跳到正文
VsTerm
首页 下载 GitHub

隐私政策

生效日期 / 最近更新:2026-09-08

本政策说明 VsTerm(“我们”)如何收集、使用、存储和共享与官网、桌面客户端及可选 Personal Cloud 相关的信息。运营主体为 vesaa,服务器位于美国。联系邮箱:[email protected]。

中英文版本如有冲突,以英文版本为准,便于支付机构与跨境合规审核。

我们明确不收集的内容

  • SSH 私钥、本机 keyring 中的密钥材料
  • 服务器登录密码、明文凭据、sudo / su 密码
  • 终端命令行日志、SSH 会话内容、屏幕输出
  • 经 SFTP / ZMODEM 传输的文件正文

本地 SSH 可以完全离线使用。可选云同步在上传前于客户端加密,服务端只保存密文;没有你的主密码,包括 VsTerm 运营方在内都无法解密。

1. 适用范围

本政策适用于 vsterm.com 网站、VsTerm 桌面应用(Windows / macOS / Linux),以及与账号、设备绑定、付费授权相关的服务。不适用于你通过 VsTerm 连接的第三方服务器——那些系统由对应运营方自行负责。

2. 我们可能收集的信息

2.1 你主动提供的信息

  • 电子邮箱:创建 Personal Cloud 账号、购买付费版本、申请退款或联系支持时。
  • 账号凭据:若使用云账号,我们保存可用于验证登录的必要数据(例如密码散列)。用于加密同步内容的主密码由你在本地派生密钥,我们不存储可还原的主密码。
  • 支持通信内容:你发送到支持邮箱的邮件正文与附件。

2.2 设备与授权相关信息

  • 设备标识:用于设备绑定与 Pro 权益校验的设备公钥 / 设备 ID。Ed25519 私钥只保存在系统钥匙串,不会上传。
  • 许可证 / 订单元数据:产品版本、交易编号、购买邮箱、授权状态、订阅周期(如适用)。

2.3 可选云同步数据

若你开启 Personal Cloud 同步,客户端会上传已用 AES-256-GCM 密封的对象(例如会话、命令片段、布局、偏好、密封后的 vault.enc)。服务端无法读取明文。你可以随时关闭同步或删除账号。

2.4 网站与服务运行日志

  • IP 地址、大致地理位置、浏览器或客户端类型、请求 URL、时间戳、安全相关事件。
  • 语言偏好(保存在本机 localStorage,不是广告追踪 Cookie)。

这些日志用于提供服务、防止滥用、诊断故障,而不是用于建立营销画像。

3. Cookie 与同类技术

官网目前只使用实现基本功能所必需的技术:

  • 语言偏好:存储在浏览器 localStorage(vsterm-lang)。
  • Cloudflare:若流量经过 Cloudflare,可能设置用于安全、CDN 与机器人防护的必要 Cookie(例如挑战通过状态)。
  • 结账 Cookie:购买时由支付服务商(Paddle)在其域名或结账页设置,用于完成付款、税务与防欺诈。

我们不使用广告 Cookie,也不向广告网络出售浏览行为。仅使用必要 Cookie 时,通常无需单独弹窗授权;非必要追踪若日后引入,会先更新本政策并提供选择。

4. 第三方服务

我们会与下列类别的服务商共享完成交易或运行服务所必需的最少信息。他们按各自隐私政策处理数据:

  • 支付 / Merchant of Record:付费购买的实际销售方为 Paddle。Paddle 可能收集姓名、邮箱、账单国家/地区、税号与支付方式;我们不接收完整银行卡号。参见 Paddle Privacy Policy 与 Paddle Checkout Buyer Terms。
  • Cloudflare:网站加速、DNS、DDoS 与安全防护。可能处理 IP 与请求元数据。参见 Cloudflare Privacy Policy。
  • GitHub:安装包与发行说明托管在 GitHub Releases。下载时适用 GitHub 的政策。
  • 支持邮箱:[email protected],用于支持、隐私、退款与商务邮件。邮件传输可能经过邮件服务商。
  • 基础设施:源站服务器位于美国,用于托管网站、账号与加密同步存储。

5. 我们如何使用信息

  • 提供、维护和保护 VsTerm 客户端、网站与 Personal Cloud
  • 完成购买、开具单据、核验许可证与设备绑定
  • 处理退款、取消订阅与支持请求
  • 防止欺诈、滥用、未授权访问与服务中断
  • 遵守税务、会计与适用法律义务
  • 在法律要求或保护自身权利时进行披露

我们不会出售你的个人信息,也不会将其用于无关的第三方广告。

6. 法律依据(GDPR 等)

若你位于欧洲经济区、英国或类似司法辖区,处理依据通常包括:履行合同(提供软件与账号)、合法利益(安全、防滥用、基本运营日志)、法律义务(税务与会计),以及在少数场景下的同意(例如你主动订阅非必要通信)。

7. 国际传输

我们的服务器在美国。使用本服务即表示相关信息可能在美国处理。对欧盟/英国用户,传输可能依赖适用的标准合同条款或支付机构提供的同等机制。支付数据主要由 Merchant of Record 按其基础设施处理。

8. 保留期限

  • 账号与设备绑定:直至你删除账号或我们依法必须删除
  • 加密同步对象:随账号删除或你关闭并清除同步而删除
  • 网站 / 安全日志:通常为安全与运维所需的有限期限(约 90 天,除非调查需要更长)
  • 交易与税务记录:按 Paddle 及适用法律(常见为数年)保留;我们不保存完整卡号
  • 支持邮件:在解决请求所需期间保留

9. 安全

同步内容使用客户端 AES-256-GCM;密钥由主密码经 Argon2id 派生。设备私钥留在系统钥匙串。传输使用 HTTPS。任何在线服务都无法保证绝对安全,请妥善保管主密码与设备。

10. 你的权利

视所在地法律,你可能有权:查阅、更正、删除、导出、限制或反对特定处理,以及撤回同意。加州居民可请求了解或删除个人信息;我们不出售或不“分享”个人信息用于跨场景行为广告。

请发送邮件至 [email protected],并说明请求类型。我们可能需要验证你对相关邮箱或账号的控制权。法律要求或防欺诈需要时,我们可能无法立即删除全部记录。

11. 儿童

VsTerm 面向系统管理员与开发者,不面向 16 岁以下儿童。我们不会故意收集儿童个人信息。若你认为我们误收了此类数据,请联系我们,我们会删除。

12. 政策变更

我们可能更新本政策。修订后的版本将发布于本页面并更新日期。对重大变更,我们会在官网或以账号邮箱通知(如适用)。

13. 联系我们

隐私请求与数据问题请发送至 [email protected]。更多联系方式见 联系我们。

Privacy Policy

Effective / last updated: 8 September 2026

This policy explains how VsTerm (“we”) collects, uses, stores, and shares information related to the website, the desktop client, and optional Personal Cloud. The operator is vesaa. Servers are located in the United States. Contact: [email protected].

If the Chinese and English versions conflict, the English version controls for payment-provider and cross-border compliance review.

What we do not collect

  • SSH private keys or key material stored in the OS keyring
  • Server login passwords, plaintext credentials, or sudo / su passwords
  • Terminal command logs, SSH session contents, or screen output
  • File bodies transferred over SFTP or ZMODEM

Local SSH works fully offline. Optional cloud sync is encrypted on the client before upload; the server stores ciphertext only. Without your master password, blobs are not decryptable — including by VsTerm operators.

1. Scope

This policy covers vsterm.com, the VsTerm desktop app (Windows / macOS / Linux), and services tied to accounts, device binding, and paid entitlements. It does not cover third-party servers you connect to with VsTerm; those systems are operated by their own owners.

2. Information we may collect

2.1 Information you provide

  • Email address, when you create a Personal Cloud account, buy a paid edition, request a refund, or contact support.
  • Account credentials needed to authenticate a cloud account (for example a password hash). The master password used to derive sync-encryption keys stays under your control; we do not store a recoverable copy.
  • Support correspondence you send to our support inbox, including attachments.

2.2 Device and license data

  • Device identifiers such as a device public key / device ID used for binding and Pro entitlement checks. The Ed25519 private key remains in the OS keyring and is never uploaded.
  • License / order metadata: product, transaction id, purchase email, entitlement status, and subscription period if applicable.

2.3 Optional cloud sync

If you enable Personal Cloud sync, the client uploads AES-256-GCM sealed objects (for example sessions, command snippets, layouts, preferences, and sealed vault.enc). The server cannot read plaintext. You can turn sync off or delete the account at any time.

2.4 Website and operations logs

  • IP address, coarse location, browser or client type, requested URL, timestamps, and security events.
  • Language preference stored in local localStorage (not an advertising cookie).

Logs exist to run the service, prevent abuse, and debug failures — not to build advertising profiles.

3. Cookies and similar technologies

The website currently uses only what is needed for basic operation:

  • Language preference in browser localStorage (vsterm-lang).
  • Cloudflare, if traffic is served through Cloudflare: essential cookies for security, CDN, and bot protection.
  • Checkout cookies set by the payment provider (Paddle) on their domain or checkout page to complete payment, tax, and fraud checks.

We do not use advertising cookies and we do not sell browsing behavior to ad networks. Essential-only cookies typically do not require a separate consent banner. If we later add non-essential tracking, we will update this policy and offer a choice.

4. Third-party services

We share the minimum information needed with the following categories of processors. Each handles data under its own privacy policy:

  • Payments / Merchant of Record: Paddle is the seller of record for paid purchases. Paddle may collect name, email, billing country, tax IDs, and payment method; we do not receive full card numbers. See the Paddle Privacy Policy and Paddle Checkout Buyer Terms.
  • Cloudflare for CDN, DNS, DDoS, and security. May process IPs and request metadata. See the Cloudflare Privacy Policy.
  • GitHub hosts installers and release notes. Downloads are subject to GitHub’s policies.
  • Support email: [email protected] for support, privacy, refunds, and business mail. Delivery may pass through a mail provider.
  • Infrastructure: origin servers in the United States host the website, accounts, and encrypted sync storage.

5. How we use information

  • Provide, maintain, and protect the VsTerm client, website, and Personal Cloud
  • Complete purchases, invoicing, license checks, and device binding
  • Process refunds, cancellations, and support requests
  • Prevent fraud, abuse, unauthorized access, and outages
  • Meet tax, accounting, and other legal duties
  • Disclose information when required by law or to protect our rights

We do not sell your personal information and we do not use it for unrelated third-party advertising.

6. Legal bases (GDPR and similar)

If you are in the EEA, UK, or a similar jurisdiction, we typically rely on: contract (delivering the software and account), legitimate interests (security, anti-abuse, basic operational logs), legal obligation (tax and accounting), and consent in limited cases (for example optional non-essential messages you opt into).

7. International transfers

Our servers are in the United States. Using the service means related information may be processed in the US. For EU/UK users, transfers may rely on Standard Contractual Clauses or equivalent mechanisms offered by payment providers. Payment data is primarily processed by the Merchant of Record on its own infrastructure.

8. Retention

  • Account and device binding: until you delete the account or we must delete it by law
  • Encrypted sync objects: deleted when the account is deleted or you clear sync
  • Website / security logs: kept for a limited operational window (about 90 days, longer if an investigation requires it)
  • Transaction and tax records: retained as required by Paddle and applicable law (often several years); we do not store full card numbers
  • Support email: retained as needed to resolve the request

9. Security

Sync objects use client-side AES-256-GCM; keys are derived from your master password with Argon2id. Device private keys stay in the OS keyring. Transport uses HTTPS. No online service is perfectly secure — protect your master password and devices.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent. California residents may request to know or delete personal information; we do not sell or “share” personal information for cross-context behavioral advertising.

Email [email protected] and describe the request. We may need to verify control of the relevant email or account. We may be unable to erase every record immediately where law or fraud prevention requires retention.

11. Children

VsTerm is intended for system administrators and developers, not for children under 16. We do not knowingly collect children’s personal information. If you believe we have, contact us and we will delete it.

12. Changes

We may update this policy. The revised version will be posted here with an updated date. For material changes we will note them on the website or via the account email where applicable.

13. Contact

Privacy and data requests: [email protected]. See also Contact.

著作权人 vesaa。个人学习可本地使用;商业使用需授权。

运营与服务器位于美国。

隐私政策 服务条款 退款政策 联系我们 许可证