Koridor tunnels your whole device through a plain SSH server — yours, not ours. No Koridor-operated backend, no account, no third party in the middle.
AllowTcpForwarding yes — that's the whole server-side requirement.
Koridor has none. There's no Koridor-operated infrastructure sitting between you and the internet, no logging policy to take on faith, no company that could be compelled to hand over your traffic — because there's no company holding it. If you can run sshd, you can run a Koridor server.
{{ f.desc }}
Each TCP flow is proxied as its own direct-tcpip channel — on the wire, it's indistinguishable from ordinary SSH port forwarding.
Credentials live only in the OS secure credential store — Android Keystore or its platform equivalent — and are sent only to the server you configured. Koridor has no GDPR data-controller relationship with you, because nothing is ever processed off-device.
Read the full privacy policy ↓Koridor does not operate any servers on your behalf and does not collect, transmit, or store any personal data, usage statistics, or diagnostic information. The app connects only to the SSH server address and credentials you provide, and those credentials are kept exclusively in your device's secure credential store. Because no data is processed by Koridor or K-Ops Oy off your device, there is no data-controller relationship between you and either party under GDPR or similar frameworks. Source and release binaries are distributed as-is; bug reports can be filed via Gitea issues, and vulnerabilities can be reported directly to koridor@k-ops.eu.