Privacy
Your project lives in your Cloudflare account.
Ghostbuild operates a small control plane while project workspaces, builds, previews, and deployments run in the Cloudflare account you connect.
Data we process and why
- Account and authentication: Cloudflare identity, name, email, avatar, session records, OAuth state, and connection status, used to authenticate you and bind requests to your account.
- Cloudflare connection: account identifiers, granted scopes, runtime locators, and encrypted credentials, used to reach the runtime you authorize. Tokens, ciphertext, IVs, credential handles, and capability secrets are never included in account-data responses.
- Projects and conversations: chat metadata, transcripts, generated project files, revisions, validation receipts, deployment plans, approvals, and deployment status, used to provide the builder and recovery features.
- Product operations: allowlisted events, opaque journey or error-event identifiers, status values, and bounded numeric metrics, used to operate and protect the service. Prompts, source code, credentials, URLs, and direct user identifiers are excluded from product telemetry. The telemetry request omits browser credentials; Cloudflare supplies a client IP that the application uses transiently only as the rate-limit key and does not include in the application event log.
- Browser data: account-local replicas, theme preference, a pending prompt in tab-scoped session storage, and short-lived recovery state, used for editing, continuity, and interface preferences on your device. The message input expires the retired prompt cookie if it is present.
Where data is held
Ghostbuild control-plane records are held in Cloudflare D1. User workspace metadata, Agent transcripts, project files, Computer state, previews, and generated infrastructure are held in the connected user Cloudflare account. Cloudflare operates a global network and may process data in locations described by its privacy and data-transfer terms; Ghostbuild does not currently offer a selectable residency region.
Processors and external services
Cloudflare provides authentication integration, Workers, D1, R2, Durable Objects, Containers, Computer, Workers AI, observability, and related infrastructure. GitHub processes information you choose to submit through public support or abuse issues and private vulnerability reports. Review Cloudflare’s Privacy Policy, its Data Processing Addendum, and GitHub’s privacy statement.
Retention and deletion
Authentication sessions expire after 30 days. Expired authentication and OAuth records are removed by bounded maintenance, and unreferenced encrypted credential records are eligible for removal after 24 hours. A deleted project enters a bounded cleanup workflow after a 30-minute recovery grace period. Other account and runtime records remain while the account or project exists or until a supported deletion request is completed.
Self-service account export and deletion are not available. Use Support to request access to or deletion of reachable Ghostbuild-held account data. Generated Workers, D1 databases, R2 buckets, Containers, Durable Objects, browser storage, and other resources in your Cloudflare account or browser remain your responsibility to download, remove, or clear.
Public-beta requests are handled manually without a promised response time. Do not put sensitive information in the public issue; a request may not be actionable until a private identity-verification path is arranged.
Retention may be extended when applicable law requires it. Material changes to the current retention approach will be documented here.
Security
Controls include encrypted Cloudflare credentials, hashed session and capability tokens, same-origin checks for state-changing control-plane requests, short-lived runtime capabilities, tenant binding, bounded request and response sizes, deployment approval, and security readback before deployment. No system is risk-free.
Your choices and rights
You can download individual project source, delete projects, disconnect by revoking Cloudflare authorization, and clear Ghostbuild site data in your browser. Depending on applicable law, you may also request access, correction, portability, restriction, objection, or erasure and complain to a supervisory authority. Use Support for account and privacy requests.