Privacy Policy
This policy explains what information Termini ("the product") collects, how it is used and stored, and the rights you have. By using the product you confirm that you have read and agree to this policy.
Information we collectHow information is usedStorage and securitySharing and disclosureYour rightsContact us
Information we collect
- Account information: registration email, sign-in credentials, and the public identifier and avatar returned by third-party sign-in (GitHub / Google).
- Device information: the name, operating system platform and client version of signed-in devices, used for multi-device management and security auditing.
- Cloud sync data: host configurations, keys and similar content you upload when you actively enable cloud backup. Backups are encrypted locally with the sync password you set before upload; the server only stores ciphertext and cannot decrypt it.
- AI usage data: token usage and billing records when you use cloud AI models. Conversation content only passes through the server while being forwarded to the model provider and is not persisted.
- Search queries: when you use the assistant's web search, the keywords you enter are forwarded to the search provider to obtain results.
- Feedback and diagnostics: the text and account email of feedback you submit; when the client hits an error, the reported error source, message, stack trace, platform and version.
- Subscription information: subscription status, product and subscription identifiers from the Apple / Microsoft / Google stores. We never touch or store your payment card details.
How information is used
- Provide sign-in, multi-device management, cloud backup and subscription services.
- Account for AI usage and subscription quota and produce your usage statement.
- Send verification codes, subscription expiry reminders and important service notices by email.
- Defend against abuse (rate limiting, risk control) and troubleshoot faults.
Storage and security
- Local session data (hosts, keys, terminal history) is stored only on your device by default, with sensitive fields encrypted locally.
- Server-side data is stored in access-controlled databases; admin console actions are audited.
- Data in transit is encrypted with TLS.
- Sign-in tokens are valid for 7 days and renew automatically while in use; expired tokens are cleaned up by a scheduled job. Device tokens can be revoked at any time from the account centre.
- Detailed AI usage statistics are kept for about two months and then deleted automatically.
Your rights
- View and remove signed-in devices and erase cloud backups in the account centre.
- Unlink third-party sign-in.
- Delete your account yourself with an email verification code. After deletion we remove your signed-in devices and tokens, third-party links and cloud backups; to prevent repeated trial quota, the account and subscription records are marked as deleted and retained, and you can reactivate with the same email.
- To have the retained part erased completely, contact us through the channel below.
Contact us
For any questions about this policy or your data, contact us by replying from your registered email or through the in-product feedback entry. We handle requests within a reasonable period after receipt.