1. Overview
Ghost Messenger is a private messaging and calling application operated by PT Money Industrial Factory, a company incorporated in Indonesia and located at Benoa Square Building, Lantai 2, Unit No. 1-4 (2/A) & 23-26 (2/B), Jl. Bypass Ngurah Rai No. 21A, Kabupaten Badung 80361, Bali, Indonesia ("Ghost Messenger", "we", "us", or "our"). PT Money Industrial Factory is the controller responsible for the limited data processed through the service. This Privacy Policy explains what information we do and do not process when you use our mobile applications, and the choices and rights you have. Ghost Messenger is available to users worldwide.
Our core principle is data minimisation. Your messages and calls are end-to-end encrypted, which means we cannot read their content. We do not require your phone number, email address, or real name, and we do not run advertising or third-party tracking. By using the app, you agree to the practices described in this policy.
2. Information We Do Not Collect
We do not require your phone number, email address, or real name to create an account. We do not upload your device address book to our servers. We cannot read the content of your messages or calls, which are end-to-end encrypted on your device. We do not use advertising identifiers, and we do not embed third-party advertising or analytics tools that profile you. We do not collect your location unless you choose to share it inside a specific message.
3. Information We Process To Provide The Service
To route encrypted messages and connect calls, our relay processes a limited amount of technical information:
- Account keys. A public identity key, signed pre-keys, and a routing identifier, all generated on your device, are stored on our relay so that other people can establish an encrypted session with you and so that messages can be delivered to your device.
- Optional profile. If you choose to set a display name or make your Ghost ID discoverable, that information is stored until you change or remove it.
- Encrypted messages in transit. Messages are held only until they are delivered to the recipient, then removed from our servers. We cannot decrypt them.
- Connection data. Your IP address and similar connection details are processed transiently to route traffic. We do not use them to profile you and do not retain them as a history of your activity.
- Push token. To deliver notifications, we register a push token with Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM).
- A last-connected timestamp. The relay records when your account was last online, only to decide whether to deliver a message immediately or hold it briefly for delivery. It records when you were connected, never what you did.
- Encrypted recovery backup. So that a lost phone does not mean a lost account, the relay stores a backup of your account key and contact list. It is sealed on your device under a key derived from your PIN and your recovery code before it is uploaded. We never receive the recovery code and cannot decrypt this backup; only you, holding the code and the PIN, can.
- Aggregate service statistics. We keep operational totals such as registrations per day, the split between Android and iOS, and a per-city count of connections. The city is derived momentarily from the connection address, which is then discarded. These are totals only; none of them is linked to your account or can be traced back to you.
4. Optional Contact Discovery
Contact discovery is optional and turned off by default. If you choose to enable it, Ghost Messenger can help you find contacts who already use the app, without ever revealing anyone’s phone number or email address to our servers.
It works through an oblivious cryptographic protocol (an OPRF). Your phone number or email is transformed on your device into an irreversible value before it ever leaves the device, and the matching against your contacts is completed on your device. Our relay only stores and compares these irreversible values; it never receives, and cannot recover, a real phone number or email address, not even a hashed one. Your device address book is read only to perform this local matching and is never uploaded. You can turn discovery off, or make yourself non-discoverable, at any time in the app.
5. Optional GHOST Wallet
The app includes an optional wallet for holding a balance and sending money to other users. The wallet is a separate, custodial service: if you never open it, no wallet account exists for you and nothing in this section applies.
If you choose to open a wallet, we process the following, in a wallet system kept separate from the messenger, with its own database and credentials and no shared identifiers:
- A wallet account key generated on your device, which is how you sign in to the wallet. It is distinct from your messenger identity.
- Your wallet balance and transaction records, kept in a ledger on our servers. This is what makes your money survive a lost or wiped phone.
- Details you provide to deposit or withdraw, such as a bank account, and records of any dispute you raise.
- An operational audit log of money movements, kept for integrity and fraud prevention.
Unlike your messages, wallet data is not end-to-end encrypted: a custodial ledger requires that our systems can see wallet balances and wallet activity. We protect it with encryption in transit and at rest, signature-based authentication, and operator review of money movements, and we do not use it for advertising, do not sell it, and do not link it to your chats, contacts, or calls. Financial records are retained as long as needed for accounting, dispute resolution, and our legal obligations.
6. Permissions You Control
The app requests only the permissions needed for the features you use, and asks for each one at the moment a feature needs it. You can grant or revoke any of them in your device settings.
- Camera, to scan contact QR codes, take photos and videos for your chats, and for video calls.
- Microphone, for voice and video calls and voice messages.
- Contacts, only if you enable contact discovery, and only to match on your device (your address book is never uploaded).
- Photos, to attach media to a chat or to save media you receive.
- Location, only if you choose to share your location inside a specific message.
- Notifications, to alert you to new messages and incoming calls.
- Face ID, biometrics, or your device passcode, handled entirely by your device to unlock the app or protect locked chats; the credential never reaches us.
7. How We Use Information
We use the limited information described above solely to operate Ghost Messenger: to deliver your encrypted messages and calls, to send notifications, and to keep the service secure and reliable. We do not use it for advertising, we do not build a profile of you, and we do not sell or rent it.
8. Legal Bases (EEA / UK Users)
If you are in the European Economic Area or the United Kingdom, we process the limited data above on the basis of our legitimate interests in operating a secure messaging service and performing our contract with you to deliver the app’s functionality. Where required, we rely on your consent, which you may withdraw at any time by discontinuing use of the service.
9. Third-Party Services
A small number of services help deliver the app and receive only what is strictly necessary:
- Apple (APNs) and Google (FCM) deliver push notifications. They receive a device push token and a wake signal, not your message content or your contacts.
- Our hosting and relay infrastructure transmits encrypted traffic between devices.
These providers process data under their own privacy policies. We do not share your information with advertisers or data brokers.
10. Data Retention
We do not keep a history of your messages or calls. Encrypted messages are removed from our relay once they are delivered. Account keys and any optional profile information remain only while your account exists; deleting your account removes them. The encrypted recovery backup is deliberately retained even after a wipe, because its purpose is to restore an account after a lost or wiped device; it remains sealed under keys we never hold, and you can ask us to remove it using the contact details in section 16. Wallet financial records, where a wallet exists, are retained as described in section 5. The large majority of your data, including your message history, exists only on your own device under your control.
11. Security
Messages and calls are end-to-end encrypted using a modern key-exchange and ratchet protocol. Data stored on your device is held in an encrypted SQLCipher (AES-256) database whose key is protected by your device hardware keystore (StrongBox or the Trusted Execution Environment). The app also offers a per-conversation lock and a Panic PIN that immediately and permanently erases the encrypted database on your device. No method of transmission or storage is perfectly secure, but we design the service to minimise what could ever be exposed.
12. Your Rights and Choices
Ghost Messenger is available worldwide, and we honor the privacy rights available where you live. Depending on your location (for example, the EEA and the UK under the GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing.
Because we hold almost no personal data and cannot read your content, most of your information exists only on your device and is within your direct control. You may delete your account and wipe your local data from within the app at any time, or use Panic Mode for an instant on-device wipe. We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising. To exercise a right or ask a question, contact us using the details in section 16.
13. International Data Transfers
We operate globally. The limited, encrypted technical data needed to route your messages may be processed on servers located outside your country, including in jurisdictions whose data-protection laws differ from your own. We minimise this data, and message and call content remains end-to-end encrypted at all times.
14. Children’s Privacy
Ghost Messenger is not directed to children. You must be at least 13 years old to use the app, or older where your country sets a higher minimum age for consent to online services (for example, up to 16 in parts of the EEA). We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided us with data, please contact us and we will take appropriate steps.
15. Account and Data Deletion
You can delete your account and erase your local data directly within the app, and Panic Mode lets you wipe the on-device database instantly. For step-by-step instructions, see our Account Deletion page.
16. Changes and Contact
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, where appropriate, provide additional notice in the app.
If you have any questions about this policy, how your data is handled, or wish to exercise a privacy right, contact us at:
PT Money Industrial Factory
Benoa Square Building, Lantai 2, Unit No. 1-4 (2/A) & 23-26 (2/B), Jl. Bypass Ngurah Rai No. 21A, Kabupaten Badung 80361, Bali, Indonesia
Email: officemoneyindustrialfactory@gmail.com
See also our Account Deletion page.
