Privacy & storage

Privacy Policy

How VPS Manager handles information in the app and on this website.

VPS Manager lets you connect directly to servers you choose over SSH and SFTP. No VPS Manager account or hosted management backend is required. This policy covers the app and this website.

Information handled by the app

When you set up a connection, the app handles the profile name, server address and port, username, authentication credentials, shell preference and trusted host fingerprint you provide. During a session it handles your commands and terminal input, server responses and logs, directory listings, file metadata and files you choose to transfer. This information can contain personal or sensitive data.

The app also handles custom command packs, including their names, descriptions, scripts, enabled selections and local review records. It reads private keys, packs and upload files only after you select them. An imported file remains at its original location.

How information is used and shared

Profiles and credentials are used to authenticate to the server you select. Trusted fingerprints help detect a changed server identity. Passwords, commands, sudo input and file data travel over the encrypted SSH or SFTP connection to that server. A private key is used locally to sign authentication messages; the key itself is not uploaded to a VPS Manager service. Your server can retain authentication, shell, command or file records under its own policies.

Terminal input goes directly to your selected server. Reviewed Scripts separately lets you inspect a command before running it. Syntax highlighting and command suggestions run on your device, without sending your scripts to a completion or AI service. The app does not automatically send profiles, credentials, commands or server output to the publisher.

Storage and security

Saved profiles, credentials, trusted fingerprints, custom packs, enabled selections and review records are stored in an AES-256-GCM encrypted vault in the app’s private data directory. The vault key is held separately through the operating system’s secure storage. Android automatic backup is disabled in the current build. Device protection and backup behaviour differ by platform; encryption does not protect an unlocked or compromised device.

The app does not save Terminal input or output as a local transcript. Reviewed-script history and output, Terminal scrollback and reading snapshots are held in memory during use. Your remote shell may keep its own history. Avoid putting secrets in command text or copied output.

Downloads, exports and other recipients

Downloads first become temporary plaintext files in the app’s private cache. You can save or share a completed download with a destination you choose. If that step is cancelled or cannot be confirmed, the temporary copy can remain for another attempt. You can discard it in the app; otherwise the app attempts to remove transfer-cache files on its next launch. Do not rely on next-launch cleanup if you never reopen the app.

Sharing a command pack creates a plaintext JSON copy that can include secrets you wrote in its scripts. Saved connection credentials and local review marks are not automatically included. Files or packs you export can be retained by the receiving app or service. Uploaded files and server records remain subject to the selected server’s permissions and retention rules.

Retention and deletion

Saved profiles and credentials remain in the local vault until you delete the connection or clear the app’s data. A trusted fingerprint may remain while another profile uses the same server endpoint; the app provides a trust-reset action. Custom packs remain until you delete them or clear app data. Deleting a connection does not delete your pack library.

Reviewed-script history is cleared on disconnect and can be cleared in the app. Clearing app data removes the local vault and key; there is no built-in credential recovery service. These actions do not delete original imports, exported copies, remote server records or data held by other apps. Delete those through their respective locations.

This website and support

This static website has no third-party analytics, advertising trackers, externally loaded fonts, cookies or contact forms. The hosting server processes ordinary request details such as IP address, browser information and access time. Nginx access and error logs rotate daily and retain up to 14 previous logs; backups or incident records, if any, still need publisher review.

If you email the developer, your email provider and the recipient process the message and anything you attach. Please remove passwords, private keys and unnecessary server logs before sending. Contact privacy@gevawo.com for privacy enquiries or support@gevawo.com for app support. Support-message access, retention and deletion practices are being confirmed.

Changes to this policy

This page will be updated when the app or website’s data handling changes. The dated notice above identifies this draft; a final effective date will be added after publisher review.