Ghostral

Privacy Policy

Last updated June 2026

Our approach

Our principle is “don't trust us, verify us.” We try to collect as little as possible, and we're building toward client-side encryption so that stored conversations are unreadable even to us.

Where inference runs

Your prompts are processed by a model we host on our own hardware — not a third-party model provider. We do not sell your conversations or use them to train external models.

What we store

An account (your email) and your chat history so you can return to it. We aim to minimize metadata and avoid retaining more than we need to run the service.

Email login codes

We send one-time login codes by email. Codes are stored hashed, expire quickly, and are deleted after use.

Your choices

You can request deletion of your account and associated data. As we roll out client-side encryption, more of your data becomes something we physically cannot read.

This is an early version provided for transparency, not legal advice. The binding terms will be finalized before paid launch.