SlipShell
Privacy Policy
Effective October 1, 2026
The Short Version
SlipShell connects your phone to servers you choose. What you type, what those servers send back, and the files you move travel between your device and your servers. Static Hum Studio does not run a SlipShell server, and none of that traffic passes through us.
There is no account, no analytics, no advertising, and no tracking SDK. Your server list, keys, and settings live on your device. Nothing from inside the app reaches us unless you choose to email us. If you buy Operator Pro, Google Play tells us about the order, as described below.
What SlipShell Stores on Your Device
- Server profiles: names, hostnames or IP addresses, ports, usernames, groups, notes, jump hosts, and port forwarding settings
- Passwords, private keys, key passphrases, and your Tailscale API key, encrypted with AES-256-GCM under a key held by the Android Keystore
- Host key fingerprints you have accepted
- Names and public halves of your SSH keys
- Command snippets and snippet packs
- Themes, including ones you build, and app settings such as your tailnet name
- Access to any folders you let SlipShell read for SSH config imports
- Operator Pro session notes: access to the one folder you pick for notes, and working copies of any notes you edited that have not been saved to that folder yet
- The list of open sessions, so the app can reconnect them after Android closes it
- The SFTP transfer queue
- Whether Operator Pro is unlocked on this device
- A short local diagnostic log, described below
Saved session notes are ordinary text files in the folder you pick. They stay there, in your storage, and that folder is the only one SlipShell reads or writes notes in. Text you have typed but not yet saved there is kept in the app’s private storage on your phone until it is. If you pick a folder that another app syncs, such as Syncthing or Nextcloud, that app moves your notes under its own terms. SlipShell does not.
Terminal output stays in memory while a session is open. It is written to a file only when you export a transcript, which saves two text files to a SlipShell folder in your Downloads. None of this is transmitted to Static Hum Studio.
Files you upload, download, or edit over SFTP pass through the app’s private cache while they are in use. SlipShell tries to remove those working copies once it is done with them, but some can stay behind until Android or you clear the app’s cache.
What SlipShell Sends, and Where
To Your Servers
SSH, Mosh, and SFTP connections go straight from your phone to the server you configured, or through the jump hosts you set up. Your login credentials, what you type, what the server returns, and the files you transfer travel on that connection. SSH and Mosh both encrypt it. Static Hum Studio is not part of that exchange and cannot see it.
To Tailscale (Optional)
If you add a Tailscale API key, SlipShell sends it to Tailscale’s API at api.tailscale.com to fetch the list of devices on your tailnet. That list stays on your phone. Tailscale handles the request under its own privacy policy. SlipShell sends your key nowhere else, and you can remove it in Settings at any time.
On Your Local Network (Optional)
When you scan for servers, SlipShell sends a standard mDNS query asking for SSH servers on the Wi-Fi network you are connected to, and collects their replies. Results stay on your device. Scanning needs no location or Nearby Wi-Fi Devices permission, and SlipShell asks for neither.
To Google Play (Operator Pro)
Operator Pro is a one-time purchase handled by Google Play. SlipShell never sees or stores your payment details. The app asks Google Play whether you own Operator Pro and keeps a record of the answer on your device. It uses the Google Play Billing Library to do that, and Google may collect information about the purchase and your device under Google’s privacy policy. As the seller, Static Hum Studio receives order details from Google, such as an order number, date, and amount, so we can handle refunds and support.
Links You Tap
A few screens link to outside pages, such as the Tailscale admin console, the source code for the bundled Mosh client, and this website. Those open in your browser only when you tap them, and from there the website you visit handles your request.
Diagnostics and Bug Reports
Local Diagnostic Log
SlipShell keeps a small log on your device to help with bug reports. Each entry records the time, the app build, the kind of event, a number standing in for the session, how long something took, and whether SSH or Mosh was in use.
It never records hostnames, usernames, commands, terminal output, file names, or credentials. Entries older than seven days are dropped. The log leaves your device only if you save a copy to a file or attach it to an email yourself.
Bug Reports (Optional)
From the Support screen, SlipShell drafts an email in your own email app, addressed to hello@statichum.studio. It includes the app version, your Android API level, and what you wrote. You can attach a snapshot of the diagnostic log and read exactly what it contains before you send. The app keeps that attachment in its private cache so your email app can read it, and removes it the next time it cleans up after the attachment is a day old. You can edit or delete anything in the email, and nothing is sent unless you send it.
We use report emails only to look into the problem you reported. If you want yours deleted, ask and we will delete it.
Backups and Exports
Android Backup
Android can back up app data to your Google account and copy it to a new phone during setup. SlipShell allows this so your setup can come with you, and it can include most of the storage list above, such as your server list, accepted host keys, snippets, themes, settings, and the SFTP transfer queue with its file paths. Passwords, private keys, key passphrases, your Tailscale API key, the diagnostic log, the list of open sessions, unsaved notes, and the folder access for notes and SSH config imports are excluded from both. Folder access cannot move to another phone anyway, so a new phone asks you to pick those folders again. Your notes themselves are files in your own storage, not app data, so they move to a new phone only if you copy them or the folder is synced. Unsaved note text stays on the old phone. Android backup is controlled by your device and Google account settings, not by us.
Files You Export
You can export your servers to a file. A normal export contains server settings and no passwords or keys. If you choose a key backup instead, the file also contains the private keys those servers and their jump hosts use, and the app asks you to confirm before creating it and tells you about any key it could not include. SlipShell adds no encryption of its own to that file, so treat it like the keys themselves.
Either file goes wherever you save or share it. When you share one, the app first writes it to its private cache so the receiving app can read it. That copy is removed after an hour, or the next time SlipShell starts if it was closed before then.
What SlipShell Does Not Collect
- No account or sign-in with Static Hum Studio
- No analytics, usage tracking, or crash reporting service
- No advertising and no advertising identifiers
- No location data
- No contacts, photos, or other files, except the ones you pick to upload or import, and the notes folder you choose
- No data sent to Static Hum Studio servers. There are no SlipShell servers
Android Permissions
- Internet and network state: to connect to your servers and notice when the network changes
- Notifications: to show active session and file transfer status
- Foreground service and wake lock: to keep sessions and transfers you started running while the screen is off
- Storage (Android 9 and older only): to save files you export or download
- Biometrics (optional): app lock uses Android’s own fingerprint or face prompt. SlipShell never receives biometric data
Children’s Privacy
SlipShell is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has sent us personal information, contact us at hello@statichum.studio and we will delete it.
Your Control
- Delete servers, keys, snippets, and notes inside the app at any time
- Remove your Tailscale API key from Settings
- Clear saved bug report attachments from the Support screen
- Clear the app’s storage or uninstall it to remove everything SlipShell keeps in its own storage
- Delete files SlipShell saved outside its own storage yourself, such as SFTP downloads and exported transcripts in your Downloads folder, your session notes folder, and any snippet exports, server backups, or diagnostic logs you saved. They stay where they were saved, so uninstalling does not remove them
- Manage or delete Android backups from your device and Google account settings
- Ask us to delete any bug report email you sent by writing to the address below
Contact
SlipShell is made by Static Hum Studio. Questions about this policy go to hello@statichum.studio.
Changes to This Policy
If this policy changes, the revised version will be posted here with a new effective date.