Privacy policy
Complete policy for Android and the documentation website.
Effective September 6, 2026. AutoSecureLogin provides ASL Keycloak Console and the Keycloak Console field guide. Contact privacy@autosecurelogin.com for privacy questions or requests. This policy covers these products; your server operator’s and third-party providers’ policies also apply to their services.
Android data: the app processes the profile label, SSH domain, ports, username, imported private key, optional passphrase, approved host fingerprint and Keycloak base path. Sensitive stored profile values use Android Keystore-backed local encryption; hardware backing depends on the device. Backup and device-transfer extraction are disabled. Non-secret interface preferences may use local preferences.
Direct connections: the selected SSH server receives authentication and network traffic. Standard mode carries Keycloak HTTP traffic through a device-loopback SSH tunnel to your infrastructure. The embedded WebView processes the login, MFA and administration session. Standard console actions can modify your server under your account permissions. Advanced mode receives bounded read-only realm, user, client and role summaries; connector credentials and tokens stay on your server.
AutoSecureLogin does not receive or relay your tunnel traffic, private key, passphrase, Keycloak password, access tokens or administration records through the app. There is no ASL connection backend, ASL login requirement, advertising SDK or analytics/telemetry endpoint in this connection workflow. We do not sell these locally handled records or use them for advertising.
Session and local retention: embedded cookies, web storage, cache and history are cleared when the console closes and before a new session. Closing or rotating the console closes its tunnel. Remove Profile deletes the stored profile and key material in this app. Uninstalling or clearing app data removes app-scoped storage under Android’s controls. These actions do not revoke server keys, delete Keycloak accounts or erase server logs.
Website: the separate documentation PWA never requests SSH keys or Keycloak credentials. It stores checklist completion in unencrypted browser local storage and guide files in a service-worker cache. Help search runs locally. Clear site data to remove these records. The site contains no advertising or analytics code. Static hosting may process ordinary request metadata, including IP address, time, requested path and user agent, for serving and operating the website.
Other recipients: your selected SSH and Keycloak infrastructure can keep authentication, administration and network logs under its own configuration. Google Play handles app purchases and distribution under its policy. The current Keycloak guide has no configured contribution checkout. If you choose an external support or payment link, that provider handles information you submit under its own policy. The Android app does not collect payment-card details.
Support: emailing us shares the address, message and attachments you choose to send. Send only information needed to resolve the issue and redact credentials and private records. Support correspondence and operational records may be retained as needed to answer requests, operate the service and meet applicable obligations. We do not promise a fixed deletion period for records controlled by your server operator, Google or another provider.
Security and control: the app pins independently approved host fingerprints, restricts the embedded session origin, binds the local tunnel to loopback, encrypts sensitive stored profile values and blocks production screenshots. Protect the device, keep a separate original key, use a passphrase and MFA, and revoke server access if a device is lost. No software can guarantee protection on a compromised device. AutoSecureLogin cannot recover your private key or reset your server credentials.
Requests and changes: contact privacy@autosecurelogin.com to ask about access, correction or deletion of information you sent to us. For data kept only on your device, use the local controls; for server records, contact the relevant operator. Applicable privacy rights depend on your location. The tool is intended for authorized administrators and is not directed to children. Material policy changes will be published with an updated effective date.