← Back to Ghast AI

Privacy Policy

Effective date: February 22, 2026 · Last updated: March 1, 2026

Ghast AI ("we", "our", or "the Extension") is a browser extension that provides an AI assistant for Web3 activities. This policy explains what data Ghast AI collects, how it is used, and how it is protected.

Key principle: Ghast AI is designed with a local-first, privacy-preserving architecture. Your private keys never leave your browser. We do not operate centralized servers that store your conversations or personal data.

1. Data We Collect

1.1 Google Account (Optional)

If you choose to sign in with Google, we request:

Your Google access token is used only for the initial authentication exchange and is never persisted to disk. Only a session token is stored locally in your browser.

1.2 Wallet Data

When you create or import a wallet:

An automatic lock mechanism clears the decrypted private key from memory after a configurable inactivity timeout (default: 10 minutes).

1.3 Conversation & Memory Data

Ghast AI maintains several memory files to personalize your experience:

FilePurposeStorage
soul.mdAI personality configurationLocal + 0G (optional)
user.mdLearned user preferencesLocal + 0G (optional)
strategy.mdUser-defined rules and limitsLocal + 0G (optional)
memory.mdLong-term conversation memoryLocal + 0G (optional)
heartbeat.mdPeriodic monitoring checklistLocal + 0G (optional)

These files are stored in your browser's local storage. If you configure 0G decentralized storage, they are also persisted to the 0G Storage KV network, identified by your wallet address. You can view, edit, and delete these files at any time.

1.4 Usage Metrics (Optional)

If you configure a backend connection, anonymous usage metrics may be synced:

Not included: conversation content, messages, personal data, or wallet balances. Backend sync is entirely optional and disabled by default.

1.5 Web Page Context

When you browse supported Web3 sites (block explorers, DeFi protocols), the Extension's content script may extract:

URL parameters that may contain sensitive data (tokens, API keys, passwords, session IDs) are automatically stripped before processing. You can disable this by setting Capture Mode to "off" in the Extension settings.

1.6 Browser Automation

When the AI uses browser automation tools, it operates in a dedicated managed tab and captures:

Full HTML source, screenshots, and raw page data are not captured. Browser automation only activates for sites where you have granted host permissions.

2. How We Use Your Data

3. Third-Party Services

3.1 0G Compute Network

AI inference requests (system prompt + conversation context + tool definitions) are sent to the 0G decentralized compute network. Requests are routed through the 0G proxy endpoint and processed by decentralized compute nodes. We do not control or store data on these nodes.

3.2 0G Storage KV (Optional)

Memory files can be persisted to the 0G decentralized storage network, identified by your wallet's stream ID. Data on 0G Storage is accessible to anyone with your stream ID. Do not store sensitive personal information in memory files if you enable 0G sync.

3.3 Telegram (Optional)

If you configure Telegram integration, messages are sent directly to the Telegram Bot API using your provided bot token. We do not intermediate or store these messages.

3.4 Google APIs

Used solely for OAuth2 authentication. We request only userinfo.email and userinfo.profile scopes.

3.5 Companion App (Optional)

The Extension can communicate with a locally installed companion desktop application ("Companion") that you install separately on your machine. The Companion expands the Extension's capabilities beyond the browser sandbox.

Data exchanged with the Companion:

Security:

3.6 Web Search APIs (Optional)

When the AI performs web searches, queries are sent to Brave Search or DuckDuckGo. Search queries originate from your conversation context.

3.7 GitHub (Skill Repository)

Skill definitions are fetched from the public Ghast skill repository on GitHub. No personal data is transmitted; only skill metadata and definitions are downloaded.

4. Data Storage & Security

5. Data Sharing

We do not sell, rent, or share your personal data with third parties. Data is only transmitted to:

6. Data Retention

7. Your Rights & Controls

8. Children's Privacy

Ghast AI is not intended for use by children under 13. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of the Extension after changes constitutes acceptance of the updated policy.

10. Contact

For privacy-related questions or concerns, please open an issue on our GitHub repository or contact us at [email protected].