Last updated: August 11, 2026
1. Data Controller
The data controller responsible for the processing of personal data described in this Privacy Policy, within the meaning of Article 4(7) of the EU General Data Protection Regulation (GDPR) and the French Loi Informatique et Libertés, is:
AIROFIRST LLC
4405 Jager Drive Northeast, Ste C4-4446
Rio Rancho, New Mexico 87144, United States
Email: Metaghost.io@gmail.com
For all data subject requests (access, rectification, erasure, portability, restriction, objection — Articles 15 to 22 GDPR), please contact us at the email address above. You also have the right to lodge a complaint with your national supervisory authority (in France, the CNIL — www.cnil.fr).
2. Information We Collect
We collect the following information:
- Account Information: Email address, name, and password (encrypted)
- Payment Information: Processed securely by Stripe or NOWPayments
- Device Information: Device ID for license verification
- Usage Data: App usage statistics for improving our service
- Anonymous Authentication Analytics: Login and signup page paths without query strings or fragments, a session-scoped pseudonymous identifier, broad browser, operating-system, device, language, and viewport categories, and bounded authentication events describing the flow, method, stage, result, and categorized failure reason. GeoIP enrichment is disabled. We do not include form values, email addresses, Team logins, raw error messages, OAuth state, confirmation codes, or access tokens. Automatic page tracking, element tracking, and session replay are disabled.
- Operational Diagnostics: Application version, operating system, feature or screen, service health events, error messages, and pseudonymous request or job identifiers used to maintain reliability and investigate support cases. Local diagnostic files are bounded and remain on the device.
- Product Reports: If you send a bug report or suggestion, we collect the text and screenshots you choose to submit. The report also includes a short, automatically generated and size-limited timeline of recent application events. This timeline is filtered before transmission and again on our server; it excludes raw log files, account credentials, media, local file paths, cookies, API keys, and authorization tokens.
- Article Feedback: If you use the optional helpfulness form on a blog guide, we collect your vote, selected improvement reasons, optional written comment, broad device category, and a random first-party browser token used to avoid duplicate responses. The feedback record does not contain your account ID or IP address; IP addresses may be processed transiently for rate limiting.
- Campaign Attribution: When you follow one of our campaign links, first-party attribution cookies store a signed campaign reference for up to 30 days and a pseudonymous visitor identifier for up to 365 days. For email signup, the verification redirect may carry the same opaque signed campaign reference so attribution survives confirmation on another device. We may record the landing path, referrer hostname, broad device, browser and operating-system category, country supplied by our hosting edge, and a keyed pseudonym derived from the network address. Tracking records do not store the raw network address or the full referrer URL. If you create an account or complete a payment, that activity may be attributed to the campaign link.
3. How We Use Your Information
We use your information to:
- Provide and maintain our service
- Process payments and subscriptions
- Verify license and device limits
- Detect service failures, secure the platform, investigate support cases, and prevent repeated incidents
- Measure where anonymous visitors encounter success or a categorized failure during login, signup, and email confirmation
- Measure whether blog guides solve readers' problems and prioritize corrections, missing steps, and content updates
- Measure campaign visits, genuine new-account signups, completed purchases, renewals, and retention without allowing a browser-provided campaign value to control payment attribution
- Send important updates about our service
- Improve our products and services
4. Local Processing
Features identified in MetaGhost as local process files on your computer. Features identified as cloud or AI processing upload only the files you select for that operation to our private processing infrastructure. Product-report screenshots are uploaded only when you add them to a report. Operational diagnostics never attach your media or raw local log files.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encrypted data transmission (HTTPS/TLS)
- Secure password hashing
- Regular security audits
6. Third-Party Services
We use the following third-party services:
- Supabase: Authentication and database
- Stripe: Card payment processing
- NOWPayments: Cryptocurrency payment processing
- Vercel: Website hosting, deployment, performance measurement, and server logs
- Cloudflare: Private object storage, abuse protection, and network services
- Modal: Isolated compute workers for features explicitly using cloud processing
- PostHog EU: Anonymous authentication-funnel analytics, with automatic page and element tracking and session replay disabled
- Resend: Transactional and operational email delivery
- Sentry: Filtered application error monitoring when enabled
7. Data Retention
We retain your account information for as long as your account is active. You may request deletion of your data at any time by contacting support.
Article feedback is kept only while it remains useful for measuring and improving guide quality, then deleted or reduced to aggregate statistics. Written comments are private and are never published automatically on article pages.
Operational events and product-report diagnostics are retained only while needed for security, reliability, support, and incident analysis. Access is restricted to authorized MetaGhost administrators. When a support record must be retained after an account is deleted, direct identifiers are removed or reduced where legally and technically possible.
Campaign attribution cookies expire after the periods stated above. Campaign visit and conversion records are retained only while needed for business measurement, payment reconciliation, fraud prevention, and legal obligations. Archiving a campaign stops new attributed visits but retains its historical aggregate and audit records.
The anonymous website analytics identifier is stored only for the current browser-tab session. Analytics events are retained only while needed to measure service reliability and improve the authentication experience, then deleted or reduced to aggregate statistics.
8. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data
9. Contact
For privacy-related questions or to exercise your data subject rights, please contact us by email at Metaghost.io@gmail.com. You may also use Telegram support at @Metaghost_Support for general inquiries; however, formal data subject requests should be sent by email for legal traceability.
Full publisher information is available in our Legal Notice.