Data Retention Policy
Last updated: July 27, 2026
Ghostline minimizes data by design. This policy defines exactly what we store, for how long, and what happens when those periods expire. If it's not listed here, we don't have it.
SMS Messages & Call Logs
| Data Type | Retention Period | Post-Deletion |
|---|---|---|
| SMS messages (sent + received) | 30 days from receipt | Permanently deleted — no backups, no archives |
| Call logs (VoIP calls) | 30 days from call completion | Permanently deleted |
| Number assignment history | Not retained | Not applicable |
Account Data
| Data Type | Retention Period | Notes |
|---|---|---|
| Email address | Duration of account | Deleted upon account deletion request |
| Password hash | Duration of account | Stored as cryptographic hash only — algorithm not disclosed |
| Payment records | Per processor policy | Retained by Stripe / NOWPayments, not by Ghostline |
| Session tokens | Until logout / expiry | RAM-only Redis, no disk persistence |
Data We Do Not Store
The following data types are never collected or stored at any point during normal operation:
- IP addresses
- User agent strings
- Browser fingerprint data
- Geolocation data
- Session recordings or click tracking
- Analytics data of any kind
- Deleted messages (no backups, archives, or deferred deletion)
Account Deletion
Account deletion from the dashboard triggers immediate and irreversible removal of all associated data. Ghostline does not maintain backups, caches, or archives of deleted accounts. Re-registration with the same email address creates a new account with no connection to the previous one.
Legal Preservation
Ghostline does not currently retain data beyond the schedules listed above. In the event of a valid legal preservation order, Ghostline will retain only the data specified in the order and only for the minimum duration required. Any such event will be recorded in our warrant canary.