Last updated: March 25, 2026
Attach is a local-first app. Sensitive credentials stay on your device. If you enable push notifications, a minimal relay server forwards encrypted notification data to your phone — we cannot read the notification content. No analytics, no ads, no tracking.
This policy covers the Attach iOS app and the optional attach-notify helper script described on attach.sh. It does not cover the attach.sh marketing website itself; the website has a separate Website Privacy Notice.
The data controller is Arbiter Technologies Ltd. (UIC 207164164), Prof. Krastyo Mirski Str., Bl. 10, Ent. A, Apt. 8, Sofia 1407, Bulgaria.
Attach does not send your SSH credentials, server details, tmux session content, keystrokes, terminal output, or connection history to Attach-operated servers. We do not use analytics, advertising SDKs, tracking pixels, or third-party crash reporting in the app.
If you enable push notifications, the relay server processes an Apple Push Notification device token and a pairing identifier to route notifications. Notification content is end-to-end encrypted before it reaches the relay — we cannot read it. See Section 5 for details.
Attach processes data locally on your device to provide the app.
Attach offers optional push notifications to alert you when tools like Claude Code need attention. Push notifications use a relay server operated by Arbiter Technologies Ltd., hosted in the EU (Hetzner, Germany).
How it works:
attach-notify script encrypts the notification content with AES-256 on your server before sending it to the relay.What the relay stores:
Data lifecycle:
SSH connections are established directly between your device and the servers you configure. Attach does not proxy or relay those sessions through our servers.
127.0.0.1 on your device.If you choose to install attach-notify, it runs on your own machine. It may add a script to your local path, generate and store a local encryption key, and update Claude Code notification hooks on the machine you control.
Those changes happen on your infrastructure. The encryption key used for end-to-end encryption is generated and stored locally on your server and never sent to Attach-operated servers.
Attach is sold through Apple's App Store. Apple processes payment, billing, and account information under Apple's own terms and privacy policies. We do not receive your full payment card details.
The app does not integrate third-party analytics, advertising, tracking, or crash-reporting services. The main third-party services involved are Apple platform services such as the App Store, iOS Keychain, and Apple Push Notification service (APNs).
Because Attach is local-first, most data remains under your control on your device or your own servers. You can remove app-stored data by deleting connections, clearing settings, unpairing push notifications, or deleting the app. Unpairing deletes your device token from the relay server.
Attach is not directed at children under 13, and we do not knowingly collect personal information from children on Attach-operated servers.
We may update this App Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of Attach after changes take effect constitutes acceptance of the revised policy.
Arbiter Technologies Ltd. is the data controller for any personal data processed through the Attach app. The relay server processes a minimal device identifier (APNs token) for push notification routing under GDPR Art. 6(1)(b) (performance of a contract / service you requested). You can request deletion of this data by unpairing in the app or by contacting us.
If you have questions about how your data is handled, contact support@arbt.tech.
You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) or with the supervisory authority in your country of residence.
Arbiter Technologies Ltd. (UIC 207164164)
Prof. Krastyo Mirski Str., Bl. 10, Ent. A, Apt. 8, Sofia 1407, Bulgaria
Email: support@arbt.tech