Privacy Policy

Last updated: July 27, 2026

I built Ghostline because I got tired of my real phone number being everywhere — data broker lists, breach dumps, spam callers who somehow know my name. This is the privacy policy I wanted to read when signing up for a service, so that's what I wrote. No legalese hiding what we do with your data. We barely touch it.

1. What We Actually Collect (Spoiler: Very Little)

Most companies have a "we collect" section that goes on for paragraphs. Ours is short, and here's why: we designed the system to know as little about you as possible. It's not a feature — it's the whole point.

  • An email address.We need somewhere to send your breach alerts and account recovery links. That's it. We don't use it for marketing, we don't sell it, we don't even send "we miss you" emails.
  • A hashed password. Your password is cryptographically hashed before it touches our database. We never see your actual password. If we got hacked, the attackers would get a pile of cryptographic garbage — we don't disclose the algorithm because that's our business, not theirs.
  • Payment info.This goes straight to Stripe or NOWPayments. We never see your full card number. We don't store billing addresses. We don't want that liability.

That's it. Three things. Most social media apps collect more data in the first 30 seconds than we collect in your entire lifetime as a customer.

2. Here's What We DON'T Collect

And this is the part that matters:

  • Your real name
  • Your physical address
  • Your IP address (not logged, not stored, not even looked at)
  • Your device fingerprint or browser type
  • Your location
  • What you do on other websites (no tracking pixels, no analytics SDKs)
  • What links you click inside the dashboard
  • How long you spend on each page
  • Anything from your clipboard, camera, microphone, or contacts

No analytics. No ads. No "behavioral insights." No data brokerage. If a feature requires collecting something that makes you less private, we don't build that feature.

3. SMS & Messages — Your Private Conversations

Every SMS that comes through your Ghostline number is encrypted at rest. We store it for 30 days — long enough for you to read and respond, short enough that we're not sitting on a pile of your conversations. After 30 days, it's gone. Permanently. Not archived, not "anonymized for analytics," not backed up in some cold storage. Deleted.

We don't read your messages. We don't scan them for keywords. We don't train AI models on them. They pass through our system and disappear. That's the whole deal.

4. Third Parties — Who We Trust (Not Many)

We use external services to make Ghostline work. Each one has strict data handling policies:

  • Telnyx — Provides VoIP phone numbers for Ghost, Basic, and Pro tiers. They handle call routing and SMS delivery. Telnyx is SOC 2 compliant.
  • JoltSMS — Provides real-SIM phone numbers for the Ghost tier. Real mobile numbers that pass non-VoIP detection. They deliver SMS to our servers. JoltSMS states they do not sell, rent, or trade personal information to data brokers.
  • Stripe — Processes card payments (all tiers). We never see your full card number.
  • NOWPayments — Processes crypto payments for the anonymity-conscious.

No analytics SDKs. No ad networks. No tracking pixels. No "marketing partners." If we add a third party in the future, we'll update this page and our warrant canary.

5. Do We Share Your Data?

Short answer: no. Long answer: we don't sell your data — there's no price at which we'd hand over what little we have. We don't share it with "partners" because we don't have marketing partners. We don't participate in data brokerages. We don't respond to voluntary data-sharing requests.

If a law enforcement agency wants your data, they need a valid subpoena or court order. And even then, we have almost nothing to give them. That's by design.

6. Legal Requests — We'll Tell You If We Can

Our architecture means there's very little to hand over — no IP logs, no session records, no message archives. If we receive a valid legal request, we'll comply only to the extent the law requires. We'll also notify you and update our warrant canary if we're legally permitted to do so.

Worth noting: we've never received one.

7. Deleting Your Account

You can delete your account from the dashboard at any time. When you do:

  • Your phone numbers go back to the pool immediately
  • All messages are deleted permanently — no backups, no waiting period
  • Your email and password hash are removed from our database
  • If you re-register later, it's a clean slate. No history. No "welcome back."

Payment records may be retained by Stripe/NOWPayments as required by financial regulations, but that's between you and them.

8. Contact

Questions about your privacy? Email us and we'll answer like a human, not a support bot:

[email protected]