Privacy
Privacy policy
These pages describe how this product works. They are not legal advice. If you need advice, speak with a lawyer licensed where you live. Last updated 14 September 2026.
Ghostedcheck is an anonymous ledger of hiring-process reports. There are no accounts, no profiles, and no way to sign in. This policy describes what the product stores and what it does not. It is not a promise that a third party will never sue over content a visitor chose to publish.
What we collect
Public reports you choose to file. Company name, job title, optional location and posting URL, pattern, process checkboxes, outcome, and the text of the report. A filing is stored when received. It is not shown on the public ledger until an automated, self-tuning recurrence rule is met. Do not include information that identifies you or anyone else.
Technical abuse-prevention hashes. When you file, flag, or preview the recurrence hold, the server may store a one-way hash derived from connection metadata (for example an IP address and user agent). Raw IP addresses are not stored. Hashes are used to limit repeat filing, limit repeat flagging, count distinct connections for the self-tuning hold, and keep an operations log of visits and filings. A hash is not a user identity and is not shown on the ledger.
Device storage. Your browser may keep a consent record and, if you allow optional storage, a list of report IDs you marked “Same here.” That data stays on your device. Optional storage also loads Google Analytics (measurement ID G-FX1LKX7SDL) so the operator can see aggregate page traffic. That tag does not run unless you accept optional storage.
Operations log. Ghostedcheck records page path, time, and a hashed connection for visits, filings, and flags so the operator can see traffic and take the site offline for maintenance. No name, email, or raw IP is stored with that log. A pin-gated operations cookie is set only after the operator unlocks the operations page. It is httpOnly, first-party, and not used for advertising.
We do not collect names, emails, phone numbers, payment data, precise location, account credentials, or government IDs. If you type those into a report, the filing is rejected. We do not store legal-notice packages in the ledger. See Legal request package.
How we use it
Public report fields that have cleared the self-tuning recurrence hold are shown to anyone who opens the ledger, used to compute the ghost index, and used to detect guideline violations. Held filings are stored to apply that hold and are not listed. Their stories are not shown. Hashes are used only for rate limits, duplicate flags, and distinct-connection counts. We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use reports to build advertising profiles. We do not run advertising cookies. If you accept optional storage, Google Analytics is used only to measure traffic, with ads personalization and Google Signals off.
Public by design
A report is not public the moment it is accepted. It is held until the current recurrence bar is met. That bar starts at three independent accounts and can move with ledger-wide and per-pattern flag and hide rates. Once public, there is no account to edit or delete it from. If a report is hidden after community flags or a legal process, or held again because a cluster fell below the local threshold, the underlying record may still exist for integrity and abuse review. Do not put anything in a report that you would not want read in public.
Children
Ghostedcheck is not directed at children under 13 and does not knowingly collect personal information from children under 13, as those terms are used in the Children’s Online Privacy Protection Act. The terms require you to be 18 or older. If you believe a child under 13 submitted information, use the Notice page. Because there are no accounts, the practical step is hiding the report, not looking up a child we do not have a record of.
Retention, access, and deletion
Public reports are retained as a ledger. Hidden and held filings may be retained for integrity. Connection hashes are used for a short abuse-prevention window and are not a user directory. Because we do not store a name or email with a report, we cannot honor a request that says “delete the report I filed” by identifying you. We also cannot provide you with a portable file of “your account,” because there is no account. Clearing site data in your browser removes device storage we do not hold. A complete legal package about a specific public report is the path for a company or a court, not a self-service delete button.
Third parties
Type is loaded from Google Fonts, which may see your IP address. If you accept optional storage, Google Analytics (G-FX1LKX7SDL) also runs and Google may see pages you open, your IP address, and a first-party analytics cookie. Ads personalization is off. The app may be hosted on infrastructure providers that process connection logs under their own terms. We do not embed advertising or social pixels. Those hosts, and Google when a tag is loaded, are independent controllers of their own logs. Formal legal process aimed at connection logs must be served on the party that actually holds them.
Legal requests
Because there are no accounts, Ghostedcheck does not hold a name or email for a reporter. A hashed technical identifier is not a user identity. We may still receive court orders. See legal notices and the legal request package. Do not paste reporter identity into a community flag.
Your choices
You can refuse optional storage in the cookie banner or on the cookie policy page. You can clear site data in your browser. You cannot un-publish a report after it becomes public, and you cannot edit a held filing.
If you are in a jurisdiction with additional privacy rights (including the CCPA/CPRA), the most important facts are these: we are not trying to know who you are; we do not sell personal information; we do not share it for cross-context behavioral advertising; and we cannot look up “your” report by identity. Do not tell us who you are.
