← ghost · privacy policy

privacy.

effective: 2026-04-28 · version 1.0 · last updated: 2026-04-28

ghost is built on a single promise: nothing leaves your phone. this policy explains, in plain language, what that means in practice. the short version is that ghost has nothing to share with anyone because it never collects anything to begin with.

at a glance: no servers · no analytics · no telemetry · no advertising · no third-party sdks · no account · no sign-in · no data leaves the device.

01what we collect

nothing. ghost does not have a server. it does not phone home. it does not contain analytics, crash reporting, advertising sdks, attribution sdks, or any other library that transmits information off your device. when you write a message, it is written to a file on your phone and stays there. when you delete a ghost, the file is removed from your phone and that is the end of it.

02what we store on your device

the following lives only on your device, in your app's private container, encrypted with the standard .completeFileProtection attribute (apple's strongest at-rest protection class):

that's the complete list. if you delete the app, all of it goes with it. there is no copy on a server because there is no server.

03imagined replies

when "imagined reply" is enabled, ghost generates fictional messages by selecting words from on-device vocabulary lists and assembling them into sentences using on-device templates. no api is called. no large language model is queried. no part of what you wrote is sent anywhere — including, specifically, to anthropic, openai, google, apple, or any other ai provider. the engine runs entirely in swift on your phone. see our imagined-reply disclosure for the technical detail.

04the real people you write to

ghost does not contact, message, notify, or in any way reach the real-world people whose names you may use inside the app. ghost has no access to your contacts, your phone book, your messaging apps, or any other source of communication. the names and photos you enter are local labels only — they exist purely to help you remember who a thread was for. nobody else sees them, ever, because there is no "else" with access.

05purchases

ghost uses apple's storekit 2 for the one-time unlock purchase. apple receives the purchase event because apple processes the payment — that is between you and apple under apple's privacy policy. ghost itself only ever sees a yes/no flag indicating whether the unlock has been verified. we never see your name, email, payment method, or location.

06permissions we ask for

07children

ghost is rated 17+ in the app store. it deals with adult themes around relationships, loss, and the words people don't say. it is not intended for, and not directed to, anyone under 13 (or under 16 in the eu/uk).

08your rights (gdpr / ccpa / etc.)

because ghost has no servers and we do not collect your data, gdpr "data subject access requests," ccpa "right to know" requests, and analogous rights under other regimes are functionally answered by the structure of the app: we have no record of you, and there is nothing for us to disclose, export, or delete on your behalf. the data on your device is yours; you can delete it any time by deleting a ghost or uninstalling the app.

09changes to this policy

if we ever change this policy in a material way — in particular, if we ever add anything that does collect data — we will update the version number and effective date above, post the new version at this url, and call it out plainly in the app's release notes. we will not silently start collecting data.

10contact

questions, complaints, or corrections — hello@ghost.app. we read everything that arrives.