Privacy Policy

Last updated: September 11, 2026

What this covers

This policy covers the ghost-detect.com website and the Ghost Artist Detector browser extension. Both work the same way — the artist you are checking is sent to our servers and a classification comes back. Requests from either reach our web server and appear in its logs. The two optional forms described below are on the website only.

When you check an artist

To check an artist we need the artist’s name or their Spotify artist ID — the identifier that appears in a Spotify URL. That, and nothing about you, is what the check runs on.

We never receive your Spotify credentials or login information.

We do not track your listening habits or your playlists.

There are no accounts and no login. We never ask for your name or email address to check an artist.

To classify an artist we query public music-metadata services — for example Spotify, Deezer, Apple Music and MusicBrainz. We send them the artist’s identifier. Nothing about you is included, and those requests are made by our servers rather than by your browser.

What we record about each check

Every check is recorded in a scan log. For each one we store: the time (UTC), which endpoint was called, the artist ID that was looked up, whether the request came from the website, the extension, or one of our own internal tools, which source answered it (our verified-human list, our ghost list, our cache, or the model), the answer given, the confidence tier, the HTTP status, how long it took, and the model version.

This log contains no IP address, no browser or device information, no cookie, and no user or session identifier. There is no column for any of them.

The scan log is append-only. Entries are never edited or deleted.

Cookies

This site sets no cookies.

Settings stored by the extension

The extension stores its settings — the API address and three display toggles — using Chrome’s storage.sync. If you have Chrome sync turned on, Chrome copies those settings through your Google account to your other signed-in Chrome installations. Cached verdicts use storage.local and never leave the device.

Server logs

Our web server keeps a standard access log of every request: IP address, time, the URL requested, the response status, the referring page, and your browser’s user-agent string. This is ordinary web-server logging, kept for debugging and security.

The live log rotates about every 15 days. We also keep an archived copy, and that archive is not currently deleted on any schedule — assume server logs are retained indefinitely.

If you apply for a Verified Human Artist badge

The application form is optional. Nothing else on the site requires it.

If you use it, we store what you submit: your artist name, the profile links you give us, any social-media links you give us, and your country.

We also store the IP address the application came from. That is how the one-application-per-hour limit is enforced.

We have no automatic deletion for applications, so assume they are kept indefinitely. If you want yours removed, email privacy@ghost-detect.com and we will delete it.

If you send us feedback

If you tell us a classification is wrong, we store the artist, what the tool said, what you say is correct, and any comment you type. Please do not put personal information in that comment — it is stored exactly as written.

Sharing

We do not sell your data.

We do not share data with third-party advertisers, analytics companies, or data brokers.

Artist classification data may be reported in aggregate — for example, “X% of artists scanned were classified as ghost” — never in a way that identifies an individual.

How long we keep things

  • Classification results are cached indefinitely, so repeat lookups are fast.
  • Server logs: currently indefinite, as described above.
  • Scan log: append-only, never deleted.
  • Verified-badge applications: currently indefinite; deleted on request.

Contact

Questions about this policy, or a deletion request: privacy@ghost-detect.com