How we handle your data

What it reads in your inbox

Ghostifier asks Google to let it see only the top part of each email, the part that says who it is from and when it was sent. For each email it reads the sender, the reply-to address, the subject, the date, and the unsubscribe and reply information. It can't open the body or attachments of any email, and Google enforces that limit on its side too.

That top part is read in memory to recognize companies, then discarded. What's kept is the list of companies and a few dates for each. Senders who aren't companies, like the people you write to, leave no trace.

What it keeps, and until when

A scheduled job enforces these dates. Mail that reaches Ghostifier's addresses but answers none of your requests keeps only its arrival time, for 7 days. A company's reply is read by software to sort it, and what it says is kept for you (encrypted, as above), never from your Gmail. Where a reply arrives through Amazon Web Services, the full message is deleted there as soon as it is recorded, and where it arrives through Resend, Resend also keeps it under its own retention period.

How requests go out

Requests are sent from Ghostifier's own address, as your authorized agent, under the permission you sign. Nothing goes out from your Gmail, and Ghostifier can't send email as you. Each request includes what a company needs to find your records: your name, email address and state. On a paid plan, if you choose it, the same request goes to data brokers on a public register, even if they never emailed you.

Who else handles it

  • Google, for Gmail access and signing in with Google.
  • Railway, which hosts the app and its database.
  • Amazon Web Services and Resend, which send requests to companies and receive their replies. Resend also sends Ghostifier's emails to you.
  • Umami, which counts visits to the public pages and sign-in pages, without cookies. It is also told when an account is created (with the visit's IP address and browser, so it can link the two) and when a plan is bought (the plan and the amount, never who bought it), unless your browser sends Do Not Track.
  • Stripe, whose Link checkout sells the plans and takes payment. It gets your email address, and your card goes straight to Stripe, never to Ghostifier.
  • The companies you ask, which receive your request and the details in it.
  • The people who run Ghostifier, who can see an account's basics (email, name, plan, whether Gmail is connected, how many requests were sent) to run accounts and answer support. Not the companies on your list, your legal name, or your requests.

Your data is used only to find companies and send your requests. Ghostifier doesn't sell it, and never uses it for advertising or to train AI models. Its few cookies only keep it working, like keeping you signed in. The public pages count visits with Umami, which sets no cookies and records only the page, the site that linked to it, your country and your type of device, and that an account was created or a plan bought, never what you do once you're signed in.

Seeing and deleting it

Signed in, Settings, then Your data shows everything stored about you right now. Delete everything on that page removes Ghostifier's access to your Gmail, deletes your data, destroys your encryption key and emails you a confirmation. Backups keep a copy until they expire. Requests already sent can't be recalled from the companies that received them.