1. Overview
This Privacy Policy describes how Aldershot ("we", "us", or "our") collects, uses, and protects information in connection with GhostWriter Review Responder ("GhostWriter", "the extension", or "the Service"), accessible at ghostreview.net.
We are committed to protecting your privacy. GhostWriter is designed to collect the absolute minimum data necessary to operate. We do not sell your data, we do not advertise to you, and we do not share your personal information with third parties except as described in this policy.
Plain English summary: We only store your email address to verify your subscription. We never read, store, or share the content of your reviews or replies. You are always in control.
2. Information We Collect
We collect only the following information:
| Data | Why we collect it | Where it's stored |
|---|---|---|
| Email address | To verify your active subscription before generating a reply | Our secure Supabase database |
| Subscription status | To determine whether your plan is active, past due, or inactive | Our secure Supabase database |
| Brand tone preference | To generate replies in your chosen style (Professional, Friendly, etc.) | Our secure Supabase database |
| Payment information | To process your subscription | Stripe — we never see or store card details |
We do NOT collect: the content of any customer reviews, the content of any AI-generated replies, your browsing history, any data from pages you visit other than Google Business and Yelp review management pages, or any personally identifiable information beyond your email address.
3. How the Chrome Extension Works
The GhostWriter Chrome extension operates as follows:
- When you visit a Google Business or Yelp review page, the extension injects a "Draft Smart Reply" button next to each review
- When you click the button, the extension reads the text of that specific review from the page and sends it — along with your saved email address — to our secure backend API hosted on Vercel
- Our backend verifies your subscription status, then forwards the review text to Anthropic's Claude AI to generate a reply
- The generated reply is returned to your browser and inserted into the platform's reply text box
- Review text is processed in real time and is never stored, logged, or retained by us after the reply is generated
Your email address is stored locally on your device using Chrome's chrome.storage.local API and is sent to our backend only when you click the "Draft Smart Reply" button.
4. How We Use Your Information
We use the information we collect for the following purposes only:
- To verify your active subscription before processing a reply request
- To generate AI-powered review replies tailored to your brand tone
- To manage your account and subscription via Stripe
- To respond to support requests you send to us directly
- To send transactional emails related to your subscription (billing, trial expiry)
We do not use your information for advertising, analytics profiling, or any purpose not listed above.
5. Data Sharing and Third Parties
We share data with the following third-party services only to operate the Service:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing and subscription management | Email address, payment information |
| Anthropic | AI reply generation via Claude API | Review text (not linked to your identity) |
| Supabase | Secure database hosting for account records | Email, subscription status, brand tone |
| Vercel | Serverless API hosting | Processes requests in transit — no persistent storage |
We do not sell, rent, trade, or otherwise transfer your personal information to any other party for any purpose.
6. Data Retention
We retain your account data (email, subscription status, brand tone preference) for as long as your account is active. If you cancel your subscription and request account deletion, we will permanently delete your data within 30 days.
Review text sent to generate replies is processed in real time and is not stored or retained by us at any point.
7. Your Rights
You have the following rights regarding your personal data:
- Access: You may request a copy of the data we hold about you
- Correction: You may request that we correct inaccurate data
- Deletion: You may request that we delete your account and all associated data
- Portability: You may request your data in a portable format
- Objection: You may object to any processing of your data
To exercise any of these rights, email us at privacy@ghostreview.net. We will respond within 30 days.
8. Security
We take reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, or misuse. These include:
- All data transmitted between your browser and our servers is encrypted via HTTPS/TLS
- Database access is protected by Row Level Security (RLS) and service-role key authentication
- We use Stripe for all payment processing — we never see or store your credit card details
- API keys and credentials are stored as environment variables and never exposed in code
No method of transmission over the internet is 100% secure. If you believe your data has been compromised, contact us immediately at privacy@ghostreview.net.
9. Children's Privacy
GhostWriter is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
10. Chrome Extension Permissions
GhostWriter requests the following Chrome permissions and uses them solely as described:
| Permission | Purpose |
|---|---|
| storage | Stores your account email locally on your device using chrome.storage.local so you don't have to re-enter it each session |
| business.google.com | Injects the reply button into Google Business review pages and reads review text when you click the button |
| yelp.com | Injects the reply button into Yelp review pages and reads review text when you click the button |
The extension does not access any other websites, does not track your browsing activity, and does not run on any pages other than Google Business and Yelp review management pages.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you by email at the address associated with your account. Continued use of GhostWriter after changes are posted constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: privacy@ghostreview.net
- Support: support@ghostreview.net
- Website: ghostreview.net
- Company: Aldershot