Ghost Suite privacy policy
The rules below apply to every product in the Ghost Suite: same controller, same rights, same processors, same retention principles. What changes from one product to the next is the data it handles, so each table names the product it describes.
Last updated:
Version 0.3, 2026-09-26. Articles 12 to 14 of Regulation (EU) 2016/679 (GDPR).
In one sentence
The products in the suite do not resemble each other on this point, and this page does not pretend otherwise. GhostPass and GhostBit cannot read what you put in them: encryption happens on your device, with a key we never hold. GhostCal, by contrast, has to read your appointments in order to organise them. GhostMail stores your messages sealed, but holds your mailbox credentials and sees your mail in cleartext while it fetches it. We write this down rather than leaving you to guess. The per-product table below says exactly what each one sees.
Who is responsible
| Publisher | StackOps, sole proprietorship of Kevin Allioli |
| Registered office | Saint-Julien-en-Genevois (Haute-Savoie), France |
| Data protection contact | privacy@stackops.ch |
| Data protection officer | None: the law does not require one here |
If you use a product of the suite through your employer or your organisation, that organisation decides the purposes, and it is therefore the controller. StackOps then acts as a processor, and the organisation’s own policy applies in addition to this one. Address your requests to it first.
What we know about you, and what we do not
This is the part that matters, and it depends on the product.
GhostPass, the password manager
| Data | What StackOps sees of it |
|---|---|
| The content of your secrets: logins, notes, cards, files | Nothing. Encrypted on your device. We hold no key, and the server contains no code able to decrypt |
| The names of your personal folders | Nothing: encrypted as well |
| Your email address | In cleartext. It is your sign-in identifier |
| The names of organisations, collections and groups | In cleartext |
| The domains of the sites you save | In transit only, and only if the icon service is enabled, to fetch the site logo |
| Your IP address and browser, at sign-in | In cleartext, erased after 90 days |
| Your sensitive actions (audit log) | In cleartext, erased after 365 days |
This table says something that vault advertising rarely says: the content is inaccessible to us, the structure is not. Knowing that you have a collection named “Bank” tells us nothing about what it contains, but it is not nothing, and you have the right to know it before signing up.
GhostCal, the shared calendar
GhostCal cannot be blind, and saying so is more honest than implying otherwise. To offer a slot, send an invitation and keep a CalDAV mirror, it has to read what it organises.
| Data | What StackOps sees of it |
|---|---|
| Your email address | In cleartext. It is your identifier |
| Your time zone | In cleartext, to place the slots |
| The title and description of your event types | In cleartext. The server needs them to display and offer them |
| The organisations and teams you belong to | In cleartext |
| Verification and reset tokens | Their fingerprint only, never their value |
On the CalDAV mirror, a fresh connection by default sends up only busy status, with no title and no detail, and the warning names the company that will receive the data.
GhostBit, ephemeral sharing
GhostBit has no accounts, and knows nothing about you. There is no email address and no identifier: the server receives an already-encrypted block and hands it back as is.
| Data | What StackOps sees of it |
|---|---|
| The content you share | Nothing. Encrypted with AES-256-GCM on your device; the key never leaves the link you pass on |
| The declared language, for syntax highlighting | In cleartext |
| The expiry date, the view count, burn on read | In cleartext: these are the rules you chose |
A share disappears at its expiry, or on first read if you asked for it to be destroyed. You set the duration, not us.
GhostMail, encrypted mail
GhostMail is not blind, and it cannot be. That follows directly from what it does: it connects to your existing mailbox (Gmail, Outlook, Fastmail, a server of your own) and adds a layer of encryption on top. To fetch your mail while you are away, it has to be able to sign in on your behalf. So it holds your credentials, and it sees your messages at the moment it fetches them.
We write this here because it is the kind of detail a product calling itself “encrypted” has every interest in keeping quiet.
| Data | What StackOps sees of it |
|---|---|
| The sender, recipients, subject, body, attachments | Nothing, once stored. Sealed on your device to your account’s public key: a theft of our database yields unreadable blocks |
| Your mailbox credentials | Encrypted, but decryptable by the server. There is no other way to fetch your mail while you are away |
| Your messages during the fetch | In cleartext, for the time it takes. They are sealed immediately afterwards, but they pass through our server in cleartext |
| The address of the connected mailbox, and of its server | In cleartext |
| The names of your folders | In cleartext. They are used to find what has already been fetched |
| Date, size, read or not, flagged or not | In cleartext: that is what allows sorting without opening |
| Technical message and conversation identifiers | In cleartext. They are written by the originating server, and often carry its domain name |
| Your account email address | In cleartext. It is your identifier with us |
| Your private key | Nothing. Wrapped on your device by your secret phrase, which we do not know |
Three limits we would rather name than let you discover:
- your current provider keeps seeing what it has always seen. GhostMail erases nothing at Gmail: it adds a layer at our end, it does not remove one at theirs;
- end-to-end encryption in the strict sense only holds between OpenPGP correspondents. A message exchanged with someone who has none is sealed at our end and readable everywhere else along its path;
- a fully compromised GhostMail server could read your mailbox, since it holds the credentials. That is true of any service that fetches mail on your behalf, and saying it does not make it less true.
These three points are not defects we will fix: they follow from the purpose of the product. They were written in our architecture decisions before they were written here, and the code is open: https://github.com/stackopshq/ghostmail.
The products still in development
GhostMon, GhostLink and GhostAuth are open to no one: no sign-up is possible, so no personal data is processed. This page will be completed before they open, not after. It has just been, for GhostMail.
Why we process this data, and on what basis
| Purpose | Legal basis |
|---|---|
| Providing the vault you asked for | Performance of the contract (art. 6.1.b) |
| Authenticating you, and spotting abusive access attempts | Legitimate interest (art. 6.1.f), to protect accounts |
| Logging sensitive actions on your account | Legitimate interest and the security obligation (art. 32) |
We do nothing else with it. No behavioural analysis, no profiling, no advertising, no model training, no resale. No automated decision is made about you.
For how long
| Data | Duration |
|---|---|
| Sign-in traces (IP, browser) | 90 days |
| Audit log | 365 days |
| Your account, and what it holds | Until you delete them |
| A GhostBit share | The expiry you set, or the first read if you asked for destruction |
| The copy of a GhostMail mailbox | Until you disconnect the mailbox. Removing a connected mailbox erases the fetched messages, their attachments and its credentials |
| Encrypted backups | Up to about 12 months after deletion |
The gap between the last two lines is real, and we write it rather than rounding it off. Deleting your account removes it from production immediately; the encrypted backups run on a longer cycle, and erasing them immediately would destroy other users’ backups too.
Who else sees this data pass
| Recipient | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Routes traffic to the suite’s instances: pass.ghostsuite.cloud, cal.ghostsuite.cloud, bit.ghostsuite.cloud, mail.ghostsuite.cloud | United States |
| Infomaniak (Swiss Backup) | Receives the backups, already encrypted before they leave | Switzerland |
| OVH | Hosts the machine, if your organisation chose a dedicated instance | France (Gravelines and Roubaix) |
Two of these destinations are outside the European Union: the United States, covered by standard contractual clauses, and Switzerland, recognised by the European Commission as offering adequate protection.
No one else. No advertising network, no audience measurement tool, no data broker.
One case apart: your mail provider, if you use GhostMail. Our server connects to the mailbox you told it about, Gmail, Outlook or the one of your choice, to fetch your mail and send yours. That provider is not our processor: it is yours, you had it before us, and we change nothing about what it sees. But it is on the path, and a message you send through GhostMail leaves through it.
What Cloudflare can do, and what we would rather write down
Cloudflare routes the traffic, so it serves you the JavaScript that encrypts. An intermediary able to modify that code could undo the encryption, without ever touching our servers.
This is not specific to GhostPass: it is the limit of all browser-delivered encryption, across every comparable product. We would rather write it than imply a guarantee the technique does not give.
You can remove it entirely: the products of the suite install on your own server, and then nothing passes through us at all.
Your rights
At any time you can:
- access your data and obtain a copy, through your account’s export button,
or
GET /api/account/export; - correct it if it is inaccurate;
- erase it, through the account deletion button, with immediate effect;
- take it elsewhere, in a machine-readable format;
- object to processing based on our legitimate interest;
- ask for the restriction of a processing operation you dispute.
Write to privacy@stackops.ch. We answer within the month, and will tell you before the deadline if it has to be extended.
One honest limit on the export: encrypted fields are returned to you as they are. We cannot decrypt them: that is the exact price of zero knowledge, not a shortcoming of the export. You open them with your key, off our servers.
If you lose your master password, there is nothing we can do. We can neither reset it nor recover the vault. That follows directly from not holding your keys, and it needs to be known before you start, not after.
Complaint
If our answer does not satisfy you, you can refer the matter to the CNIL, 3 place de Fontenoy, 75007 Paris, https://www.cnil.fr/fr/plaintes.
If you live in Switzerland, you can also refer it to the FDPIC, https://www.edoeb.admin.ch.
Security
The full detail lives in the data processing agreement and the record of processing activities, provided on request at privacy@stackops.ch. In summary: end-to-end encryption, a second factor, the second-factor secret itself encrypted at rest, hardened containers, dependency and secret scanning on every code change, mandatory review before any production release, encrypted off-site backups.
Changes
This page is versioned: its full history can be consulted, and every change is dated. In the event of a substantial change, we will inform you before it takes effect.
| Version | Date | Change |
|---|---|---|
| 0.3 | 2026-09-26 | GhostMail is described: what the server sees of your messages, the mailbox credentials it holds, and the three limits that follow from what it does. Your mail provider is also added among the recipients, along with the retention period for a connected mailbox. |
| 0.2 | 2026-09-24 | The suite’s instances are named by their current addresses, on the Cloudflare line. Neither the recipients nor the data processed change: this is a correction for accuracy. |
| 0.1 | 2026-08-31 | Created |