LinuxCLI
ToolsCommandsChangelogAbout
Log in · Sign up

Privacy Policy

LinuxCLI is built to keep as little data as possible while still being able to run a shared service responsibly — preventing abuse, keeping the sandbox available, and following the law. This page describes exactly what is collected, why, and for how long.

Command activity (audit log)

Every command you submit — whether it runs successfully, fails, or is rejected by the command validator — is recorded: a hashed identifier derived from your IP address (HMAC-SHA256, not the raw address), the command and arguments (or the rejected raw text), a timestamp, and the outcome (exit code, duration, whether output was truncated).

This log exists to investigate abuse reports and keep the service reliable — it is never used for advertising or profiling. Entries are insert-only (nothing is ever edited) and are automatically deleted after 90 days by the database itself, with no separate manual step.

Account data (if you register)

Registering with email and password stores your email (used only to log in — never shown anywhere else in the interface) and a username (a public-facing nickname). Your password is never stored: only a salted scrypt hash of it is, using a memory-hard algorithm designed to resist offline cracking.

Signing in with GitHub or Google stores your provider account ID, email, and the username it gave us — there is no password to store for these accounts at all. LinuxCLI never sees your GitHub or Google password; the whole exchange happens directly between your browser, the provider, and our backend.

API key / session token

Whether you're anonymous or signed in, your session is a random 256-bit token. Your browser keeps the real value in local storage; the server only ever stores a SHA-256 hash of it — the same approach used for passwords, adapted for a value that's already high-entropy and needs a fast lookup.

Cookies

LinuxCLI itself does not set any cookies. Your login session and preferences (theme, API key) live in your browser's local storage, not cookies. The one exception is Cloudflare Turnstile, the anti-bot check that runs invisibly in the background — it may set its own cookie as part of verifying you're not a bot. This is a security mechanism, not tracking or advertising; see Cloudflare's own privacy policy for details on what it does with that cookie.

Third parties

Cloudflare (hosting, and Turnstile for anti-bot protection) sees every request the way any host or CDN would. GitHub or Google are only contacted if you click their sign-in button yourself. LinuxCLI does not use any analytics, advertising, or tracking scripts.

What's kept, and for how long

Audit log entries (command, hashed IP, outcome)90 days, automatic (database TTL), regardless of account deletion
Session / API keyUntil you log out, delete your account, or 24 hours of inactivity
Account (email, username, password hash)Until you delete your account

Your rights

If you have an account, you can see your username and log out or delete your account entirely from your account page. Deleting your account permanently removes your account record and revokes every session token stored for it, so nothing can log in as you again.

Two honest caveats. First: deleting your account does not retroactively erase audit log entries already written before the deletion. Those entries are pseudonymized (hashed IP, not linked directly to your account) and insert-only by design — they simply age out on their own within the 90-day window above, the same as everyone else's. Second: if you have a terminal session already open in another tab at the moment you delete your account, that specific open connection can keep running until you close or reload it — deletion prevents new connections and logins, it does not forcibly disconnect ones already in progress.

LinuxCLI — disposable, sandboxed network diagnostic tools in your browser.

Privacy · Terms