Back

Legal

Privacy Policy

What we collect, and what we deliberately don't. GhostRecon runs on your machine, so your targets, traffic, findings, and model keys never leave it.

Effective September 1, 2026 · Last updated September 1, 2026

01

The short version

GhostRecon is a desktop application. Crawling, intercepting traffic, testing, and writing findings all happen on your computer, not on our servers. That design decision is why this policy is short.

What never reaches us

Your targets and scope. The traffic you capture. The vulnerabilities found and the reports written. Your AI model API key. The credentials, tokens, and data the agent handles during an engagement. None of it is transmitted to us, and we have no way to retrieve it from your machine.

What we do hold is the small amount of information needed to run a waitlist, an account, and a subscription, set out below in full.

02

Who we are

GhostRecon operates GhostRecon and the ghostrecon.tech website, and is the controller of the personal data described here. You can reach us about anything in this policy at privacy@ghostrecon.tech.

03

What we collect

Waitlist signup. When you join the early-access waitlist we store the email address you enter, the page it came from, your browser's user-agent string, and the time you signed up. The user agent is kept only to distinguish real signups from automated ones.

Account and subscription. If you create an account, we store your email address, which plan you are on, and when it expires. The application checks that record to unlock paid features. If you subscribe, our payment processor handles your card details and gives us back a customer reference, the status of the subscription, and billing metadata such as country for tax. We never see or store your card number.

Website and request logs. Our hosting provider records standard request information (IP address, timestamp, page requested, user agent) for delivery, security, and abuse prevention. We also hold an IP address in memory very briefly to rate-limit waitlist submissions; it is not written to our database.

GhostMail. If you use the disposable-inbox feature, the request for an inbox and the messages it receives pass through our server so we can keep the underlying provider key out of the application. Those inboxes are throwaway addresses created for a test run, and we do not use their contents for anything else.

When you contact us. If you email us, send a bug report, or attach a log, we keep that correspondence and whatever you chose to include in it so we can help you.

04

What we don't collect

  • No engagement data. Target hosts, crawled pages, captured requests and responses, findings, and generated reports stay in local storage on your machine.
  • No model keys. Your AI provider key is stored locally and used to call your provider directly from your machine. It is never transmitted to us.
  • No prompt contents. What the agent sends to your model provider goes from your computer to that provider. We are not in the middle of it and we do not log it. Your provider's own privacy policy governs that exchange.
  • No advertising or analytics profiles. We do not run ad trackers, we do not sell or share personal data for advertising, and we do not build behavioural profiles.
05

How we use it

  • To send you an early-access invitation and occasional product updates you asked for.
  • To create your account and confirm which features your plan includes.
  • To take payment, handle renewals and refunds, and meet our tax and accounting duties.
  • To answer support requests and diagnose bugs you report.
  • To keep the Service working and safe: rate limiting, blocking abuse, and investigating security incidents.
  • To understand how many people are on the waitlist and how that is changing over time.
07

Who we share it with

We do not sell your personal data. We share it only with the service providers we need to run the product, each bound to use it only for the work we ask of them:

  • Hosting and delivery, serving ghostrecon.tech and keeping request logs.
  • Database, storing the waitlist and account records described above.
  • Payments, processing subscriptions and storing card details on their own systems, under their own policy.
  • Email, sending invitations, receipts, and account notices.

We may also disclose information where the law requires it, to enforce our Terms of Service, or to protect the rights and safety of our users. If the business is ever sold or merged, account data may transfer with it, and you will be told before that changes how your data is handled.

08

How long we keep it

  • Waitlist entries, until you ask us to delete them, or within a reasonable period after we stop running a waitlist.
  • Account records, for as long as your account is open, and up to 12 months after you close it in case you come back.
  • Billing records, for as long as tax and accounting law requires, typically six to seven years.
  • Request logs, short retention, typically no more than 30 days.
  • Support email, kept while it is useful for context, then deleted.
09

How it's protected

Traffic to ghostrecon.tech is encrypted in transit. The waitlist database is locked down so the public API key can read nothing at all. Only our server can write to it, using a key that never reaches the browser. Access to production data is limited to the people who need it.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator as the law requires.

10

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive a portable copy, or withdraw consent. California residents additionally have the right to know what is collected, to delete it, to correct it, and not to be treated differently for exercising those rights.

Email privacy@ghostrecon.tech and we will respond within the time the law allows, usually 30 days. We may need to confirm who you are first. If you are in the UK or EEA and are unhappy with our response, you can complain to your national data protection authority.

11

International transfers

Our service providers may process data in countries other than yours, including the United States. Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.

12

Cookies

We do not use advertising or analytics cookies on ghostrecon.tech, and there is no tracking pixel on this site. If you sign in to an account, we use only the cookies strictly necessary to keep you signed in and to protect the form against abuse. If that ever changes, we will ask for your consent first.

13

Children

The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@ghostrecon.tech and we will delete it.

14

Changes to this policy

We will update this policy as the product changes. Material changes will be announced on ghostrecon.techor by email before they take effect, and the “last updated” date at the top of this page will move.

15

Contact

For anything about your data, privacy, or this policy, write to privacy@ghostrecon.tech. For contractual questions, see the Terms of Service.