Privacy Policy
Last updated: July 12, 2026
This Privacy Policy explains how Questifier, LLC (“Ghosters”, “we”, “us”, or “our”) collects, uses, and protects information when you use the Ghosters website, relay service, and desktop client (together, the “Service”). We built Ghosters to collect as little personal data as possible.
The short version
- We use your email address only to sign you in and to contact you about your account. It is stored encrypted.
- We support passwordless sign-in (passkeys). We never see or store a password.
- Your live “ghost” is reconstructed from tiny, ephemeral game telemetry that is relayed between players and not stored.
- We use a single essential cookie to keep you signed in. No advertising, analytics, or cross-site tracking.
- We do not sell or rent your personal information.
Information we collect
Account information. When you create an account we collect the email address you provide and a username (which you may choose or which may be derived from your email). Your email address is encrypted at rest, and we keep a one-way keyed index of it so we can look up your account without storing it in plain text.
Authentication data. If you add a passkey, we store the passkey’s public key, credential identifier, signature counter, and authenticator transport hints. These cannot be used to sign in on your behalf. When you request an email sign-in link, we store only a hash of that one-time link, together with its purpose and a short expiry.
Security logs. To operate and protect the Service we record limited security events (for example, a sign-in or the addition of a passkey) together with the associated IP address and a timestamp.
Presence (ephemeral). When you choose to appear online to broadcast or view ghosts, we hold your username, the room you joined, and an optional game title/status in memory only. This information expires within about a minute of inactivity and is never written to disk.
Gameplay telemetry (ephemeral, relayed). To draw your ghost for other players in a room you join, the Service exchanges very small numeric game-state values (such as on-screen position, a level or area identifier, and animation flags). This telemetry is relayed between participants in real time and is not persistently stored by us.
Technical data. Like any internet service, we transiently process connection metadata (such as IP address and timestamps) to deliver, secure, and troubleshoot the Service.
What we do not collect. We do not collect passwords (there are none), payment information, precise geolocation, your contacts, or the contents of your games, ROMs, BIOS files, or save data.
How we use information, and our legal bases
- To provide the Service — create and operate your account, sign you in, and enable ghost broadcasting/viewing. (Legal basis: performance of a contract.)
- To send transactional email — one-time sign-in links. (Contract.)
- To secure the Service — authenticate requests, prevent abuse, rate-limit, and keep security logs. (Legitimate interests and, where applicable, legal obligation.)
- To comply with law and to establish, exercise, or defend legal claims. (Legal obligation / legitimate interests.)
Cookies
We use a single, strictly necessary session cookie to keep you signed in and to protect against cross-site request forgery. It is sealed (authenticated and expiring), HTTP-only, marked Secure, and set with SameSite=Lax. Because we use only this essential cookie — and no advertising, analytics, or cross-site tracking — no cookie-consent banner is required.
How we share information
We do not sell or rent your personal information. We share it only:
- With service providers (processors) acting on our behalf under confidentiality obligations — currently an email-delivery provider used solely to send your sign-in links.
- With other players, who can see your public username and your cosmetic ghost telemetry, but only within a room you choose to join. Your email address is never shared with other players.
- For legal reasons — when required by law, or to protect the rights, property, or safety of Ghosters, our users, or the public.
- In a business transfer — if the Service is ever transferred, subject to this Policy.
Data retention
We keep account information for as long as your account is active. One-time sign-in link records expire and are invalidated after use or after a short window (about 15 minutes). Security logs are retained for a limited period as needed for security and compliance. Presence and gameplay telemetry are ephemeral and are not stored. When you delete your account, we delete or anonymize associated personal data except where we must retain it to comply with law or resolve disputes.
How we protect information
Security is a core design goal. We encrypt data in transit (HTTPS/TLS and secure WebSockets) and encrypt sensitive fields such as your email address at rest using authenticated encryption (AES-256-GCM). Sign-in is passwordless and phishing-resistant (passkeys / WebAuthn), so there is no password to steal. Encryption keys are protected using operating-system key protection. No method of transmission or storage is 100% secure, but we work to protect your information and to minimize what we hold.
International users
The Service is operated from the United States. If you access it from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your country.
Your rights
EEA/UK (GDPR). You may request access to, correction of, or deletion of your personal data; restrict or object to certain processing; request portability; and withdraw consent where processing is based on consent. You may also lodge a complaint with your local supervisory authority.
California (CCPA/CPRA). You may request to know, delete, or correct personal information, and you may opt out of the “sale” or “sharing” of personal information — though we do not sell or share it. We will not discriminate against you for exercising these rights.
To exercise any right, email privacy@ghosters.net. To protect your account, we may verify your request using your account email.
Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are in the EEA or UK, you must be at least 16 (or the minimum age of digital consent in your country). If you believe a child has provided us personal information, contact us at privacy@ghosters.net and we will delete it.
Third-party services
The Service works alongside third-party software and platforms you choose to use — for example, your emulator, your game software, and (in the future) services such as Twitch or Discord. Those third parties are governed by their own terms and privacy policies, which we do not control.
Changes to this Policy
We may update this Policy from time to time. We will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you.
Contact us
For privacy questions or requests, contact privacy@ghosters.net. Questifier, LLC is the data controller for the personal data described here.
See also our Terms of Service.