Privacy policy
Ichor has no server, no account and no ads. The developer receives none of your data. The app talks to your own Talos clusters and, only for the features listed below, to GitHub, to Google's on-device barcode library, and, if you turn them on, to an icon download service and an AI provider you choose yourself.
What stays on your phone
- Talos configurations (talosconfig: endpoints, client certificate and private key). Encrypted with a key held in the Android Keystore (StrongBox or TEE) or the iOS Secure Enclave/Keychain, and excluded from device backups.
- AI provider API keys, if you add one. Encrypted the same way.
- Settings and the last cluster check, used by background alerts and the home-screen widget.
- Files you save, such as packet captures, etcd snapshots or a kubeconfig, are written only where you choose.
Removing a cluster in the app deletes its credentials. Uninstalling the app on Android deletes everything it stored. On iOS, Keychain items can survive uninstalling, so use Settings → Delete in the app first.
What the app sends, and to whom
- Your Talos clusters. The app connects directly to the endpoints in
your talosconfig, over mutually authenticated TLS, as
talosctldoes. With an admin talosconfig, the Kubernetes screens also reach the cluster's Kubernetes API with the admin kubeconfig Talos issues, kept in memory only and never written to storage. The developer is not involved in these connections. - GitHub (
api.github.com). The app reads the public list of Talos releases to tell you when an upgrade is available, and the app's own release notes from its source repository. Builds installed from GitHub releases also check that repository for app updates. GitHub sees your IP address, as for any web request, and its privacy statement applies. Nothing about your cluster is sent. - Google ML Kit (QR code import). Camera frames are decoded on the phone and are neither stored nor sent. The library itself sends Google diagnostics and usage data: device model and OS version, the app's package name and version, a per-installation identifier that does not identify you or your device, performance metrics and error codes. See Google's ML Kit data disclosure.
- App icons, only if you turn it on. The logos of about 250 common apps
ship inside Ichor. When the Download missing app icons setting is on (it is off by
default), the logos of other recognised apps are downloaded from jsDelivr
(
cdn.jsdelivr.net, the Dashboard Icons set) and kept in the app's cache. Each request carries only the icon's public name, never your image names, namespaces or other cluster details. jsDelivr sees your IP address, as for any web request, and its privacy policy applies. An Argo CD app may also link its own icon in itsichor.levis.name/iconannotation: with the setting on, it is downloaded from that address, whose server sees your IP address. An icon written inline in the annotation is never downloaded. - AI diagnosis, only if you turn it on. It is off by default. When you tap Ask, a report of the cluster state (node readiness, services, resource usage, etcd status, recent events and the last lines of unhealthy services' logs) is sent over HTTPS, with your own API key, to the provider you picked: Anthropic, OpenAI, or a server whose address you entered. Node names, addresses and the cluster domain are replaced with placeholders by default, but other text in the logs is sent as it is. The report never contains the talosconfig, a machine configuration or a kubeconfig. That provider's own privacy policy then applies: Anthropic, OpenAI.
- Google Play, for feature funding (Play version only). The app downloads
the public list of features open for funding from this website
(
cyrinux.github.io, hosted by GitHub). If you back a feature, Google Play handles the payment under the Google Privacy Policy; the developer receives Play's sales reports, not your name or payment details. The app remembers on the phone which features you backed, and sends that nowhere. - Apps you share with. When you use the share sheet (an AI report, a packet capture, a talosconfig QR code), the content goes to the app you pick, and only then.
Permissions
- Camera: only to scan a talosconfig QR code, and only while the scanner is open.
- Notifications: cluster alerts and certificate-expiry reminders. With the app lock on, lock-screen notifications show only a generic text.
- Biometrics: the optional app lock uses the system prompt. The app never sees your fingerprint or face data.
- Network: the connections listed above.
What the app does not do
- No account, no sign-in, no developer server.
- No advertising, no advertising identifier, no tracking across apps or websites.
- No sale or transfer of personal data. The developer never receives it.
Children
The app is a tool for administering server clusters and is not directed at children.
Changes
Changes to this policy are published on this page, with a new effective date. Its history is in the source repository.
Contact
Questions or requests: open an issue at github.com/cyrinux/ichor/issues.