The short version. GHOSTFACE is built so that we hold as little about you as possible. We don't ask for your name, phone number or email address. Your messages and calls are end-to-end encrypted — we cannot read them, and neither can anyone who compromises our servers. Your conversations, contacts and call history live on your device, not ours.
This page explains exactly what does reach us, and why.
Ghostface Limited, a company registered in New Zealand, operates the GHOSTFACE application and this website. Where privacy law applies, Ghostface Limited is the data controller.
Contact: support@ghostface.co.nz
Because these are the questions people actually ask, they come first:
The service cannot function without a small amount of data. This is the whole of it:
| Data | Why | Notes |
|---|---|---|
| Alias | So others can find you and start an encrypted session | Chosen by you. 3–20 characters, letters, digits and underscore. |
| Delivery ID | Routing messages to you | A random token generated at registration. Messages are addressed to this, not to your alias, so stored rows and network frames don't reveal who a message is for. |
| Public keys | Letting other people start an encrypted session with you | Identity, signed prekeys, post-quantum prekeys and their signatures. Public halves only — private keys never leave your device. |
| Queued messages | Holding a message until your device comes online | Stored as encrypted payload addressed to a delivery ID, with a delivered flag and a timestamp. We cannot read the contents. |
| Push token | Waking your device for a new message or call | Stored as a hash, not the raw token. |
| Subscription status | Unlocking paid features | Which plan is active. Card details are handled by our payment provider and never reach us. |
Server logs and infrastructure metrics are produced by our hosting provider in the ordinary course of running the service.
These never reach our servers at all. They are stored in encrypted storage on your phone, and are lost if you delete the app or trigger a wipe:
Messages and calls use end-to-end encryption with a hybrid classical and post-quantum handshake — X25519 combined with ML-KEM-768 (NIST FIPS 203) — followed by a Double Ratchet using ChaCha20-Poly1305. Every algorithm is a published public standard; we have not designed or implemented any proprietary cryptography.
Practically, this means the encryption keys exist only on the devices at each end of a conversation. We do not hold them and cannot recover your messages for you, for law enforcement, or for anyone else.
Messages expire automatically. The timer can be set between 5 seconds and 7 days, and defaults to 1 hour. Expiry is enforced on both devices; undelivered messages also expire from our queue.
The in-app cryptocurrency wallet is non-custodial. Keys are generated on your device and never transmitted to us. We do not hold your funds, cannot move them, and cannot restore them. If you lose your device and your recovery phrase, the funds are unrecoverable — by us or by anyone.
GHOSTFACE is not directed at children and is not intended for use by anyone under the age required by their app store's terms.
If this policy changes materially we will update this page and revise the effective date above.
Questions, requests, or anything that looks wrong: support@ghostface.co.nz