Extension privacy practices and permissions

This is the privacy and permissions disclosure for the Wharfsync extension as listed on the Visual Studio Marketplace and Open VSX.

Data collection

QuestionAnswer
Does the extension collect telemetry, analytics or usage data?No.
Does it send your files, file names, paths, server names, usernames or passwords to the publisher?No. They go only to the servers you configure.
What does it send to the publisher?Only your licence key (if you have one), about once a day, to renew it; and the same key when you choose "Manage or cancel subscription". Automatic renewal can be turned off.
Is data sold or used for advertising?No.
Where is the licence server?UK (OVHcloud, London), operated by Nikah AI Ltd.
Privacy noticePrivacy Notice

What the extension accesses, and why

VS Code extensions do not have a formal permission system, so here is everything Wharfsync uses:

AccessWhy
Files in your open workspaceTo read files you upload and to write files you download or sync.
.vscode/sftp.jsonYour connection settings. Rewritten only when you approve the move of secrets into your keychain.
Network connections to your servers (SFTP, FTP, FTPS)To transfer files. Only to hosts in your config.
Network connection to wharfsync.com (HTTPS)Licence renewal and opening the subscription portal. Nothing else.
Your OS keychain (via the editor's secret storage)To keep passwords, key passphrases and your licence key out of files.
Private key files named in privateKeyPathTo sign in to SSH servers. Read locally, never sent anywhere.
SSH agent socket (if agent is set)To sign in with keys held by your SSH agent. On Windows, the built-in OpenSSH agent.
Your project's .git/configRead locally, only to find remote host names for the exposed-password warning. Never sent anywhere.
Editor storage (global and workspace state)Pinned host keys, sync records and settings.
The .wharfsync folder in your projectPro backups of files before they are overwritten (kept 7 days).
File watchersUpload on save, and watch mode (Pro).
Opening your web browserOnly when you choose Get Pro or Manage subscription.

Wharfsync does not start other programs, does not use your git credentials, and only runs in trusted workspaces.