Privacy policy
Ghostifier ("we", "us") finds the companies that hold your personal information and, as your authorized agent, asks them to stop using it and to delete it. This policy explains what we collect to do that, how we use and share it, how long we keep it, and your choices. For a shorter version, see how we handle your data.
1. What we collect
Information you give us
- Account: your email address, and your password stored only as a one-way hash. If you sign in with Google, your Google account's email address and name.
- Permission to act for you: your legal name, your US state, and the authorization you sign appointing us as your authorized agent, with the date you signed it.
- Your choices: which companies to contact, what to ask them for, and your settings.
- Payments: if you buy a plan, which plan, when, and until when it is paid, with the customer and subscription identifiers Stripe gives us. Stripe collects your card details directly; we never see or store them.
- Messages to us: anything you send to support@ghostifier.com.
- What we do to your account: if we give you a complimentary plan, disable the account, or take a similar step, we record what was done, when, by whom and why.
Information from your Gmail account
With your permission, we connect to Gmail through Google's API with a read-only, headers-only permission (gmail.metadata). We read each email's headers (the top part of an email, which shows who it is from and when it was sent): sender, reply-to address, subject, date, the unsubscribe headers, and the headers that show what an email replies to. We cannot read the body or attachments of any email. We process these headers in memory to recognize companies and then discard them. We keep only information about companies (their names and domains, and a few dates such as a company's first email, last order or bill, and last marketing email to you) and the unsubscribe link from a company's latest marketing email. We do not keep the headers of individual emails, message identifiers, or anything about people you correspond with who aren't companies. We keep an access key to your Gmail, encrypted, so we can check for new companies.
Information about the requests we send
- Requests: each request we send for you, the company and address it went to, its text, and its delivery status.
- Replies: when a company replies to one of your requests, we keep the reply so you can see how the request is going and what the company asked for: its own words (not our letter quoted back), its subject, the sender's address, any reference number it quotes, and when it arrived. It is stored encrypted with a key that belongs to your account, so only you can read it: staff can't, and it never appears in our logs. Software also reads each reply to sort it (for example confirmed, declined, asking you to verify your identity, a receipt or an automatic reply) and we keep that category. We keep a reply until 30 days after its request is finished, or, for a request that never finishes, until 180 days after the company's last reply. You can delete it sooner at any time from the company's page. This is only for replies sent to Ghostifier's own addresses: we never keep the content of anything in your Gmail. A reply received through Amazon Web Services is deleted there as soon as it is recorded; a reply received through Resend is also kept by Resend under its own retention period.
Information collected automatically
We use a small number of cookies needed for the site to work: one that keeps you signed in, one that protects signing in with Google, one that carries a one-time message between pages, and one that remembers whether you minimized your first inbox scan. We don't use advertising or tracking cookies. On our public pages and the sign-in pages, never once you're signed in, we count visits with Umami, a privacy-focused analytics service. It sets no cookies, and it records which page was visited, the website that linked to it, any campaign tag in the link, your country, and your browser, operating system and type of device; the rest of the address and anything else in the link are removed before it's sent. We use it only to see how people find Ghostifier, never to identify you or follow you across sites. Two things are counted by our own server, not by your browser. When an account is created, we tell Umami that it happened, along with the IP address and browser your visit used, which Umami scrambles into the same anonymous visit number it uses for page views, so we can see how many visits become accounts; it never includes your name, email address or account number. When someone buys a plan, we tell Umami which plan and how much, and nothing about who bought it. Neither is sent if your browser signals Do Not Track or Global Privacy Control. Our servers keep short technical logs of events, such as a request being sent, without the contents of email. To stop abuse, we count attempts to sign in, sign up and reset a password against a scrambled (hashed) form of the IP address and email address used; those counts are deleted within a day.
2. How we use it
- To find the companies that hold your data, and to keep finding new ones.
- To send unsubscribe, opt-out and deletion requests to those companies on your behalf, and one follow-up if they miss the legal deadline, and to match and track their replies.
- On a paid plan, if you choose it, to send deletion requests to data brokers on a public register, whether or not they ever emailed you.
- To run your account and answer you when you write to us, including plan changes and disabling an account.
- To send you account emails: confirming your email address, password resets, a weekly summary on Autopilot that you can turn off, and confirmation when you delete your account.
- To take payment for a plan and know which requests it covers.
- To keep the service secure, prevent abuse, and meet legal obligations.
We do not sell your personal information, share it for cross-context behavioral advertising, use it for advertising of any kind, or use it to train artificial intelligence models.
3. Google user data
Ghostifier's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide the features described in this policy: finding companies that hold your data and tracking their replies to your requests. We do not use it for advertising, sell it, or transfer it except as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you. People at Ghostifier do not read your email. We cannot access email bodies at all.
The people who run Ghostifier use an admin area that shows an account's basics: the email address and name, the plan, whether Gmail is connected and when it was last checked, how many companies were found and how many requests were sent, and a record of what our staff have done to the account. They use it to run accounts, answer support requests, and look into abuse or a security issue. It does not show the companies on your list, your legal name, or the text of your requests. We look at anything else we hold only with your permission, to investigate abuse or a security issue, or when required by law.
4. Who we share it with
- The companies you ask us to contact. Each request includes what a company needs to find your records and act on it: your name, email address and state, and a statement that you authorized us. On a paid plan, and only if you choose it, this includes the data brokers on a public register, which get the same details even if they never emailed you.
- Service providers that process data for us under contract: Railway (hosting and database), Amazon Web Services (sending requests to companies and receiving their replies), Resend (sending requests to companies, receiving their replies, and sending our emails to you), Google (Gmail access and signing in with Google), Stripe (payments), and Umami (counting visits to our public pages, accounts created and plans bought). Plans are sold through Link, Stripe's checkout, which is the seller of record and collects the details it needs to take payment and charge sales tax. We give Stripe only your email address and your Ghostifier account number; it keeps its own payment records under its privacy policy.
- For legal reasons: when required by law or legal process, or to protect the rights, safety or security of our users, the public or Ghostifier.
- In a business transfer: if Ghostifier is merged or acquired, in which case this policy continues to apply and we will tell you.
5. How long we keep it
- Your account, settings, signed permission and the list of your companies: until you delete your account.
- An account that never connects Gmail, buys a plan or has a company found: deleted 30 days after it was created.
- The name of a company you remove from your list, and the day you removed it: until you add it back or delete your account.
- Your Gmail access key: until you disconnect Gmail or delete your account.
- The record of what we did to your account: until you delete it. After that only what was done, when and by whom stays, with your email address replaced by a scrambled form that can't be turned back into it, and without your account number or our notes.
- Your plan and payment identifiers: until you delete your account. Stripe keeps its payment records for as long as the law requires.
- The text of each request, the company address it went to, and the details of replies to it: 30 days after the request finishes. The fact that it was sent, to which company and when, stays until you delete your account.
- Anonymous totals: counts, by day and by company, of how many requests Ghostifier has sent and how many companies have been unsubscribed from, opted out of or deleted. They contain no name, email address or account number, so they can't be traced to you. They stay after you delete your account, because they aren't about any one person.
- Mail to our addresses that doesn't match any request: its arrival time, for 7 days.
- Full incoming replies: until their verdict is recorded, and never more than 3 days, for replies received through Amazon Web Services. Replies received through Resend are kept by Resend under its retention period.
A scheduled job deletes data when these periods end. Deleted data can remain in backups until they expire. Requests we have already sent remain with the companies that received them, under their own policies.
6. How we protect it
Your Gmail access key and your signed permission are encrypted with a key unique to you, and deleting your account destroys that key. Connections to the site and to our email and Google services are encrypted, and access to production systems is limited. No system is perfectly secure, and we will notify you of a breach affecting your information as the law requires.
7. Your choices and rights
- See your data: signed in, Settings, then Your data, shows everything we hold about you.
- Delete everything: on that page. It revokes our access to your Gmail, deletes your data, destroys your encryption key and confirms by email.
- Disconnect Gmail, revoke your permission, turn off the weekly summary: in Settings. You can also remove our access from your Google account's security settings.
Depending on your state, you may have the right to know what personal information we collect, use and disclose; to access, correct or delete it; to opt out of its sale, sharing or use for targeted advertising (we do none of these); and to not be discriminated against for exercising these rights. You can use the tools above or email support@ghostifier.com. We will verify your request, may accept requests from an agent you authorize, and will respond within the time the law requires. If we decline a request, you may appeal by replying to our decision.
8. Who can use Ghostifier
Ghostifier is for residents of the United States who are 18 or older. We don't knowingly collect information from anyone younger, and will delete it if we learn we have.
9. Changes
We will post any change here with a new effective date, and tell you by email or in the app before a material change takes effect.
10. Contact
Questions or requests about this policy: support@ghostifier.com.