GHOST
Home Terms

Privacy Policy

Last updated: [DATE — fill in when you publish this]

This Privacy Policy explains what information GHOST ("GHOST," "we," "us") collects when you use the GHOST mobile app, why we collect it, and how you can access, control, or delete it. GHOST is built to watch publicly available Instagram activity for accounts you choose — it never accesses private accounts, direct messages, or anything Instagram itself doesn't make publicly visible.

Information you provide directly

Account & authentication data. When you sign in, GHOST uses Sign in with Apple or Sign in with Google, handled by our authentication provider, Supabase. Depending on the method you choose and what you authorize, we receive:

  • Your email address
  • Your display name (if provided by Apple/Google)
  • A profile photo URL (if provided by Google — Apple does not share one)
  • A unique account identifier generated by our authentication system

We never see or store your Apple ID or Google account password — authentication is handled entirely by Apple/Google and Supabase.

Information about who you watch

Public Instagram profile data. When you add a Watch, GHOST uses Instagram's official API to access publicly available profile information for that account — such as profile photo, display name, bio, website, account type, follower/following counts, and public posts. GHOST only ever reads what Instagram's official API makes available for a public or authorized account; it does not and cannot access private accounts, direct messages, stories not exposed by the API, or any other non-public data.

Watch history and detected changes. GHOST stores the snapshots it captures over time and the specific changes it detects (for example, a new post or a bio update), so it can show you Spotted and Rewind, and answer questions in Ask GHOST. This history is tied to your account and only visible to you.

Push notifications

If you enable notifications, we store a device push token (provided by Apple's push notification system via Expo) so we can deliver GHOST's own alerts to your device when something you're watching changes. This token is not used for anything other than delivering GHOST notifications, and is deleted when you sign out or delete your account.

Subscriptions & purchases

GHOST+ subscriptions are purchased and billed entirely through Apple's App Store In-App Purchase system. We use RevenueCat to manage and verify subscription status. GHOST never receives, processes, or stores your payment card details — Apple handles all payment information directly. We only receive subscription status (for example, whether you have an active GHOST+ subscription) to unlock the corresponding features.

How we use this information

We use the information above only to operate GHOST's core features: authenticating you, running the Watch you've set up, detecting and showing you changes (Spotted, Rewind), answering your questions in Ask GHOST, delivering notifications, and managing your GHOST+ subscription entitlement.

What we don't do

GHOST does not use advertising or ad-tracking SDKs, does not track your location, does not request access to your contacts, and does not sell your personal information to third parties. We do not use analytics tools beyond what's necessary to operate and maintain the service described above.

Third parties we rely on

  • Supabase — our database, authentication, and backend infrastructure provider. Your account and Watch data are stored on Supabase's servers, protected by row-level access controls so only you can read your own data.
  • Apple — provides Sign in with Apple, processes GHOST+ payments through the App Store, and delivers push notifications to your device.
  • Google — provides Sign in with Google, if you choose that option.
  • RevenueCat — manages and verifies GHOST+ subscription status on our behalf.
  • Instagram / Meta Platforms, Inc. — the source of the public profile data GHOST observes, accessed exclusively through Instagram's official API. GHOST is not affiliated with, endorsed by, or sponsored by Instagram or Meta.
  • Expo — relays push notifications between our servers and Apple's push notification service.

Data retention

We retain your account and Watch data for as long as your account remains active, so GHOST can continue showing you accurate history. If you remove a Watch, its history is deleted along with it. If you delete your account, everything described in this policy is permanently deleted, as described below.

Account deletion

You can permanently delete your account at any time directly in the app (Profile → Delete Account). This immediately and permanently deletes your account and all associated data — Watches, observation history, detected signals, and your push notification token. This action cannot be undone. If you're unable to use the in-app flow for any reason, you can request deletion by contacting us at the email below.

Your rights

Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to certain processing. You can exercise most of these rights directly in the app; for anything else, contact us using the details below.

Children's privacy

GHOST is not directed at children, and we do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us with personal information, please contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you in the app.

Contact us

Questions about this policy or your data? Contact us at contact@ghostapp.com.

Privacy Policy Terms of Use Support
© 2026 GHOST. All rights reserved.