Ghost and Core Privacy Policy

Effective date: October 4, 2026

ZMJ, Inc., doing business as Ghost ("Ghost," "we," "us" or "our"), makes Core, a personal AI computer whose conversational AI and memory run on your hardware.
This Privacy Policy explains how personal information is handled when you use Core, its companion software, our websites and related services, or purchase a product from us. It also explains your privacy rights and choices.

Information Core uses on your devices

In simple terms

On-device AI and memory. Core stores and processes conversations, files, connected-app content and memories on-device.
Accounts and local copies. Imported browser passwords and signed-in sessions are saved on Core for account access. Memories on Core and copies on paired devices can remain after you remove the original source.
Core uses the information you provide and the sources you connect to answer questions, carry out tasks and remember useful context. Depending on the features and permissions you enable, this can include:
  • Conversations, instructions, attachments and task results.
  • Files and information from connected applications, such as email, calendars, contacts, messages, documents and health or fitness records.
  • Information from connected devices, such as screen content, camera images and location when a feature has access to it.
  • Memories, summaries, preferences and other information Core derives from these sources.
This information may contain sensitive details about you or other people, including private communications and health, financial or location information.
Core does not use a remote AI model as a fallback for its local conversational AI or memory processing. Online features can still send task information to external services, as described in Section 2.
Some features give Core ongoing access to information:
  • Connected applications can synchronize in the background while the connection remains enabled.
  • Screen history is off until you enable it. While enabled, it captures screen images and recognized text, with details such as the application, window title, time and available page address, and sends them to your connected Core for search and recall. It does not capture audio. Private browsing does not pause screen capture.
  • Connected cameras can provide images, including repeated captures, for analysis and recall on Core. A camera provider may separately store or transmit images under its own settings and privacy policy.
  • Importing a browser profile can bring in browsing history, bookmarks, autofill data, extensions, site storage, saved passwords and signed-in sessions. Those credentials and sessions can allow Core to access websites and act through your accounts.
Core can create or update memories in the background. A memory can exist separately from the conversation or file it came from, and it may be inaccurate. You can use the available controls to review, correct or remove it.
When you use a paired phone or computer to view or download conversations, files or previews from Core, that device may save its own local copies. Depending on your backup settings, those copies may also be included in device or cloud backups. Erasing Core does not erase these separate copies; manage them using the paired device’s storage and backup settings.

Online services

In simple terms

Simple setup. Ghost-managed services let you use features such as phone calls and web search without setting up a separate provider account or API key.
No stored request content at Ghost. Ghost's gateway forwards request and response content without saving it in databases, logs or backups. We do not use that content for analytics, profiling or AI training and it is never retained.
Use your own API keys. In the app, you can always replace Ghost-managed services with your own provider connections and API keys

Third-party services

Some online features use third-party services to carry out a task. Ghost provides managed access to make these features simple to set up. For example, you can enable a service without obtaining a separate API key from its provider.
For a Ghost-managed service, the request travels from Core to Ghost's managed-service gateway, then to the third-party provider. The response returns through the gateway to Core. The request contains the information needed for the task: for example, a search query, or a phone number and instructions for a call. That information can include personal details from your task.
Ghost handles the request and response content only to forward it. The gateway does not save that content in databases, request logs, backups or troubleshooting records. We do not use it for analytics, profiling or AI training. Core can still save the conversation or result on your hardware.
The third-party provider receives and processes the request content. Its retention and use of that information depend on its own policies and applicable agreements. Ghost's decision not to store forwarded content is not a guarantee that the provider does not store it. Deleting a result on Core does not necessarily delete the provider's copy.
You can configure direct provider connections in the app using your own API keys, often called bring your own key or BYOK. Core then sends requests directly to that provider, without passing through Ghost's managed-service gateway. This changes the route for that service; other Ghost-managed services you leave enabled still use the gateway. Using your own key does not change the provider's privacy practices.

Connected accounts and service records

When you connect an existing account, Core receives the permissions you approve. Some connections continue syncing in the background. Ghost may handle account identifiers, access credentials, permissions, connection status and change notifications to establish or maintain the connection. Sending a message or uploading a file also gives its contents to the service and the intended recipient.
Ghost retains records needed to authorize devices, maintain connections, manage usage limits and protect the service, such as device identifiers, authorization records and service-usage counts. These records do not include the content forwarded by the managed-service gateway or remote-access relay. These no-storage commitments concern forwarded content; they do not mean that Ghost holds no account, connection, purchase or support information.

Accessing your Core from another location

In simple terms

Your Core still does the work. You can connect to Core while away from home through Ghost's remote-access relay. The connection is encrypted, and the relay forwards traffic between your paired device and Core with no retention or data being saved. Your conversational AI and memory continue to run on Core.
Use your own remote connection. You can always replace Ghost's relay with your own remote-access setup, such as Tailscale.
Remote access connects a paired phone or computer to your Core over the internet. Ghost provides a remote-access relay so you can reach Core from another location. The connection is encrypted. The relay forwards traffic; it does not run your conversational AI or store your conversations, files or memories.
The relay does not save the content it forwards in databases, traffic logs, backups or troubleshooting records. We do not retain that content for analytics, profiling or AI training. Information you access or create remains subject to storage on your Core, paired devices and any third-party services you choose to use.
You can replace Ghost's remote-access relay with your own connection, such as a private network set up using Tailscale. Your remote-access traffic then travels over that connection without using Ghost's relay. Replacing the remote connection and using your own API providers are separate choices. Using both can remove Ghost's gateway and relay from those data paths.

Purchases, support and our website

In simple terms

Buying Core from Ghost. We receive contact, payment-status and delivery information to process your order, deliver the product and handle returns or warranty service.
Visiting our website. Our website handles connection details, such as your IP address, and information you enter in forms. We do not use optional website analytics or advertising tracking.

Buying a product from us

When you buy Core or another product from Ghost, we receive information from you and our payment and delivery providers, such as your contact details, billing and shipping addresses, order details, payment status and delivery information. We use it to process and deliver your purchase, handle returns and warranty service, prevent fraud, resolve disputes and maintain required business records.

Support and feedback

When you contact us, we receive your contact details, message and anything you choose to include, such as screenshots, logs, attachments or conversation content. People handling your request can read that material to investigate the issue and respond. Review it before sending if it contains private information.
We do not automatically collect product telemetry, usage analytics or diagnostic reports from Core or its companion software. Diagnostic material is sent to us only when you choose to include it in a support or bug report. We do process the operational records of requests to our online services described in Section 2.

Our website and communications

Our website infrastructure receives the technical information needed to serve a page, such as your IP address and request details. Forms collect the information you submit so we can respond or provide the requested service.
We do not use optional analytics, advertising pixels or other optional tracking on our customer website. You can unsubscribe from marketing messages using the link in the message. We may still send communications about purchases, support, service or security.

How Ghost uses information it receives

In simple terms

No stored collection of your Core content. Your on-device conversations, files and memories are not backed up to Ghost. Our gateway and remote-access relay do not retain the content they forward.
The information Ghost does receive. We receive limited personal information such as order details, support messages and service records. We will never sell it, use it for targeted advertising or use it to train AI models.
Ghost does not keep a cloud copy of your on-device conversations, files, connected-app content or memories, or store content forwarded through its gateway or remote-access relay. This section concerns the purchase, support, account and service information Ghost receives, including any private material you choose to submit to us.
We use that information to fulfill requests, operate and protect our services, handle purchases and support, and meet legal obligations. We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising or use it to train AI models.
We share relevant records with providers that help us operate, such as payment, delivery, hosting and support providers. They must handle those records under their agreements with us and applicable law.
We may disclose relevant information to professional advisers, to comply with law or valid legal process, address fraud or security incidents, protect rights and safety, or establish or defend legal claims. Records may also be disclosed during a merger, acquisition or other business transfer, subject to applicable confidentiality and privacy obligations. These disclosures do not provide access to content stored only on your devices or create copies of content Ghost does not retain.
Information Ghost receives may be processed in countries where we or our providers operate. Contact us for information about the safeguards applicable to international transfers.

Retention and deletion

In simple terms

Stopping collection is not deletion. Pausing capture or disconnecting an app stops new collections through that feature. It does not erase information already saved on Core.
Delete the copies you want removed. Conversations, source files and memories can be separate records. Removing one may leave another, and Core can learn information again if its source remains connected. Erasing Core does not erase other devices, backups or information already sent to someone else.

Information on your devices

Local conversations, files, imported information and memories remain until removed through the relevant controls or retention rules. Synchronization and storage limits can also affect what is retained.
Screen-history records expire seven days after the content was last observed, or sooner if storage limits are reached. You can pause capture or clear the stored history. Clearing history also stops that capture session, but does not delete information already saved separately in a conversation, file or other output.
Pausing capture or disconnecting a source stops further collection through that feature; it does not delete information already saved. Deleting a source file or conversation does not necessarily delete a separate memory derived from it. If a source remains available, later synchronization or memory processing can bring the information back.
Use the relevant controls to delete local content and memories, remove credentials or erase Core's managed user data. A connected service may also require you to revoke access or signed-in sessions through its own settings.
Erasing Core does not remove copies on companion devices, in exports or backups, or with Ghost, another service or a message recipient. Restoring a backup may restore previously deleted information. Requests about information Ghost holds are covered in Section 8.

Information Ghost receives

  • Device identifiers and authorizations: we keep your Core's device identifier and authorization records to recognize it and confirm its eligibility for Ghost services. These records remain while needed to provide that access. We remove obsolete links to previous owners and authorizations no longer needed for access, subject to specific security or legal requirements.
  • Connection credentials and records: we keep access credentials, approved permissions and connection status while needed to establish or maintain a connection you authorized. We remove credentials when they expire, are revoked or are no longer needed for the connection.
  • Forwarded request and response content: Ghost's managed-service gateway and remote-access relay do not save the content they forward in databases, logs or backups. This content is not retained for troubleshooting, analytics, profiling or AI training.
  • Service-usage counts: we keep request totals for each Ghost-managed service, linked to the relevant account and day, to enforce daily usage limits designed to prevent abuse. We delete these counts when the daily limit resets. These records do not include queries, call instructions, conversations, files or response content.
  • Submitted logs, screenshots and diagnostic attachments: deleted by the earlier of seven days after the issue is resolved or 30 days after receipt. If we need further diagnostics after that period, we may ask for a new submission.
  • Support correspondence and case records: retained while the case is open and for up to 90 days after closure. Diagnostic material included in a message follows the shorter diagnostic deadline above.
  • Purchase, payment and warranty records: retained for the time needed to complete the transaction, provide warranty service, resolve disputes and meet accounting, tax and other legal recordkeeping requirements.
  • Communication preferences: retained while needed to honor your choices, including a limited record of an unsubscribe request.
A legal hold or another lawful exception may require us to keep records we already hold for longer. We continue to restrict their use and access. This does not create a stored copy of gateway or remote-access content that our systems do not retain. Our retention and deletion commitments for records kept by Ghost also apply to copies held by providers on our behalf, including backups. External services that receive a task request may retain information under their own policies and applicable agreements; Ghost's no-storage commitment does not guarantee deletion of their copies.

Security

In simple terms

Access to your devices. Keep Core, paired phones or computers, and connected accounts secure. Someone who can use an unlocked device or an authorized account may be able to see or use its information.
We use device-access controls and protected connections to help secure Core and communications between paired devices.
The security of your devices and connected accounts also matters: someone with access to an unlocked device or an authorized account may be able to access its information.
Before returning a Core or sending it for repair, back up what you need and follow the erasure instructions. Contact us before sending it if you cannot erase it. No security measure eliminates every risk; we provide notice of an incident when required by law.

Your privacy rights

In simple terms

Information on your devices. Use Core's controls to manage connections and permissions, review or remove memories, and delete local information.
Your rights. Contact us to access, copy, correct or delete personal information we hold. Other rights depend on the law that applies to you.
Your choices. You can unsubscribe from marketing and withdraw consent where processing relies on it. Contact other providers directly about information they hold independently.
Depending on where you live and the law that applies, you may have rights to learn what personal information is processed; access or receive a copy of it; correct or delete it; restrict or object to processing; withdraw consent; or limit certain uses of sensitive information. Applicable law may also give you rights concerning sale, sharing, targeted advertising or certain significant profiling, and rights to appeal a decision or complain to a privacy regulator.
Contact us using the details below to make a request. Describe what you need and the purchase, device or interaction involved. We may need to verify your identity and, where relevant, an authorized agent's authority. Do not send passwords or recovery keys.
We respond within the time required by applicable law and explain any extension or limitation. We do not unlawfully discriminate against you for exercising your rights. If an appeal is available, contact us with "Privacy appeal" and the details of your original request.
For information stored only on your devices, we can help you use the relevant local controls. Information independently held by another provider may require a separate request to that provider. Where processing depends on consent, you can withdraw it through the relevant control or by contacting us. Withdrawal applies to future processing and may affect the feature that depends on it.

Children's privacy

In simple terms

Who the service is for. Ghost's online services are intended for people aged 13 and older. We do not knowingly collect personal information online from children under 13.
Ghost's online services are intended for people aged 13 and older and are not directed to children under 13. We do not knowingly collect personal information online from children under 13. If we learn that we have collected it without the authorization required by law, we take steps to remove it and stop the unauthorized processing.

Independent security review

We welcome independent security firms to audit the managed-service gateway and remote-access relay. Contact support@ghost.ai to arrange a review of these data flows.

Contact and policy updates

For privacy questions, requests or appeals, contact:
Ghost
Attention: Privacy
325 9th Street
San Francisco, CA 94103, United States
Email: support@ghost.ai
We update this policy when our practices or applicable requirements change. The effective date identifies the current version. For material changes, we provide notice through the product, website or another suitable channel before the change takes effect where required. If a change requires consent, we obtain it; posting an update or continued use of Core does not replace that consent.
ghost