Skip to content

Privacy ​

AeroFTP is a privacy-enhanced file manager. It collects no telemetry, sends no analytics, and makes no network requests beyond user-initiated connections.

Data Collection ​

AeroFTP collects nothing.

CategoryStatus
Usage analyticsNone
Crash reportingNone
TelemetryNone
Phone-home requestsNone
User trackingNone

The application makes network connections only when the user explicitly initiates a file transfer, cloud provider connection, AI chat request, or update check.

Local Storage ​

All application data is stored locally in the user's configuration directory:

PlatformPath
Linux~/.config/aeroftp/
macOS~/Library/Application Support/aeroftp/
Windows%APPDATA%\aeroftp\
DataStorageEncryption
Server credentialsvault.dbAES-256-GCM per entry
OAuth tokensvault.dbAES-256-GCM per entry
AI API keysvault.dbAES-256-GCM per entry
Application settingsvault.dbAES-256-GCM per entry
Chat historyai_chat_history.dbSQLite (local, not encrypted)
Agent memoryagent_memory.dbSQLite (local, not encrypted)
Sync journalssync_*.dbSQLite WAL (local)
File tagsfile_tags.dbSQLite WAL (local)
UI stateBrowser localStorageNot encrypted (non-sensitive: window size, panel layout)

AI Provider Connections ​

When using AeroAgent, the application connects directly to the user's chosen AI provider using the user's own API key. AeroFTP does not proxy, log, or inspect AI conversations. Supported providers: OpenAI, Anthropic, Gemini, xAI, OpenRouter, Ollama (local), Kimi, Qwen, DeepSeek, Mistral, Groq, Perplexity, Cohere, Together, and custom endpoints.

For local AI (Ollama), all processing happens on the user's machine with zero external network traffic.

Memory Protection ​

Sensitive values are actively cleared from memory after use:

  • Passwords, API keys, and OAuth tokens are wrapped in secrecy::SecretString
  • When the wrapper is dropped, the underlying memory is overwritten with zeros before deallocation
  • This prevents credential recovery from memory dumps, swap files, or core dumps on systems with encrypted swap

What AeroFTP Is Not ​

AeroFTP is privacy-enhanced, not anonymous. Network connections to remote servers are visible to network observers. For network-level privacy, combine AeroFTP with a VPN or Tor. AeroFTP's privacy protections focus on local data at rest and minimizing traces on the host system.

Deletion ​

To remove all AeroFTP data from a system:

  1. Uninstall the application.
  2. Delete every AeroFTP data directory that exists. After an update more than one can exist, because a directory named after the previous application identifier is left in place:
    • Linux: ~/.config/aeroftp/, ~/.local/share/app.aeroftp.AeroFTP/ and ~/.local/share/com.aeroftp.AeroFTP/
    • macOS: ~/Library/Application Support/aeroftp/, and any app.aeroftp.AeroFTP or com.aeroftp.AeroFTP folder under ~/Library/Application Support/, ~/Library/Caches/ and ~/Library/WebKit/
    • Windows: %APPDATA%\aeroftp\, and any app.aeroftp.AeroFTP or com.aeroftp.AeroFTP folder under %APPDATA% and %LOCALAPPDATA%
  3. If the vault is protected by the system keyring rather than by a master password, delete the keyring entry too. It is stored under the service name com.aeroftp.AeroFTP (account vault-passphrase, or vault-passphrase-portable, vault-passphrase-flatpak or vault-passphrase-snap for those installations), and deleting the directories above does not remove it. The per-platform commands are in PRIVACY.md.

AeroFTP does not create cloud accounts and does not store data on external servers.

aeroftp.app - Released under the GPL-3.0 License. AeroFTP Reviews