The short version
GhostRecon is a desktop application. Crawling, intercepting traffic, testing, and writing findings all happen on your computer, not on our servers. That design decision is why this policy is short.
What never reaches us
Your targets and scope. The traffic you capture. The vulnerabilities found and the reports written. Your AI model API key. The credentials, tokens, and data the agent handles during an engagement. None of it is transmitted to us, and we have no way to retrieve it from your machine.
What we do hold is the small amount of information needed to run a waitlist, an account, and a subscription, set out below in full.
Who we are
GhostRecon operates GhostRecon and the ghostrecon.tech website, and is the controller of the personal data described here. You can reach us about anything in this policy at privacy@ghostrecon.tech.
What we collect
Waitlist signup. When you join the early-access waitlist we store the email address you enter, the page it came from, your browser's user-agent string, and the time you signed up. The user agent is kept only to distinguish real signups from automated ones.
Account and subscription. If you create an account, we store your email address, which plan you are on, and when it expires. The application checks that record to unlock paid features. If you subscribe, our payment processor handles your card details and gives us back a customer reference, the status of the subscription, and billing metadata such as country for tax. We never see or store your card number.
Website and request logs. Our hosting provider records standard request information (IP address, timestamp, page requested, user agent) for delivery, security, and abuse prevention. We also hold an IP address in memory very briefly to rate-limit waitlist submissions; it is not written to our database.
GhostMail. If you use the disposable-inbox feature, the request for an inbox and the messages it receives pass through our server so we can keep the underlying provider key out of the application. Those inboxes are throwaway addresses created for a test run, and we do not use their contents for anything else.
When you contact us. If you email us, send a bug report, or attach a log, we keep that correspondence and whatever you chose to include in it so we can help you.
What we don't collect
- No engagement data. Target hosts, crawled pages, captured requests and responses, findings, and generated reports stay in local storage on your machine.
- No model keys. Your AI provider key is stored locally and used to call your provider directly from your machine. It is never transmitted to us.
- No prompt contents. What the agent sends to your model provider goes from your computer to that provider. We are not in the middle of it and we do not log it. Your provider's own privacy policy governs that exchange.
- No advertising or analytics profiles. We do not run ad trackers, we do not sell or share personal data for advertising, and we do not build behavioural profiles.
How we use it
- To send you an early-access invitation and occasional product updates you asked for.
- To create your account and confirm which features your plan includes.
- To take payment, handle renewals and refunds, and meet our tax and accounting duties.
- To answer support requests and diagnose bugs you report.
- To keep the Service working and safe: rate limiting, blocking abuse, and investigating security incidents.
- To understand how many people are on the waitlist and how that is changing over time.
Legal bases (UK/EU)
If you are in the UK or the European Economic Area, we rely on these bases under the GDPR:
- Contract, to give you an account, deliver the plan you paid for, and provide support.
- Consent, to email you about early access after you join the waitlist. You can withdraw it at any time using the unsubscribe link or by emailing us.
- Legitimate interests, to secure the Service, prevent abuse, and improve the product, balanced against your rights.
- Legal obligation, to keep financial records and respond to lawful requests.
How long we keep it
- Waitlist entries, until you ask us to delete them, or within a reasonable period after we stop running a waitlist.
- Account records, for as long as your account is open, and up to 12 months after you close it in case you come back.
- Billing records, for as long as tax and accounting law requires, typically six to seven years.
- Request logs, short retention, typically no more than 30 days.
- Support email, kept while it is useful for context, then deleted.
How it's protected
Traffic to ghostrecon.tech is encrypted in transit. The waitlist database is locked down so the public API key can read nothing at all. Only our server can write to it, using a key that never reaches the browser. Access to production data is limited to the people who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator as the law requires.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive a portable copy, or withdraw consent. California residents additionally have the right to know what is collected, to delete it, to correct it, and not to be treated differently for exercising those rights.
Email privacy@ghostrecon.tech and we will respond within the time the law allows, usually 30 days. We may need to confirm who you are first. If you are in the UK or EEA and are unhappy with our response, you can complain to your national data protection authority.
International transfers
Our service providers may process data in countries other than yours, including the United States. Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.
Children
The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@ghostrecon.tech and we will delete it.
Changes to this policy
We will update this policy as the product changes. Material changes will be announced on ghostrecon.techor by email before they take effect, and the “last updated” date at the top of this page will move.
Contact
For anything about your data, privacy, or this policy, write to privacy@ghostrecon.tech. For contractual questions, see the Terms of Service.
