GChat
Privacy and support
Updated 21 September 2026
This notice covers the GChat application, gchat.boo and the Gh0st-operated notification gateway at push.gchat.boo. GChat is published by Iggy Gullstrand under the Gh0st name. Other network and relay operators may have their own practices; review the network invitation before connecting.
Your identity, conversations and files
You create an identity on your device. GChat does not require an email address, telephone number or central user account. Your passphrase protects the local profile, identity and conversation state. Optional remembered unlocking uses the operating system's protected credential storage.
Messages and shared files are encrypted for their recipients. Relays transport encrypted data and retain temporary delivery queues; they do not receive your profile passphrase or conversation decryption keys. Your recipients can read, copy and retain content you send them. Files you export outside GChat are governed by the destination application's storage and backup settings.
Network information
Network providers and relay operators process connection addresses, timing, encrypted traffic sizes, routing and delivery information to provide the service. Bootstrap providers also process invitation and access-authorisation information. Encryption does not hide all connection metadata. Traffic-analysis resistance and whole-client privacy remain areas for improvement; GChat does not claim independently qualified anonymity.
Optional mobile notifications
Supported mobile releases let you opt into notifications. Android uses Google's Firebase Cloud Messaging (FCM); iOS uses Apple's Push Notification service (APNs). These services process device or installation identifiers and notification delivery metadata under their own privacy terms. GChat includes no advertising or analytics SDK for measuring your conversations.
When enabled, our gateway stores a notification token, an opaque installation reference, app/platform identifiers, authorisation expiry and revision information. It uses these to send a generic activity notification. The notification payload contains no message text, sender name or filename. The app fetches actual content through GComs after reconnecting; a notification does not unlock your profile.
Gateway registrations expire with their authorisation and are removed by expiry cleanup. Disabling notifications requests revocation; if the device is offline or the request fails, server-side expiry still applies. Limited replay and revision records are retained until their expiry to prevent reuse of old requests. Storage journals and infrastructure backups may retain older data beyond removal from the live database. Push delivery is optional and is not guaranteed.
Provider information: Firebase privacy and Apple privacy.
Website, diagnostics and support
This website uses no analytics scripts, advertising trackers or tracking cookies. Hosting and network infrastructure may process ordinary connection information for operation and abuse prevention. Downloads and source links take you to GitHub, which has its own privacy practices.
If you send a support request, we receive the contact details and information you choose to include. Do not send passphrases, private keys, notification tokens or private conversations. Diagnostic logs may contain operational metadata; review them before sharing.
Control and deletion
You can disable notifications in GChat or system settings. Removing the app's local data removes its local profile; separately retained exports, operating-system backups and recipients' copies are not deleted by that action. There is no central GChat account to close and no server-side passphrase recovery.
For help, privacy questions or a request concerning data held by the Gh0st-operated service, email iggy@gchat.boo. Describe the issue without including secrets. We may need information that establishes your control of the relevant installation before acting on a request. A request cannot erase another recipient's copy of a conversation.