Ghost Agents

Privacy Policy

Last updated: February 27, 2026

Ghost Agents ("we", "us", "our") operates the ghostagents.app platform. This policy explains what data we collect, why, and how we handle it. This policy is governed by the General Data Protection Regulation (GDPR) and French data protection law.

1. Data We Collect

Account data: When you sign in with Google, we receive your name, email address, and profile picture from Google OAuth. We do not receive or store your Google password.

Bot data: Content you provide to your bots (messages, files, instructions) is stored in your bot's workspace on our servers. Bot conversation history is stored in a per-bot SQLite database inside the bot's container.

Integration credentials: When you connect third-party services (Google, Slack, Notion), OAuth tokens are stored encrypted (AES-256-GCM) in our database. We only request the minimum scopes needed for the features you enable.

Usage data: We record API usage (token counts, model used, cost) for billing and display in your dashboard. We log bot activity (messages sent/received) for your activity feed.

Payment data: Payments are processed by Stripe. We do not store credit card numbers. We store your Stripe customer ID to link purchases to your account.

2. How We Use Your Data

PurposeLegal Basis (GDPR)
Operate your bots and deliver the servicePerformance of contract
Meter AI usage and enforce spending limitsPerformance of contract
Process credit purchases via StripePerformance of contract
Send bot outputs to channels you connectedYour explicit consent (via OAuth)
Display activity, usage, and billingPerformance of contract
Debug issues and improve reliabilityLegitimate interest

3. Third-Party Services

Your bot messages are sent to Anthropic's Claude API for processing. Anthropic's privacy policy and API terms apply. We use their commercial API with zero-retention terms β€” Anthropic does not train on your data.

We also use:

  • Stripe β€” payment processing
  • Google β€” authentication (OAuth) and optional integrations (Gmail, Sheets, Calendar, Drive)
  • Brave Search β€” web search tool
  • Slack, Notion β€” optional integrations you connect

Each third-party service has its own privacy policy. Your data may be transferred to and processed in the United States. We ensure appropriate safeguards (Standard Contractual Clauses, encryption in transit and at rest).

4. Data Storage and Security

Data is stored on servers located in Europe (France). Security measures include:

  • Integration tokens encrypted at rest with AES-256-GCM
  • All connections use TLS encryption
  • Bot workspaces isolated per-bot in separate Docker containers
  • Access to production servers restricted to the platform operator

5. Data Retention

Data TypeRetention Period
Account informationUntil account deletion + 30 days
Bot data (conversations, files, workspace)Until bot deletion or account closure
Integration tokensUntil you disconnect the integration
Payment records7 years (French accounting requirement)

When you delete a bot, its container and workspace are removed. When you delete your account, all associated data is removed within 30 days, except payment records retained for legal compliance.

6. Your Rights (GDPR)

Under the General Data Protection Regulation and French data protection law, you have the right to:

  • Access β€” request a copy of all personal data we hold about you
  • Rectification β€” correct inaccurate or incomplete data
  • Erasure β€” request deletion of your personal data
  • Restriction β€” limit how we process your data
  • Portability β€” receive your data in a machine-readable format
  • Object β€” object to processing based on legitimate interests
  • Withdraw consent β€” revoke consent at any time (e.g., disconnect integrations)

You can also export your bot's workspace files at any time via the dashboard, delete individual bots, and disconnect integrations.

To exercise your rights, contact privacy@ghostagents.app. We will respond within 30 days.

You may lodge a complaint with your data protection authority. In France: Commission Nationale de l'Informatique et des LibertΓ©s (CNIL).

7. Cookies

We use a single session cookie for authentication (connect.sid). We do not use tracking cookies, analytics scripts, or advertising pixels.

8. Children

Ghost Agents is not intended for users under 16. We do not knowingly collect data from children.

9. Changes

We may update this policy. Material changes will be communicated via email. The "Last updated" date above reflects the latest version. Continued use of the service after changes constitutes acceptance.

10. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users within 72 hours and report to the relevant data protection authorities as required by GDPR.

11. Contact and Legal Information

For privacy questions: privacy@ghostagents.app

Data Controller (GDPR Article 13):
P.H.J. Humblot, Entrepreneur Individuel
SIREN: 823 531 157 Β· SIRET: 823 531 157 00019
Activity: 62.01Z β€” Computer programming
4 Place Louis Chazette, 69001 Lyon, France

Supervisory authority: CNIL (France)