Data Retention Policy

Last updated: July 27, 2026

Ghostline minimizes data by design. This policy defines exactly what we store, for how long, and what happens when those periods expire. If it's not listed here, we don't have it.

SMS Messages & Call Logs

Data TypeRetention PeriodPost-Deletion
SMS messages (sent + received)30 days from receiptPermanently deleted — no backups, no archives
Call logs (VoIP calls)30 days from call completionPermanently deleted
Number assignment historyNot retainedNot applicable

Account Data

Data TypeRetention PeriodNotes
Email addressDuration of accountDeleted upon account deletion request
Password hashDuration of accountStored as cryptographic hash only — algorithm not disclosed
Payment recordsPer processor policyRetained by Stripe / NOWPayments, not by Ghostline
Session tokensUntil logout / expiryRAM-only Redis, no disk persistence

Data We Do Not Store

The following data types are never collected or stored at any point during normal operation:

  • IP addresses
  • User agent strings
  • Browser fingerprint data
  • Geolocation data
  • Session recordings or click tracking
  • Analytics data of any kind
  • Deleted messages (no backups, archives, or deferred deletion)

Account Deletion

Account deletion from the dashboard triggers immediate and irreversible removal of all associated data. Ghostline does not maintain backups, caches, or archives of deleted accounts. Re-registration with the same email address creates a new account with no connection to the previous one.

Legal Preservation

Ghostline does not currently retain data beyond the schedules listed above. In the event of a valid legal preservation order, Ghostline will retain only the data specified in the order and only for the minimum duration required. Any such event will be recorded in our warrant canary.