Privacy
Privacy Policy
Ghost OS is built for wallet-connected crypto workflows. This page explains what the app should collect, what it must never expose, and how provider-backed data is handled.
Data We Use
Ghost OS may process account identity, connected wallet addresses, Ghost Wallet public addresses, chat commands, token scans, watchlists, alerts, trade intents, provider status, transaction hashes, and usage limits. This data is used to operate the command layer, protect accounts, and show execution history.
Wallet And Secret Handling
Ghost OS never asks for seed phrases. Private keys and wallet secrets must never be sent to the browser or AI model. If embedded wallet infrastructure is enabled, key material must be encrypted server-side and access must be controlled by authentication, policy checks, audit logs, and emergency stop controls.
Third-Party Providers
The app can call wallet, RPC, scanner, route, analytics, auth, payment, and AI providers. Examples include Firebase, OpenAI-compatible providers, WalletConnect/RainbowKit, RPC networks, swap aggregators, and token data APIs. Missing providers should show a clear not-configured state instead of fake results.
Cookies And Sessions
Ghost OS uses secure session cookies for login state. Production sessions should be httpOnly, same-site protected, HTTPS-only, and scoped to the Ghost OS domain.
Your Controls
Users should be able to disconnect external wallets, logout, pause automation, review transaction history, and request removal of account data where legally and technically possible. On-chain transactions and public blockchain records cannot be deleted by Ghost OS.

