Privacy Policy
Last updated: October 6, 2026
The short version: Shellpocket connects straight from your iPhone to your own server. Your server addresses, passwords, keys and files never reach us. The only thing the app reports is an anonymous app-launch count through TelemetryDeck. Purchases are handled entirely by Apple.
1. Overview
Shellpocket (formerly HomePilot) is a native iOS app for managing your own self-hosted servers. It connects directly from your iPhone to your server over your local network, a VPN, or the internet. There is no Shellpocket account and no intermediary cloud service.
2. Data We Collect
Shellpocket does not collect personal data. One embedded third-party SDK receives limited, anonymous information, described below.
TelemetryDeck (Analytics)
Shellpocket uses TelemetryDeck to count app launches. It sends one event, "app launched", with no information about your servers, credentials, files or activity in the app.
- The user identifier is a random value, hashed with SHA-256 and a salt before it leaves your device, so it cannot be traced back to you
- Each event includes app version, iOS version, device type (for example "iPhone") and locale
- IP addresses are not stored
- No name, email, Apple ID, Advertising Identifier (IDFA) or cross-app tracking
TelemetryDeck's privacy policy: telemetrydeck.com/privacy
Purchases
The Shellpocket Pro subscription is sold and managed by Apple through the App Store. Shellpocket checks your subscription status on your device using Apple's StoreKit. We never receive your name, email, payment details or Apple ID, and no other company handles your purchase.
3. Data Stored on Your Device
Shellpocket stores the following on your iPhone only:
- Server addresses and profiles (names, IP addresses or hostnames, ports, chosen services) — in the app's local settings
- Credentials (usernames, passwords, API keys, session tokens, SSH private keys and passphrases) — in the iOS Keychain, encrypted by iOS
- SSH host fingerprints — in the iOS Keychain, used to warn you if a server's identity changes
- Latest metrics (CPU, memory, disk, container and download counts) — in storage shared with Shellpocket's own widgets
- Free-trial start date — in the Keychain, so reinstalling the app doesn't reset the trial
None of this is sent to us or to any third party.
4. iCloud
Shellpocket uses Apple's iCloud key-value storage, which only you can access through your Apple ID:
- Always: the free-trial start date, so the trial stays the same across your devices
- Only if you turn on iCloud Sync in Settings: your server address, your SSH hosts' names, addresses, ports and usernames, and whether Face ID lock is on
Passwords, API keys, SSH keys and session tokens are never synced to iCloud. They stay in the Keychain on each device.
5. Network Connections
Shellpocket talks directly to your own server using:
- Socket.IO (Dockge container management)
- HTTP (qBittorrent, Sonarr, Radarr, Prowlarr, Prometheus, Grafana)
- SSH and SFTP (terminal and file access)
- A built-in web view (Grafana dashboards)
Every connection goes from your iPhone to an address you entered. No traffic passes through our infrastructure.
Push notifications (optional)
If you turn on notifications, your device's push token and the alert types you chose are sent to the Shellpocket Notifier container running on your own server. That container sends alerts through Apple's Push Notification service. The token never reaches us.
6. Third-Party Services and Libraries
- TelemetryDeck — anonymous launch count (see Section 2)
- Apple StoreKit, iCloud and Push Notification service — purchases, sync and alerts (see Sections 2, 4 and 5)
- Socket.IO-Client-Swift — container management connection to your server
- Citadel — SSH and SFTP connections to your server
- SwiftTerm — terminal display
Socket.IO-Client-Swift, Citadel and SwiftTerm only communicate with your own server and send nothing to third parties.
7. Data Sharing
We do not sell or share data. Apart from the anonymous launch count above, we never receive any.
8. Children's Privacy
Shellpocket is a server management tool not directed at children under 13. We do not knowingly collect data from anyone, including children.
9. Deleting Your Data
- Settings → Danger zone → Reset everything — removes all servers, credentials and settings from the app
- Delete the app — removes the app's local data. iOS may keep Keychain items (including the trial start date) until you reset the device; using Reset everything first removes your credentials
- iCloud — turn off iCloud Sync in Settings to stop syncing; Apple's iCloud settings let you remove stored app data
10. Changes to This Policy
If this policy changes, the new version will be posted at this address with a new date at the top.
11. Contact
Questions about privacy? Email muzyukins@gmail.com.