Legal

Privacy Policy

This policy explains what personal data SSH Protector collects, why, on what legal basis, who we share it with and how long we keep it. It covers the website, the control panel and the Windows agent.

Version 1.0 · Effective 26 August 2026 · Governing language: English

1. Who is responsible

The controller is File Master LLC, Serena app., office C13, Golden Sands, Varna 9007, Bulgaria, VAT 180842207. Because we are established in the EU, the General Data Protection Regulation (GDPR) applies to our processing.

For data about your own end users that may reach us through your use of the service, you are the controller and we act as processor — see the Data Processing Addendum.

2. Account and organisation data

When you create an account we store:

  • your email address;
  • a hash of your password (never the password itself), using a modern slow hashing algorithm;
  • your multi-factor authentication secret, if you enable MFA;
  • your interface language;
  • the organisations you belong to, their names, and your role in each;
  • an audit log of administrative actions in your organisation: who did what, to which object, with what parameters, and when.

If you sign in with Google or GitHub, we receive your email address and the provider's user identifier from that provider. We do not receive your password there, and we do not post anything on your behalf.

3. Data your servers report

Each installed agent reports, about the machine it runs on:

  • hostname, and any display name you set;
  • operating system version and CPU architecture;
  • the server's public IP address;
  • which ports the protected services (SSH, SFTP, FTP) are listening on;
  • agent version and configuration hash;
  • a machine fingerprint, used to detect an agent key being reused on a different host;
  • last-seen timestamp and health status.

Where your servers are individual people's machines rather than infrastructure, this data can be personal data. It is processed to deliver the service you asked for.

4. Attack data and third-party IP addresses

The agent reads the host's own authentication log (journald, or /var/log/auth.log) for failed authentication events and reports, for each banned source:

  • the source IP address or the subnet (CIDR) it belongs to;
  • the autonomous system number and operator name for that network;
  • the country the address is registered to, on a best-effort basis;
  • which service was targeted (SSH, SFTP, FTP);
  • timestamps and the number of attempts.

Under the GDPR, an IP address can be personal data even when it belongs to someone attacking a server. We process it on the basis of legitimate interest in network and information security — the interest that Recital 49 of the GDPR describes explicitly. We have assessed that the interest in preventing unauthorised access to our customers' servers outweighs the limited privacy impact on the source of that traffic, and we minimise what is collected: no payloads, no attempted usernames beyond what is needed for detection, and no content of any kind.

To resolve an address to its network and country we use ipinfo.io. Results are cached so the same address is not looked up repeatedly.

5. Shared threat intelligence

On paid plans, addresses and subnets that attacked one customer can be blocked pre-emptively for other customers. What is shared across the customer base is the attacking network's address, its network metadata, the targeted service and timing — never the identity of the customer that was attacked, never their server names or addresses, and never any content.

You cannot opt out of contributing attack metadata while using a plan that includes shared reputation, because the feature is reciprocal by design. You can use the Free plan, which relies on local detection only.

6. Billing data

We do not receive or store payment card numbers. Payments are processed by PayPro Global (international), YooKassa (Russian Federation) or a cryptocurrency channel. From them we receive confirmation of payment, the subscription state, and the billing identifiers needed to reconcile an account.

Where a provider acts as merchant of record, it is an independent controller for the payment data it collects from you, under its own privacy policy.

7. Website, cookies and analytics

Strictly necessary cookies

  • a refresh-token cookie, set after sign-in, which keeps you signed in. It is HTTP-only, restricted to the authentication path, and cleared when you sign out;
  • a short-lived OAuth nonce cookie during a Google or GitHub sign-in, used to prevent request forgery, and deleted immediately afterwards.

These are required for the service to function and are set on the basis of legitimate interest.

Analytics

The public marketing pages load Google Analytics 4 to understand which pages are read and how visitors arrive. This is used for aggregate statistics, not to identify you. Google Analytics sets its own cookies and processes data under Google's terms; you can prevent it entirely with any standard browser tracking protection or ad blocker, and the site works fully without it.

We do not use advertising cookies, cross-site tracking pixels, or third-party marketing tags.

8. Support correspondence

When you open a support ticket or email us, we store the message, your email address and the thread history, so that we can answer and so that a later question can be understood in context.

If you enable Telegram alerts, we send notification messages to the Telegram chat you nominate through Telegram's Bot API. Those messages contain the alert content — for example, a banned address and the server it was banned on. Telegram processes them under its own policy.

9. What we do not collect

The agent reads its own host's authentication log and writes nftables rules. It does not read your files, your databases, your application data, your users' documents, your shell history or your SSH keys. It has no remote-execution capability, does not scan other machines, and opens no inbound connection of its own — it communicates outbound over HTTPS only.

We do not sell personal data, we do not share it for advertising, and we do not perform automated decision-making that produces legal effects for you.

10. Legal bases

ProcessingLegal basis (GDPR Art. 6)
Providing the panel and the agent to youPerformance of a contract, Art. 6(1)(b)
Billing and accounting recordsContract, and legal obligation Art. 6(1)(c)
Detecting and blocking attacks; shared threat intelligenceLegitimate interest, Art. 6(1)(f) — network and information security
Security and audit loggingLegitimate interest, Art. 6(1)(f)
Transactional email (security, billing, account notices)Performance of a contract, Art. 6(1)(b)
Website analyticsConsent where required by local law, otherwise legitimate interest
Support correspondencePerformance of a contract, Art. 6(1)(b)

11. Sub-processors and recipients

RecipientPurposeData involved
PayPro GlobalInternational payment processingBilling details you give them; we receive only subscription state
YooKassaPayment processing in the Russian FederationAs above
Google (OAuth)Optional "sign in with Google"Email address, provider user ID
GitHub (OAuth)Optional "sign in with GitHub"Email address, provider user ID
Google AnalyticsAggregate website statisticsUsage events, IP address (as processed by Google)
ipinfo.ioResolving an IP to its network, operator and countryThe attacking IP address only
TelegramOptional alert deliveryAlert content, your chat identifier
Email delivery provider (SMTP)Transactional emailYour email address, message content
Hosting providerRunning the panel and databasesAll service data, at rest and in transit

We may also disclose data where legally required, or where necessary to establish, exercise or defend legal claims. We will tell you unless legally prohibited.

We give at least 30 days' notice by email before adding a new sub-processor that handles customer personal data. Business customers may object under the DPA.

12. International transfers

Service data is hosted in the European Union. Some sub-processors listed above are established outside the EEA. Where that involves a transfer of personal data, it is made under an adequacy decision where one applies, or otherwise under the European Commission's Standard Contractual Clauses together with supplementary measures where required.

13. Retention

DataKept for
Attack history visible in the panelSet by your plan: 24 hours (Free), 90 days (Solo), 365 days (Pro and Enterprise)
Account, organisation and server recordsUntil you delete the account
Administrative audit logRetained with the organisation, deleted with it
Shared threat-intelligence recordsWhile the address remains operationally relevant; entries age out as they stop being observed
Support correspondence3 years after the ticket is closed
Invoices and accounting recordsAs required by Bulgarian tax law, currently 10 years
Website analyticsAs configured in Google Analytics, currently 14 months

When you delete your account, account and organisation data is erased. Threat-intelligence records about attacking networks are not tied to your identity and remain in the database; accounting records are retained where the law requires.

14. Security

  • All traffic between the agent, your browser and the panel is encrypted with TLS.
  • Passwords are stored only as slow hashes; we cannot recover them.
  • Agent credentials are stored hashed and can be revoked centrally at any time.
  • The panel supports multi-factor authentication, and we recommend enabling it.
  • Access to production systems is restricted to personnel who need it.
  • Administrative actions are recorded in an append-only audit log.

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Bulgarian supervisory authority within 72 hours and inform you without undue delay where the regulation requires it.

15. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • have inaccurate data corrected;
  • have your data erased, where no legal obligation requires us to keep it;
  • restrict or object to processing carried out on the basis of legitimate interest;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, where processing is based on consent.

Write to tech.support@recoverytoolbox.com. We answer within one month. You may also complain to the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни, cpdp.bg), or to the supervisory authority where you live.

If you are the source of a blocked address and believe it was blocked in error, write to the same address with the IP or subnet. We will review the observations behind the entry and remove it if it is not justified.

16. Changes

We may update this policy. Material changes are announced by email to account holders at least 30 days in advance, and the version and effective date at the top of this page are updated.

17. Contact

File Master LLC
Serena app., office C13, Golden Sands, Varna 9007, Bulgaria
VAT: 180842207
Email: tech.support@recoverytoolbox.com
Phone: +359 88 2253194

See also the Terms of Service and the Data Processing Addendum.