Privacy Policy

Last updated September 12, 2026

This privacy notice for Ghostline, Inc ("Company," "we," "us," or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:

Download and use Ghostline on iOS or Android, or any other application of ours that links to this privacy notice

Engage with us in other related ways, including any sales, marketing, or events

Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at privacy@ghostline.app.

SUMMARY OF KEY POINTS

This summary provides key points from our privacy notice. More details can be found below.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with Ghostline, Inc and the Services, the choices you make, and the products and features you use.

Do we process any sensitive personal information? We do not request health information or use photos for biometric identification. Images you choose to import may contain personal or sensitive information. We process those images to provide the requested features and diagnose processing problems; we do not use them to train models.

Do we receive any information from third parties? We receive subscription and transaction information through RevenueCat and the app store used for your purchase, and usage analytics and crash diagnostics through Firebase when the corresponding collection is enabled. These records may be associated with an app installation or subscription identifier. We do not receive information about you from advertising networks or data brokers.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so.

In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.

How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.

What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.

How do you exercise your rights? The easiest way to exercise your rights is by contacting us at privacy@ghostline.app. We will consider and act upon any request in accordance with applicable data protection laws.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE PROCESS YOUR INFORMATION?
  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
  4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
  6. HOW LONG DO WE KEEP YOUR INFORMATION?
  7. HOW DO WE KEEP YOUR INFORMATION SAFE?
  8. DO WE COLLECT INFORMATION FROM MINORS?
  9. WHAT ARE YOUR PRIVACY RIGHTS?
  10. CONTROLS FOR DO-NOT-TRACK FEATURES
  11. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
  12. DO WE MAKE UPDATES TO THIS NOTICE?
  13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
  14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

We collect information needed to operate Ghostline, generate stencils, manage subscriptions, provide service notices, and diagnose problems. You do not create a Ghostline login account. We do not ask for your name, email address, or postal address to use the app, but receive information you provide when contacting us.

Images and image imports. You can choose images through the system photo picker, take a photo, select a file, or import an image shared from another app. On iOS, the app uses Apple's system photo picker and requests camera permission when you use the camera. On Android, the app uses the system photo or document picker and can launch your camera app to take a photo. These import methods give Ghostline access to the images you select or capture; we do not request broad access to your entire photo library. Images or documents you export, print, or share are provided to the destination you choose.

Pro Stencil processing. When you request a Pro Stencil, the image being processed and your generation settings are sent to our servers. Processing may also involve contracted AI image-processing providers as described in Section 4. We may cache generated stencils and retain input images and results as diagnostic copies to investigate failed processing or compare processing results. All of these cached and diagnostic image copies are scheduled for automatic deletion fourteen (14) days after each copy is created. Deletion runs asynchronously, so copies may remain briefly while cleanup completes. We do not use your images or generated stencils to train models. Classic Stencil image processing takes place on your device and does not upload the image to our processing servers. Using Classic Stencil does not disable the separate subscription, service-notice, or optional telemetry functions described in this notice.

Subscription and purchase information. Subscriptions are purchased through Apple's App Store on iOS or Google Play on Android. We use RevenueCat to verify subscription access. RevenueCat processes store purchase records, transaction identifiers or purchase tokens, and an app user identifier. We receive subscription status and transaction information, such as the product purchased, purchase and expiry dates, renewals, cancellations, price, currency, and country information. We do not receive your full payment-card details, billing address, or app-store login credentials through this processing. The store and its payment providers handle payment processing.

Purchase and notice records held by Ghostline. When you start or complete a subscription purchase, we record the plan, displayed price and trial, versions of the purchase screen and legal wording, language, device class, app version, event times, and the RevenueCat identifier. A completion record may include the transaction identifier. We also receive subscription transaction updates through RevenueCat. Requests for service notices include the app version, platform, language, and device class; where applicable, a subscription identifier lets us check renewal information. When a notice requires a delivery receipt, we record that it was displayed, along with its identifier, event times, app version, and subscription identifier.

Generation and service records. Pro requests may carry a RevenueCat identifier so we can verify access and apply usage limits. We record generation times, request identifiers, the processing service used, and the applicable user or subscription identifier. These records can associate processing requests with a subscription; they are separate from the image files and their fourteen-day automatic-deletion schedule.

App usage analytics. When analytics is enabled, Firebase Analytics receives events such as screen views, button taps, selected settings, image dimensions, processing durations, and purchase activity. Purchase events may include transaction identifiers, product identifiers, price, currency, and trial status. Analytics properties include subscription status or tier, device capabilities, selected settings, and usage counts or ranges. Events are associated with an Analytics app-instance identifier. These are pseudonymous records, meaning they use identifiers rather than your name; they are not necessarily anonymous or limited to aggregate reports.

Crash and performance diagnostics. When crash reporting is enabled, Firebase Crashlytics receives crash reports and diagnostic information such as device model, operating system version, stack traces, installation identifiers, recent navigation, image dimensions, and processing state. Our custom diagnostics do not intentionally attach your RevenueCat identifier to crash reports. Crash information may be stored locally on your device while automatic reporting is disabled and sent to Crashlytics if you later enable reporting.

Local storage and device backups. Ghostline stores preferences, privacy choices, subscription-access state, and work in progress on your device. It also stores pending purchase and notice events so they can be delivered reliably. Selected preferences, such as paper size and stencil engine, are also reported when analytics is enabled. Depending on your operating system and backup settings, local data may be included in your device backup. Android excludes working-job images and saved documents from its app backup rules, and both platforms exclude the service-event queue from backup. Exported files and any backups you control are managed separately from our server storage.

Network and approximate location information. Our servers receive your IP address when the app connects. Access and diagnostic logs may include IP addresses, request information, app versions, and user or subscription identifiers. We use these records to deliver the service, investigate errors, and prevent abuse. Analytics may derive approximate geographic information, such as country or city, from IP addresses, and subscription records may include country information. We do not request device location permission or collect GPS location through the app.

Support and privacy correspondence. If you contact us, we receive your email address, the contents of your message and attachments, and any Support ID, transaction details, or other information you choose to provide.

Information we do not request. Ghostline does not request access to contacts, calendars, microphone audio, or health records, and does not use photos for biometric identification. Images you choose may themselves contain personal or sensitive information. We do not use advertising identifiers for advertising or cross-app tracking.

2. HOW DO WE PROCESS YOUR INFORMATION?

We use the information described above for the following purposes:

  • Provide the app and requested image processing: import and edit images, generate and deliver stencils, cache results, recover work, and support export, printing, and sharing.
  • Manage subscriptions: verify purchases, restore access, check entitlements, and respond to subscription support requests.
  • Keep purchase records: document the price, trial, and terms shown when you started or completed a purchase, reconcile store updates, and address billing disputes and applicable legal obligations.
  • Deliver service notices: provide operational notices and renewal reminders, and record delivery when a receipt is required.
  • Protect and operate the service: enforce generation limits, prevent abuse, investigate service errors, and maintain security.
  • Diagnose image-processing problems: use limited diagnostic image copies to investigate failures and compare processing results. These copies follow the same fourteen-day automatic-deletion schedule as cached image outputs. We do not use them for model training.
  • Understand usage and fix app problems: use analytics and crash reporting in accordance with your settings and applicable consent requirements.
  • Respond to you and comply with law: handle support and privacy requests, maintain necessary records, and establish, exercise, or defend legal claims.

We do not use your uploaded images or generated stencils to train models. We do not sell personal information or use it for cross-context behavioral advertising.

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.

If you are located in the EU or UK, this section applies to you.

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:

Performance of a contract. We process information where necessary to provide the service you request, including generating stencils, verifying subscription access, and responding to service requests.

Consent. Where consent is required for analytics or crash reporting, we rely on your consent. You can change those choices in Info → Privacy. We obtain consent for other processing when required by applicable law.

Legitimate interests. Where permitted and after considering your rights and interests, we process information to operate and secure the service, apply usage limits, diagnose errors, document purchases and notice delivery, and address disputes. Where consent is not required, we may also rely on legitimate interests to understand app usage and improve reliability, subject to your privacy choices. We do not use this basis to override a consent requirement.

Legal obligations. We process information where necessary to comply with applicable legal duties, including recordkeeping and responding to lawful requests.

If you are located in Canada. We process information with express or implied consent where permitted by applicable law. You can withdraw consent subject to legal or contractual restrictions and reasonable notice. Limited exceptions may permit processing without consent, such as complying with a legal requirement or investigating fraud, where the applicable legal conditions are met. Contact privacy@ghostline.app to discuss your choices and any effect on the service you request.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We use the service providers and categories of providers below to operate Ghostline. We do not sell personal information or share it with advertising networks or data brokers for advertising purposes.

Firebase Analytics and Firebase Crashlytics. These services receive the usage events, identifiers, purchase analytics, and crash diagnostics described in Section 1 when the corresponding collection is enabled. Selected data can be associated with an installation or purchase. Processing is subject to the applicable Analytics terms, Firebase data-processing terms, and privacy information. Data is processed in regions including the United States.

Cloud hosting and operational service providers. These providers host our processing infrastructure, store cached and diagnostic images, maintain subscription and service records, and support logging and service monitoring on our behalf. Our hosted processing infrastructure is located in the United States and Canada. Our cached and diagnostic image copies are scheduled for automatic deletion fourteen (14) days after creation, as described in Section 6.

Contracted AI image-processing providers. Pro Stencil normally processes images using models operated by Ghostline. We may also use contracted AI image-processing providers to generate stencils on our behalf, including when our primary processing service is unavailable. These providers process submitted images under data-protection agreements that prohibit using the images or generated results to train or improve their general-purpose models.

RevenueCat, Inc. RevenueCat manages subscription verification and processes the relevant App Store or Google Play purchase records and pseudonymous app user identifier. It provides subscription and transaction updates to us. See RevenueCat's Privacy Policy. Data is processed in the United States.

App stores and payment processing. Apple handles App Store purchases on iOS, and Google Play handles purchases on Android, together with their payment providers. Their account, billing, and payment processing is governed by their own policies: Apple's Privacy Policy and Google's Privacy Policy. We receive the subscription records described in Section 1, not your store login credentials or full payment-card details.

Destinations you select. If you export, print, or share an image or document, the destination app, printer, storage service, or recipient you choose receives that content.

International processing. Information may be processed outside your country, including in the United States and Canada. For transfers to certified US providers, we rely on the EU-U.S. Data Privacy Framework and its UK Extension or Swiss-U.S. counterpart where applicable. You can contact privacy@ghostline.app for information about the transfer safeguards applicable to your data.

Business transfers and legal requirements. We may disclose information in connection with a merger, acquisition, financing, or sale of company assets, or when necessary to comply with law or establish, exercise, or defend legal claims. We will provide notice of material changes to our handling of your information as described in Section 12.

5. DO WE USE COOKIES OR OTHER TRACKING TECHNOLOGIES?

The Ghostline mobile app does not use HTTP cookies, web beacons, or tracking pixels. It uses identifiers and local storage for the functions described in this notice:

  • Analytics app-instance identifiers associate events with an app installation when analytics is enabled. The app labels this value “INSTALLATION ID” in Info → Privacy.
  • Firebase installation identifiers and Crashlytics installation identifiers support the applicable Firebase services and diagnostics. These are not interchangeable with the Analytics app-instance ID.
  • RevenueCat app user identifiers associate subscription access, purchase records, and applicable service requests with an app installation or subscription. The Info screen provides a “SUPPORT ID” for assistance with these records. RevenueCat may call this an “anonymous” app user ID, but records connected to it are pseudonymous, not necessarily anonymous.
  • Store and request identifiers link purchase events, subscription updates, notice receipts, and generation requests to the relevant records.
  • Local preferences and working data support your settings, privacy choices, recovery of work, and reliable event delivery. Selected settings are also sent when analytics is enabled.

Deleting or reinstalling the app may change some identifiers, but does not erase historical server records or guarantee that every subscription identifier changes. We do not use these identifiers for cross-app or cross-site advertising tracking.

6. HOW LONG DO WE KEEP YOUR INFORMATION?

Different types of information have different retention periods. The fourteen-day deletion schedule for image copies does not apply to separate subscription, event, or security records.

Cached generated stencils and diagnostic input/output image copies

Scheduled for automatic deletion fourteen (14) days after each copy is created. Deletion runs asynchronously, so copies may remain briefly while cleanup completes. The same schedule applies to failed-processing diagnostics and processing comparisons. We do not use these images to train models.

Purchase-start, purchase-completion, and subscription transaction records held by Ghostline

Seven years from receipt, to document the purchase process and subscription history and address billing disputes and applicable recordkeeping obligations, unless a valid deletion request requires earlier deletion.

Service-notice delivery receipts

Two years from receipt, to document delivery, unless a valid deletion request requires earlier deletion.

Generation usage records

Scheduled for automatic deletion thirty (30) days after creation. These records support the rolling thirty-day usage limit. Automatic deletion runs asynchronously, so expired records may remain briefly while cleanup completes.

Local operational/security logs

For as long as needed to diagnose incidents, prevent abuse, and address related disputes, taking account of local log rotation and applicable system retention settings.

Centralized application and infrastructure logs

Application logs in our cloud logging service have a 30-day retention setting. Logs forwarded to our monitoring service have a 14-day retention setting. Cloud infrastructure audit logs have a 400-day retention setting.

Firebase Analytics data

Our event-data retention setting is two months and our user-data retention setting is fourteen months. The user-data retention period resets on new activity, so identifiers associated with a returning user may remain for fourteen months after their most recent activity. These settings govern scheduled removal; aggregate reports may have different retention periods.

Firebase Crashlytics data

The provider keeps crash stack traces and associated identifiers for 90 days before beginning removal from its live and backup systems.

Subscription records held by RevenueCat or the app store

For the subscription relationship and the provider's applicable legal, accounting, and operational retention periods.

Support and privacy-request correspondence

For as long as needed to resolve the request, document our response, and address applicable legal obligations or disputes.

Local preferences, working images, and pending service events

Until removed or replaced through app use, successful event delivery where applicable, clearing app data, or uninstalling. Device backups and exported files may remain until you remove them through the relevant device or service.

Where information other than image copies covered by the fourteen-day deletion schedule must be retained for a legal obligation or dispute, we limit its use to that purpose. If such information remains in backup archives after routine deletion, we restrict its use until the backup expires. Our fourteen-day image rule describes copies in Ghostline's server storage; any separate processing or limited safety retention by a contracted AI service is governed by the applicable processing agreement.

7. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

8. DO WE COLLECT INFORMATION FROM MINORS?

Ghostline is intended for people aged 18 and over. We do not permit people under 18 to use the service and do not knowingly collect personal information from them. If we learn that we have collected personal information from a user under 18, we will take reasonable steps to delete it, subject to applicable legal requirements. Please contact privacy@ghostline.app if you believe this has occurred.

9. WHAT ARE YOUR PRIVACY RIGHTS?

Depending on where you live, you may have rights to access, obtain a copy of, correct, delete, or restrict the processing of your personal information; to data portability; and to object to certain processing. You do not have a Ghostline login account to close. Requests about records associated with your installation or subscription can be sent to privacy@ghostline.app as described in Section 14. We will consider and act on requests in accordance with applicable law.

Analytics and crash-reporting choices. You can independently change analytics and crash reporting at any time in Info → Privacy. The app uses your device's region setting to determine its initial settings. For a device region in the EEA, United Kingdom, or Switzerland, optional analytics and crash-report uploads remain disabled until you make an affirmative choice. For other or unrecognized device regions, these settings default to enabled until you turn them off. The device region setting is not a measurement of your physical location.

Turning off analytics disables optional Analytics collection. Changes to crash-reporting settings are saved when you change the switch; disabling automatic crash-report uploads takes effect the next time you launch the app. Fully close and reopen Ghostline after turning crash reporting off. These choices do not automatically delete records already received, and crash information may remain stored locally as described in Section 1. They also do not disable subscription verification, purchase and notice records, requested Pro image processing, generation limits, or essential server security and operational logs. These functions are described separately in Sections 1, 2, and 6. Declining optional telemetry does not prevent you from using the app's core functionality.

Withdrawing consent. Where processing relies on consent, you may withdraw it at any time using Info → Privacy for analytics and crash reporting, or by contacting us for other processing. Withdrawal does not affect the lawfulness of processing before withdrawal or processing that lawfully relies on another basis. Use Section 14 to request deletion of existing records.

Complaints. You may complain to the data-protection authority where applicable law gives you that right. EEA authorities are listed by the European Data Protection Board. In the United Kingdom, you can contact the Information Commissioner's Office. In Switzerland, you can contact the Federal Data Protection and Information Commissioner.

For questions about these rights, contact privacy@ghostline.app.

10. CONTROLS FOR DO-NOT-TRACK FEATURES

The mobile app does not use browser Do-Not-Track settings to control analytics or crash reporting. Use Info → Privacy to manage those choices. We do not sell personal information or share it for cross-context behavioral advertising. Your rights to object to processing or request deletion are described in Sections 9, 11, and 14.

11. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: Yes, if you are a resident of California, you are granted specific rights regarding access to your personal information.

California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.

CCPA Privacy Notice

The California Code of Regulations defines a "resident" as:

(1) every individual who is in the State of California for other than a temporary or transitory purpose and (2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose

All other individuals are defined as "non-residents."

If you are a California resident and the CCPA applies to our processing, you have the rights provided by that law.

What categories of personal information do we collect?

We have collected the following categories of personal information in the past twelve (12) months:

  • Identifiers: Analytics, Firebase, Crashlytics, and RevenueCat identifiers; App Store or Google Play transaction identifiers; service request identifiers; IP addresses; and contact information you provide to support.
  • Personal information (Cal. Civ. Code § 1798.80(e)): Contact and other information you choose to provide in support or privacy requests. We do not receive full payment-card details or billing addresses through store subscription processing.
  • Protected classification characteristics: We do not request these characteristics; user-selected images or correspondence may contain them.
  • Commercial information: Subscription purchase history, renewals, cancellations, prices, currencies, and records of the plan and terms shown when you started or completed a purchase.
  • Biometric information: We do not use images for biometric identification.
  • Internet or other electronic network activity information: App interactions, selected settings, processing durations, purchase analytics, notice delivery receipts, generation usage records, and crash and operational diagnostics.
  • Geolocation data: Approximate geographic information derived by analytics from IP addresses and country information in subscription records. We do not request device location permission or collect GPS location through the app.
  • Audio, electronic, visual, thermal, olfactory, or similar information: Images uploaded for Pro Stencil and generated results. Cached outputs and diagnostic image copies are scheduled for automatic deletion fourteen (14) days after creation; deletion runs asynchronously. We do not use them for model training.
  • Professional, employment-related, or education information: Not requested to use the app; correspondence or uploaded content may include it.
  • Inferences: Analytics properties such as subscription tier, device capabilities, and usage ranges, as described in Section 1.

We also receive information you choose to provide when seeking support or exercising your privacy rights.

How do we use and share your personal information?

More information about our data collection and sharing practices can be found in this privacy notice.

You may contact us by email at privacy@ghostline.app, or by referring to the contact details at the bottom of this document.

If you are using an authorized agent to exercise your right to opt out we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.

Will your information be shared with anyone else?

We disclose information to the providers described in Section 4 for the purposes in Section 2. Where a provider processes personal information on our behalf, the processing is subject to the applicable contractual protections. App stores also process information for their own account and payment functions.

Our use of information to operate and improve the app does not include training models on your uploaded images or generated stencils.

Ghostline, Inc has not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve (12) months. Disclosures to service providers to operate the app are described in Section 4. Ghostline, Inc does not sell or share personal information for cross-context behavioral advertising, and has no plans to do so.

Your rights with respect to your personal data

Right to request deletion of the data — Request to delete

You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.

Right to be informed — Request to know

Depending on the circumstances, you have a right to know:

whether we collect and use your personal information;

the categories of personal information that we collect;

the purposes for which the collected personal information is used;

whether we sell your personal information to third parties;

the categories of personal information that we sold or disclosed for a business purpose;

the categories of third parties to whom the personal information was sold or disclosed for a business purpose; and

the business or commercial purpose for collecting or selling personal information.

In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.

Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights

We will not discriminate against you if you exercise your privacy rights.

Verification process

We verify requests using information appropriate to the records involved, such as the installation or Support ID, relevant transaction information, and details of the request. We do not require a Ghostline login account or routinely ask for government identification. We may ask for additional information if reasonably necessary to verify your authority and protect another person's data. See Section 14 for how to provide the identifiers already available in the app.

We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.

Other privacy rights

You may object to the processing of your personal information.

You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.

You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.

You may request to opt out from future selling of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.

To exercise these rights, you can contact us by email at privacy@ghostline.app, or by referring to the contact details at the bottom of this document. If you have a complaint about how we handle your data, we would like to hear from you.

12. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this privacy notice from time to time. The date at the top shows when it was last updated. We will bring material changes to your attention through an appropriate notice, such as a prominent notice in the app or on our website. Where required, we will notify you before using your information for a new purpose and obtain any necessary consent before that processing begins. Publishing an updated notice does not override your privacy choices or replace consent required by law.

13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, you may email us at privacy@ghostline.app or by post to:

Ghostline, Inc 24302 Del Prado Ave., Unit A Dana Point, CA, 92629

14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Email privacy@ghostline.app or write to the address in Section 13. Tell us whether you are requesting access, correction, or deletion, and whether your request concerns analytics, images, subscriptions, or other service records.

  • For subscription and service records, use the copy control next to SUPPORT ID on the Info screen and include the full copied value.
  • For analytics records, include the INSTALLATION ID shown in Info → Privacy if it is available. This is the Analytics app-instance ID. It may not be displayed while analytics is disabled; you do not need to enable analytics to make a request. Contact us with the information you have if you cannot obtain it.
  • For uploaded images, include your Support ID if available and the approximate processing date so we can assess the request and applicable automatic expiry. Cached and diagnostic image copies follow the fourteen-day deletion schedule in Section 6; images already deleted are no longer available.

We will use the information you provide to locate relevant records and verify the request proportionately. Where required, we will delete or correct records we hold and direct processors handling those records on our behalf to do the same. If we cannot identify the relevant records, or a legal exception requires us to keep certain information, we will explain the limitation and any additional information needed.

Turning off telemetry or uninstalling the app does not by itself delete records already held by Ghostline or its providers. Uninstalling also does not remove files you exported or copies in device backups. Requests concerning an app store's independently held account or payment records may need to be made to that store.

Deleting data does not cancel a subscription. To stop renewal, use Info → Manage subscription, Apple's subscription settings for an App Store purchase, or Google Play's subscription settings for an Android purchase.