Shellaro Download

Privacy

Release-ready draft, pending professional legal review. It describes what the software does.

Shellaro is published by Dvir Horev under the DvirLabs brand (DvirLabs is a brand name, not a company). Its use is governed by the Shellaro Software License.

Shellaro is a desktop application that runs on your computer. It has no telemetry, no analytics, no crash reporting service and no account. The publisher of Shellaro does not receive your sessions, commands, files, logs or settings.

Shellaro is not "offline only", though: the features below connect to other computers, and each one is listed here with what it sends.

What Shellaro connects to

FeatureConnects toWhat is sentWhen
SSH terminals, SFTP, tunnels, MultiExec, runbooksThe servers you configure (and jump hosts)What any SSH client sends: your user name, the password or key you chose, your commands and filesWhen you open or use a session
Update checksShellaro's update server, https://updates.shellaro.dev (hosted on Cloudflare; shown in Settings > Updates), or a server you setAn HTTPS request for <channel>/latest.json, then the installer download. The server sees your IP address and the request; Shellaro adds no identifiers (the user agent is the updater library's name and version)A minute after start and every six hours, while automatic checks are on; or when you click Check now. Turn it off in Settings > Updates
MarketplaceThe built-in catalog is part of the app (no connection). Sources you add, and the addresses of packages you install from themRequests for the catalog and package files. A source of the "API" type also receives the Shellaro version with its catalog requestWhen you open the Marketplace with a source added, or install from it. While extensions are installed, also shortly after Shellaro starts, to check them for updates
ExtensionsHosts an extension declared and you approved at install timeWhatever that extension sendsWhen the extension runs
Explain This (AI), optional, off by defaultA local model (e.g. Ollama on this computer) or an external provider you chooseThe command output you ask about and, only if you allow each item, host name, OS, environment, directory and Kubernetes context. A preview shows it firstOnly when you click Explain This
Local Kubernetes cluster, labsDocker on this computer; Docker downloads container images from their registries (e.g. Docker Hub), and building the cluster's toolbox image downloads Alpine Linux packages from Alpine's package mirrors. Lab setup scripts run on the target you choose and may pull container images thereDocker's and Alpine's normal download requests; none of them go to ShellaroWhen you create the local cluster (downloads only what is not already on this computer) or start a lab
LinksYour web browserThe page addressWhen you click a link

Shellaro uses Microsoft Edge WebView2 to draw its window. WebView2 is a Windows component maintained by Microsoft and has its own update and diagnostic behavior, governed by Microsoft's terms.

What stays on your computer

Support bundles

Settings > Help & About > Save support bundle writes a zip you save. Nothing is uploaded. It contains versions, a settings summary, the extension list, preferences and the redacted log; never sessions, known hosts, AI settings, extension data or credentials. Host and user names that appear in error messages may remain: read the files before sharing them.

Command history

History is stored locally and can be turned off or limited in Settings. Commands typed into a session are sent to that server, as with any SSH client.

Removing your data

Uninstall Shellaro and tick Delete the application data, or delete %APPDATA%\com.shellaro.app and %LOCALAPPDATA%\com.shellaro.app yourself. Credential Manager entries starting with Shellaro/ can be removed in Control Panel > Credential Manager.

The website

https://shellaro.dev is a static website hosted on Cloudflare Pages; downloads come from https://updates.shellaro.dev. The website has no account, forms, analytics, advertising or third-party scripts, and sets no cookies of its own. To serve pages and downloads, Cloudflare receives your IP address and the request, as any web host does.

Contact

Privacy questions and requests about your data: Dvir Horev, [email protected].

Security vulnerabilities: report them privately to [email protected] (see the security policy).