Moku is provided by the developer identified on its store listing (GitHub account: wilsen0; “we,” “us,” or “the developer”). Privacy questions and requests may be submitted through: https://github.com/wilsen0/Agent-SSH/issues
This policy describes how the Moku application (“Moku” or “the App”) handles data. Moku is an account-free, local-first SSH, Mosh, SFTP, server-management, and coding-workspace client. We do not operate a Moku cloud account service, advertising service, analytics service, or data-broker service.
1. Data stored on your device
Depending on the features you use, Moku may store the following app data locally:
- Saved host names, addresses, ports, usernames, passwords, SSH key material or local key references, jump-host settings, ProxyCommand settings, environment variables, tags, and host-key fingerprints.
- Terminal-session metadata, command snippets, SFTP path history, server status caches, coding-project/session metadata, port-forward settings, app preferences, and diagnostic logs.
- Optional AI endpoint, model, and API key settings.
- Optional backup configuration, including WebDAV username and URL, and credentials required to access a remote destination.
App databases are encrypted at rest using a device-generated key kept through the operating system’s secure-storage facility. Particularly sensitive backup and WebDAV credentials are stored through system secure storage. No storage method can guarantee absolute security, so you should also secure your device and remote accounts.
When biometric app protection is enabled, Moku asks the operating system to authenticate you. Moku does not receive or store fingerprint, face-template, or other biometric-template data.
2. Remote-server connections
When you initiate SSH, Mosh, SFTP, Wake-on-LAN, Docker, process, systemd, coding-workspace, or related operations, Moku communicates with the server or local-network device you selected. Data necessary for the requested operation—including connection address, authentication exchange, commands, terminal input/output, and transferred files—passes between your device and that destination.
These transfers are necessary to provide the feature you requested. The Moku developer does not proxy or receive this traffic. The destination server, network operator, or service administrator may process connection metadata and content according to its own configuration and policies.
3. Optional AI features
AI features are off until you configure an API endpoint, API key, and model and choose to use them. Before selected terminal text is sent to a newly configured host, Moku displays an in-app disclosure and asks you to continue.
When you use an AI feature, the following may be transmitted directly from your device to the API endpoint you configured:
- Selected terminal text, command output, prompts, follow-up messages, and limited conversation context.
- The configured model name and authentication credential required by that API.
- Technical request metadata normally exposed by a network request, such as IP address and user agent or protocol headers.
Moku requires HTTPS for remote AI endpoints; unencrypted HTTP is permitted only for a loopback address on your own device. The developer does not receive a copy of AI requests or responses. The configured AI provider may log, retain, or use the content under its own terms and privacy policy. Do not send passwords, private keys, access tokens, personal data, or other confidential information to an AI provider unless you have authority to do so and accept that provider’s practices.
4. Backups, exports, and sharing
Moku does not enable Android system cloud backup for its app data. Optional backup and sharing functions are controlled by you:
- Local file export: You may export a backup to a file or the system share sheet. A local export may be protected with a backup password. You control where an exported copy is stored or sent.
- iCloud or WebDAV: If you explicitly enable a remote destination, Moku requires a backup password and encrypts the backup on your device before upload. The selected provider receives the encrypted file and ordinary network metadata. Destination credentials are stored using system secure storage where supported.
- QR sharing: Server QR codes generated by the current App exclude passwords, key references, jump-host topology, proxy commands, custom commands, and environment variables. A QR code still contains connection metadata such as host name/address, port, and username; share it only with intended recipients.
- Operating-system share sheet: If you share a file or text with another app, that app’s privacy practices apply.
Remote backup providers retain copies until you delete them using Moku or the provider’s tools, subject to the provider’s retention rules. Backups uploaded by an older app version may not have had the same safeguards; we recommend deleting older remote copies and uploading a newly encrypted backup.
5. Camera, files, notifications, and background operation
- Camera: Used only when you open QR import. Camera frames are processed on the device and are not recorded, saved, or uploaded by Moku. Moku does not record audio.
- Files: System file pickers and app-specific storage are used when you import keys, upload/download through SFTP, edit files, or export/import backups. Moku does not request broad legacy external-storage access in the current Android release.
- Notifications and foreground service: If you enable background connection support, Android may show a persistent notification while user-started SSH or Mosh sessions are active. The notification may show a server alias and session status. You can stop the sessions from the notification or disable the feature in Settings.
- Biometric authentication: Used only to ask the operating system to unlock protected app access.
- Network and vibration: Network access provides remote connectivity; vibration may provide interaction feedback.
Permissions are requested only when required by the selected feature. Denying an optional permission may disable that feature without preventing unrelated features from working.
6. Diagnostic logs
Moku keeps bounded local diagnostic logs to help identify failures and performance problems. Logs are not automatically uploaded to the developer. They may include timestamps, feature names, status codes, server aliases or internal identifiers, file-transfer sizes, and error or stack information. We design logs not to intentionally record passwords, private-key contents, API keys, tokens, AI prompts, terminal payloads, or full SFTP paths, but an operating-system or third-party-library error could still contain unexpected details.
You decide whether to copy or share logs. Review and redact them before sending. If you submit logs through GitHub or another service, that service’s policy applies.
7. Third parties and data sharing
Moku contains no third-party advertising SDK and no developer-operated behavioral analytics or tracking SDK. Data leaves your device only as needed for a feature you direct or enable, including transfers to:
- Servers, jump hosts, proxies, or local-network devices you configure.
- An AI API endpoint you configure.
- Apple iCloud or a WebDAV service when you enable that backup destination.
- An app or person you choose through export, QR, or the operating-system share sheet.
- GitHub if you voluntarily contact us or submit an issue.
We do not sell personal data. We do not receive these feature transfers through a Moku server. Third-party destinations act under their own terms, security controls, and retention practices.
8. Retention and deletion
Local data remains on the device until you delete individual records, choose Settings → Delete all local data, clear the App’s storage through the operating system, or uninstall the App. Android automatic app-data backup is disabled in the current release. Because some operating systems may retain secure-storage entries after uninstall, use the in-app deletion action before uninstall when you need a complete user-directed wipe. The in-app action removes app databases, preferences, locally stored backup state, and app secrets, but does not delete copies you previously exported, shared, or uploaded.
To delete remote copies, use Moku’s applicable backup controls or the destination provider’s deletion tools. To delete AI-provider records, contact or use the controls of that provider. Because Moku has no user accounts and the developer does not receive your local data or feature traffic, the developer normally has no server-side copy to delete.
9. Children
Moku is a professional server-administration tool and is not directed to children under 13 (or the minimum age required in their country). We do not knowingly operate a service that collects children’s personal data. A parent or guardian who believes a child submitted data to us through our support channel should contact us.
10. Security and international transfers
Moku uses encrypted local databases, system secure storage, SSH/Mosh or HTTPS transport where applicable, and encrypted remote-backup payloads. Data sent to a destination you choose may be processed in the country where that destination or provider operates. You are responsible for selecting destinations and configurations appropriate for your legal and security requirements.
11. Changes to this policy
We may update this policy when features, laws, or data practices change. We will update the “Last Updated” date and, when appropriate, provide an in-app notice or request renewed acknowledgement. Materially different processing will not be hidden behind an old consent.
12. Contact
Developer: Moku developer listed on the app store (GitHub: wilsen0)
Privacy and deletion inquiries: https://github.com/wilsen0/Agent-SSH/issues