Privacy
Privacy Policy
askghost ("we", "us") provides an email-channel feedback tool for SaaS operators ("Customers") to collect opt-in feedback from their own end users ("Recipients"). This Privacy Policy describes how we collect, use, and protect personal data.
1. Data we collect
- Customer account data: name, email address, authentication tokens, billing identifiers (via Polar, our Merchant of Record).
- Recipient data uploaded by Customers: email address, first name, custom attributes, and prior consent timestamps. Customers warrant they have a lawful basis (opt-in consent) for processing.
- Engagement data: open / click / response events for messages we send on behalf of Customers.
- Suppression data: bounce and complaint records from AWS SES, retained to prevent re-sending to addresses that have asked to stop or that have hard-bounced.
2. How we use it
- To deliver the feedback emails Customers compose.
- To honor unsubscribe (RFC 8058 list-unsubscribe) and complaints.
- To bill Customers and prevent abuse.
- To improve product reliability (aggregate analytics — no personal content scanning).
3. Sub-processors
- Cloudflare (Workers / Pages / R2 / D1 / KV — application hosting)
- Neon (Postgres database, on AWS)
- AWS SES (email delivery)
- Polar (payments, Merchant of Record)
- Sentry (error monitoring)
- Google Analytics 4 (aggregate visit statistics)
4. Google Analytics 4
Our website uses Google Analytics 4 (GA4) to understand aggregate visit statistics. GA4 uses cookies to collect anonymized, aggregated data such as page views, and that data is transmitted to Google. We do not send personally identifiable information — email addresses, names, or response content — to GA4.
How collection works depends on your region. In the EU/EEA, the United Kingdom, and Switzerland, GA4 is enabled only after you accept the consent banner (opt-in). In other regions it is enabled by default, and we honor your browser's Global Privacy Control (GPC) signal. In any region you can opt out by blocking cookies in your browser. Ad personalization (Google Signals) is disabled everywhere.
5. Data location and retention
Production data is stored on Cloudflare's network and on AWS (Neon Postgres, AWS SES). Data is automatically deleted on the following schedule: uploaded recipient CSV files are deleted 30 days after upload; recipient records are deleted 90 days after creation, or — where a send has occurred — together with the related delivery records, which are retained for 180 days for unsubscribe enforcement and dispute handling. An upload that progressed to a send keeps its summary row, so some addresses stay in that summary, and that copy is removed in askghost's own systems when the campaign or the account is deleted. Suppression entries are retained indefinitely as required by anti-spam law (e.g. CAN-SPAM) and sender reputation best practice, except that they are removed in askghost's own systems when a Customer deletes their tenant data. Customers can delete their tenant data at any time via account settings, which triggers immediate erasure in askghost's own systems. Section 6 describes each stage in detail.
6. Recipient data in a feedback request
This section describes the recipient data a Customer uploads for one feedback request and what happens to that data at each stage.
- A feedback request starts from a CSV file: the file itself is archived as uploaded in object storage and stays there for up to 30 days from upload. From that file we store the address, its row number, and its row status, plus — when a row is skipped — the exclusion reason and its detail, which holds the local part for a role account, the domain for a disposable or undeliverable domain, the raw email cell for a malformed row, or the consent source value for a row without consent evidence, and every column other than the consent timestamp and the consent source is counted as an ignored extra column and dropped.
- The stored addresses serve one feedback request: sending it, recording the responses it receives, and honoring unsubscribes from it.
- Once 30 days pass from upload, the archived CSV file becomes eligible for automatic deletion, but a batch that was sent from keeps its upload summary row, so some addresses stay in that summary's preview rows and excluded-row report. Recipient rows become eligible for automatic deletion 90 days after they are created, and a row that was actually sent to stays as long as its delivery record does, up to 180 days. Delivery records and response records become eligible for automatic deletion 180 days after they are created.
- Four paths remove recipient data from our operational data: automatic expiry on the retention schedule, account erasure, campaign deletion, and a per-address deletion request to [email protected]. A per-address deletion request removes that address's recipient row, delivery records, and response records in askghost's own systems, while the copy left in the upload summary goes with that summary row when the campaign or the account is deleted.
- Three vendors handle recipient data: Cloudflare (application hosting and file storage), Neon (Postgres database, on AWS), and AWS SES (email delivery). A domain check during upload sends only the domain part of an address to Cloudflare's public DNS resolver, and an error report reaching Sentry carries an address only in masked form — its first 2 characters plus its domain.
- Recipient rows, delivery records, and response records are stored in our Neon Postgres database, where a new workspace is created in the us-east-1 region by default, while the uploaded CSV files in Cloudflare object storage sit in no region we pin in our configuration.
- Every message carries a one-click List-Unsubscribe header (RFC 8058), and [email protected] accepts the same request. An address that opts out is recorded on that workspace's suppression list, which blocks any later send from that workspace.
- Six things never happen to recipient data:
- Recipient data is never sold or rented.
- Every query for recipient data is scoped to a single workspace, so one Customer's list is not readable from another Customer's account.
- Recipient addresses and responses are never used to train AI models.
- Recipient data is never sent to advertising or tracking networks.
- Recipient data never becomes a contact list for anyone else's outreach.
- Recipient addresses receive the feedback request they were uploaded for, and no marketing from askghost.
7. Your rights
Recipients can unsubscribe via the one-click List-Unsubscribe header in every message, or by emailing [email protected]. Customers can export or delete their tenant data via the in-app account settings or by contacting support. Even after an account is deleted, billing and tax records are retained by Polar, our Merchant of Record, for the period its own legal obligations require.
8. Contact
Privacy inquiries: [email protected]