# GHAN privacy policy

> GHAN processes behavioural counters and install-fraud signals. It does not process file contents, window titles, clipboard data, raw hardware identifiers or any directly identifying field, and the SDK emits nothing at all until the host application reports consent.

Source: https://ghan.io/privacy/  
Published: 2026-09-22 · Updated: 2026-09-22  
Publisher: GHAN — the audited cross-promotion network for desktop apps (https://ghan.io)

---

**Effective 22 September 2026.** GHAN is operated by the entity named on the [contact page](/contact/). Questions: `hello@ghan.io`.

## Who this covers

Two different groups, with different relationships to GHAN:

1. **Member apps and their contacts** — the developers who register applications. GHAN is a controller for this data.
2. **End users of member apps** — people who use software containing the GHAN SDK. The member app is the controller; GHAN is a processor acting on its instructions. See the [DPA](/dpa/).

## What is processed

### From member apps

Application name, bundle identifier, platform, domain, download URL, contact email, code-signing status, malware scan results, payment and payout details held by Stripe, and the full ledger and event history of the account.

### From end users of member apps, after consent

- Session start and end timestamps
- Coarse feature counters defined by the member app
- Whether a rendered card was dismissed

### From end users of member apps, at install claim, as a fraud signal

- Virtual machine and hypervisor indicators
- Operating-system install age
- A **salted** hardware hash — the raw identifier is never transmitted or stored
- Clock skew against the server
- Country and autonomous system of the claiming IP, resolved from a local offline database

## What is never processed

File names, file contents, file paths, window titles, clipboard contents, keystrokes, screen contents, raw hardware identifiers, MAC addresses, device serial numbers, advertising identifiers, cross-application identity, browsing history, or anything outside the host application.

## Legal bases

| Data | Basis |
|---|---|
| Member app and contact data | Performance of a contract |
| Install-fraud signals | Legitimate interest in preventing payment fraud |
| Behavioural counters | Consent, collected by the member app and passed to the SDK |
| Ledger and event records | Legal obligation and legitimate interest in maintaining auditable financial records |

## Retention

| Data | Retained |
|---|---|
| Event chains and signatures | As long as the ledger line they justify |
| Behavioural counters | Aggregated after 90 days |
| Device fraud signals | 180 days, then discarded |
| Member account data | Duration of the account plus statutory retention |

## Sharing

- **Stripe** — payments, payouts and identity verification.
- **Supabase** — database hosting within the EU.
- **VirusTotal** — binary hashes submitted for the malware gate. Binaries, not user data.
- No advertising networks, no data brokers, no analytics resale. Ever.

## Rights

Access, rectification, erasure, restriction, portability and objection. For end users of member applications, exercise these with the member app, which is the controller; GHAN will assist that app as its processor. Contact `hello@ghan.io`.

## Transfers

Primary processing is in the EU. Where a processor operates outside it, transfers rely on standard contractual clauses.

## Changes

Material changes are announced in the [changelog](/changelog/) and its [RSS feed](/feed.xml) before they take effect.

## Questions people ask about this

### Does GHAN track individual users?

No. GHAN's attribution is deterministic - a single-use signed token rather than an identity - which means the system does not need to recognise a person and is not built to. The device signals attached to an install claim exist to kill fraudulent chains and are deliberately worse at identifying a person than the fingerprinting GHAN refuses to perform.

### What is the legal basis for processing?

For member apps and their contacts, performance of a contract. For install-fraud signals, legitimate interest in preventing payment fraud, which is a narrow and well-established basis. For behavioural telemetry, the consent the host application collects and passes to the SDK, and nothing is emitted before it is true.

### How long is data retained?

Event chains and their signatures are retained for as long as the ledger line they justify, because an append-only ledger whose evidence had been deleted would not be auditable. Behavioural counters are aggregated after 90 days. Device signals are retained for 180 days for fraud investigation and then discarded.

