Skip to content
Ghost Suite

Ghost Suite privacy policy

The rules below apply to every product in the Ghost Suite: same controller, same rights, same processors, same retention principles. What changes from one product to the next is the data it handles, so each table names the product it describes.

Last updated:

Version 0.3, 2026-09-26. Articles 12 to 14 of Regulation (EU) 2016/679 (GDPR).

In one sentence

The products in the suite do not resemble each other on this point, and this page does not pretend otherwise. GhostPass and GhostBit cannot read what you put in them: encryption happens on your device, with a key we never hold. GhostCal, by contrast, has to read your appointments in order to organise them. GhostMail stores your messages sealed, but holds your mailbox credentials and sees your mail in cleartext while it fetches it. We write this down rather than leaving you to guess. The per-product table below says exactly what each one sees.

Who is responsible

PublisherStackOps, sole proprietorship of Kevin Allioli
Registered officeSaint-Julien-en-Genevois (Haute-Savoie), France
Data protection contactprivacy@stackops.ch
Data protection officerNone: the law does not require one here

If you use a product of the suite through your employer or your organisation, that organisation decides the purposes, and it is therefore the controller. StackOps then acts as a processor, and the organisation’s own policy applies in addition to this one. Address your requests to it first.

What we know about you, and what we do not

This is the part that matters, and it depends on the product.

GhostPass, the password manager

DataWhat StackOps sees of it
The content of your secrets: logins, notes, cards, filesNothing. Encrypted on your device. We hold no key, and the server contains no code able to decrypt
The names of your personal foldersNothing: encrypted as well
Your email addressIn cleartext. It is your sign-in identifier
The names of organisations, collections and groupsIn cleartext
The domains of the sites you saveIn transit only, and only if the icon service is enabled, to fetch the site logo
Your IP address and browser, at sign-inIn cleartext, erased after 90 days
Your sensitive actions (audit log)In cleartext, erased after 365 days

This table says something that vault advertising rarely says: the content is inaccessible to us, the structure is not. Knowing that you have a collection named “Bank” tells us nothing about what it contains, but it is not nothing, and you have the right to know it before signing up.

GhostCal, the shared calendar

GhostCal cannot be blind, and saying so is more honest than implying otherwise. To offer a slot, send an invitation and keep a CalDAV mirror, it has to read what it organises.

DataWhat StackOps sees of it
Your email addressIn cleartext. It is your identifier
Your time zoneIn cleartext, to place the slots
The title and description of your event typesIn cleartext. The server needs them to display and offer them
The organisations and teams you belong toIn cleartext
Verification and reset tokensTheir fingerprint only, never their value

On the CalDAV mirror, a fresh connection by default sends up only busy status, with no title and no detail, and the warning names the company that will receive the data.

GhostBit, ephemeral sharing

GhostBit has no accounts, and knows nothing about you. There is no email address and no identifier: the server receives an already-encrypted block and hands it back as is.

DataWhat StackOps sees of it
The content you shareNothing. Encrypted with AES-256-GCM on your device; the key never leaves the link you pass on
The declared language, for syntax highlightingIn cleartext
The expiry date, the view count, burn on readIn cleartext: these are the rules you chose

A share disappears at its expiry, or on first read if you asked for it to be destroyed. You set the duration, not us.

GhostMail, encrypted mail

GhostMail is not blind, and it cannot be. That follows directly from what it does: it connects to your existing mailbox (Gmail, Outlook, Fastmail, a server of your own) and adds a layer of encryption on top. To fetch your mail while you are away, it has to be able to sign in on your behalf. So it holds your credentials, and it sees your messages at the moment it fetches them.

We write this here because it is the kind of detail a product calling itself “encrypted” has every interest in keeping quiet.

DataWhat StackOps sees of it
The sender, recipients, subject, body, attachmentsNothing, once stored. Sealed on your device to your account’s public key: a theft of our database yields unreadable blocks
Your mailbox credentialsEncrypted, but decryptable by the server. There is no other way to fetch your mail while you are away
Your messages during the fetchIn cleartext, for the time it takes. They are sealed immediately afterwards, but they pass through our server in cleartext
The address of the connected mailbox, and of its serverIn cleartext
The names of your foldersIn cleartext. They are used to find what has already been fetched
Date, size, read or not, flagged or notIn cleartext: that is what allows sorting without opening
Technical message and conversation identifiersIn cleartext. They are written by the originating server, and often carry its domain name
Your account email addressIn cleartext. It is your identifier with us
Your private keyNothing. Wrapped on your device by your secret phrase, which we do not know

Three limits we would rather name than let you discover:

  • your current provider keeps seeing what it has always seen. GhostMail erases nothing at Gmail: it adds a layer at our end, it does not remove one at theirs;
  • end-to-end encryption in the strict sense only holds between OpenPGP correspondents. A message exchanged with someone who has none is sealed at our end and readable everywhere else along its path;
  • a fully compromised GhostMail server could read your mailbox, since it holds the credentials. That is true of any service that fetches mail on your behalf, and saying it does not make it less true.

These three points are not defects we will fix: they follow from the purpose of the product. They were written in our architecture decisions before they were written here, and the code is open: https://github.com/stackopshq/ghostmail.

The products still in development

GhostMon, GhostLink and GhostAuth are open to no one: no sign-up is possible, so no personal data is processed. This page will be completed before they open, not after. It has just been, for GhostMail.

Why we process this data, and on what basis

PurposeLegal basis
Providing the vault you asked forPerformance of the contract (art. 6.1.b)
Authenticating you, and spotting abusive access attemptsLegitimate interest (art. 6.1.f), to protect accounts
Logging sensitive actions on your accountLegitimate interest and the security obligation (art. 32)

We do nothing else with it. No behavioural analysis, no profiling, no advertising, no model training, no resale. No automated decision is made about you.

For how long

DataDuration
Sign-in traces (IP, browser)90 days
Audit log365 days
Your account, and what it holdsUntil you delete them
A GhostBit shareThe expiry you set, or the first read if you asked for destruction
The copy of a GhostMail mailboxUntil you disconnect the mailbox. Removing a connected mailbox erases the fetched messages, their attachments and its credentials
Encrypted backupsUp to about 12 months after deletion

The gap between the last two lines is real, and we write it rather than rounding it off. Deleting your account removes it from production immediately; the encrypted backups run on a longer cycle, and erasing them immediately would destroy other users’ backups too.

Who else sees this data pass

RecipientWhat it doesWhere
Cloudflare, Inc.Routes traffic to the suite’s instances: pass.ghostsuite.cloud, cal.ghostsuite.cloud, bit.ghostsuite.cloud, mail.ghostsuite.cloudUnited States
Infomaniak (Swiss Backup)Receives the backups, already encrypted before they leaveSwitzerland
OVHHosts the machine, if your organisation chose a dedicated instanceFrance (Gravelines and Roubaix)

Two of these destinations are outside the European Union: the United States, covered by standard contractual clauses, and Switzerland, recognised by the European Commission as offering adequate protection.

No one else. No advertising network, no audience measurement tool, no data broker.

One case apart: your mail provider, if you use GhostMail. Our server connects to the mailbox you told it about, Gmail, Outlook or the one of your choice, to fetch your mail and send yours. That provider is not our processor: it is yours, you had it before us, and we change nothing about what it sees. But it is on the path, and a message you send through GhostMail leaves through it.

What Cloudflare can do, and what we would rather write down

Cloudflare routes the traffic, so it serves you the JavaScript that encrypts. An intermediary able to modify that code could undo the encryption, without ever touching our servers.

This is not specific to GhostPass: it is the limit of all browser-delivered encryption, across every comparable product. We would rather write it than imply a guarantee the technique does not give.

You can remove it entirely: the products of the suite install on your own server, and then nothing passes through us at all.

Your rights

At any time you can:

  • access your data and obtain a copy, through your account’s export button, or GET /api/account/export;
  • correct it if it is inaccurate;
  • erase it, through the account deletion button, with immediate effect;
  • take it elsewhere, in a machine-readable format;
  • object to processing based on our legitimate interest;
  • ask for the restriction of a processing operation you dispute.

Write to privacy@stackops.ch. We answer within the month, and will tell you before the deadline if it has to be extended.

One honest limit on the export: encrypted fields are returned to you as they are. We cannot decrypt them: that is the exact price of zero knowledge, not a shortcoming of the export. You open them with your key, off our servers.

If you lose your master password, there is nothing we can do. We can neither reset it nor recover the vault. That follows directly from not holding your keys, and it needs to be known before you start, not after.

Complaint

If our answer does not satisfy you, you can refer the matter to the CNIL, 3 place de Fontenoy, 75007 Paris, https://www.cnil.fr/fr/plaintes.

If you live in Switzerland, you can also refer it to the FDPIC, https://www.edoeb.admin.ch.

Security

The full detail lives in the data processing agreement and the record of processing activities, provided on request at privacy@stackops.ch. In summary: end-to-end encryption, a second factor, the second-factor secret itself encrypted at rest, hardened containers, dependency and secret scanning on every code change, mandatory review before any production release, encrypted off-site backups.

Changes

This page is versioned: its full history can be consulted, and every change is dated. In the event of a substantial change, we will inform you before it takes effect.

VersionDateChange
0.32026-09-26GhostMail is described: what the server sees of your messages, the mailbox credentials it holds, and the three limits that follow from what it does. Your mail provider is also added among the recipients, along with the retention period for a connected mailbox.
0.22026-09-24The suite’s instances are named by their current addresses, on the Cloudflare line. Neither the recipients nor the data processed change: this is a correction for accuracy.
0.12026-08-31Created