Privacy Policy
This Privacy Policy explains how Ghost Story Review ("GSR," "we," "us," or "our") collects, uses, discloses, and protects information when you use the Ghost Story Review mobile application (the "App") and any related services (collectively, the "Service").
By creating an account or otherwise using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Account Information
When you register for an account, we collect:
- Email address — used to create and authenticate your account, send account-related notices, and enable password recovery.
- Display name — the name shown to other users alongside your reviews, photos, videos, and messages.
1.2 Location Data
With your permission, the App collects precise or approximate location data while the App is in use (foreground only). We do not collect location data while the App is running in the background or is closed. Location data is used to:
- Show your position on the in-app map;
- Let you place and view location "pins" for haunted or paranormal sites;
- Show you reviews and content associated with nearby locations.
You can deny or revoke location permission at any time through your device settings. If you do, map and pin features that depend on location will not function, but you can still use other parts of the Service.
1.3 User-Submitted Content
The Service allows you to create and upload:
- Written reviews and "lore" entries about locations;
- Photos;
- Videos;
- Direct messages ("DMs") sent to other users.
Photos and videos may contain embedded metadata (such as the time and place a photo or video was taken). We recommend reviewing your device's camera and photo-sharing settings if you do not want this metadata included.
1.4 Direct Messages
Direct messages you send to other users through the Service are stored on our servers so that conversations can be delivered and retained across devices. DMs are not reviewed by GSR as a matter of routine, but we may access message content where necessary to investigate harassment, abuse, or violations of our Terms of Service, to respond to a user report, or to comply with a legal obligation.
1.5 Usage and Device Data
We use Firebase (a Google service) and Google Analytics for Firebase to automatically collect standard usage and diagnostic data, which may include:
- Device identifiers, device model, and operating system version;
- App version, crash logs, and performance data;
- Feature usage and in-app events (e.g., screens viewed, actions taken);
- General, coarse analytics-level location (such as country or region), which is separate from the foreground GPS location described in Section 1.2;
- Push notification token — a device-specific identifier issued by Firebase Cloud Messaging, used solely to deliver notifications you have enabled (such as new comments, replies, follows, and direct messages). This token is deleted when you delete your account.
We use Google Analytics for Firebase to collect data about how the App is used and how it performs — including which screens are viewed, general usage patterns, app crashes, and performance issues. We use this information solely to monitor app stability, identify and fix bugs, and improve the App's features and performance. We do not use this data for advertising or ad targeting, and we do not sell, rent, or share this data with third parties for their own marketing or advertising purposes.
2. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Service, including account creation, authentication, and the map/review/lore features;
- Display your reviews, photos, videos, lore entries, and display name to other users as intended by the App's core functionality;
- Deliver direct messages between users;
- Monitor, maintain, and improve the performance, stability, and features of the App;
- Detect, investigate, and prevent fraud, abuse, harassment, and violations of our Terms of Service;
- Respond to your requests, questions, and support inquiries;
- Comply with applicable law, legal process, or governmental request.
We do not sell your personal information.
3. Third-Party Service Providers
We rely on the following third-party infrastructure providers ("processors") to operate the Service. These providers process data on our behalf and under their own respective privacy and security commitments:
| Provider | Purpose | Data involved |
|---|---|---|
| Firebase Authentication (Google) | Account creation and login | Email address, account identifiers |
| Cloud Firestore (Google Firebase) | Storing app data — accounts, reviews, lore entries, pins, direct messages | Display name, location data, review/lore text, DM content |
| Firebase Storage (Google) | Storing user-submitted photos | Photo files and associated metadata |
| Firebase Cloud Messaging (Google) | Delivering push notifications you have enabled | Push notification token, device identifier |
| Cloudflare Stream | Video hosting, encoding, and playback | User-submitted video files |
| Google Analytics for Firebase | App usage analytics and crash/performance monitoring (not used for advertising) | Device data, usage events, diagnostic logs |
| Google Places API | Map search, location lookup, and location photo display | Search queries, location coordinates, and location name/address |
These providers may process and store data on servers located outside your country of residence. We use them because we consider their security and privacy practices to be consistent with the protections described in this policy. You can review their own privacy documentation here:
4. How We Share Information
Aside from the service providers described above, we share information only in the following circumstances:
- With other users, as part of core App functionality — your display name, reviews, lore entries, photos, and videos are visible to other users by design. Direct messages are visible only to the sender and recipient(s).
- For legal reasons — if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of GSR, our users, or the public.
- In connection with a business transfer — if GSR is involved in a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction, subject to this policy or a successor policy.
- With your consent — in any other case where you direct us to share information.
Data collected through Google Analytics for Firebase is used only for our own internal purposes — monitoring app stability, diagnosing and fixing bugs, and improving the App's features and performance. We do not use this data for advertising or ad targeting, and we do not sell, rent, or share it with third parties for their own marketing or advertising purposes.
5. Data Retention
We retain account information, content, and messages for as long as your account is active. If you delete a specific review, photo, video, or lore entry, we remove it from active display and delete the underlying file from storage within a reasonable period. If you delete your account, we process the deletion as described in Section 7 below.
6. Your Rights and Choices
- Access and correction — you can view and edit your display name and other profile details within the App.
- Location permission — you can grant, deny, or revoke location access at any time in your device settings.
- Content deletion — you can delete individual reviews, photos, videos, and lore entries you have submitted directly within the App.
- Account and data deletion — you may request deletion of your account and associated personal data at any time (see Section 7).
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you may have additional rights under the GDPR, including the right to data portability and the right to object to or restrict certain processing. If you are a California resident, you may have rights under the CCPA/CPRA, including the right to know what personal information is collected and the right to request deletion. To exercise any of these rights, contact us using the information in Section 10.
7. Account and Data Deletion
You can permanently delete your account at any time from within the App via Profile > Delete Account. To confirm the request is really coming from you, we require you to re-authenticate immediately beforehand (by re-entering your password, or, for accounts linked to Google, a fresh Google sign-in prompt), and to explicitly confirm the deletion, including typing a confirmation phrase, before anything is removed.
When you complete account deletion, we delete, in this order: every review, post, and lore entry you authored (including any photos or videos attached to them); every comment, reply, and like you have left anywhere on the Service; every follow relationship connected to your account, in both directions; every block you created; your profile photo; and your account profile record. Your authentication credentials (your email/password or linked Google sign-in) are deleted last, once everything above has been removed.
Some information is not deleted as part of this process:
- Direct messages. Conversations and messages you have sent or received are not deleted when you delete your account. Message content is retained so that other participants' conversation history is preserved, and so that any message that has been reported remains available for trust-and-safety review. After deletion, your name and photo will no longer be shown in any existing conversation; you will instead appear under a generic placeholder identity, the same way any user whose profile can no longer be resolved appears elsewhere in the Service.
- Your @username. The unique username you claimed is not released when you delete your account. It remains permanently reserved and cannot be claimed by another user, even though your account and profile no longer exist.
- Locations you submitted. Haunted-location records you created or submitted remain on the Service after you delete your account; only GSR administrators can remove a location.
- Reports, moderation records, feedback, and audit logs. If you have reported another user or piece of content, or have been the subject of a report, those reports — along with related moderation decisions, feedback you submitted, and internal audit records — are retained even after account deletion. We keep these for trust and safety, to investigate abuse, and to comply with legal obligations.
Account deletion is irreversible. Once your authentication credentials are removed, you will not be able to sign back in or recover any of the data described above. Some content you posted that other users have copied, screenshotted, or otherwise saved outside the Service is also not within our control and may not be deleted.
If you are unable to access the in-app deletion option, you may also request deletion by contacting us at the support address listed in Section 10.
8. Children's Privacy
The Service requires all users to be at least 18 years old and is not directed to, or intended for use by, anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from someone under 18, we will take steps to delete that information. If you believe someone under 18 has provided us with personal information, please contact us using the information in Section 10.
9. Data Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your information, including the security infrastructure provided by Firebase and Cloudflare. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Contact Us
If you have questions about this Privacy Policy, or want to exercise any privacy right described above, including account or data deletion, contact us at:
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and post the revised policy at ghoststoryreview.com. Your continued use of the Service after a change becomes effective constitutes your acceptance of the revised policy.