What we process
GhostStack services pair AI agents with your accounts and machines under your explicit control. To do that we process:
- Authentication information. Your GhostStack account email and sign-in credentials (handled by Identity), OAuth tokens, and (only when you explicitly approve a read in the GhostStack Pilot popup) cookie values from domains you allowlisted, passed through to your authorized agent.
- Website content. Page text, screenshots, and file paths read by Pilot from allowlisted pages transit our broker to your agent. We do not store page content.
- User activity. Command metadata (tool name, decision, target domain, timestamps) recorded in your tenant's activity log, visible to you in the Pilot popup.
- Technical logs. Standard web-server access logs (IP address, user agent) for security and abuse prevention.