GHOSTFACE
Secure Identity

Privacy Policy

Effective 22 August 2026

The short version. GHOSTFACE is built so that we hold as little about you as possible. We don't ask for your name, phone number or email address. Your messages and calls are end-to-end encrypted — we cannot read them, and neither can anyone who compromises our servers. Your conversations, contacts and call history live on your device, not ours.

This page explains exactly what does reach us, and why.

1. Who we are

Ghostface Limited, a company registered in New Zealand, operates the GHOSTFACE application and this website. Where privacy law applies, Ghostface Limited is the data controller.

Contact: support@ghostface.co.nz

2. What we don't collect

Because these are the questions people actually ask, they come first:

3. What we do hold

The service cannot function without a small amount of data. This is the whole of it:

DataWhyNotes
Alias So others can find you and start an encrypted session Chosen by you. 3–20 characters, letters, digits and underscore.
Delivery ID Routing messages to you A random token generated at registration. Messages are addressed to this, not to your alias, so stored rows and network frames don't reveal who a message is for.
Public keys Letting other people start an encrypted session with you Identity, signed prekeys, post-quantum prekeys and their signatures. Public halves only — private keys never leave your device.
Queued messages Holding a message until your device comes online Stored as encrypted payload addressed to a delivery ID, with a delivered flag and a timestamp. We cannot read the contents.
Push token Waking your device for a new message or call Stored as a hash, not the raw token.
Subscription status Unlocking paid features Which plan is active. Card details are handled by our payment provider and never reach us.

Server logs and infrastructure metrics are produced by our hosting provider in the ordinary course of running the service.

4. What stays on your device

These never reach our servers at all. They are stored in encrypted storage on your phone, and are lost if you delete the app or trigger a wipe:

5. Encryption

Messages and calls use end-to-end encryption with a hybrid classical and post-quantum handshake — X25519 combined with ML-KEM-768 (NIST FIPS 203) — followed by a Double Ratchet using ChaCha20-Poly1305. Every algorithm is a published public standard; we have not designed or implemented any proprietary cryptography.

Practically, this means the encryption keys exist only on the devices at each end of a conversation. We do not hold them and cannot recover your messages for you, for law enforcement, or for anyone else.

6. Disappearing messages

Messages expire automatically. The timer can be set between 5 seconds and 7 days, and defaults to 1 hour. Expiry is enforced on both devices; undelivered messages also expire from our queue.

7. The wallet

The in-app cryptocurrency wallet is non-custodial. Keys are generated on your device and never transmitted to us. We do not hold your funds, cannot move them, and cannot restore them. If you lose your device and your recovery phrase, the funds are unrecoverable — by us or by anyone.

8. Others who process data for us

9. Your choices

10. Children

GHOSTFACE is not directed at children and is not intended for use by anyone under the age required by their app store's terms.

11. Changes

If this policy changes materially we will update this page and revise the effective date above.

12. Contact

Questions, requests, or anything that looks wrong: support@ghostface.co.nz