Privacy Policy
NexTerm is built to keep your credentials on your Mac. There is no account, no sync service and no analytics. This page describes exactly what the application sends, to whom, and when.
The short version. Your passwords, SSH keys and database credentials are encrypted on your own disk and never leave it. We operate no server that receives them and no account system that could. The application makes outbound requests in only five situations, all listed below, and four of them are optional or under your direct control.
Contents
1. What stays on your Mac
Connection details, passwords, SSH private keys, database credentials, API tokens, notes and application settings are stored locally in an encrypted vault. On Macs with a Secure Enclave the vault key is protected by hardware. Terminal scrollback, SFTP history and query results are held only in memory or on your local disk.
None of this is transmitted to us. We do not operate a service that receives it. There is no account to create and nothing to sync.
2. What leaves your Mac, and when
a. The servers you connect to
When you open an SSH, SFTP, database, Docker or Cloudron connection, NexTerm contacts the host you configured, using the credentials you supplied. That traffic goes directly from your Mac to your server. We are not in the path and cannot see it.
b. Licence activation and validation
To activate or check a licence, NexTerm sends your licence key and a machine instance name and identifier to Lemon Squeezy at api.lemonsqueezy.com. This is what enforces one-Mac-per-key and lets you deactivate and move machines. No other application data is included.
c. Update checks
NexTerm checks nexterm.io/updates/appcast.xml for new versions using Sparkle. Like any web request this reveals your IP address, and the request includes your current application version. We do not use this to build user profiles, and system profiling is not enabled. You can disable automatic update checks in Settings.
d. AI assistant — off unless you enable it
The AI features are disabled until you both supply your own Anthropic API key and explicitly opt in. Once enabled, the text of your request and the terminal context you include are sent to api.anthropic.com under your own API key and Anthropic's terms. Command output is passed through a redaction step before transmission, but you should treat anything you send to an AI service as leaving your control and avoid including secrets. We never receive this traffic.
e. Optional integrations
If you add a DigitalOcean account, your API token is sent to api.digitalocean.com to list and manage your droplets. If you connect to a DB2 database, NexTerm downloads the IBM JDBC driver from Maven Central (repo1.maven.org) the first time. Both are triggered only by your use of those features.
3. What we do not collect
- No analytics or usage telemetry of any kind from the application. (The website uses cookie-free, self-hosted page-view counting — see section 5.)
- No crash reports sent to us.
- No account, email address or profile is required to use the application.
- No advertising identifiers, no third-party trackers, no data sold or shared with brokers.
- No copies of your connections, credentials, commands, files or query results.
4. Purchases and billing
Purchases are handled by Lemon Squeezy as merchant of record. When you buy, Lemon Squeezy collects the information needed to process payment and comply with tax law — typically your name, email address, billing country and payment details. We never see or store your payment card details.
We receive from Lemon Squeezy the limited order information needed to provide support and honour refunds: your email address, order number, licence key and activation status. We use it only for that purpose. See the Lemon Squeezy privacy policy for how they handle your data.
5. This website
nexterm.io serves static pages. It uses Umami, a privacy-focused analytics tool that we self-host at stats.accusense.io, to count page views. Umami sets no cookies, does not fingerprint your device, and does not collect or share personal data; it records only the page visited, referrer, browser type, and country. No third-party analytics or advertising trackers are used. Web fonts are loaded from Google Fonts, which receives your IP address as part of serving them. Standard server logs may record request metadata such as IP address and user agent; these are used for operating and securing the site and are not used to identify individuals.
6. Your rights
Depending on where you live, you may have rights to access, correct, export or delete personal data held about you, and to object to certain processing. Because we hold almost no personal data, most such requests concern the order information held by Lemon Squeezy — you can contact them directly or ask us and we will help.
To exercise any right, or to have your order record deleted, email support@nexterm.io. We do not discriminate against anyone for exercising these rights. We do not sell personal information.
7. Retention
Order and licence records are retained for as long as needed to support your licence and to meet tax and accounting obligations, which are generally several years and are driven by Lemon Squeezy's obligations as merchant of record. Support email is retained until it is no longer useful.
8. Children
NexTerm is a professional developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
9. Changes
If this policy changes materially — particularly if the application ever begins transmitting something new — we will update this page and its “last updated” date, and note it in the changelog.
10. Contact
Innovative Supply LLC
support@nexterm.io