Privacy Policy

Your identity is the whole point. We protect it.

This policy explains what personal data Ghosted collects, why, and the rights you have over it under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it. Ghosted ("we", "us") is the Data Fiduciary for your personal data.

Last updated: 2 October 2026

The short version

  • Your posts are anonymous by default. Other users and companies see a random handle, not your name or email.
  • We collect only what we need to run the service and keep it safe.
  • We never sell your personal data, and we never share your identity with employers.
  • You can access, correct or delete your data, and withdraw consent, at any time.

1. Data we collect

Data you give us:

  • Account details: your full name, email address and password. Passwords are stored only in hashed form, and your name is encrypted at rest and never shown unless you choose to reveal it.
  • Profile choices: your generated handle, chosen avatar, and any optional details you decide to show publicly, such as name, role, experience, city or LinkedIn URL.
  • Content: stories, ratings, salary ranges, comments and reactions you post.
  • Messages you send us, such as support requests, reports and grievances.

Data collected automatically:

  • Technical data: IP address, device and browser type, and log records of access, used for security and abuse prevention.
  • Sign-in records: for each device you are signed in on, its type (phone, tablet or computer), browser, operating system, an approximate city-level location derived from your network's public IP address (looked up through our hosting provider or the geolocation service ipwho.is), a masked form of that IP address with its last half hidden (for example 49.36.x.x; the full address is never stored), a random device identifier kept in a cookie so one browser shows up once instead of once per sign-in (only a keyed hash of it is stored), and when it signed in and was last active. We show these to you in Settings → Security and in the security email sent for each new sign-in, and delete a record as soon as that device is signed out.
  • Usage data: pages viewed and features used, in aggregated form, to improve the service.
  • Feedback you send us: what you write, the part of the app it's about, an optional rating, and for bug reports, if you leave the box ticked, your browser, screen size, theme and the page you were on (never your IP address). Only the Ghosted team reads it.

We do not ask for, and ask you not to post, sensitive information such as financial account details, health information, government ID numbers or caste, religion or other personal characteristics.

If you verify as a company representative, we send a code to your work email and keep only its domain (never the address), the company, and when you were verified or revoked. We record which stories about that company you opened, to show authors a count (never who), and keep what you post as a representative. To protect candidates, representatives cannot see who wrote about their company.

2. Why we use it

We process personal data only for the purposes described below, on the basis of your consent or for legitimate uses permitted under Section 7 of the DPDP Act:

  • To create and secure your account and let you log in.
  • To publish your content under your anonymous handle, or with the details you choose to reveal.
  • To calculate company Flag Scores and show aggregated salary and hiring data.
  • To detect and prevent spam, fraud, abuse and fake reviews.
  • To respond to your requests, reports and grievances.
  • To comply with Indian law, court orders and lawful requests from government authorities.

3. How anonymity works

Your email address and any details you have not chosen to reveal are never shown to other users or to companies. Employers cannot pay us to learn who wrote a review.

Anonymity has limits you should know about. What you write can identify you: a very specific timeline, team name or event may be recognisable to your interviewer. We may also be legally required to disclose information to law enforcement or a court under a valid order issued under Indian law. Where the law allows, we will tell you before we do.

4. Who we share it with

  • Service providers who process data on our behalf, such as cloud hosting, email delivery and security, under contracts that require them to protect it and use it only for our instructions.
  • Razorpay, only if you choose to donate: it processes the payment (UPI, card, netbanking or wallet) directly, so we never see or store your card or bank details. We keep the amount, the date, the Razorpay order and payment references, your optional note, and whether you asked to appear on the thank-you wall.
  • Authorities, where required by law, a court order or a lawful direction under the Information Technology Act, 2000 or other applicable law.
  • A successor entity, if Ghosted is merged or acquired, subject to this policy.

We do not sell personal data or share it with employers, recruiters or advertisers.

5. How long we keep it

We keep account data for as long as your account is active. If you delete your account, we erase your personal data within 30 days, except where we must keep it longer to meet a legal obligation, for example security logs and records we are required to retain under the DPDP Rules, 2025 and the Intermediary Rules, 2021.

Posts you have published may remain on the platform in anonymised form after deletion, with no link back to you, unless you delete them first.

6. Your rights

As a Data Principal under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how we process it.
  • Correct, complete or update inaccurate or incomplete data.
  • Erase your personal data, subject to legal retention requirements.
  • Withdraw your consent at any time. This will not affect processing already carried out, but we may no longer be able to provide the service.
  • Nominate another person to exercise your rights in the event of your death or incapacity.
  • Seek grievance redressal from us, and then complain to the Data Protection Board of India.

Most of this can be done from your account settings. You can also use Feedback & Support in the app or contact the Privacy team. We may ask you to verify your identity before acting on a request.

Contact the Privacy team

7. Children

Ghosted is only for people aged 18 and over. We do not knowingly process the personal data of children as defined by the DPDP Act. If we learn that an account belongs to someone under 18, we will delete it.

8. Security and breaches

We use reasonable security safeguards to protect personal data, including encryption in transit, hashed passwords, AES-256 encryption of names and other identifying details at rest, strict access controls, rate limiting and monitoring. Our code is open source at https://github.com/CosmicShreyas/Ghosted, so these safeguards can be independently checked.

If a personal data breach occurs, we will inform affected users and the Data Protection Board of India as required by the DPDP Act and the DPDP Rules, 2025, explaining what happened, the likely impact and the steps we are taking.

9. Cookies

We use essential cookies to keep you logged in and secure, and privacy-friendly analytics to understand overall usage. We do not use third-party advertising or cross-site tracking cookies.

On your first visit we ask for your choice: Accept all (essential cookies plus analytics), Necessary only, or Decline (no optional cookies; essential ones remain, because signing in can't work without them). Your choice is remembered for one year in your browser and you can change it at any time from “Cookie settings” at the bottom of every page. Withdrawing consent is as easy as giving it, and doesn't affect anything you've already done on Ghosted.

10. Where data is stored

Your data may be processed on servers located in or outside India. Any transfer outside India is made only in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government.

11. Grievances and privacy requests

Ghosted is currently in pre-launch testing. Before public launch, we will appoint a Grievance Officer and publish that person's name, monitored contact details, and the complaint mechanism here, as required by Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

During testing, use Feedback & Support in the app or the monitored contacts below for privacy requests, content complaints, or account concerns. These temporary routes do not replace the statutory grievance mechanism required for a public launch.

Send a privacy request

Submit a grievance

Once launched, complaints will be acknowledged within 24 hours and resolved within the period required by applicable law. Eligible decisions may be appealed to the Grievance Appellate Committee. Rights under the DPDP Act may be pursued through the statutory process when that framework applies.

12. Changes to this policy

We may update this policy from time to time. If the changes are significant, we will notify you by email or on the site before they take effect. The date at the top shows when it was last updated.