🔒 HideGhost

Privacy Policy

Last Updated: 2026

🔐 Your Privacy is Our Priority. HideGhost is built with privacy at its core. We collect zero personal data, store nothing permanently, and cannot read your encrypted messages. This policy explains exactly what happens to your data (spoiler: nothing).

1. Introduction

HideGhost is committed to protecting your privacy. This policy explains how we handle data in our anonymous, encrypted chat service.

2. Information We DON'T Collect

✅ What We DON'T Collect:

  • No user registration or accounts
  • No email addresses
  • No phone numbers
  • No personal identification information
  • No IP addresses or access logs
  • No long-term message storage
  • No tracking cookies
  • No analytics or user behavior tracking
3. Information We Temporarily Store

For the service to function, we temporarily store in RAM memory:

  • Chat messages: All messages are AES-256 encrypted and stored only in server RAM
  • Files (images, videos, voice): Encrypted before upload and stored in temporary encrypted folders
  • Room IDs: Temporary identifiers for chat rooms
  • Connection data: WebSocket session IDs (cleared on disconnect)
  • Timestamps: For auto-deletion timing only

⏰ All data is automatically deleted after 5 minutes of inactivity or when the chat is manually ended. Nothing is saved to disk.

4. Encryption

All messages are automatically end-to-end encrypted using AES-256 encryption in your browser:

  • Encryption/decryption happens entirely in your browser
  • The encryption key is derived from your Room ID
  • We cannot read your messages - only you and the recipients can
  • Images, videos, and voice messages are also AES-256 encrypted before upload

🔒 Audio and video calls use WebRTC with DTLS-SRTP encryption - calls are peer-to-peer and end-to-end encrypted.

5. Server Logs

✅ We do NOT maintain server logs. No IP addresses, no access logs, no persistent records of any kind.

Our infrastructure is designed for maximum privacy with zero logging.

6. Cookies and Local Storage

We use minimal browser storage for essential functionality only:

  • Theme preference: localStorage for dark/light mode (stays on your device)

No tracking cookies. No analytics cookies. No third-party cookies.

7. Third-Party Services

None. HideGhost uses no third-party services, no CDNs, no analytics, and no advertisements. Everything runs on our own servers.

8. Data Retention

All data retention periods:

  • Chat messages: Stored encrypted in RAM, deleted after 5 minutes of inactivity
  • Files (images/videos/voice): Encrypted on disk, deleted when chat ends
  • Room data: Deleted when chat ends or after timeout
  • Server logs: None - we don't keep logs
  • User data: None - we don't have accounts

⚡ If the server crashes: All data in RAM is instantly lost and unrecoverable. This is a feature, not a bug.

9. Law Enforcement

We cooperate with law enforcement when legally required. However, due to our architecture:

  • We cannot provide historical messages (nothing is stored)
  • We cannot decrypt end-to-end encrypted messages (we don't have the keys)
  • We cannot identify users (no accounts, no IP logs)
  • We have no data to preserve or disclose

Privacy by design: We built HideGhost so that even if compelled by law, we have nothing to give.

10. Children's Privacy

HideGhost is intended for general use. We do not knowingly collect information from anyone, including minors. Due to our zero-data-collection model, we cannot verify user ages.

Parents should supervise their children's internet usage.

11. International Users

HideGhost can be accessed from anywhere in the world. Since we don't collect or store user data, there is no data transfer or processing to worry about.

Your encrypted messages stay in RAM on our server briefly before being deleted forever.

12. Security

We implement multiple security measures:

  • HTTPS/TLS: All connections are encrypted in transit
  • AES-256 encryption: All messages, images, videos, and voice encrypted
  • WebRTC encryption: Peer-to-peer calls with DTLS-SRTP
  • Rate limiting: Prevents abuse and brute-force attempts
  • Security headers: Protection against XSS, CSRF, and clickjacking
  • No persistent storage: RAM-only means data dies with the server
13. Your Rights

Given our zero-data-collection model:

  • Right to Access: No personal data is stored, so there's nothing to access
  • Right to Deletion: Data auto-deletes; you can manually end chats anytime
  • Right to Portability: Not applicable (no user accounts or stored data)
  • Right to Objection: Simply don't use the service
  • Right to Rectification: Not applicable (no stored personal data)

✅ Your privacy rights are protected by default - we can't violate what we don't collect.

14. Changes to This Policy

We may update this privacy policy from time to time. The "Last Updated" date at the top will reflect any changes. Continued use of HideGhost after changes constitutes acceptance of the updated policy.

15. Contact

For privacy concerns, questions, or feedback, contact us through our Contact Form.