gh0st
Privacy Policy
No legalese. The CLI provides the current encrypted workflow; native macOS and browser vault integration remains pending in this release candidate.
gh0st collects no personal data by default.
0
Analytics events
0
Tracking pixels
0
Ad SDKs
No gh0st account required. No hosted database. No cloud service. Your data never touches our infrastructure.
What Stays On Your Device (CLI Encrypted; Native Integration Pending)
Conversations and messages
Attachments and files
Agents and preferences
CLI encrypted continuation state
CLI vault-encrypted API keys
Local search index
What Goes to xAI (Only When You Send a Message)
Message content (encrypted in transit via HTTPS)
Optional: file content you explicitly attach
Optional: tool results from web search, X search, code execution
Strict mode sends store:false and verifies the ZDR header before sending sensitive content.
Third-Party Services
| Service | Purpose | Data Sent | ZDR Status |
|---|---|---|---|
| xAI API | AI inference | Message content, attachments, tool calls | Covered by ZDR when verified |
| External MCP | User-enabled tools | Only what you explicitly route | NOT covered by xAI ZDR |
Data intentionally sent to MCP is governed by that provider's policies and is outside xAI ZDR.gh0st shows destinations before use. No silent data exfiltration.
Privacy Modes
Strict (default)
- ZDR Required
- Required
- Behavior
- Blocks sensitive requests until ZDR verified
Extended
- ZDR Required
- Optional
- Behavior
- Allows MCP and tools with explicit consent
Your Rights
gh0st wipe removes all local dataNo Tracking
We don't know any of the following because we don't collect it:
Who you are
What you chat about
How often you use gh0st
Which model you prefer
Whether you use strict mode
This Website
Contact
- Privacy questions
- privacy@gh0st.dev
- Security vulnerabilities
- security@gh0st.dev
- General questions
- GitHub Discussions