Effective August 2026

Privacy policy

GhostPost drafts social posts grounded in the work your team is already doing. To do that, it reads workspace content you explicitly connect. This page says — in plain language — what we collect, where it lives, and what we do with it.

01

What we collect

Account basics.Your name and email address, via Google sign-in or a password login. That’s what it takes to have an account.

Workspace content you explicitly connect.Slack channels and threads, Jira issues, Confluence pages — connected by you, through each tool’s OAuth flow, with read-only scopes. GhostPost cannot write to your tools, and it never sees content from a tool you haven’t connected.

Files you upload directly. Exported agent transcripts, such as a Claude Code /export, dropped in by you. These are the one thing we receive that nobody at your company reviewed first, so before the file is stored we scan it and redact anything shaped like a credential: API keys, access tokens, private keys, and database connection strings. We keep no unredacted copy, and the upload tells you how many secrets were removed.

02

Where it lives

Connected content is stored in our Postgres database and retained while your account is active. A mirror lives in Supermemory, a third-party memory-and-retrieval processor we use so drafts can be grounded in your real work. Each customer’s content is isolated — yours is never blended with anyone else’s.

OAuth tokens are encrypted at rest with AES-256-GCM and never leave our servers. The AI agents that draft your content never hold credentials — they work from retrieved content, not from access to your tools.

03

How we use it

One purpose: generating grounded social-media drafts for you. Retrieval finds the relevant work; drafting turns it into posts. As part of drafting, your content is processed by large-language-model APIs to produce the drafts.

Your content is never sold, never shared across customers, and never used to train our own or any third party’s foundation models.

04

Private channels

The GhostPost bot can only read a private Slack channel you have explicitly invited it to. No invite, no access.

05

Deletion and disconnection

Email chris@ghostpost.dev and we delete your account’s stored content and its Supermemory mirror.

Disconnecting a tool stops any further ingestion from it, immediately.

06

Cookies

Cookies keep you signed in. That’s the whole list — no ad tracking.

07

Questions

GhostPost is an early-stage product, built and run by its founder. Write to chris@ghostpost.dev with any privacy question and you’ll get an answer from the person who operates the system. If this policy changes, this page changes.

Nothing ships that can’t say what it’s grounded in — that goes for our posts and for this policy