Scope
This policy describes data handling in the Mightty app, website, optional host helper, pairing service, and notification relay. It does not cover the machines, services, or coding agents you choose to access through Mightty.
Data stored on your device
Mightty stores the information needed to reconnect to your hosts, including:
- host names or addresses, ports, usernames, and saved connection settings;
- SSH passwords and private keys in platform-provided secure credential storage;
- server lists, themes, keyboard settings, and other app preferences; and
- terminal state and history retained by the app on that device.
Mightty does not currently provide cross-device synchronization for saved SSH connections. Your credentials are not uploaded to Mightty servers.
Easy Pair and notification relay
Easy Pair uses a one-time code to establish trust between the app and your host. The code becomes invalid after pairing completes.
The relay processes hashed host and app identifiers and briefly caches supported agent events, such as task completion or an approval request, so they can be delivered to your device. It does not receive SSH passwords, private keys, terminal input, or command content.
What Mightty does not use your data for
- We do not store SSH passwords or private keys on Mightty servers.
- We do not read or upload terminal input or command content.
- We do not use advertising trackers.
Device permissions
- Camera: scanning a pairing QR code or creating an attachment when you choose that feature.
- Local network: reaching hosts on your local network and discovering available hosts.
- Biometrics: unlocking the app or protected credentials when enabled.
- Microphone and speech recognition: voice input, only when you use it.
- Notifications: delivering supported connection and agent events when enabled.
Service providers
Mightty uses infrastructure providers to operate its website, Easy Pair, and the notification relay. When notifications are enabled, the device platform's push service processes the delivery information required to send them. Those providers process data under their own terms and privacy policies.
Security
Mightty uses platform secure storage for saved credentials and SSH or Mosh for terminal connections. Related service communication uses encrypted transport. No system is completely secure, so protect your device, verify new host fingerprints, and use a dedicated SSH key for mobile access when practical.
Your choices
- Remove saved hosts, credentials, and local app data from your device.
- Disable permissions such as camera, microphone, biometrics, or notifications in system settings.
- Run
mightty uninstallon a host to remove installed hooks. - Contact us to ask about relay data associated with your installation.
Changes to this policy
We may update this policy when the product or its data practices change. The date at the top of this page identifies the current version.
Contact
For privacy questions or requests, emailsupport@mightty.app.