GHAN— by singular Get started

GHAN privacy policy

GHAN processes behavioural counters and install-fraud signals. It does not process file contents, window titles, clipboard data, raw hardware identifiers or any directly identifying field, and the SDK emits nothing at all until the host application reports consent.

Effective 22 September 2026. GHAN is operated by the entity named on the contact page. Questions: [email protected].

Who this covers

Two different groups, with different relationships to GHAN:

  1. Member apps and their contacts — the developers who register applications. GHAN is a controller for this data.
  2. End users of member apps — people who use software containing the GHAN SDK. The member app is the controller; GHAN is a processor acting on its instructions. See the DPA.

What is processed

From member apps

Application name, bundle identifier, platform, domain, download URL, contact email, code-signing status, malware scan results, payment and payout details held by Stripe, and the full ledger and event history of the account.

  • Session start and end timestamps
  • Coarse feature counters defined by the member app
  • Whether a rendered card was dismissed

From end users of member apps, at install claim, as a fraud signal

  • Virtual machine and hypervisor indicators
  • Operating-system install age
  • A salted hardware hash — the raw identifier is never transmitted or stored
  • Clock skew against the server
  • Country and autonomous system of the claiming IP, resolved from a local offline database

What is never processed

File names, file contents, file paths, window titles, clipboard contents, keystrokes, screen contents, raw hardware identifiers, MAC addresses, device serial numbers, advertising identifiers, cross-application identity, browsing history, or anything outside the host application.

DataBasis
Member app and contact dataPerformance of a contract
Install-fraud signalsLegitimate interest in preventing payment fraud
Behavioural countersConsent, collected by the member app and passed to the SDK
Ledger and event recordsLegal obligation and legitimate interest in maintaining auditable financial records

Retention

DataRetained
Event chains and signaturesAs long as the ledger line they justify
Behavioural countersAggregated after 90 days
Device fraud signals180 days, then discarded
Member account dataDuration of the account plus statutory retention

Sharing

  • Stripe — payments, payouts and identity verification.
  • Supabase — database hosting within the EU.
  • VirusTotal — binary hashes submitted for the malware gate. Binaries, not user data.
  • No advertising networks, no data brokers, no analytics resale. Ever.

Rights

Access, rectification, erasure, restriction, portability and objection. For end users of member applications, exercise these with the member app, which is the controller; GHAN will assist that app as its processor. Contact [email protected].

Transfers

Primary processing is in the EU. Where a processor operates outside it, transfers rely on standard contractual clauses.

Changes

Material changes are announced in the changelog and its RSS feed before they take effect.

Questions people ask about this

Does GHAN track individual users?

No. GHAN's attribution is deterministic - a single-use signed token rather than an identity - which means the system does not need to recognise a person and is not built to. The device signals attached to an install claim exist to kill fraudulent chains and are deliberately worse at identifying a person than the fingerprinting GHAN refuses to perform.

What is the legal basis for processing?

For member apps and their contacts, performance of a contract. For install-fraud signals, legitimate interest in preventing payment fraud, which is a narrow and well-established basis. For behavioural telemetry, the consent the host application collects and passes to the SDK, and nothing is emitted before it is true.

How long is data retained?

Event chains and their signatures are retained for as long as the ledger line they justify, because an append-only ledger whose evidence had been deleted would not be auditable. Behavioural counters are aggregated after 90 days. Device signals are retained for 180 days for fraud investigation and then discarded.

Machine-readable versions of this page: markdown · llms.txt · llms-full.txt · OpenAPI · AI catalog