<!-- https://missblue.dev/privacy -->

Legal · Privacy

# Privacy Policy

How Ghost AI Lab handles your Miss Blue account, payments, number requests, conversations, calls, and recordings.

Updated September 8, 2026 Ghost AI Lab

## 1. Who we are and when this applies

KUKU10 LLC, doing business as [Ghost AI Lab](https://ghostailab.com/), operates Miss Blue. This policy explains how we handle personal information through our websites, accounts, messaging and calling services, APIs, and support. Contact us at [hello@missblue.dev](mailto:hello@missblue.dev) about privacy.

We determine how account, billing, website, security, and support information is used to operate our business. When a customer uses Miss Blue to communicate with its contacts, that customer determines the purpose of those communications, and we process conversation data to provide the service on its behalf. The customer’s privacy notice also applies. Apple, carriers, payment providers, and integrations may have their own privacy practices.

## 2. Information we collect

### Accounts and workspace access

Name, email address, business and workspace details, project membership, permissions, preferences, authentication and verification records, and account activity. Account passwords are stored as one-way hashes, not readable plaintext.

### Payments and subscriptions

Plan and quantity, customer and subscription references, payment status, transaction amounts, invoices, renewal dates, and upgrade, downgrade, or cancellation requests. Stripe collects payment-method and billing information through its payment interfaces. We receive payment and subscription records needed to operate your plan; we do not store your full card number or card security code.

### Number setup and forwarding

Requested quantity, project, ZIP or area preference, existing phone number, carrier, carrier account number, transfer PIN where supplied, forwarding destination, callback phone, use case, and notes. These details come from you or your workspace and are used to provision, transfer, and configure lines. Transfer credentials are sensitive; submit them only through the intended setup process.

### Contacts and conversations

Contact names and identifiers, phone numbers or Apple addresses, message text, attachments, voice notes, reactions, delivery and read information, timestamps, conversation history, and other data submitted or received through the inbox, API, or connected workflows.

### Calls and optional recordings

Call type, participating numbers or identifiers, teammate initiating the call, time, outcome, ring and talk duration, connection details, and recording status. During a call we and the providers used for that call process audio to connect participants. If recording is enabled, we also process and store recorded audio, which can include both participants’ voices, and the record of who enabled recording and when.

### Website, device, and support information

IP addresses, browser and device characteristics, page visits, feature usage, cookie or browser-storage identifiers, request metadata, diagnostic and security events, and information you provide in support, sales, scheduling, or employment inquiries. We receive information directly from you, from your workspace and its contacts or integrations, from payment and communications providers, and automatically when the service is used.

## 3. How and why we use information

-   Create and authenticate accounts, manage workspace and project access, and apply permissions.
-   Verify payments, manage subscriptions, process plan changes, provision numbers, and configure transfers and forwarding.
-   Send, receive, and synchronize conversations; connect calls; and provide enabled recordings and playback.
-   Deliver configured API and webhook events and carry out customer-directed integrations or automation.
-   Send verification, security, billing, setup, service-status, and support communications, including reminders to finish number setup.
-   Measure product usage, improve reliability and usability, investigate faults, prevent abuse, and meet legal and accounting obligations.

We do not use the contents of customer conversations to build advertising profiles or sell message contents. Connecting an AI service may send content to that provider according to the workflow you enable; its data-use terms also apply.

Where applicable data-protection law requires a legal basis for our own processing, we rely on performing a contract, legitimate interests such as service security and support, legal obligations, or consent when required. For customer-controlled conversations, the customer is responsible for its lawful basis and instructions.

## 4. Call audio, recording choices, and access

Recording starts off for each number and can be enabled by an authorized user. FaceTime Audio recording captures audio through the browser; regular phone-call recording uses the phone provider’s recording path. Microphone access is needed for browser calls even when recording is off. A call can appear in history without a recording.

Customers must inform participants and obtain legally required consent before recording. The acknowledgment recorded in Miss Blue documents the customer’s choice, not the other participants’ consent. Authorized teammates can access call history and available recordings according to their permissions.

Disabling recording affects future recording; it does not erase audio already stored or copies already downloaded or sent to another service. For deletion or retention questions, contact your workspace administrator or [hello@missblue.dev](mailto:hello@missblue.dev).

## 5. Who receives information

### Your workspace and integrations

Members and administrators can access information according to workspace, project, and number permissions. Webhooks, CRM connections, API clients, and AI services receive data when configured by the customer. The receiving provider controls its own copies and practices.

### Providers that operate the service

We use hosting and storage providers to run the application and retain service data, Stripe for payments and subscriptions, email delivery providers for account and service messages, and Apple services and communications providers for messaging and calls. Depending on the feature, calling uses Telnyx or LiveKit-based audio infrastructure. Providers receive the information needed for the functions they perform.

When configured, PostHog receives product analytics and Sentry receives diagnostic error reports. PostHog automatic click-content capture and session recording are disabled; Sentry session replay is not enabled. Diagnostic filtering is designed to reduce sensitive data, including message content, credentials, and payment details.

### Support, legal obligations, and business changes

Authorized staff may access relevant account, setup, conversation, or call information to fulfill a request, troubleshoot a problem, investigate abuse, or meet legal obligations. We may disclose information when required by law, to protect rights and safety, or as part of a merger, financing, acquisition, or transfer of business assets, subject to applicable protections.

## 6. Cookies, browser storage, and analytics

We use cookies and similar storage for sign-in sessions, security, preferences such as timezone, and interface choices such as dismissed notices. The sign-in session cookie is HttpOnly, so page JavaScript cannot read it.

When enabled, PostHog uses browser identifiers and page or usage events to help us understand how the product is used. Stripe and embedded third-party tools may use their own cookies or similar technologies for payments, fraud prevention, or the feature you open. These technologies are distinct from recording the audio of a call.

You can use browser settings to restrict or clear cookies and local storage. Blocking essential storage may prevent sign-in, payments, or preferences from working. For questions about analytics or to exercise privacy rights available to you, email [hello@missblue.dev](mailto:hello@missblue.dev). A browser setting does not delete information already held in your account.

## 7. Retention and deletion

We retain account and service data while needed to provide the service, follow customer instructions, maintain security, meet accounting or legal requirements, and resolve disputes. The period depends on the type of information, account status, configuration, and those purposes.

Conversation history, attachments, call records, and recordings can remain available while the account uses the service. Recordings do not have an automatic expiry by default; a configured retention deadline may limit availability. Ending a call, turning off recording, cancelling a number, or downgrading a plan does not itself request immediate deletion of all stored information.

After cancellation or number release, access and recovery are not guaranteed. Contact us about export or deletion before ending service. Billing, fraud-prevention, security, and dispute records may need to remain after account closure. Copies in backups or held by a customer’s integrations and recipients may be subject to separate deletion schedules or obligations.

## 8. Security and messaging infrastructure

We use access controls, hashed account passwords, authenticated sessions, and protected connections designed to secure information. We restrict access according to permissions and use filtering intended to keep private content and secrets out of operational diagnostics. No service can guarantee absolute security.

Miss Blue processes messages and media on the Macs and servers used to provide your inbox and API. Apple’s protections for iMessage transport do not mean Ghost AI Lab cannot access content at these service endpoints. Do not assume that messages or recordings stored in Miss Blue are readable only by the sender and recipient.

Protect credentials, review teammate and integration access, and report suspected compromise to [hello@missblue.dev](mailto:hello@missblue.dev).

## 9. International processing

Miss Blue and its providers may process information in countries other than where you live, whose privacy laws may differ. Where applicable law requires a transfer mechanism or additional safeguards, those requirements apply to our processing. Contact us for information about processing locations and any arrangements needed for your organization.

## 10. Your choices and privacy rights

Depending on the law that applies to you, you may have rights to know about, access, correct, delete, or receive a portable copy of personal information; restrict or object to processing; withdraw consent; opt out of certain uses or disclosures; or appeal a decision about a request. You may also complain to the relevant data-protection authority. We will not unlawfully discriminate against you for exercising applicable rights.

To make a request to Ghost AI Lab, email [hello@missblue.dev](mailto:hello@missblue.dev) with the subject “Privacy request.” Describe your request and the account or business involved without sending passwords, transfer PINs, or full payment-card details. You do not need to create a Miss Blue account to contact us. We may verify your identity or an authorized representative’s authority and apply lawful exceptions before responding.

If a business contacted you through Miss Blue, contact that business about its messages, recordings, or use of your information. We can help route a request when we process the information on its behalf. A request to Ghost AI Lab does not automatically remove copies held by that business, other recipients, or its integrations.

You can opt out of non-essential marketing communications using the instructions in the message or by contacting us. Necessary account, billing, security, and requested service messages may continue while you use Miss Blue.

## 11. Children

Miss Blue is a business service for account holders aged 18 or older and is not directed to children. We do not knowingly collect personal information from children through account registration. Contact us if you believe a child has provided personal information to us so we can review and address it.

## 12. Updates and contact

We may update this policy when the service or our practices change. We will post the revised date here and provide additional notice or obtain consent when required for a material change.

For privacy questions or requests, contact KUKU10 LLC dba Ghost AI Lab at [hello@missblue.dev](mailto:hello@missblue.dev). Our [Terms of Service](https://missblue.dev/terms) describe subscription and service rules, and our [calling guide](https://missblue.dev/docs/calling) explains recording controls.
