Last updated: July 2026
GhostTyper has no servers, no analytics endpoint, and no telemetry system. There is no backend. The extension runs entirely inside your browser.
When GhostTyper fetches a suggestion, it sends the text before your cursor (the "context prefix") directly from your browser to the AI provider you have configured in Settings. That request goes browser → provider. It does not pass through any GhostTyper-controlled server.
GhostTyper never reads or sends text from:
input[type=password] — password fieldsautocomplete set to a credit-card attribute (cc-number, cc-csc, cc-exp, cc-name, cc-type, etc.)type=hidden)name or id matches common credit-card patternsThis exclusion is enforced in the content script before any network call is made — it is not configurable and cannot be bypassed by settings.
Settings (provider choice, API key, site list, delay) are stored in chrome.storage.local — your browser, your device. They are never uploaded or synced by GhostTyper.
If you add an API key, it is stored locally and included only in requests to your chosen provider. It is never logged, transmitted to a third party, or stored outside your browser.
You can block GhostTyper on specific domains via Settings. On blocked domains, no text is ever read or sent.
None. GhostTyper collects no usage statistics, error reports, or identifiers of any kind.
GhostTyper is MIT-licensed. You can read every line of code at github.com/chirag127/ghosttyper-bs-ext.
Questions? Open a GitHub issue or see the contact page.