Skip to main content
GhostStack
Menu

Privacy policy

Effective 2026-09-29. Applies to all GhostStack services.

What we process

GhostStack services pair AI agents with your accounts and machines under your explicit control. To do that we process:

  • Authentication information. Your GhostStack account email and sign-in credentials (handled by Identity), OAuth tokens, and (only when you explicitly approve a read in the GhostStack Pilot popup) cookie values from domains you allowlisted, passed through to your authorized agent.
  • Website content. Page text, screenshots, and file paths read by Pilot from allowlisted pages transit our broker to your agent. We do not store page content.
  • User activity. Command metadata (tool name, decision, target domain, timestamps) recorded in your tenant's activity log, visible to you in the Pilot popup.
  • Technical logs. Standard web-server access logs (IP address, user agent) for security and abuse prevention.

What we never do

  • We do not sell or transfer user data to third parties.
  • We do not use or transfer user data for purposes unrelated to the service.
  • We do not use or transfer user data to determine creditworthiness or for lending.
  • We do not run advertising, analytics trackers, or behavioral profiling.

Pilot's consent model

The GhostStack Pilot browser extension acts only after your session grant, only on domains you allowlist, with per-action approvals for sensitive tools and an always-available kill switch. Tokens and consent state live in your browser profile's local storage. Every agent gets its own labeled browser window, and every decision is logged.

Your controls

You can revoke any agent session, remove allowlist entries, or unpair entirely at any time from the Pilot popup. Account deletion removes your tenant data from our stores. For anything else, write to privacy@ghoststack.app.