netshell❯
Download Releases
Legal

Privacy Policy

Last updated: July 19, 2026 · This policy covers the netshell software (the "Software"), a product of Zapit Technologies (Texas, USA). The data controller is Zapit Technologies; contact support@zapittech.com.

netshell is a desktop application you install and run on your own machine. This policy explains what the Software does with data. Company-wide practices (our website, how we handle a support request or an order) are covered by the Zapit Technologies company Privacy Policy; this policy is about the Software itself.

The short version

Most of your data never leaves your machine. The AI features send data to your own AI provider using your own key — not to us, and not through our servers. We don't run analytics or advertising trackers in the Software. The main thing the Software sends to us (indirectly) is a license check to our licensing provider — apart from a possible crash report from a bundled component we are still removing (see Section 5).

1. What stays on your machine

  • Your terminal sessions — what you type and what your devices print, including configurations — are handled locally.
  • Your credentials (SSH passwords, keys, key passphrases, enable/secret values) are stored by the app in your operating system's secure credential store, not in a plain file.
  • Your AI provider key is stored in your OS keychain and is used only to authenticate your own calls to your provider. It is not sent to us.
  • Local log files. By default the Software writes two kinds of plain-text logs to a folder on your machine (Documents/netshell-logs): a per-session log of terminal output, and a log of your AI conversations. These are for your own records. The session log is deliberately verbatim and is not scrubbed — it can contain secrets your device printed. These files stay on your machine and are not sent to us. You can turn session logging off and delete the folder at any time.

2. AI features — your key, sent to your provider

netshell's AI features work with an AI provider account that you supply (Anthropic, OpenAI, Azure OpenAI, or Google). When you use those features:

  • Relevant session data is sent directly from your machine to the AI provider you chose, using your key, under that provider's terms and privacy policy — not through us. We are not in the middle of that connection and do not receive that data. As with contacting any online service, your chosen provider can see your connection and its IP address.
  • Only a limited, purpose-built payload is sent: your typed question, the specific command(s) involved, and — when you're actively asking for help — relevant device output plus non-secret device metadata. Output that contains a device's configuration is included only if you confirm it.
  • Before anything is sent, the Software is designed to strip credentials and other sensitive values (the "data wall"). This is best-effort, not a guarantee — it reduces, but cannot promise to remove, every secret that might appear in device output.

What your provider does with the data (including retention and whether it is used for training) is governed by your account and that provider's policy — please review the policy of the provider whose key you use.

3. License activation

When you activate a paid license, the Software contacts our licensing provider, Lemon Squeezy, over an encrypted connection. It sends only your license key, an activation/instance identifier, and your device's name (hostname). It does not send your terminal contents, credentials, or device configurations. As with contacting any online service, our licensing provider, Lemon Squeezy, can see the network connection and its IP address. The Software re-checks the license periodically when you are online; an outage does not lock you out of work you have already licensed.

4. Purchases

Payments are processed by our reseller and merchant of record, Lemon Squeezy. When you buy, you provide your payment and billing details to them; we don't see or store your full card number. Lemon Squeezy handles the transaction and any tax under its own privacy policy, and we receive limited order information (such as your name, email, and what you bought) so we can deliver your license and support you.

5. Analytics, telemetry, and crash reports

netshell's own code contains no advertising trackers and no third-party usage analytics, and it disables the analytics and automatic-update features of the open-source Tabby terminal it is built on. One caveat, stated plainly: Tabby includes its own crash reporter that can send crash diagnostics to a third-party service (Sentry, operated by Functional Software, Inc.). We have not yet fully removed this component from the packaged build. Until we confirm it is removed, we cannot promise the app sends no crash data at all — a crash could cause diagnostic information to be sent to Sentry under Sentry's terms. We do not use any such data for analytics or advertising, and our intended posture is that crash reporting is off by default and opt-in. We will update this policy when the component is removed or made opt-in.

6. Third parties involved

  • Lemon Squeezy (Lemon Squeezy, LLC) — our payments provider, merchant of record, and license-validation provider. This is our sub-processor. Data shared: order/billing details (to them, as merchant of record), and, on activation, your license key, an instance identifier, and your device hostname.
  • Your chosen AI provider (Anthropic / OpenAI / Azure OpenAI / Google) — not our sub-processor. You engage this provider directly, with your own key and account; data goes from your machine to them under your agreement with them. We neither receive it nor control it.
  • Sentry (Functional Software, Inc.) — crash diagnostics only, and only to the extent the not-yet-removed Tabby component described in Section 5 is triggered.

7. Legal bases (EU / UK users)

Where the EU or UK GDPR applies, we rely on: performance of a contract to validate your license and deliver and support your order; legitimate interests to protect against license abuse and keep the Software secure, balanced against your rights; and your consent for any optional crash reporting, if and when we make it available. The AI features operate under your agreement with your chosen provider; we are not the controller for that transmission.

8. International transfers

We and our providers are in the United States. Where EU or UK personal data is transferred, transfers rely on appropriate safeguards such as the EU/UK Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Our providers (Lemon Squeezy; and, if triggered, Sentry) maintain their own transfer safeguards. Contact us for more detail. If and where we are required to appoint an EU or UK representative under Article 27, we will identify them here.

9. How long we keep it

Your local logs and data remain on your machine until you delete them — we don't hold them. We keep the limited order and license records described above for as long as your license is active and for a period afterward to meet tax and accounting obligations (typically up to seven years), then delete or anonymise them.

10. Your rights

Depending on where you live, you have rights to access, correct, delete, restrict, or object to our use of, and to receive a copy of (portability), the limited personal information we hold about you (such as order and support records). Where we rely on consent, you may withdraw it at any time. To exercise any of these, email support@zapittech.com. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office) — we'd appreciate the chance to resolve it first.

California (CCPA/CPRA). The categories of personal information we collect are: identifiers (name, email); commercial information (your purchase); and a device hostname and instance identifier used for license validation. We collect these to deliver and support your license. We do not sell your personal information and do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. California residents have the rights to know, delete, and correct, and to non-discrimination for exercising them — we will not deny you service or charge you differently for doing so.

11. Security

Credentials and keys are held in your OS keychain, and the data wall is designed to keep secrets out of the AI path. We take reasonable measures to protect the limited information we hold. No method of transmission or storage is completely secure, and the data wall is best-effort, so we cannot guarantee absolute security.

12. Children

The Software is a professional tool intended for businesses and adults; it is not directed at children, and we do not knowingly collect information from them.

13. Changes and contact

We may update this policy; the "last updated" date shows when it last changed, and material changes will be posted here. Questions: support@zapittech.com · Zapit Technologies, Texas, USA. See also the License Agreement and Terms of Sale & Use.

Download Releases · EULA Terms Privacy Refunds
a product of Zapit Technologies zapittech.com