GHOSTWIRE
Privacy policy
GHOSTWIRE is the iPhone app for the GHOSTWIRE server, which runs a WireGuard® VPN on a Linux machine that you run or have admin access to. It is made by Daniel Redetzke, an individual developer in Ireland. This policy covers the iPhone app. It explains what the app stores and where your data goes.
What GHOSTWIRE stores on your device
- Pairing: your server's address, the access token from the pairing code, and the certificate fingerprint for servers with a self-signed certificate. These are stored in the iOS Keychain on this device only and are not synced to or restored onto other devices.
Your devices, traffic figures, connection history and logs are loaded from your server each time and are not saved by the app. Tapping "Disconnect this iPhone" deletes the pairing. iOS may keep it in the Keychain after the app is deleted; only GHOSTWIRE can read it.
Camera
GHOSTWIRE asks for the camera only to scan the pairing QR code shown in the GHOSTWIRE web interface. The image is read on the device and is not saved or sent anywhere. You can enter the pairing code by hand instead.
Where your data goes
GHOSTWIRE talks only to the server you paired it with, using its access token. It sends the requests you make there: loading the dashboard, devices and logs, and adding, changing or removing devices and settings. Like any server, yours sees your iPhone's IP address. What your server does with that data is up to you and whoever runs it.
When you add a device, the app shows its VPN config or setup link once. It goes only where you send it: when you share it, copy it, or show its QR code.
What GHOSTWIRE collects
Nothing. GHOSTWIRE has no servers of its own, no accounts, analytics, advertising or tracking, and it contains no third-party code. The developer receives no data from the app.
Security
A full-access token can add and remove VPN devices and change your server's settings, so keep your iPhone locked. You can pair with read-only access instead, and revoke the token in the web interface at any time. Self-signed certificates are pinned during pairing, so the app refuses any other certificate. Let's Encrypt and other trusted certificates are checked as usual.
Children
GHOSTWIRE does not collect any information from anyone, including children.
Your rights
Because GHOSTWIRE sends nothing to the developer, there is no personal data about you to access, correct or delete. If you have a question, email [email protected]. If you are in the EU or UK, you may also complain to your data protection authority; in Ireland that is the Data Protection Commission.
Changes
If this policy changes, the new version is published on this page with a new date.