Last updated: August 6, 2026
Terminal X is a tool. We collect the minimum data needed to run that tool: who you are (so you can log in), what you ask it to do (so it can do it), and what you paid (so we can bill you).
"Terminal X", "we", "us", or "our" refers to the operator of terminalxapp.com and the Terminal X mobile apps for iOS and Android. This policy applies to the website and to both mobile apps. If you have questions about this policy, email support@terminalxapp.com.
Account data — your email, name, and avatar image as provided through your sign-in provider (Clerk handles authentication). If you sign in with Google, your basic Google profile.
Usage data — the commands (prompts) you type into Terminal X, the AI-generated outputs returned to you, the sessions you create, the AI Teams you configure, and the memories Terminal X extracts from your conversations (which you can disable or wipe in Settings).
Billing data — your subscription tier, credit balance, and payment status. On the web, card details are processed and stored by Stripe — we never see your full card number. If you subscribe inside the mobile app, your purchase is processed by Apple (App Store) or Google (Google Play) through In-App Purchase; we never receive your card details, only your subscription status via RevenueCat (which validates your store receipt).
Photos and camera (mobile app) — when you attach an image to a prompt in the iOS or Android app, the app accesses your photo library or camera only after you grant permission, and only the images you choose are uploaded as part of that prompt. On Android these are the photo (READ_MEDIA_IMAGES) and CAMERA permissions. We do not otherwise access your photos, and we do not scan or index your library.
Connection tokens — if you connect a third-party service via the Connections page (Vercel, GitHub, Stripe, Gmail, Shopify), we store the OAuth access token (and refresh token where applicable) so Terminal X can act on your behalf in that service. Tokens are encrypted at rest with AES-256-GCM; a database dump alone cannot reveal them. You can disconnect at any time, which deletes the token.
MCP server registrations — if you register a Model Context Protocol server, we store its URL and the auth header you provided. The auth header is encrypted at rest with the same AES-256-GCM envelope used for connector tokens. We use these to discover and call your MCP server's tools when the TX Agent runs.
Generated artifacts — images, audio, video, 3D models, and large HTML builds produced by your prompts are stored in our Supabase Storage bucket (public-read URLs so the in-app result viewer can render them). Small text replies stay inline in the database. You can delete any session — including its artifacts — from your session history.
Technical data — IP address, browser type, timestamps of requests (standard server logs, retained ~30 days). Product analytics via PostHog (page views, feature usage) — no individual prompt text, no PII beyond your Clerk user id.
Terminal X is a multi-provider product. To run your commands, we send the necessary parts of your request to:
If you use a Terminal X API key: we store a one-way hash of the key, never the key itself — which is why a lost key cannot be recovered and has to be replaced. Every request made with a key is written to a usage log containing the models that ran, the credits charged, the duration, and whether it succeeded. That log deliberately contains no prompt text and no generated output. If you are building on our API, your own users' content is not retained in that record.
We have contracts with each of these providers requiring them to handle your data per applicable law (GDPR, CCPA where relevant) and to not use it for their own purposes beyond providing the service to us. Provider-specific data handling is governed by each provider's own privacy policy.
We do not allow any provider to train their AI models on your data. All API calls are made through endpoints and account settings that opt out of training. If a provider's defaults change, we update our configuration to maintain this commitment.
Terminal X uses:
You have the right to:
For any other privacy request, email support@terminalxapp.com. We respond within 30 days.
We keep your account data as long as your account is active. When you delete your account, we delete all your data within 30 days, except where we are legally required to retain it (e.g. billing records for tax purposes, typically 7 years).
Server logs are auto-deleted after 30 days.
API key usage logs are kept for the life of the key, not 30 days. Every request made with a Terminal X API key writes one row recording which models ran, the credits charged, how long it took, and whether it succeeded or was refused. That row contains no prompt text and no generated output — the database schema has no column for either, deliberately, so building on our API does not put your own users' content into our logs. The rows are deleted when you permanently delete the key they belong to, and when you delete your account. Revoking a key stops it working but keeps its history.
We use industry-standard practices to protect your data — TLS everywhere, encrypted-at-rest databases via Supabase, scoped API keys, and an additional AES-256-GCM envelope on top of every OAuth token, API key, and MCP auth header we store (so a database leak alone cannot reveal them — the attacker also needs our server-side encryption key). WebSocket sessions for the TX Agent are signed with HMAC tokens, and OAuth callbacks are bound to the originating browser session to prevent token hijacking. No system is perfectly secure, but we treat security as a serious and ongoing responsibility.
If you discover a vulnerability, email support@terminalxapp.com with the subject "Security". We appreciate responsible disclosure.
Terminal X is not directed at children under 13 (or 16 in the EU) and we do not knowingly collect their data. If you believe a child has signed up, email support@terminalxapp.com and we will delete the account.
Terminal X is operated from the United States. By using Terminal X you consent to your data being processed in the US and other countries where our providers operate. For EU residents, we provide GDPR-equivalent rights (Section 6).
Most providers process in the United States. Some do not: Mistral and Black Forest Labs process in the European Union, and Alibaba (Qwen), DeepSeek, Moonshot (Kimi) and Z.ai process in China. Which of these ever sees your request depends on which models your prompt is routed to.
You can constrain this. In Settings → Preferences a data-residency preset restricts routing to providers in the regions you allow — for example excluding China entirely. When a preset blocks the model that would otherwise have been chosen, we substitute an allowed one rather than sending the request anyway.
We will update this policy as Terminal X evolves. Material changes will be announced in-app and via email. The "Last updated" date at the top reflects the most recent change.
Privacy questions or requests: support@terminalxapp.com.