Your data stays with you
Orchid SSH doesn't collect telemetry, doesn't use analytics and doesn't require an account.
Last updated: October 7, 2026.
Summary
Orchid SSH is a desktop application. Everything you configure — servers, credentials, preferences and host keys — is stored locally, on your computer. There is no backend of ours collecting usage data.
What we don't do
- We don't collect telemetry, usage statistics or identifiers.
- We don't use cookies, pixels or trackers on this site.
- We don't require an account, login or sign-up to use the app.
- We don't send your connections, commands, files or credentials to us.
- We don't sell or share data with third parties.
What stays on your computer
The data stays in the app's userData folder, varying by system:
- Windows:
%APPDATA%\Orchid SSH - macOS:
~/Library/Application Support/Orchid SSH - Linux:
~/.config/Orchid SSH
workspace.jsonFolders and connections (no passwords)settings.jsonPreferences (theme, font)secrets.vault.jsonPasswords and passphrases encrypted via safeStorageknown_hosts.jsonFingerprints of trusted SSH host keys and FTPS certificatesCredentials
Passwords and passphrases are encrypted by the operating system through safeStorage:
DPAPI on Windows, Keychain on macOS and libsecret on Linux. They are never written in plain text, in
workspace.json or in logs.
What leaves your machine
- Connections: SSH, SFTP, FTP(S) and RDP sessions leave your computer directly to the server you configured — they never pass through us. The data transmitted depends on your server.
-
Automatic update: the app reads a public, anonymous feed at
downloads.orchidssh.com(Cloudflare R2) to check for new versions. There is no embedded token and no data sent beyond the HTTP request — like any request, the provider sees the IP and the user-agent. - Downloads: when downloading from the site page, the browser accesses the installers on the same Cloudflare domain.
Third-party services
- GitHub — hosts the source code, the issues and this repository.
- Cloudflare (R2) — hosts the update manifests and the installers.
When accessing these services (including through links on the site), they may record access data in accordance with their own privacy policies.
Questions
If anything here isn't clear, open an issue on GitHub. The code is open under the MIT license and can be audited by anyone.