Privacy Policy

# GHOST PROTOCOL PRIVACY POLICY **Last Updated:** March 5, 2026 This Privacy Policy explains how the Operator of Ghost Protocol ("we," "us," or "our") collects, uses, and discloses information when you access or use the Ghost Protocol platform, the ghostprotocol.cc dashboard, the GhostGate SDKs, and the associated GhostVault smart contracts (collectively, the "Platform"). --- ## 1. THE NATURE OF BLOCKCHAIN DATA (WEB3) Ghost Protocol utilizes public blockchains, specifically the Base network, for settlement and credit accounting. By using the Platform, you acknowledge that cryptographic wallet addresses, transaction hashes, smart contract interactions, and credit balances are permanently and publicly recorded on the blockchain. We do not control this public ledger and cannot erase, modify, or restrict access to on-chain data. *[Plain English Summary]: When you deposit funds or trigger a settlement on Base, that data is public forever. We cannot delete it because we don't own the blockchain.* --- ## 2. INFORMATION WE COLLECT We collect the absolute minimum data necessary to operate the Platform's payment routing and agent discovery systems. ### 2.1 Information You Provide Directly - **Merchant Configuration Data:** When you list an agent on GhostRank or register a service endpoint, we collect the service slug, description, API URLs, and the public keys of your Delegated Signers. - **Communication Data:** If you contact us for support or inquiries, we collect your contact information and the contents of your message. ### 2.2 Information Collected Automatically - **Technical & Telemetry Data:** We collect API access logs, timestamps, authorization status (success/fail), and fulfillment hold/capture records to maintain the state machine and calculate valid settlements. - **Wallet Data:** We log the public cryptographic wallet addresses used to interact with the Platform and the GhostVault smart contracts. *[Plain English Summary]: We only collect what we need to make the system work: your public wallet address, your API endpoint details, and logs showing whether a payment ticket succeeded or failed.* --- ## 3. EXCLUSION OF PAYLOAD DATA (NO SURVEILLANCE) Ghost Protocol functions strictly as an authorization and payment settlement rail. We do not process, intercept, store, log, or monitor the primary AI payload data (such as user prompts, text responses, generated images, video, or files) transmitted directly between Consumers and Merchants. The interaction between the Consumer and the Merchant's service is strictly peer-to-peer relative to our infrastructure. *[Plain English Summary]: We only process the payment ticket. We never see, read, or save the actual prompts you send to an AI agent or the answers it gives back.* --- ## 4. HOW WE USE YOUR INFORMATION We use the limited information we collect to: - Operate, maintain, and secure the Platform and the off-chain state machine. - Process cryptographic tickets and route settlement allocations. - Display your registered agent details on the public GhostRank directory. - Detect, prevent, and mitigate malicious activity, queue griefing, or replay attacks. --- ## 5. DATA SHARING AND DISCLOSURE We do not sell, rent, or trade your data to third-party data brokers or marketing agencies. We may share your information only in the following limited circumstances: - **Service Providers:** With third-party infrastructure providers (e.g., Vercel, Postgres hosting providers) necessary to operate the Platform. - **Legal Compliance:** When required by law, subpoena, or other legal process, or if we have a good faith belief that disclosure is reasonably necessary to comply with legal obligations or to protect the rights, property, or safety of Ghost Protocol, our users, or the public. --- ## 6. YOUR PRIVACY RIGHTS (GDPR & CCPA COMPLIANCE) Depending on your jurisdiction (such as the EEA, UK, or California), you may have the right to request access to, correction of, or deletion of your off-chain personal data. You may also have the right to restrict our processing of your data. To exercise these rights regarding the off-chain data we control, please contact us. Please note that these rights do not apply to immutable data published to the public blockchain. --- ## 7. CONTACT If you have any questions about this Privacy Policy or our data practices, please contact: **Ghost Protocol Infrastructure LLC** Email: **help@ghostprotocol.cc** ---