privacy.
ghost is built on a single promise: nothing leaves your phone. this policy explains, in plain language, what that means in practice. the short version is that ghost has nothing to share with anyone because it never collects anything to begin with.
at a glance: no servers · no analytics · no telemetry · no advertising · no third-party sdks · no account · no sign-in · no data leaves the device.
01what we collect
nothing. ghost does not have a server. it does not phone home. it does not contain analytics, crash reporting, advertising sdks, attribution sdks, or any other library that transmits information off your device. when you write a message, it is written to a file on your phone and stays there. when you delete a ghost, the file is removed from your phone and that is the end of it.
02what we store on your device
the following lives only on your device, in your app's private container, encrypted with the standard .completeFileProtection attribute (apple's strongest at-rest protection class):
- the names and optional photos you assigned to each ghost (photos are blurred at render time and never uploaded)
- the messages you wrote, the imagined replies (if you opted in), timestamps, and the platform context you selected
- a single boolean for whether you've completed onboarding
- a single boolean for whether you've made the one-time unlock purchase (this is also stored independently in your apple id's purchase history)
that's the complete list. if you delete the app, all of it goes with it. there is no copy on a server because there is no server.
03imagined replies
when "imagined reply" is enabled, ghost generates fictional messages by selecting words from on-device vocabulary lists and assembling them into sentences using on-device templates. no api is called. no large language model is queried. no part of what you wrote is sent anywhere — including, specifically, to anthropic, openai, google, apple, or any other ai provider. the engine runs entirely in swift on your phone. see our imagined-reply disclosure for the technical detail.
04the real people you write to
ghost does not contact, message, notify, or in any way reach the real-world people whose names you may use inside the app. ghost has no access to your contacts, your phone book, your messaging apps, or any other source of communication. the names and photos you enter are local labels only — they exist purely to help you remember who a thread was for. nobody else sees them, ever, because there is no "else" with access.
05purchases
ghost uses apple's storekit 2 for the one-time unlock purchase. apple receives the purchase event because apple processes the payment — that is between you and apple under apple's privacy policy. ghost itself only ever sees a yes/no flag indicating whether the unlock has been verified. we never see your name, email, payment method, or location.
06permissions we ask for
- photos (optional, only when you tap "add face"): we read a single image you choose, blur it locally, and store the blurred bytes inside the ghost record on your device. we do not access your photo library otherwise. you can decline this and the app works exactly the same.
- everything else: ghost does not request notifications, location, contacts, microphone, camera, calendar, or any other permission.
07children
ghost is rated 17+ in the app store. it deals with adult themes around relationships, loss, and the words people don't say. it is not intended for, and not directed to, anyone under 13 (or under 16 in the eu/uk).
08your rights (gdpr / ccpa / etc.)
because ghost has no servers and we do not collect your data, gdpr "data subject access requests," ccpa "right to know" requests, and analogous rights under other regimes are functionally answered by the structure of the app: we have no record of you, and there is nothing for us to disclose, export, or delete on your behalf. the data on your device is yours; you can delete it any time by deleting a ghost or uninstalling the app.
09changes to this policy
if we ever change this policy in a material way — in particular, if we ever add anything that does collect data — we will update the version number and effective date above, post the new version at this url, and call it out plainly in the app's release notes. we will not silently start collecting data.
10contact
questions, complaints, or corrections — hello@ghost.app. we read everything that arrives.