Moku Privacy Policy

Last Updated: July 22, 2026 | Effective Date: July 22, 2026

Moku is provided by the developer identified on its store listing (GitHub account: wilsen0; “we,” “us,” or “the developer”). Privacy questions and requests may be submitted through: https://github.com/wilsen0/Agent-SSH/issues

This policy describes how the Moku application (“Moku” or “the App”) handles data. Moku is an account-free, local-first SSH, Mosh, SFTP, server-management, and coding-workspace client. We do not operate a Moku cloud account service, advertising service, analytics service, or data-broker service.

1. Data stored on your device

Depending on the features you use, Moku may store the following app data locally:

App databases are encrypted at rest using a device-generated key kept through the operating system’s secure-storage facility. Particularly sensitive backup and WebDAV credentials are stored through system secure storage. No storage method can guarantee absolute security, so you should also secure your device and remote accounts.

When biometric app protection is enabled, Moku asks the operating system to authenticate you. Moku does not receive or store fingerprint, face-template, or other biometric-template data.

2. Remote-server connections

When you initiate SSH, Mosh, SFTP, Wake-on-LAN, Docker, process, systemd, coding-workspace, or related operations, Moku communicates with the server or local-network device you selected. Data necessary for the requested operation—including connection address, authentication exchange, commands, terminal input/output, and transferred files—passes between your device and that destination.

These transfers are necessary to provide the feature you requested. The Moku developer does not proxy or receive this traffic. The destination server, network operator, or service administrator may process connection metadata and content according to its own configuration and policies.

3. Optional AI features

AI features are off until you configure an API endpoint, API key, and model and choose to use them. Before selected terminal text is sent to a newly configured host, Moku displays an in-app disclosure and asks you to continue.

When you use an AI feature, the following may be transmitted directly from your device to the API endpoint you configured:

Moku requires HTTPS for remote AI endpoints; unencrypted HTTP is permitted only for a loopback address on your own device. The developer does not receive a copy of AI requests or responses. The configured AI provider may log, retain, or use the content under its own terms and privacy policy. Do not send passwords, private keys, access tokens, personal data, or other confidential information to an AI provider unless you have authority to do so and accept that provider’s practices.

4. Backups, exports, and sharing

Moku does not enable Android system cloud backup for its app data. Optional backup and sharing functions are controlled by you:

Remote backup providers retain copies until you delete them using Moku or the provider’s tools, subject to the provider’s retention rules. Backups uploaded by an older app version may not have had the same safeguards; we recommend deleting older remote copies and uploading a newly encrypted backup.

5. Camera, files, notifications, and background operation

Permissions are requested only when required by the selected feature. Denying an optional permission may disable that feature without preventing unrelated features from working.

6. Diagnostic logs

Moku keeps bounded local diagnostic logs to help identify failures and performance problems. Logs are not automatically uploaded to the developer. They may include timestamps, feature names, status codes, server aliases or internal identifiers, file-transfer sizes, and error or stack information. We design logs not to intentionally record passwords, private-key contents, API keys, tokens, AI prompts, terminal payloads, or full SFTP paths, but an operating-system or third-party-library error could still contain unexpected details.

You decide whether to copy or share logs. Review and redact them before sending. If you submit logs through GitHub or another service, that service’s policy applies.

7. Third parties and data sharing

Moku contains no third-party advertising SDK and no developer-operated behavioral analytics or tracking SDK. Data leaves your device only as needed for a feature you direct or enable, including transfers to:

We do not sell personal data. We do not receive these feature transfers through a Moku server. Third-party destinations act under their own terms, security controls, and retention practices.

8. Retention and deletion

Local data remains on the device until you delete individual records, choose Settings → Delete all local data, clear the App’s storage through the operating system, or uninstall the App. Android automatic app-data backup is disabled in the current release. Because some operating systems may retain secure-storage entries after uninstall, use the in-app deletion action before uninstall when you need a complete user-directed wipe. The in-app action removes app databases, preferences, locally stored backup state, and app secrets, but does not delete copies you previously exported, shared, or uploaded.

To delete remote copies, use Moku’s applicable backup controls or the destination provider’s deletion tools. To delete AI-provider records, contact or use the controls of that provider. Because Moku has no user accounts and the developer does not receive your local data or feature traffic, the developer normally has no server-side copy to delete.

9. Children

Moku is a professional server-administration tool and is not directed to children under 13 (or the minimum age required in their country). We do not knowingly operate a service that collects children’s personal data. A parent or guardian who believes a child submitted data to us through our support channel should contact us.

10. Security and international transfers

Moku uses encrypted local databases, system secure storage, SSH/Mosh or HTTPS transport where applicable, and encrypted remote-backup payloads. Data sent to a destination you choose may be processed in the country where that destination or provider operates. You are responsible for selecting destinations and configurations appropriate for your legal and security requirements.

11. Changes to this policy

We may update this policy when features, laws, or data practices change. We will update the “Last Updated” date and, when appropriate, provide an in-app notice or request renewed acknowledgement. Materially different processing will not be hidden behind an old consent.

12. Contact

Developer: Moku developer listed on the app store (GitHub: wilsen0)

Privacy and deletion inquiries: https://github.com/wilsen0/Agent-SSH/issues