Last updated: July 22, 2026
Terminal X is a tool. We collect the minimum data needed to run that tool: who you are (so you can log in), what you ask it to do (so it can do it), and what you paid (so we can bill you).
"Terminal X", "we", "us", or "our" refers to the operator of terminalxapp.com and the Terminal X mobile app for iOS. This policy applies to both the website and the app. If you have questions about this policy, email support@terminalxapp.com.
Account data — your email, name, and avatar image as provided through your sign-in provider (Clerk handles authentication). If you sign in with Google, your basic Google profile.
Usage data — the commands (prompts) you type into Terminal X, the AI-generated outputs returned to you, the sessions you create, the AI Teams you configure, and the memories Terminal X extracts from your conversations (which you can disable or wipe in Settings).
Billing data — your subscription tier, credit balance, and payment status. On the web, card details are processed and stored by Stripe — we never see your full card number. If you subscribe inside the iOS app, your purchase is processed by Apple through In-App Purchase; we never receive your card details, only your subscription status via RevenueCat (which validates your App Store receipt).
Photos and camera (mobile app) — when you attach an image to a prompt in the iOS app, the app accesses your photo library or camera only after you grant permission, and only the images you choose are uploaded as part of that prompt. We do not otherwise access your photos.
Connection tokens — if you connect a third-party service via the Connections page (Vercel, GitHub, Stripe, Gmail, Shopify), we store the OAuth access token (and refresh token where applicable) so Terminal X can act on your behalf in that service. Tokens are encrypted at rest with AES-256-GCM; a database dump alone cannot reveal them. You can disconnect at any time, which deletes the token.
MCP server registrations — if you register a Model Context Protocol server, we store its URL and the auth header you provided. The auth header is encrypted at rest with the same AES-256-GCM envelope used for connector tokens. We use these to discover and call your MCP server's tools when the TX Agent runs.
Generated artifacts — images, audio, video, 3D models, and large HTML builds produced by your prompts are stored in our Supabase Storage bucket (public-read URLs so the in-app result viewer can render them). Small text replies stay inline in the database. You can delete any session — including its artifacts — from your session history.
Technical data — IP address, browser type, timestamps of requests (standard server logs, retained ~30 days). Product analytics via PostHog (page views, feature usage) — no individual prompt text, no PII beyond your Clerk user id.
Terminal X is a multi-provider product. To run your commands, we send the necessary parts of your request to:
We have contracts with each of these providers requiring them to handle your data per applicable law (GDPR, CCPA where relevant) and to not use it for their own purposes beyond providing the service to us. Provider-specific data handling is governed by each provider's own privacy policy.
We do not allow any provider to train their AI models on your data. All API calls are made through endpoints and account settings that opt out of training. If a provider's defaults change, we update our configuration to maintain this commitment.
Terminal X uses:
You have the right to:
For any other privacy request, email support@terminalxapp.com. We respond within 30 days.
We keep your account data as long as your account is active. When you delete your account, we delete all your data within 30 days, except where we are legally required to retain it (e.g. billing records for tax purposes, typically 7 years).
Server logs are auto-deleted after 30 days.
We use industry-standard practices to protect your data — TLS everywhere, encrypted-at-rest databases via Supabase, scoped API keys, and an additional AES-256-GCM envelope on top of every OAuth token, API key, and MCP auth header we store (so a database leak alone cannot reveal them — the attacker also needs our server-side encryption key). WebSocket sessions for the TX Agent are signed with HMAC tokens, and OAuth callbacks are bound to the originating browser session to prevent token hijacking. No system is perfectly secure, but we treat security as a serious and ongoing responsibility.
If you discover a vulnerability, email support@terminalxapp.com with the subject "Security". We appreciate responsible disclosure.
Terminal X is not directed at children under 13 (or 16 in the EU) and we do not knowingly collect their data. If you believe a child has signed up, email support@terminalxapp.com and we will delete the account.
Terminal X is operated from the United States. By using Terminal X you consent to your data being processed in the US and other countries where our providers operate. For EU residents, we provide GDPR-equivalent rights (Section 6).
We will update this policy as Terminal X evolves. Material changes will be announced in-app and via email. The "Last updated" date at the top reflects the most recent change.
Privacy questions or requests: support@terminalxapp.com.