Last updated: September 13, 2026
Flitra is provided by Shenzhen Shazi Technology Co., Ltd. This policy covers the Flitra app, the flitra.app website, and communications with our support team. For privacy questions or requests, contact support@flitra.app.
Your device and your hosts
Flitra connects directly over SSH to the hosts you choose. You do not need a Flitra account. Your code and coding agents run on your remote machine; Flitra provides access to their workspaces and terminals.
Saved host names, addresses, ports, usernames, authentication types, and host key fingerprints are stored in the app's local database. App preferences are also stored locally. This information lets Flitra reconnect to your hosts and retain your settings.
SSH credentials
SSH passwords, imported private keys, and key passphrases are stored separately from the local database in platform secure storage: Keychain on iOS and macOS, and encrypted storage on Android. Flitra uses them to authenticate connections to the hosts you select. Private-key authentication does not send the private key to the host.
Flitra verifies the saved host key before authenticating subsequent connections. SSH protects data in transit between your device and the host.
Terminal input, prompts, and images
Commands, prompts, and images you choose to send travel to the selected host over SSH. Terminal output and workspace information travel back to your device for display. These connections do not pass through a Flitra-operated relay.
Unsent prompt drafts and prepared image attachments are held in memory rather than saved as drafts. Selected images are uploaded to a temporary directory on the remote host so the agent can use them. Successful uploads are not automatically deleted by Flitra; their retention depends on the host's temporary-file policy and any copies made by the agent. Deleting a local attachment or saved Host does not delete an uploaded remote file.
Camera, photo, file, and clipboard access is used when you choose the corresponding input action. You can manage applicable permissions in your device settings. Image files may contain metadata, so review what you share.
Conversation history
When conversation history is used, Flitra may cache session records in the app's private storage to load history faster. These records can contain messages, tool output, images, and other session data, including records not displayed in the interface.
This cache is not separately encrypted by Flitra. It is excluded from system backups, limited to 512 MiB in total, and older sessions are removed as space is needed. Deleting a saved Host removes its associated conversation cache. The original session files remain on the remote host.
Services you use on your host
Your remote host and coding agents process the input you send. If an agent uses an AI provider or another external service, it may send prompts, images, code, or other context to that service according to its configuration. Those services have their own privacy policies and retention practices. Choose and configure them before sharing sensitive material.
The current Flitra app does not include advertising or third-party analytics SDKs, and does not send terminal sessions or SSH credentials to our support team automatically.
Website visits and support
The website's hosting infrastructure processes connection information, such as your IP address, browser information, and requested URL, to serve the website and maintain its security. The current website does not include advertising trackers or third-party analytics scripts, and its fonts are served with the site.
If you email us, we receive your email address, message, and any attachments you provide. We use them to respond to your request and investigate reported issues. Our hosting and email providers process information needed to deliver those services. We do not sell your personal information.
Retention and your choices
You can delete saved Hosts in Flitra to remove their local connection details, secure-storage credentials, and associated conversation caches. Remote files, agent sessions, and any data held by services on your host must be managed separately. Do not rely on uninstalling the app to erase Keychain credentials; remove saved Hosts in the app first.
We retain support correspondence only as reasonably needed to handle your request, resolve related issues, and meet applicable obligations. You can ask us to access, correct, or delete personal information you have sent to support by emailing support@flitra.app. We may need to verify the request and may retain information where required by law. We cannot access or delete files on your own hosts or data held by your chosen AI providers.
Changes to this policy
We will update this page when our practices change and revise the date above. Material changes will also be communicated through the app or website as appropriate. You can always reach us through our Support page.