privacy
What this site and this app know about you.
Last updated 25 August 2026
Short version: the site knows almost nothing, and the app is built so that it cannot know anything. The longer version is below, and it is written to be checked rather than to reassure.
This website
There are no accounts and no forms. Two things are stored in your browser. One is your theme choice, under vortex-theme, holding the word “dark” or the word “light” because you pressed the theme button; it is read by this page and sent nowhere. The other is a pair of Google Analytics cookies, _ga and _ga_KCL50QWBNF, which are how one reader is told apart from another and one visit from the next. Clearing your site data removes all of them.
Three typefaces load from Google’s font servers, fonts.googleapis.com and fonts.gstatic.com. That means Google receives your IP address and your browser’s user agent when the page opens, in the same way it would for any site using them.
Google Analytics runs on the front page. This page and the terms page carry no tag at all, so reading either of them is counted nowhere. What the front page reports to Google is that it was opened, how you arrived — the link or the search that sent you — roughly where you are, worked out from your IP address, and what browser and device you are on. Analytics also measures a few interactions on its own account, including how far down the page you scrolled and whether you followed a link that leaves the site. It is there to answer how many people read the page and which parts they read. It is the plain measurement product: no advertising pixel, no remarketing tag, and nothing that follows you to another site. What Google does with what it collects is covered by their privacy policy. If you would rather not be counted, a tracker blocker stops it, and so does Google’s own opt-out extension.
The page is served by Amazon Web Services, who keep ordinary server logs: the request, the time, the IP it came from. That is the host’s doing rather than ours, and we do not build anything on top of it.
If you buy a copy
Payment is taken by Stripe, who handle the card details: they never reach us and we could not hold them if we wanted to. What Stripe does with them is covered by their privacy notice. What reaches BlazeOps Enterprise is what is needed to sell you something and to be able to prove we did: an email address, the amount, the date, and whatever the processor’s receipt contains. We use it to deliver the download, to answer you if you write, and to keep the tax records we are required to keep.
No marketing list, and no mail you did not ask for. If a new version is worth telling you about, that is a thing you would have to opt into.
The app itself
Vortex has no account, no licence server and no telemetry. It makes exactly the network connections you ask it to make, to the hosts you typed in, and it makes them directly. There is no check-in on launch, no update ping, and no crash reporting.
Everything it remembers stays on your machine: the host list, your settings, and any key it creates for you, in your own ~/.ssh. Passwords you choose to store go to your operating system’s credential store, and the limits of that are described on the front page, in the section about the parts that have to be right. None of it is synced anywhere by us, because there is no “anywhere”.
Asking us about your data
Write to developer@vortexssh.com and ask what we hold, ask for a copy, or ask us to delete it. Purchase records we are obliged to keep for tax are the one thing we cannot delete on request, and we will say so plainly rather than ignore the request.
BlazeOps Enterprise operates from Malaysia, so what we hold falls under Malaysian data protection law, the Personal Data Protection Act 2010. If you are somewhere with stronger rights than that, ask anyway: the answer to all three questions above is the same wherever you are writing from.