is not sent to us.
Data sent over the network
The app sends data only to the servers you configure, using SSH (an encrypted connection). This includes your login credentials (password or key-based authentication), the commands the app runs to talk to herdr on that server, and the keystrokes you type in a terminal. That data goes directly from your device to your server. We never see it. What your server does with it is governed by you and your server’s operator.
The app verifies each server’s host key, and asks you to confirm a server the first time you connect and whenever its key changes.
If you use a copy action (for example copying a public key, or a connection report from the connection details screen), the text is placed on the system clipboard at your request. Other apps on your device may be able to read the clipboard.
If you tap a web address (URL) shown in a terminal, the app asks you to confirm and then hands that URL to your device’s browser or another app that handles it. The full URL, including any path, query parameters or tokens it contains, then goes to that app and to the website it points to, under their own privacy policies. Nothing is opened without your confirmation, and the app never sends the URL to us.
Purchases
Shepherdr is free for one saved server. A one-time, non-consumable in-app purchase (“Unlimited servers”) unlocks unlimited servers. The purchase is processed entirely by Google Play Billing on Android, or by Apple’s App Store (StoreKit) on iOS, under Google’s or Apple’s terms and privacy policy. We, the developer, do not receive your payment details or card number. The app only asks Google Play or the App Store, on your device, whether the unlock has been purchased on your Google or Apple account, and keeps a local yes/no flag on your device so the unlock still works offline. The app has no accounts and no backend, so we do not receive or store your purchase history. Google or Apple handles it.
Permissions
- INTERNET: needed to open SSH connections to your servers.
- BILLING (com.android.vending.BILLING): needed to offer and verify the one-time purchase through Google Play. Payment is handled by Google Play; the app never sees your payment details.
- USE_BIOMETRIC: needed for the optional app lock, which asks for your fingerprint, face or device screen lock when opening the app. Biometric data is handled entirely by Android. The app only receives a success or failure result and never sees your biometric data. On older Android versions the device-authentication library also adds the USE_FINGERPRINT permission, used for the same purpose.
The app also contains an internal, signature-level permission added by AndroidX (DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION) that only the app itself can use and that is not user-facing. The app requests no location, contacts, camera, microphone, storage or phone permissions.
On iOS, the app asks for two permissions: Face ID (NSFaceIDUsageDescription), used only for the optional app lock, where iOS returns only success or failure and the app never sees your biometric data; and Local Network access, used only so the app can reach SSH servers on your local network. In-app purchases use the App Store and need no extra permission.
App lock and screen protection
If you turn on the app lock, the app asks you to authenticate when you open it, and it blocks screenshots and hides its content in the recent-apps view (the Android secure-window flag). On iOS, the app covers its window when it is inactive so that the app switcher does not show terminal contents; iOS does not allow an app to block screenshots.
Data retention and deletion
We hold no data, so there is nothing for us to delete. To delete the data on your device, remove individual servers, keys and saved passwords in the app, or clear the app’s storage or uninstall it in Android or iOS settings. Uninstalling removes everything the app stored.
Children
The app is a technical tool for developers and system administrators. It is not directed at children, and we do not knowingly collect information from anyone, including children.
Changes to this policy
We may update this policy, for example if the app’s behaviour changes. The latest version will be published at the same location with a new effective date. Material changes will be noted in the app’s release notes.
Contact
Google Play (Imperial AI Limited): [email protected]
Apple App Store (Techarge Limited): [email protected]