q quicktuiv1

Privacy Policy

Last updated: September 27, 2026

This policy covers the QuickTUI apps for iPhone, iPad and Android ("the App"), the QuickTUI server you install on your own computer, the optional QuickTUI Cloud services (account, subscriptions and Relay), and the quicktui.ai website.

The App contains no analytics, advertising or crash-reporting SDKs. Most features work without an account; a QuickTUI Cloud account is only needed for the optional cloud features described below.

Data on Your Devices

When you use the setup wizard, your SSH login is used to install the QuickTUI server on your computer. It is not saved unless you choose to save an SSH profile, and it is never sent to QuickTUI.

Pairing and Connections

Pairing uses a one-time code that expires after 15 minutes. It registers your device's public key and a device label (the device model and a short identifier) on your QuickTUI server. After pairing, everything between your device and your server, including terminal, file and Agent traffic, is end-to-end encrypted. When you connect through QuickTUI Relay, the Relay only forwards encrypted data and cannot read it. The one exception is Agent notifications, described below. You can list and revoke paired devices on your server at any time.

Your QuickTUI Server

The QuickTUI server runs on a computer you control. Terminal sessions, files, logs and pairing records stay on that computer. To work properly, the server makes these requests:

Requests Made by the App

Update checks, announcements and configuration from quicktui.ai are served by Cloudflare's network and do not send any information to QuickTUI. As with any website, Cloudflare processes technical connection data, such as IP addresses, as our infrastructure provider.

QuickTUI Cloud Account (Optional)

You sign in with Apple (on iPhone and iPad) or with Google (on Android). We store:

Sign-in credentials on your device are kept in the Keychain on iOS or in secure storage on Android. Users in mainland China are served by QuickTUI's services in China.

Purchases and Subscriptions

QuickTUI Pro (a one-time purchase) and QuickTUI Cloud subscriptions are currently available on iPhone and iPad through the App Store. Apple processes payment; we never receive your payment details. QuickTUI Pro is verified on your device with the App Store. For QuickTUI Cloud subscriptions, we store your plan, status, purchase and expiry dates, transaction identifiers, and the App Store notifications Apple sends us about your subscription, to keep your subscription status accurate. Purchases are not currently available in the Android App.

QuickTUI Relay

If your subscription includes QuickTUI Relay, we store what is needed to run it: your Relay IDs, the public key and fingerprint of the QuickTUI server bound to each Relay ID, the Relay server assigned to it, and usage counters such as bytes transferred, connection counts, and first and last connection times, used to enforce plan limits. Relay traffic is end-to-end encrypted between your device and your QuickTUI server; the Relay cannot read terminal, file or Agent content. Agent notifications are the only content that passes through the Relay unencrypted, as described below.

Agent Notifications (Optional)

Agent notifications require QuickTUI Relay and are sent only to devices that have granted notification permission and registered for notifications. Each QuickTUI server has its own preferences that control whether notifications are sent, which events trigger them and which optional details appear.

A server can notify you when an Agent needs approval, finishes a task, reports an error or ends a session, or when an Agent provider needs attention. By default a notification only says what happened. If enabled, it can also include the Agent type, the project folder name, the Agent session identifier, and a task or error summary. Notifications never include full terminal output, source code or credentials, although names and summaries may contain text written by you or an Agent.

To deliver and open a notification, it also carries routing data: the device ID, event category, notification ID and revision, collapse ID, time sent, and references to the Agent session and request. Long references are replaced with one-way hashes that only your App can match against data from your server.

Your QuickTUI server stores its notification preferences and each device's push registration. For delivery, it sends the notification, routing data and the device's push token through QuickTUI Relay to Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM). The Relay does not store push tokens or notification content; it keeps short-lived in-memory data (up to 2 minutes) to avoid duplicate delivery, and logs each delivery's status and category with a partial Relay ID. On Android, notifications are received through Firebase Cloud Messaging, which may create an installation identifier; Apple and Google process push tokens and notification content under their own terms.

To stop notifications, turn off notifications for QuickTUI in your device's system settings. Removing the last server profile that uses a device's credential also removes that device's push registration from the server. A notification already accepted by APNs or FCM cannot be recalled.

The quicktui.ai Website

The website is served by Cloudflare. It uses Cloudflare Zaraz to count two events: copying an install command and clicking an App Store link, together with where on the page it happened and, for install commands, the operating system and install source. The website shows no ads and does no cross-site tracking.

How We Use and Share Data

We use the data above only to provide QuickTUI and its cloud services, keep them secure and prevent abuse. We do not sell your data or use it for advertising. We share it only with the service providers that make QuickTUI work, and where required by law:

Our cloud services keep technical logs of requests, including IP addresses, for security, abuse prevention and troubleshooting. Routine logs are kept for 72 hours and error logs for up to 90 days. They are not used for marketing or profiling.

Data Retention and Account Deletion

Account and subscription data is kept while your account exists. On iPhone and iPad you can delete your account in the App with Delete Account. To delete an account created with Google, contact us at the address below.

Deleting your account permanently removes your account identifier, email hash, subscription records, sessions and Relay data from our servers, and revokes Sign in with Apple. We keep only a hashed App Store account token, used to handle App Store notifications about past purchases, and technical logs until they expire as described above.

Deleting your account does not cancel an active App Store subscription. To stop billing, cancel the subscription in your Apple Account settings.

Security

Traffic between your devices and your QuickTUI server is end-to-end encrypted, and all communication with QuickTUI Cloud uses TLS. Email addresses are stored only as one-way hashes, and credentials on your device are kept in the platform's secure storage.

Changes and Contact

We may update this policy on this page and will change the date above when we do.

For privacy questions or requests, visit the Support page or email dualface@gmail.com.