Privacy Policy
How GHOST AI TECHNOLOGIES collects, uses and protects information across this website and our applications.
Last updated: 17 September 2026
This policy applies to the website error.ae, and to applications published by GHOST AI TECHNOLOGIES (“Ghost”, “we”, “us”), a licensed establishment in Abu Dhabi, United Arab Emirates (Licence No. CN-6755606). We are the data controller for the processing described here.
1. Our approach
We design our products to collect as little personal data as possible. Where a feature can work with data kept on your device, we keep it there. We do not sell personal data and we do not use advertising networks or third-party tracking in our apps.
2. Website (error.ae)
- Hosting logs. Our website is served by Firebase Hosting (Google). Standard server logs, which may include your IP address, user agent and the pages requested, are retained by the hosting provider for security and operational purposes.
- Contact form. The contact form opens an email in your own mail application; nothing is stored on our servers until you choose to send it. Emails you send us are kept for as long as needed to handle your enquiry and for our business records.
- Cookies. This website does not set analytics or advertising cookies.
- Fonts. Typefaces are loaded from Google Fonts, which receives your IP address as part of the request.
3. Ghost VPN app
Ghost VPN is built so that we cannot see what you do online.
Data we process
- Device enrolment. When the app sets itself up it sends the selected server identifier and a public key generated on your device, together with an Apple App Attest assertion that proves the request comes from a genuine copy of the app. The matching private key is stored only in your device Keychain and is never transmitted.
- Lease records. Our control plane stores the public key, an assigned internal tunnel address, timestamps and lease expiry so the server knows which devices are permitted to connect. Leases expire automatically and are cleaned up.
- Server health. Servers report aggregate metrics (CPU, memory, disk, total tunnel bytes and recent-handshake counts) once a minute. These are totals for the server, not per user.
- Crash and diagnostic data. Only if you have enabled sharing with developers in iOS settings, Apple may provide us anonymised crash reports.
Data we do not collect
- No account, name, email address or phone number: the app has no sign-up.
- No browsing history, DNS query logs, connection destinations or content of traffic.
- No advertising identifiers, analytics SDKs or third-party trackers.
Legal basis and retention
We process enrolment and lease data because it is necessary to provide the service you request. Lease records are deleted when they expire or when you remove your profile. Aggregate server-health history is retained for operational monitoring.
4. Client projects
When we build software for clients, the client remains the controller of their users' data. Our processing is governed by the contract with that client. We apply the same minimisation and security principles described here.
5. Where data is stored
Our control plane and databases run on Google Cloud and Firebase in Middle East regions (currently Doha, Qatar). VPN servers are located in the country shown in the app for each location. Website hosting uses Google's global content-delivery network.
6. Sharing
We share data only with the infrastructure providers needed to run our services (Google Cloud / Firebase, our VPN server hosting providers and Apple for app distribution and attestation), each acting on our instructions, or where required by applicable law. We do not sell or rent personal data.
7. Security
We use encrypted transport everywhere, device attestation, per-device keys, hardened servers with firewall isolation, secret management and access restricted to authorised personnel. No system is perfectly secure; if we become aware of a breach affecting you we will notify you as required by law.
8. Your rights
Subject to applicable law, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), you may request access to, correction of, or deletion of personal data we hold about you, and object to or restrict certain processing. Because our apps do not hold accounts, some requests can be fulfilled directly by removing your profile in the app. To make a request, email m@error.ae. We respond within 30 days.
9. Children
Our products are not directed at children under 13 and we do not knowingly collect personal data from them.
10. Changes
We will post any changes to this policy on this page and update the date at the top. Significant changes affecting our apps will also be noted in the app's release notes.
11. Contact
GHOST AI TECHNOLOGIES
Abu Dhabi, United Arab Emirates
Email: m@error.ae
Phone: +971 52 222 2404