Privacy Policy

Last updated: July 2026

Architecture — no backend

GhostTyper has no servers, no analytics endpoint, and no telemetry system. There is no backend. The extension runs entirely inside your browser.

What text is sent and where

When GhostTyper fetches a suggestion, it sends the text before your cursor (the "context prefix") directly from your browser to the AI provider you have configured in Settings. That request goes browser → provider. It does not pass through any GhostTyper-controlled server.

Sensitive fields — always excluded

GhostTyper never reads or sends text from:

This exclusion is enforced in the content script before any network call is made — it is not configurable and cannot be bypassed by settings.

Local storage

Settings (provider choice, API key, site list, delay) are stored in chrome.storage.local — your browser, your device. They are never uploaded or synced by GhostTyper.

API keys

If you add an API key, it is stored locally and included only in requests to your chosen provider. It is never logged, transmitted to a third party, or stored outside your browser.

Site allow/deny list

You can block GhostTyper on specific domains via Settings. On blocked domains, no text is ever read or sent.

Telemetry and analytics

None. GhostTyper collects no usage statistics, error reports, or identifiers of any kind.

Open source

GhostTyper is MIT-licensed. You can read every line of code at github.com/chirag127/ghosttyper-bs-ext.

Contact

Questions? Open a GitHub issue or see the contact page.