Privacy
Chapar has no backend. There is no Chapar account, no analytics, and no server of ours your data could sit on — so there is nothing for us to collect, sell, or lose.
Last updated 30 August 2026
What goes where
Every category of data the app touches, and how far it travels.
| Data | Where it goes | Notes |
|---|---|---|
| Passwords | never leaves | Device Keychain, marked device-only. Not in iCloud, not in backups. |
| Private keys | never leaves | Secure Enclave keys are hardware-bound and cannot be exported at all. |
| Host key pins | never leaves | A pin is one device’s judgement; syncing it silently would undermine it. |
| Keystrokes | never leaves | Not recorded at all. History logs only commands Chapar sent for you. |
| Server output | on device | Travels between your phone and your server. Nothing passes through us. |
| AI features | on device | Apple’s on-device model. No cloud provider sees your commands or output. |
| Scans & captures | on device | Run from your device or a host you chose. Results come straight back. |
| Hosts & snippets | your iCloud | Only if you turn sync on. Your iCloud account, never a Chapar server. |
| Secure notes | your iCloud | With end-to-end encryption on, iCloud stores only ciphertext. |
We collect no personal data. Chapar contains no analytics, no advertising, no tracking, and no third-party SDKs. It makes no network connection except to the servers and resolvers you explicitly point it at.
The detail
Data you enter
Hostnames, usernames, ports, snippets, runbooks and notes are stored on your device using Apple’s standard app storage. Credentials — passwords, key passphrases and private keys — are stored separately in the device Keychain with device-only protection, meaning they are excluded from iCloud and from device backups, and are unavailable while the phone is locked.
Connections you make
When you connect to a server, that traffic goes directly from your device to that server. Chapar operates no proxy, relay or intermediary. We cannot see your sessions, and no record of them reaches us.
On-device intelligence
Features that explain commands, summarise output, diagnose failures, suggest a command, assess a scan or search your history by meaning all run on Apple’s on-device foundation model. Your data is not sent to Apple, to us, or to any AI provider. If the model is unavailable on your device, these features fall back to Chapar’s own built-in rules rather than reaching for a network.
Optional iCloud sync
Sync is off by default. If you enable it, host definitions, snippets, runbooks and command history sync through your own iCloud account using Apple’s CloudKit — we have no access to that data and no ability to read it. Credentials and host key pins are excluded by construction, not by policy.
Enabling end-to-end encryption additionally encrypts your secure notes with a key stored only in your iCloud Keychain, which Apple end-to-end encrypts across your devices. In that mode CloudKit holds ciphertext that neither Apple nor we can decrypt.
Network tools
The scanner, nmap, packet capture, DNS, SNMP and TLS tools contact only the hosts and resolvers you specify. DNS lookups use DNS-over-HTTPS via the public resolver you select in the app (Cloudflare or Google), and are subject to that resolver’s own privacy policy. No results are reported to us.
These tools are intended for infrastructure you administer or have permission to test. Scanning networks you do not control may be illegal in your jurisdiction.
Diagnostics and crash reports
Chapar contains no crash-reporting or telemetry SDK. If you opt into
sharing analytics with Apple at the system level, Apple may provide us
with aggregated, anonymised crash reports through App Store Connect. That
is an Apple system feature you control in
Settings › Privacy & Security › Analytics, and it
contains no data from your servers or sessions.
Children
Chapar is a developer and system-administration tool. It is not directed at children and collects no data from anyone, regardless of age.
Your rights
Because we hold no data about you, there is nothing for us to disclose, correct, export or delete on request. All app data lives on your device and, if you enabled sync, in your own iCloud account — both entirely under your control. Deleting the app removes its local data; Keychain items are removed with it.
Changes to this policy
If this policy changes, the updated date above will change with it, and material changes will be noted in the app’s release notes.
Contact
Questions about privacy, or about anything on this page: privacy@chapar.app.