Trust
Security at GhostVault.
You give us your name and email so we can act as your CCPA agent with 500+ registered data brokers. Here's exactly how we protect that data, and what we don't do with it.
Last updated: April 21, 2026
Encrypted in transit
TLS 1.2+ with HSTS, and passwords hashed with bcrypt
Minimum data
We only keep what's needed to send your deletion demands
Delete anytime
Deleting your account erases your data right away
No third-party sales
We never sell, rent, or share your data for ads
1. Encryption and password storage
Every request between your browser and GhostVault is served over HTTPS using TLS 1.2 or higher, with HSTS enforced (max-age=63072000). Two-factor secrets are encrypted with a key kept outside the database. Passwords are hashed with bcrypt (cost factor 10), so we cannot read them even if compelled.
2. What we actually store about you
We collect the minimum needed to send legally-binding CCPA deletion demands on your behalf:
- Account: Email address, bcrypt-hashed password
- Scan data: First name, last name, optional city/state, optional email for breach lookup
- Billing: Handled entirely by Stripe. We never see or store your card number, CVC, or billing address
- Usage: Login times, feature usage via Vercel Analytics (anonymized)
We do not collect your SSN, date of birth, driver's license, financial account numbers, or health data. We never ask for a phone number unless you explicitly add one for removal.
3. Access controls
Internal access to production data follows the principle of least privilege. Engineering access to the production database is gated behind multi-factor authentication and is logged. We do not export bulk user data to analytics warehouses, BI tools, or marketing platforms.
4. Retention and deletion
Scan results are retained only as long as they're needed to track removal status and respond to data-broker follow-ups (typically 12 months). If you delete your account, your scan data and monitored addresses are erased from active systems right away. Cancelling a subscription alone does not delete your data.
5. Sub-processors and vendors
We use a small number of vendors to operate the service:
- Stripe: Payment processing (PCI-DSS Level 1)
- Cloudflare: Website hosting (Cloudflare Pages)
- Railway: Database hosting (SOC 2 Type II)
- Resend: Transactional email (GDPR-compliant)
We do not use advertising networks, data enrichment services, or third-party trackers that could de-anonymize your visit. Meta Pixel is loaded only for ad conversion measurement and never receives scan data.
6. Incident response
In the event of a security incident that affects your personal information, we will notify you by email without unreasonable delay, as state breach-notification laws require. Our response covers containment, review of what was affected, customer notification, and regulator disclosure where the law requires it.
7. Compliance posture
- CCPA / CPRA: We act as your authorized agent under the CCPA once you sign our agent authorization. We track the 45-day response window on every deletion demand.
- SOC 2 Type I: In scoping. Target audit window: TBD. We'll update this page with the auditor and timeline as soon as it's signed.
- GDPR (EU/UK): We do not currently target EU/UK users. If you are outside the US, our scan is available but removal coverage is US-only for now.
- HIPAA: Not applicable. We do not collect or process protected health information.
8. Responsible disclosure
If you've found a security issue in GhostVault, please email security@ghostvault.live with details. We review every report, do not pursue legal action against good-faith researchers, and credit reporters who want to be credited.
9. Contact
Questions about this page, or about how we handle your data? Email privacy@ghostvault.live.