Privacy policy
Last updated: August 25, 2026
Ghostkey ("we", "us") is an AI-assisted writing studio for novelists, available at ghost-key.app and as desktop and mobile apps. This policy explains what we collect, why, and what happens to it. The short version: your manuscripts are yours, we store them to provide the service and for nothing else, we don't sell data, and we don't use your writing to train AI models.
Questions or requests about your data: support@ghost-key.app.
What we collect
- Account data. Your email address and a password. The password is stored only as a salted hash (argon2id) — we cannot read it.
- Your content. The manuscripts, chapters, notes, outlines, boards, and images you create or upload. If you use dictation, the audio you record; if you use the photo-import feature, the photos you submit. This is the product — everything you write is stored so it can sync between your devices.
- Billing data. Payments are handled by Stripe. We store your subscription plan and status and a Stripe customer reference. Your card number never touches our servers.
- Usage and technical data. Server logs (IP address, request identifiers, timestamps) for security, rate limiting, and debugging, and per-feature usage metering (how many AI runs you've used against your plan's allowance). We also keep simple product analytics: cookieless page-view counts on the website, and milestone events on accounts (signed up, verified the email, subscribed), recorded under an internal account identifier — never your email, and never anything you write.
- Ad attribution — only if you accept it. If you agree on the cookie banner,
standard attribution cookies (Meta's
_fbp/_fbcand Google's_gcl_*) are set on the website and may accompany a later sign-up or purchase, so we can tell the ad platform that it resulted from an ad. Those reports identify you only by a one-way cryptographic hash of your email address — never the address itself, and never anything you write. This measures our own advertising and is the only marketing-related data we process. If you decline, no such tag is ever loaded, the cookies are never set, and we send the ad platforms nothing about you — not from your browser and not from our servers.
How we use it
- To run the service: storing and syncing your projects, authenticating you, billing.
- To power the AI features you invoke: when you run an AI feature (proofreading, analysis, outlines, dictation cleanup, and similar), the relevant portions of your text, audio, or images are sent to an AI provider to produce the result, and the result is returned to you. We initiate this only when you use a feature — never in the background for our own purposes.
- To send transactional email: verification, password reset, billing notices. No marketing email without your consent.
- To keep the service safe: abuse prevention, rate limiting, debugging.
AI processing, in plain terms
Ghostkey's AI features are proxied through our servers to third-party model providers — currently Anthropic, Google, and others via aggregators, plus ElevenLabs for speech-to-text. We use these providers' commercial APIs, which contractually do not use submitted content to train their models. See below.
Ghostkey is also built so that AI never quietly becomes the author: AI-generated prose is never inserted into your manuscript. Editing features surface suggestions and mechanical corrections for you to approve; analysis features produce commentary that lives alongside your text, not in it. AI-generated text from major providers may carry statistical watermarks, and this design keeps them out of your book.
We do not train AI on your writing
Nothing you put into Ghostkey is used to train an AI model. Not your manuscripts, chapters, notes, outlines or boards; not the audio you dictate; not the images you upload. Not by us, and not by the AI providers we call on your behalf.
We are able to say this flatly because we do not train models at all — Ghostkey has no model of its own and no training pipeline for one to feed. Your text reaches a provider only when you run a feature, only for as long as it takes to produce that result, and only over their commercial APIs, whose terms exclude submitted content from training. We never sell or share your content with anyone else to train on either.
There is no setting for this and no opt-out to find, because there is nothing to opt out of. If that ever changed, it would be an opt-in you were asked for in plain words — never a default, and never a quiet edit to this page.
Where your data lives
Our servers run on Fly.io in Paris, France, and your data is stored with Supabase on AWS in the EU (eu-west-1). AI providers process feature requests in their own regions, which may include the United States; such transfers rely on the providers' standard contractual clauses or EU–US Data Privacy Framework certification.
Who else touches it (subprocessors)
- Supabase — database and file storage
- Fly.io — application hosting
- Stripe — payments and subscription management
- Resend — transactional email
- Anthropic, Google, OpenRouter — AI text and image processing
- ElevenLabs — speech-to-text for dictation
- Upstash — rate limiting
- Dropbox — only if you connect your own Dropbox account for draft import; we access only the app folder you authorize, and you can disconnect at any time
- Meta — ad conversion measurement, only for the attribution events described above
- Google Ads — ad conversion measurement, only for the attribution events described above. This is separate from Google's AI services listed above and shares nothing with them
- PostHog — product analytics: cookieless page views and the account milestones described above, under an internal identifier — never your email or your content
We never sell your data or share it with anyone beyond this list.
Cookies and your choice
Strictly necessary — always on. Signing you in and keeping you signed in needs cookies and local storage, as does remembering your own preferences (theme, panel sizes, and the like). The app cannot work without these, so they are not offered as a choice. They are ours, they stay on our own domains, and they are not used to profile you.
Advertising measurement — only with your consent. The one non-essential thing
we would like to set is a pair of advertising cookies — Meta's
_fbp/_fbc and Google's _gcl_* — which tell us whether an
advertisement led someone to sign up. We ask before loading either: on your first visit to
ghost-key.app a banner asks, and until you accept, no
advertising script is loaded and no such cookie exists. One answer covers both — we do not ask
twice, and accepting does not mean accepting one of them. If you decline, we remember the
refusal so you are not asked again, and the server-side half of the same measurement is
suppressed too — a refusal silences the whole thing, not just the part you can see.
Changing your mind. "Cookie settings" in the footer of this page brings the banner back, whichever way you answered. Withdrawing consent deletes every advertising cookie — both platforms' — and reloads the page so the tags stop running immediately.
We set no analytics cookies, on the marketing site or in the app, and no session recording — ever. The website does count its page views, so we can see where the signup path loses people, but it does so without cookies or local storage: the counter runs in page memory under a random identifier that disappears when you close the tab, so two visits can never be linked to each other. If you sign up, that single visit is linked to your new account so we can tell which pages led there. The desktop and mobile apps carry no advertising tag at all, which is why they never ask.
Retention and deletion
Your content is kept for as long as your account exists — that's the point of a writing studio. Chapter version history is kept so you can recover earlier drafts. When you delete a project, it is removed from the live database; when you ask us to delete your account, we delete your account data and content within 30 days, except what we must keep for legal or accounting reasons (such as invoices). Server logs rotate on a short schedule.
Your rights
Under the GDPR (and similar laws elsewhere) you can ask for access to your data, correction, deletion, restriction of processing, or a portable copy. The app's export feature (DOCX, EPUB, HTML) gives you a complete portable copy of any manuscript at any time. For anything else, email support@ghost-key.app. If you're in the EU and unhappy with our answer, you can complain to your data-protection authority (in France, the CNIL).
Security
All traffic is encrypted in transit (TLS). Passwords are hashed with argon2id. AI provider keys are held server-side only and never reach your device. Access to production systems is limited to the operator.
Children
Ghostkey is not directed at children and requires you to be at least 16 to create an account.
Changes
If this policy changes materially, we'll note it here and, for significant changes, tell you by email or in the app before it takes effect.