Privacy Policy
Effective: September 12, 2026
1. Who we are and scope
This Privacy Policy explains how Belova Tech Private Limited (Belova Tech Pvt. Ltd.) (“Belova Tech”, “we”, “us” or “our”), a private limited company incorporated in India, collects, uses, discloses, stores and protects personal data when you use GhostAI, ghostai.one, our desktop applications, customer support, payments and related services (the “Service”). Belova Tech determines the purposes and means of this processing and acts as the data fiduciary or controller, as applicable.
This Policy applies to visitors, account holders, purchasers, trial users, referral participants and people who contact us. It does not govern a third-party website, platform or service linked from GhostAI.
2. Personal data we collect
2.1 Data you provide
- Account data: name, email address, login method, authentication identifiers, profile details and preferences.
- Purchase data: billing name and address, country, tax details where requested, plan, amount, currency, payment status, transaction and subscription identifiers. Payment processors receive full payment credentials; we generally receive only limited payment details and tokens.
- User Content: prompts, questions, responses, resumes, documents, code, custom instructions, selected screen content, screenshots, transcripts, audio and session context you choose to process, save or sync.
- Communications: support requests, emails, feedback, survey responses, refund reasons and attachments.
- Referral data: referral codes, attribution, conversions, payout contact or tax/KYC details where applicable.
2.2 Data collected automatically
- Device and network data: IP address, approximate location derived from IP, device and installation identifiers, operating system, architecture, application version, language, time zone, browser and network diagnostics.
- Usage and reliability data: feature events, session timing, credit consumption, plan limits, model routing, latency, error reports, update status, security events and audit logs.
- Website and attribution data: pages, referrer, campaign parameters, interactions, visitor and session identifiers, and conversion events collected through first-party analytics, Google Analytics and Meta Pixel where enabled.
- Cookies and local storage: authentication, security, preferences, referral attribution, session continuity, analytics and marketing identifiers described in Section 9.
2.3 Data from other sources
We may receive identity data from sign-in providers, payment and fraud signals from Razorpay or Stripe, referral information, app-store or distribution data, and information lawfully supplied by service providers, authorities or a person reporting abuse.
3. How capture and AI features work
GhostAI processes audio, transcripts, screenshots, prompts, resumes and session context only when you activate or configure a feature that requires them. Depending on the feature and your settings, processing may occur on your device, through Belova Tech systems, through selected AI or speech-to-text providers, or through a combination of these.
Live audio may be streamed to a transcription provider to produce text. Screenshots, prompts, transcript excerpts, resume excerpts and conversation context may be transmitted to an AI provider to generate a response. Temporary buffers, retry queues and security logs may be created to deliver and recover a session. If session-history or sync features are enabled, selected content may be stored until you delete it or it expires under the applicable setting.
4. Purposes and legal grounds
We process personal data for the following purposes and on the grounds available under applicable law:
| Purpose | Data and basis |
|---|---|
| Create and secure accounts | Account, device and security data; your request, consent and service delivery |
| Provide transcription and AI output | User Content and usage data; your request and consent |
| Process purchases and renewals | Account, order and payment data; contract and legal obligations |
| Meter credits and enforce plan limits | Account and usage data; service delivery and prevention of abuse |
| Support, debugging and recovery | Communications, diagnostics and relevant content you submit; your request |
| Security, fraud and legal compliance | Account, payment, device, logs and content where necessary; legitimate uses and legal obligations |
| Analytics and product improvement | Usage, attribution, diagnostics and feedback; consent or legitimate use as applicable |
| Marketing and referrals | Contact, campaign and referral data; consent and requested transactions |
Where consent is the basis, you may withdraw it using the relevant control or by contacting us. Withdrawal does not affect processing already carried out and may prevent the affected feature from functioning. We may also process data for uses expressly permitted without consent under applicable law.
5. How we disclose personal data
We do not sell your personal data. We may disclose the minimum data reasonably needed to:
- Infrastructure and database providers that host the website, API, authentication, storage, backups and operational systems, including Supabase and hosting providers.
- AI and transcription providers that process prompts, screen content, audio, transcripts and contextual excerpts to return the feature you request. Providers may include OpenAI, Google and specialist speech providers selected by our managed-routing systems.
- Payment providers, including Cashfree Payments, Razorpay and Stripe, for checkout, recurring mandates, tax, fraud checks, refunds and chargebacks.
- Analytics and advertising providers, including Google and Meta, for measurement, attribution and marketing where those tools are enabled.
- Communication and support providers for transactional email, notices and customer assistance.
- Professional advisers, insurers and transaction parties for audits, claims, financing, merger, acquisition, restructuring or sale, subject to confidentiality and applicable law.
- Authorities and affected parties where reasonably necessary to comply with law, enforce our Terms, protect rights and safety, investigate fraud or respond to a valid legal process.
We may publish or share aggregated or de-identified information that does not reasonably identify you. We require processors to handle personal data only for authorised purposes and with appropriate safeguards.
6. International processing
Our providers and their systems may be located in India and other countries. This means personal data may be processed outside your state or country, including where privacy protections differ. We use contractual, technical and organisational safeguards and comply with restrictions notified under Indian law. We may change provider regions as the Service evolves.
7. Retention and deletion
We retain each category only as long as reasonably necessary for the purpose collected, account operation, security, dispute resolution, enforcement and legal, tax or accounting obligations. Typical criteria are:
- account and entitlement records while your account is active and for a limited period afterwards;
- User Content for the session, history or sync period you select, plus short-lived buffers and backups needed for reliable delivery;
- payment, invoice, refund and tax records for the period required by applicable financial and tax law;
- security, access, metering and fraud logs for a period proportionate to investigation and legal needs;
- support and grievance records until resolution and for a reasonable limitation period;
- analytics and attribution identifiers according to configured cookie or provider retention periods.
Deletion removes or de-identifies data from active systems unless retention is required for law, security, fraud prevention, unresolved disputes or exercise of legal rights. Data may remain temporarily in encrypted backups until normal rotation. Third parties may retain data under their own legal duties.
8. Security
We use measures appropriate to the nature and risk of processing, including access controls, encryption in transit, credential protection, logging, environment separation, rate limiting, backups and incident procedures. Access is limited to personnel and processors with an operational need.
No system or transmission is completely secure. You are responsible for device security, updates, passwords and preventing unauthorised access. If a personal-data breach requires notice, we will notify affected people and competent authorities in the form and time required by law.
9. Cookies, analytics and advertising
9.1 Essential technologies
Authentication, security, checkout, preferences and load-management technologies are necessary to provide requested functions. Blocking them may prevent login, payment or other features.
9.2 Measurement and attribution
We use first-party visitor, session and attribution identifiers and may use Google Analytics to understand traffic, feature use and conversions. These technologies may collect IP-derived location, device data, referrer, campaign and interaction events.
9.3 Advertising technology
Meta Pixel and similar technologies may measure advertising performance and create or match audiences where enabled. The provider may receive browser, device, event and page data and process it under its own policy.
You can limit cookies through browser or device controls and advertising choices offered by the relevant provider. Where law requires consent before placing a non-essential technology, we will request it. Browser deletion or blocking may reset your choices and attribution.
10. Your privacy rights
Subject to applicable law and its commencement provisions, you may have the right to:
- obtain a summary of personal data being processed and information about processing;
- correct, complete or update inaccurate personal data;
- request erasure when retention is no longer required;
- withdraw consent and unsubscribe from marketing communications;
- raise a grievance and, where available, approach the Data Protection Board of India or another competent authority;
- nominate another person to exercise applicable rights in the event of death or incapacity.
Send a request from your registered email to contact@ghostai.one. We may verify identity, ask for details needed to locate the data and refuse or limit a request where law permits. We will respond within the period required by applicable law.
11. Children
The Service is intended only for people aged 18 or older. We do not knowingly offer accounts to children or seek children’s personal data. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.
12. Automated processing
GhostAI uses automated systems to generate content, route requests, transcribe speech, detect abuse, measure usage and prevent fraud. AI output assists you and is not a decision by Belova Tech about your employment, education, credit, insurance or legal rights. Payment and security providers may independently use automated fraud controls under their own policies.
13. Third-party links and platforms
Links, integrations, sign-in services, payment pages and third-party platforms are governed by their own notices. Belova Tech does not control their independent processing. Review their terms before submitting personal data.
14. Changes to this Policy
We may update this Policy to reflect product, provider, security or legal changes. We will publish the new effective date and give additional notice of material changes where required. If a new purpose requires fresh consent, we will request it before processing on that basis.
15. Contact and grievances
Data fiduciary: Belova Tech Private Limited, India
Product: GhostAI · ghostai.one
Privacy requests: contact@ghostai.one
Grievance Officer: support@ghostai.one
Support: support@ghostai.one
Please include your registered email, the nature of the request and enough information to investigate. We aim to acknowledge consumer grievances within 48 hours and resolve them within one month.