Privacy
This page covers what Ghostwriter sends to the model and the photo libraries, what it never sends, and what it keeps in your database.
What is sent, and where
Nothing is sent anywhere until someone in the panel asks for it: by starting a piece, writing a guide, asking for kinds or ideas, or using the image button. Ghostwriter sends no analytics and doesn't phone home.
To the writing provider (Anthropic, OpenAI or Google, whichever is chosen, on your own account, or the gateway you set):
| When | What is sent |
|---|---|
| Writing or editing a piece | The voice guide, the kind's brief, guidance and checklist, the answers to the brief, the conversation, the form's fields (names, labels, helper text, hints, options), and up to six example records as YAML |
| Filling in a brief | The kind's questions, a working title and notes |
| Writing the voice guide | The text of up to 24 published records |
| Changing the voice guide | The guide and your request |
| Suggesting or learning kinds | Titles and openings of up to 60 published records; for learning, the chosen examples in full |
| The content plan | Titles and the first lines of up to 150 records per resource (published or not), the voice guide, the kinds and the plan |
| The image style guide | Small copies of up to ten images per resource |
| Finding photos | The text of the block and page, small copies of images already used in that place, and thumbnails of the photos found |
| Making an image | The same text and images, your direction, and any image of your own you add (to the image provider) |
Records are read through the resource's own query, so only what the resource would list is ever read, scoped to the current tenant.
To the photo libraries: search words go to Openverse, and to Unsplash, Pexels or Pixabay when their keys are set. Choosing a photo downloads it and, for Unsplash, tells Unsplash it was used. Only the search words are sent, never record content.
What is not sent
- API keys, except each to its own service
- records beyond the samples listed above
- user details: names and email addresses stay in your app. A shared conversation's "Started by" names are shown in the panel, not sent.
Each provider's terms
How long a provider keeps what it's sent, and whether it may train on it, depends on its terms and your account. On paid API plans, Anthropic, OpenAI and Google don't train on API data by default. Gemini's free tier is different: Google may use what's sent to improve its products. See Google (Gemini, and images).
What is kept, and where
Everything is kept in your database, in the ghostwriter_ tables (see Where things are kept):
- Conversations in
ghostwriter_sessions: the brief, every message with who sent it, the draft, and who started and last changed each piece. Delete rows from that table to clear them; nothing else depends on old ones. - Photo requests in
ghostwriter_states, with the user who made each one. Made images not yet used wait on thelocaldisk underghostwriter/imagesand are cleared after a day. - The guides, kinds and plan, in their own tables.
Logs hold retries and failures, with the provider and the error, never keys (see Logging).
API keys are read from the environment when they're needed. Ghostwriter never stores them, never shows them, and never sends them anywhere but the service they belong to.