← Back to Home

Trust

Security at GhostVault.

You give us your name and email so we can act as your CCPA agent with 500+ registered data brokers. Here's exactly how we protect that data, and what we don't do with it.

Last updated: April 21, 2026

Encrypted in transit

TLS 1.2+ with HSTS, and passwords hashed with bcrypt

Minimum data

We only keep what's needed to send your deletion demands

Delete anytime

Deleting your account erases your data right away

No third-party sales

We never sell, rent, or share your data for ads

1. Encryption and password storage

Every request between your browser and GhostVault is served over HTTPS using TLS 1.2 or higher, with HSTS enforced (max-age=63072000). Two-factor secrets are encrypted with a key kept outside the database. Passwords are hashed with bcrypt (cost factor 10), so we cannot read them even if compelled.

2. What we actually store about you

We collect the minimum needed to send legally-binding CCPA deletion demands on your behalf:

  • Account: Email address, bcrypt-hashed password
  • Scan data: First name, last name, optional city/state, optional email for breach lookup
  • Billing: Handled entirely by Stripe. We never see or store your card number, CVC, or billing address
  • Usage: Login times, feature usage via Vercel Analytics (anonymized)

We do not collect your SSN, date of birth, driver's license, financial account numbers, or health data. We never ask for a phone number unless you explicitly add one for removal.

3. Access controls

Internal access to production data follows the principle of least privilege. Engineering access to the production database is gated behind multi-factor authentication and is logged. We do not export bulk user data to analytics warehouses, BI tools, or marketing platforms.

4. Retention and deletion

Scan results are retained only as long as they're needed to track removal status and respond to data-broker follow-ups (typically 12 months). If you delete your account, your scan data and monitored addresses are erased from active systems right away. Cancelling a subscription alone does not delete your data.

5. Sub-processors and vendors

We use a small number of vendors to operate the service:

  • Stripe: Payment processing (PCI-DSS Level 1)
  • Cloudflare: Website hosting (Cloudflare Pages)
  • Railway: Database hosting (SOC 2 Type II)
  • Resend: Transactional email (GDPR-compliant)

We do not use advertising networks, data enrichment services, or third-party trackers that could de-anonymize your visit. Meta Pixel is loaded only for ad conversion measurement and never receives scan data.

6. Incident response

In the event of a security incident that affects your personal information, we will notify you by email without unreasonable delay, as state breach-notification laws require. Our response covers containment, review of what was affected, customer notification, and regulator disclosure where the law requires it.

7. Compliance posture

  • CCPA / CPRA: We act as your authorized agent under the CCPA once you sign our agent authorization. We track the 45-day response window on every deletion demand.
  • SOC 2 Type I: In scoping. Target audit window: TBD. We'll update this page with the auditor and timeline as soon as it's signed.
  • GDPR (EU/UK): We do not currently target EU/UK users. If you are outside the US, our scan is available but removal coverage is US-only for now.
  • HIPAA: Not applicable. We do not collect or process protected health information.

8. Responsible disclosure

If you've found a security issue in GhostVault, please email security@ghostvault.live with details. We review every report, do not pursue legal action against good-faith researchers, and credit reporters who want to be credited.

9. Contact

Questions about this page, or about how we handle your data? Email privacy@ghostvault.live.