GHAN data processing agreement
Where GHAN processes data about the end users of a member application, the member application is the controller and GHAN is the processor. This page sets out what is processed, on what instructions, with which subprocessors, and under what security measures.
Effective 22 September 2026. Incorporated into the terms of service.
1. Roles
The member application is the controller for its end users. GHAN is the processor, acting only on documented instructions, which are these terms plus the configuration the member sets through the SDK and the API.
For member account data — the developer's own contact and billing details — GHAN is the controller. See the privacy policy.
2. Subject matter and duration
Processing of end-user data for cross-promotion placement, deterministic attribution, install-fraud prevention and settlement, for the duration of the membership plus the retention periods below.
3. Categories of data
| Category | Fields | Purpose |
|---|---|---|
| Behavioural counters | Session start and end, coarse feature counts, card dismissals | Determining whether a referred install survived 48 hours |
| Fraud signals | VM indicators, OS install age, salted hardware hash, clock skew, IP country and ASN | Preventing payment fraud |
| Attribution tokens | Token id, nonce, issue and expiry times, use timestamp | Deterministic attribution |
No special-category data is processed. No directly identifying data is processed.
4. Instructions and limits
GHAN will not process end-user data for any purpose other than those above, will not sell or share it with advertising networks or data brokers, and will not attempt to re-identify any individual from the fraud signals.
5. Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting | EU |
| Stripe | Payments, payouts, identity | EU / US under SCCs |
| Cloudflare | Content delivery, edge security | Global |
| Resend | Transactional email | EU / US under SCCs |
| VirusTotal | Binary malware scanning — hashes only, no end-user data | US |
New subprocessors are announced in the changelog before they take effect, giving controllers an opportunity to object.
6. Security measures
- TLS in transit, with certificate verification against a pinned root rather than disabled verification
- Row-level security on every table; public API roles revoked
- Append-only ledger enforced by database trigger
- ed25519 signing with private keys generated and retained on end-user devices only
- Secrets in environment variables; no credentials in source control
- Tests covering every fraud rule and every ledger mutation before merge
7. Confidentiality and personnel
Access is limited to personnel who require it, under confidentiality obligations.
8. Assistance
GHAN will assist the controller with data subject requests, data protection impact assessments and regulator enquiries, within a reasonable time and at no charge for ordinary volumes.
9. Breach notification
Without undue delay and within 72 hours of becoming aware: what is known, what is not yet known, the measures taken and the measures proposed. Notification is not delayed pending a complete investigation.
10. Deletion and return
On termination, end-user data is deleted within 90 days, except event chains and signatures which are retained for as long as the ledger lines they justify. An append-only ledger whose supporting evidence had been deleted would not be auditable, which is the property the whole network is sold on.
11. Audit
GHAN will provide the information necessary to demonstrate compliance and will allow audits by the controller or an appointed auditor, on reasonable notice, no more than once per year absent a specific concern.
12. Transfers
Standard contractual clauses apply where a subprocessor operates outside the EEA.
Questions people ask about this
Do I need to sign anything?
These terms are incorporated into the terms of service and apply automatically when you register an application, so no separate signature is required. A countersigned copy on your own paper is available on request to [email protected] for procurement processes that need one.
Who are the subprocessors?
Supabase for database hosting in the EU, Stripe for payments and payout identity, Cloudflare for content delivery and edge security, and Resend for transactional email. VirusTotal receives binary hashes for the malware gate and no end-user data. New subprocessors are announced in the changelog before they take effect.
What happens in a breach?
GHAN notifies affected controllers without undue delay and in any event within 72 hours of becoming aware, with what is known, what is not yet known, the measures taken and the measures proposed. Notification is not delayed to complete an investigation.
Machine-readable versions of this page: markdown · llms.txt · llms-full.txt · OpenAPI · AI catalog