Legal
Privacy Policy
This page explains the data GhostAPI needs to operate mock API projects, team invitations, request logs, and account access.
Data use
What GhostAPI handles
GhostAPI exists to process API contracts and mock traffic, so schema and request data are part of the core product workflow.
- Account data
- We use account information to authenticate users, secure sessions, send verification messages, and manage project membership.
- Project data
- Project names, descriptions, environments, settings, members, and schema metadata are used to run the workspace experience.
- Uploaded schemas
- Uploaded OpenAPI documents are parsed into normalized endpoints so GhostAPI can mount mock routes and generate responses.
- Request logs
- Mock runtime logs may include request paths, headers, bodies, response data, status, duration, and endpoint match details for debugging.
- Invitations
- Invitation emails use the recipient address, inviter identity, project name, role, and expiration metadata to deliver project access.
- Retention
- Project owners can configure activity log retention where the product exposes that setting.