← Back to Ghost Claw

Privacy Policy

Last updated: April 30, 2026

Overview

Ghost Claw ("the App") is a desktop application that runs locally on your Windows computer. Your privacy is important to us. This policy explains what data we collect, how we use it, and your rights.

What Data Stays on Your Computer

Ghost Claw runs locally. The following data is stored only on your machine and never sent to us:

What Data is Sent to Third Parties

Ghost Claw connects to AI providers (such as OpenAI, Anthropic, Google, etc.) that you choose and configure. When you chat with the AI:

Web search queries (via Brave Search) are sent to the search provider when you use the search feature.

If you connect a Google account for Gmail send and Google Calendar features, see the Google API Services disclosure below for the full details on scopes, data flow, storage, and revocation.

Google API Services — User Data Disclosure

This section is provided in compliance with the Google API Services User Data Policy and the Google APIs Terms of Service. It supersedes any conflicting language elsewhere in this document for matters involving Google user data.

A. Data Accessed

Ghost Claw requests the following Google OAuth scopes only when you explicitly choose to connect your Google account inside the app. No Google data is accessed without user-initiated authorization.

Ghost Claw does not request gmail.readonly or gmail.modify. Inbox reading, when you enable it, is performed via IMAP using credentials you supply separately, not via the Gmail API.

B. Data Usage

Google user data is used solely to fulfill the specific in-session request you make:

Ghost Claw does not use Google user data for advertising, analytics, profiling, AI model training, or any purpose other than fulfilling your direct, in-session request.

C. Data Sharing

Ghost Claw does not transmit Google user data to any server operated by Ghost Claw — no such server exists. Google user data leaves your device only in two situations, both initiated by you:

Google user data is not shared with any other third party, is not sold, and is not used in any advertising network.

D. Data Storage & Protection

All Google user data is held on your local Windows device:

All API calls to Google use HTTPS/TLS encryption in transit, as required by Google's endpoints.

E. Data Retention & Deletion

Because no Google user data is stored on infrastructure operated by Ghost Claw, retention is governed entirely by your local installation:

You may take any of the above actions at any time. There is no server-side data to delete because none is collected.

What We Collect

When you purchase Ghost Claw through our website:

We do not collect:

License Verification

When you first activate your license key, Ghost Claw contacts DodoPayments to register your device (one of 5 activation slots). Once per day on app launch, Ghost Claw sends your license key and device ID to DodoPayments to confirm the license is still valid (e.g. has not been refunded). The app works offline for up to 10 consecutive days between revalidations to handle travel and ISP outages.

No conversation content, AI responses, files, or telemetry are sent to DodoPayments — only the license key and device fingerprint required for activation and revalidation.

Cookies

Our website uses no tracking cookies. DodoPayments (payment provider) may set cookies during checkout — refer to their privacy policy.

Data Security

All data stored by Ghost Claw on your computer is in standard formats (JSON, SQLite). It is not encrypted at rest — it is protected by your Windows user account permissions. We recommend using Windows disk encryption (BitLocker) for additional protection.

Children's Privacy

Ghost Claw is not directed at children under 13. We do not knowingly collect data from children.

Your Rights

You can:

Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date.

Contact

For privacy questions or data deletion requests:
GhostClaw.team@gmail.com