GHAN— by singular Get started

GHAN data processing agreement

Where GHAN processes data about the end users of a member application, the member application is the controller and GHAN is the processor. This page sets out what is processed, on what instructions, with which subprocessors, and under what security measures.

Effective 22 September 2026. Incorporated into the terms of service.

1. Roles

The member application is the controller for its end users. GHAN is the processor, acting only on documented instructions, which are these terms plus the configuration the member sets through the SDK and the API.

For member account data — the developer's own contact and billing details — GHAN is the controller. See the privacy policy.

2. Subject matter and duration

Processing of end-user data for cross-promotion placement, deterministic attribution, install-fraud prevention and settlement, for the duration of the membership plus the retention periods below.

3. Categories of data

CategoryFieldsPurpose
Behavioural countersSession start and end, coarse feature counts, card dismissalsDetermining whether a referred install survived 48 hours
Fraud signalsVM indicators, OS install age, salted hardware hash, clock skew, IP country and ASNPreventing payment fraud
Attribution tokensToken id, nonce, issue and expiry times, use timestampDeterministic attribution

No special-category data is processed. No directly identifying data is processed.

4. Instructions and limits

GHAN will not process end-user data for any purpose other than those above, will not sell or share it with advertising networks or data brokers, and will not attempt to re-identify any individual from the fraud signals.

5. Subprocessors

SubprocessorPurposeLocation
SupabaseDatabase hostingEU
StripePayments, payouts, identityEU / US under SCCs
CloudflareContent delivery, edge securityGlobal
ResendTransactional emailEU / US under SCCs
VirusTotalBinary malware scanning — hashes only, no end-user dataUS

New subprocessors are announced in the changelog before they take effect, giving controllers an opportunity to object.

6. Security measures

  • TLS in transit, with certificate verification against a pinned root rather than disabled verification
  • Row-level security on every table; public API roles revoked
  • Append-only ledger enforced by database trigger
  • ed25519 signing with private keys generated and retained on end-user devices only
  • Secrets in environment variables; no credentials in source control
  • Tests covering every fraud rule and every ledger mutation before merge

7. Confidentiality and personnel

Access is limited to personnel who require it, under confidentiality obligations.

8. Assistance

GHAN will assist the controller with data subject requests, data protection impact assessments and regulator enquiries, within a reasonable time and at no charge for ordinary volumes.

9. Breach notification

Without undue delay and within 72 hours of becoming aware: what is known, what is not yet known, the measures taken and the measures proposed. Notification is not delayed pending a complete investigation.

10. Deletion and return

On termination, end-user data is deleted within 90 days, except event chains and signatures which are retained for as long as the ledger lines they justify. An append-only ledger whose supporting evidence had been deleted would not be auditable, which is the property the whole network is sold on.

11. Audit

GHAN will provide the information necessary to demonstrate compliance and will allow audits by the controller or an appointed auditor, on reasonable notice, no more than once per year absent a specific concern.

12. Transfers

Standard contractual clauses apply where a subprocessor operates outside the EEA.

Questions people ask about this

Do I need to sign anything?

These terms are incorporated into the terms of service and apply automatically when you register an application, so no separate signature is required. A countersigned copy on your own paper is available on request to [email protected] for procurement processes that need one.

Who are the subprocessors?

Supabase for database hosting in the EU, Stripe for payments and payout identity, Cloudflare for content delivery and edge security, and Resend for transactional email. VirusTotal receives binary hashes for the malware gate and no end-user data. New subprocessors are announced in the changelog before they take effect.

What happens in a breach?

GHAN notifies affected controllers without undue delay and in any event within 72 hours of becoming aware, with what is known, what is not yet known, the measures taken and the measures proposed. Notification is not delayed to complete an investigation.

Machine-readable versions of this page: markdown · llms.txt · llms-full.txt · OpenAPI · AI catalog