Privacy Policy

Effective July 21, 2026

This Privacy Policy describes how White Ghost ("White Ghost", "we", "us") collects, uses, and protects information when you use the White Ghost platform, the White Ghost command-line tool, and the websites we operate under getghosty.dev (together, the "Service").

Who we are

White Ghost is a deployment platform that lets companies give their employees a safe, isolated environment to build and ship internal applications. Each customer company operates in its own dedicated cloud environment.

Information we collect

  • Account information via Google Sign-In. When you sign in with Google, we receive your basic profile information: your name, email address, and profile picture. We request only the openid, email, and profile scopes. We do not request access to your Gmail, Drive, Calendar, contacts, or any other Google service data.
  • Workspace activity. When you build or manage applications on the Service, we record the operations you perform (for example: app creation, deployments, configuration changes, and database console queries) so your company has an audit trail.
  • GitHub organization metadata. When a company connects its GitHub organization, we store the organization name and the installation identifier of the White Ghost GitHub App. Application source code remains in the company's own GitHub organization.
  • Technical data. Standard server logs (IP address, browser type, timestamps) used for security and reliability.
  • Product analytics. We use PostHog to understand how getghosty.dev is used — the pages you visit, the features you use, and session replays of console activity. Replays mask everything you type, and we never track the applications you build or the data inside them. If you'd like your activity excluded, email hello@getghosty.dev.

How we use information

  • To authenticate you and associate you with your company's environment.
  • To restrict access to your company's environment to email domains your company has approved.
  • To provision and operate the applications and infrastructure your company creates.
  • To provide audit logs, deployment history, and usage information to your company's administrators.
  • To secure, maintain, and improve the Service.

Google user data

White Ghost's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data (name, email address, profile picture) only to authenticate you and operate your account.
  • We do not sell Google user data, use it for advertising, or transfer it to third parties except as necessary to provide the Service, comply with applicable law, or as part of a merger or acquisition with notice to you.
  • Humans do not read this data except with your permission, for security purposes, or to comply with applicable law.

How information is shared

  • With your company. Your company's administrators can see your name, email, the applications you own, and your activity within their environment.
  • Service providers. We run on Google Cloud Platform; data is processed and stored there. We use GitHub (to create and manage application repositories in your company's organization), npm (to distribute our CLI), and PostHog (product analytics and session replay).
  • Legal. We may disclose information if required by law or to protect the rights, safety, and security of White Ghost, our customers, or the public.

We do not sell personal information.

Data retention & deletion

We retain personal information for as long as your account is active or as needed to provide the Service to your company. When a company offboards, its environment — including databases, secrets, and logs — is deleted. You may request deletion of your personal data at any time by emailing hello@getghosty.dev; we will respond within 30 days.

Security

Each customer company runs in an isolated cloud project with separate databases, secrets, and networking. Credentials are stored in a managed secret store, never in source code. Access to production systems is limited and audited.

Children

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new effective date, and for material changes we will notify customer administrators by email.

Contact

Questions about this policy or your data: hello@getghosty.dev.