Privacy details | Updated August 22, 2026

How GhostReply Handles Your Data

GhostReply reads iMessage history on your Mac, stores its working profile locally, and sends only the context needed for a profile or reply through its Cloudflare backend for hosted AI processing.

The short version

GhostReply needs access to private information to do its job. It reads the Messages database on your Mac so it can understand a conversation and learn how you write. The app keeps its configuration, reply profile, and usage statistics in your home folder. When it needs an AI answer, it sends relevant conversation material through GhostReply's Cloudflare backend to Cloudflare Workers AI. You do not provide an AI API key.

GhostReply also uses network services for the free trial, license checks, software delivery, checkout, and basic product analytics. Those services receive identifiers and event information. Message text is sent only as part of hosted profile and reply requests and is not written to GhostReply's D1 license, trial, inference, or analytics records. This page separates those data paths so you can decide whether the tradeoff works for you.

Information that stays on your Mac

With Full Disk Access, the terminal app running GhostReply can read the local Messages database. GhostReply uses that access to load recent one-to-one conversation history, identify new incoming messages, and build examples of your writing style. It may also use local Contacts data to replace phone numbers or email handles with names. Group chats are not a supported auto-reply target.

The main GhostReply folder is ~/.ghostreply. It contains the downloaded app plus local files such as config.json, profile.json, and stats.json. These files can include license or trial state, a signed hosted-AI session, preferences, a learned writing profile, contact examples, and reply counts. An older installation may still contain an encrypted legacy Groq key, but the current app does not use it. Sensitive configuration fields are obfuscated and tied to the Mac, but you should not treat that as a substitute for securing your macOS account and backups.

Anyone or any software with sufficient access to your Mac account may be able to inspect local files. Use a strong Mac password, keep the system current, and do not share your user account with people who should not see this information.

Information sent for hosted AI processing

Depending on the feature and reply mode, a hosted-AI request can contain selected conversation samples, recent messages, the message that needs a reply, local style or life-profile instructions, and instructions for the chosen tone. The request goes from the GhostReply app on your Mac through GhostReply's Cloudflare Worker to Cloudflare Workers AI. The Worker records request status, model, token counts, timing, and credit accounting, but does not write the message text to D1.

This means GhostReply is not a completely offline or on-device AI product. Cloudflare controls the infrastructure used to process the request and can change its service and policies. Review Cloudflare's current Workers AI data-usage documentation before using GhostReply.

GhostReply license, trial, and event data

GhostReply's backend handles license activation, hosted AI requests, credit accounting, and the 10-reply trial. Requests can include a machine identifier, signed session or trial token, app version, license key for validation, selected AI context, activation status, and error information. The backend may store a shortened hash of a license key, the machine identifier, entitlement balances, request status and token counts, validation results, version, timestamps, and non-content product events. Message text is processed in memory for AI generation and is not written to D1 records.

The app and backend may send product analytics to PostHog. Examples include the app version, trial status, reply mode, discovery source, whether a reply was sent, and whether a license was activated. If you give GhostReply an optional email or buy a license, the email associated with that flow may also be attached to analytics. Reply event analytics do not include the reply text, incoming message text, or contact name.

On the website, GhostReply creates a random source identifier in local browser storage. Page and checkout events can include that source ID, the current and first landing page, referrer, UTM campaign values, page name, and the button used. This helps connect a visit with an installation or purchase without adding message content.

Services involved

Each provider has its own terms, security practices, and retention rules. GhostReply cannot promise how a third party will handle data beyond the controls and agreements that provider offers.

Retention, removal, and support

GhostReply does not publish a fixed deletion schedule for backend license, trial, or analytics records. Provider records follow each provider's policies and legal obligations. Running ghostreply --uninstall removes the main local GhostReply folder and shell alias, but it does not erase provider records, macOS logs or backups, or every trial-related system record.

For a privacy question, email support@ghostreply.lol. Do not include message contents, a license key, or an unredacted screenshot. Explain the issue in general terms and include only the minimum account or purchase information needed to find the relevant record.

Privacy questions

Yes. GhostReply reads history locally, then sends only the context needed for a profile or reply through its Cloudflare backend to Cloudflare Workers AI. GhostReply does not store message text in its D1 license, trial, or inference records.

No. Message history access and the saved reply profile are local, but AI inference is processed through GhostReply's Cloudflare backend. License checks, trial accounting, analytics, downloads, and checkout also require network services.

Running ghostreply --uninstall removes the main ~/.ghostreply directory and the shell alias. It does not promise deletion of records held by GhostReply's backend, macOS, Cloudflare, PostHog, LemonSqueezy, GitHub, or other service providers.