Security and Privacy
Your remote work runs on the hosts you connect to. Mightty does not upload terminal input or command content to its servers, and the first version does not provide cross-device sync.
Credentials stay on your device
Host details are stored on the device where you add them. Passwords and private keys are stored in the system keychain rather than on Mightty’s servers.
Protect the app with its biometric lock when saved credentials can reach a sensitive host. Privacy Mode can hide host addresses and usernames when you do not want connection details visible on screen.
Verify each host
SSH and Mosh encrypt traffic between Mightty and the host. On a new manual connection, check the SSH host fingerprint before trusting it. If a fingerprint changes later, verify the reason on the host before resetting trusted-host data in Mightty.
Pairing creates a dedicated key
Scan to Pair uses a one-time QR code. Mightty generates the private key on your device and installs its public key on the host. The private key is not copied to the host or sent through the QR code.
Paired host hooks can relay events such as task completion or an approval request. The relay uses hashed identities and briefly caches events for delivery; it does not receive terminal input or command content.
When you retire a host, remove its saved connection from Mightty and run this on the host to remove installed hooks:
mightty uninstall
Permissions are feature-specific
Mightty asks for system access only when a related feature needs it:
- Camera scans pairing QR codes.
- Photos lets you attach a selected image to terminal input.
- Local Network reaches LAN hosts and discovers nearby devices.
- Microphone and Speech Recognition provide voice input when you choose it.
- Notifications deliver supported host or agent events.
You can deny an optional permission and continue using unrelated terminal features.
A practical checklist
- Use a dedicated SSH key for mobile access when possible.
- Add it only to hosts you intend to reach from Mightty.
- Keep the device and Mightty app lock enabled.
- Verify fingerprints and unexpected approval requests.
- Remove saved connections, public keys, and host hooks you no longer need.
- Never share a pairing QR code, password, or private key.
For the complete policy, read Privacy.