Privacy Policy
This Privacy Policy explains how BURSUsofts ("we", "us") handles your information when you use the BURSU Connection Manager desktop application ("the app") and the BURSUcloud service at bursucm.com ("the service").
1. Information we collect
- Account data. When you create a BURSUcloud account we store your email address, a securely hashed password, and optional profile fields (first name, last name, nickname).
- Google sign-in. If you choose "Continue with Google", we receive your verified email, basic profile and a Google account identifier to create or link your account. We never receive your Google password.
- Service data. Connection catalogs you sync to BURSUcloud are stored in an isolated PostgreSQL database. Stored secrets (passwords, SSH keys) are encrypted at rest.
- Technical data. Standard web server logs (IP address, timestamp, user agent) and a session cookie required to keep you signed in.
2. How we use it
- To create and operate your account and the service.
- To provision and connect your cloud database over our secure API.
- To secure the service and prevent abuse.
- To respond to support requests.
3. The desktop app and local data
Used in local mode, the app stores your connections and credentials only on your own computer (local SQLite, protected by a portable AES-256-GCM master password, or Windows DPAPI on Windows). That data never leaves your device unless you choose to sync it to BURSUcloud.
The optional AI assistant sends your conversation — and, if you attach them, terminal output and files — directly from your device to the AI provider you chose, or to a local model on your own machine. Our servers never see this traffic. Secret Shield redacts detected passwords, keys and tokens before text is sent, provider API keys are stored encrypted, and the assistant does nothing until you add a key. A single setting turns the feature off completely.
4. Problem reports you send us
You can send us a problem report from this website, and the BURSU CM apps are getting the same feature. Nothing is ever sent automatically: a report leaves your device only when you press Send, and before you do, you are shown the exact text and files it is about to transmit.
A report contains what you write, the software version and your operating system, the failure itself where the program can describe it (error message and stack trace), and any log or screenshot you choose to attach. Passwords, master passwords, private keys and access tokens are removed on your device before the report is shown to you, and connection host names and user names are hidden unless you explicitly include them.
We record the country the report came from and a one-way hash of the network address — enough to recognise repeat reports and abuse, not enough to recover the address itself. Reports are used only to diagnose the problem and to answer you, are never shared or sold, and are deleted after 90 days.
5. Sharing
We do not sell your data. We share information only with infrastructure providers needed to run the service, or where required by law.
6. Security
Passwords are hashed, stored secrets are encrypted, PostgreSQL is not exposed to the public internet, and access runs over our zero-knowledge API and HTTPS. No system is perfectly secure, but we take reasonable measures to protect your data.
Desktop and mobile apps send only ciphertext. Website vault actions process the master password temporarily on the server.
7. Data retention & your rights
We keep account and service data while your account is active. You may request access, correction or deletion of your data, or delete your databases and account at any time.
8. Cookies
We use an essential session cookie to keep you signed in and a cookie that remembers your language. Site traffic is measured with Google Analytics.
9. Contact
Questions about this policy? Contact us at support [at] bursucm.com.