The short version: we never see your files, and we keep nothing.
GhostX tools process your files entirely in your browser. This policy covers every tool at ghostx.tools — GhostSign, GhostPDF, GhostImage, GhostQR, GhostAudio, GhostVideo, GhostSheet, GhostDev, GhostSend, and GhostBeam. For the in-browser tools (PDF, image, audio, video, QR, spreadsheet, and developer tools) and single-signer GhostSign, your files never leave your device. No upload, no server, no database entry. It's like they were never there. Open DevTools and watch the Network tab — there is no upload endpoint to send them to.
For the in-browser tools and single-signer signing, your file contents never leave your device. The file lives in browser memory, is processed by client-side code, and downloads directly back to you — there is no upload endpoint, and we never store or see your files. We do collect lightweight, anonymous usage analytics through Google Analytics to see which tools get used: the page or tool, whether an action succeeded or failed, and coarse file metadata such as size and page count — never your file, its name, or its contents. Like any website, our analytics and abuse-prevention providers also receive your IP address and browser user-agent. We don't create accounts and we don't build advertising or identity profiles — but we're not a zero-telemetry product: Google Analytics and the reCAPTCHA we run on server-backed flows collect their own device and behavioral signals. You can turn analytics off entirely by setting ghostx:no-analytics=1 in your browser's local storage.
A few flows need a server to relay data between people — multi-signer GhostSign documents, GhostSend one-time sends, and GhostBeam transfer signaling. For these we hold ciphertext only. The AES-GCM 256 key is generated in your browser, never sent to our servers, and lives only in the link's URL fragment (the part after the #, which browsers do not transmit). GhostBeam goes further: file bytes travel browser-to-browser over WebRTC and never touch our servers at all.
Everything server-backed auto-deletes on a TTL. Multi-signer documents and their encrypted blobs are wiped 7 days after creation; GhostSend payloads burn the moment they're read (or when they expire). Once a flow completes or expires, every trace is wiped from our servers — we never keep a copy and we have no recovery mechanism.
What we never see: document or file content, signatures, signer names, signer emails, or your recipients' email addresses. Names + emails in multi-signer documents are encrypted inside the document blob; link delivery uses your own email client (no server-mediated send), so we never learn who you sent links to.
We're honest about where the system is strong and where it isn't. These caveats apply to the link-based flows (multi-signer GhostSign, GhostSend, GhostBeam):
mailto: so the email goes through your mail provider (we never see the recipient address), but the underlying email pipeline is what it is. For sensitive documents, prefer Signal / iMessage / a private channel where the intermediaries don't keep copies.We store your theme preference and, for signing, your name (so it's pre-filled next time) in local storage. Google Analytics sets its own cookies (such as _ga) to count visits. For link-based flows, the key-bearing URL fragment is briefly stashed in sessionStorage during page load — it's scrubbed from the URL bar before any third-party script (including analytics) can read it, and it is never put in a cookie or sent in any request. Your file contents are likewise never placed in a cookie or transmitted.
Every multi-signer document auto-deletes 7 days after it's created — Storage blobs and the database record are wiped at that point. GhostSend links burn on first read. We never keep a copy and we have no recovery mechanism. If you sent a link to the wrong person, tell them to ignore it; the link expires on its own.
GhostX loads a small, fixed set of third-party services — all from Google or our payment/abuse providers:
We do not currently display ads. If we add ad-supported hub pages in the future, we'll update this policy and load Google AdSense there; Google may then use cookies for ad personalization, which you can opt out of in your Google ad settings.
We monitor for spam, automated abuse, and excessive usage patterns that could degrade the service for others. If we detect activity that appears to be abusive — including but not limited to automated scripting, bot-driven requests, or excessive volume designed to exploit our infrastructure — we reserve the right to rate-limit, temporarily block, or permanently ban the offending IP address or device without prior notice. We do this to keep GhostX free and fast for everyone.
Because your files are processed entirely in your browser and never touch our servers (for the in-browser tools and single-signer signing), we have no access to, no control over, and no responsibility for your files, documents, signatures, or any data you process through any GhostX tool. You use these services entirely at your own risk. See our Terms of Service for full details.
Last updated: July 2026. GhostX (ghostx.tools) is operated by IN2Labs. in2labs.dev