LEGAL · VERSION 1.0
Privacy Policy
Effective August 24, 2026
TermiSec is local by design. This policy explains what stays on your Mac, what limited information the website processes, and the choices available to you.
1. Who operates TermiSec
TermiSec is operated by Cem Bas in San Diego, California, United States. For privacy questions or requests, email cem@tokensurf.io.
2. The macOS app
TermiSec does not require an account and does not include first-party analytics, advertising, crash reporting, or telemetry. Repository files, paths, scan findings, terminal input, and command history are processed on your Mac. The working copy is placed in a temporary workspace, runtime state is held locally, and TermiSec attempts to remove its temporary workspace when the app exits and when it next starts.
TermiSec starts with guest networking blocked. If you approve a repository fetch, package download, audit, or another network operation, that command communicates with the destination specified by the command or tool. The destination may receive normal network information such as your IP address and any data the command sends. TermiSec does not route that traffic to Cem Bas or a TermiSec service.
No security tool can guarantee that third-party code is safe. Review the destination and command before approving network access.
3. Website information
Download counting
When you use the normal download endpoint, the server reads your IP address, browser user-agent, and the UTC date. It immediately combines and hashes those values into a daily event key used to avoid counting repeated downloads from the same browser more than once per day. TermiSec stores the event key, a counter identifier, and a timestamp; it does not store the source IP address or user-agent in the download-events database.
Event keys older than 30 days are deleted by daily counter maintenance, normally within 24 hours after the retention period ends. The non-identifying aggregate download total may be retained indefinitely.
Hosting logs
The hosting and content-delivery provider may process standard request information, including IP address, request time, requested URL, user-agent, and security signals, to deliver and protect the website. Its retention is governed by the provider settings and applicable service terms.
Messages
If you email TermiSec, the message, address, and related correspondence are used to respond, provide support, prevent abuse, and maintain appropriate business records. They are kept only as long as reasonably necessary for those purposes or legal obligations.
4. Cookies and tracking
TermiSec does not use advertising cookies, cross-site tracking, behavioral profiling, or third-party marketing analytics. The public website does not require a TermiSec account. A hosting provider may use strictly necessary security or delivery technology.
5. Purposes and legal bases
TermiSec processes the limited website information described above to:
- deliver the requested website and download;
- maintain an abuse-resistant aggregate download count;
- protect the website and diagnose failures; and
- answer messages and provide support.
Where European or UK data-protection law applies, these activities rely on legitimate interests in operating, measuring, supporting, and securing the service, except where consent or another legal basis is required. TermiSec does not sell personal information or share it for cross-context behavioral advertising.
6. Service providers and international processing
TermiSec uses Supabase to maintain the download counter and uses a hosting or content-delivery provider to serve the website and download. Email providers process correspondence. These providers process information to supply their services and may process it in the United States or other countries where they operate, subject to their contractual and legal safeguards.
7. Your privacy choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or an objection to certain processing, and to appeal or complain to a privacy regulator. Email cem@tokensurf.io to make a request. TermiSec may need information to verify and locate the relevant record.
Because the download event is stored only as a daily hash and is not tied to an account, TermiSec usually cannot identify a particular person or retrieve that person's event without additional information. TermiSec will not collect extra identifying information solely to identify an otherwise pseudonymous event.
8. Security, children, and changes
TermiSec uses reasonable technical and organizational safeguards, but no system is completely secure. TermiSec is a developer tool for a general audience and is not directed to children under 13. TermiSec does not knowingly collect children's personal information.
This policy may change as the product changes. Material updates will be posted here with a new effective date. Continued use after an update is subject to the revised policy.