Privacy
Release-ready draft, pending professional legal review. It describes what the software does.
Shellaro is published by Dvir Horev under the DvirLabs brand (DvirLabs is a brand name, not a company). Its use is governed by the Shellaro Software License.
Shellaro is a desktop application that runs on your computer. It has no telemetry, no analytics, no crash reporting service and no account. The publisher of Shellaro does not receive your sessions, commands, files, logs or settings.
Shellaro is not "offline only", though: the features below connect to other computers, and each one is listed here with what it sends.
What Shellaro connects to
| Feature | Connects to | What is sent | When |
|---|---|---|---|
| SSH terminals, SFTP, tunnels, MultiExec, runbooks | The servers you configure (and jump hosts) | What any SSH client sends: your user name, the password or key you chose, your commands and files | When you open or use a session |
| Update checks | Shellaro's update server, https://updates.shellaro.dev (hosted on Cloudflare; shown in Settings > Updates), or a server you set | An HTTPS request for <channel>/latest.json, then the installer download. The server sees your IP address and the request; Shellaro adds no identifiers (the user agent is the updater library's name and version) | A minute after start and every six hours, while automatic checks are on; or when you click Check now. Turn it off in Settings > Updates |
| Marketplace | The built-in catalog is part of the app (no connection). Sources you add, and the addresses of packages you install from them | Requests for the catalog and package files | When you open the Marketplace with a source added, or install from it |
| Extensions | Hosts an extension declared and you approved at install time | Whatever that extension sends | When the extension runs |
| Explain This (AI), optional, off by default | A local model (e.g. Ollama on this computer) or an external provider you choose | The command output you ask about and, only if you allow each item, host name, OS, environment, directory and Kubernetes context. A preview shows it first | Only when you click Explain This |
| Local Kubernetes cluster, labs | Docker on this computer; Docker downloads images from their registries (e.g. Docker Hub). Lab setup scripts run on the target you choose and may pull container images there | Docker's normal image requests | When you create the local cluster or start a lab |
| Links | Your web browser | The page address | When you click a link |
Shellaro uses Microsoft Edge WebView2 to draw its window. WebView2 is a Windows component maintained by Microsoft and has its own update and diagnostic behavior, governed by Microsoft's terms.
What stays on your computer
- Saved sessions, groups, host keys, history, runbooks, tunnels, preferences, workspace layout, lab progress, extension data: in the data folder (
%APPDATA%\com.shellaro.app). The full list is in docs/data-and-storage.md. - Passwords, key passphrases and AI API keys: in Windows Credential Manager. They are never written to the data folder, logs, exports, workspace state or support bundles.
- The local log (
logs\shellaro.log), redacted before it is written.
Support bundles
Settings > Help & About > Save support bundle writes a zip you save. Nothing is uploaded. It contains versions, a settings summary, the extension list, preferences and the redacted log; never sessions, known hosts, AI settings, extension data or credentials. Host and user names that appear in error messages may remain: read the files before sharing them.
Command history
History is stored locally and can be turned off or limited in Settings. Commands typed into a session are sent to that server, as with any SSH client.
Removing your data
Uninstall Shellaro and tick Delete the application data, or delete %APPDATA%\com.shellaro.app and %LOCALAPPDATA%\com.shellaro.app yourself. Credential Manager entries starting with Shellaro/ can be removed in Control Panel > Credential Manager.
Contact
Privacy questions: Dvir Horev, through the contact published on the official Shellaro website (the contact address is still to be published).