Ghost-Hub

Ghost-Hub

Docker app from allornothing's Repository

Overview

Self-hosted digital-footprint cleaner. Connect your Gmail inbox with your own Google OAuth client, discover every service you have ever signed up for, check them against known breaches, find shadow profiles under your email, phone or username, and bulk-unsubscribe from newsletters. Everything is review-first -- nothing happens without your approval. Raw email is processed in memory and never stored, and your data never leaves your server. Requires a PostgreSQL container (set its address in DATABASE_URL) and a Google OAuth client (see the project README). Early development: the app is a work in progress.

Ghost-Hub

A self-hosted digital-footprint cleaner. Connect your inbox, discover every account you've ever signed up for, see what's breached, and clean up — on your own hardware, with your own OAuth credentials. Your email never goes to a third-party service.

Status: early development. See docs/PLAN.md for the roadmap.

What it does

  1. Connect — Gmail via Google OAuth (read-only). Outlook is planned.
  2. Scan — finds services from sign-up, welcome, verification and receipt emails; optionally searches the web for "shadow profiles" under your email, phone or username. Everything is checked against breach data.
  3. Dashboard — accounts grouped by service, risk-scored, with breach flags and newsletter detection.
  4. Act — deletion guides, review-first bulk newsletter unsubscribe. Nothing happens without your approval.

Privacy model

  • Self-hosted: runs on your machine or Unraid server. No hosted backend, no telemetry.
  • Raw email content is processed in memory and never written to disk. Only derived facts are stored (service domain, first/last seen, message count, category, unsubscribe link).
  • OAuth refresh tokens are encrypted at rest (AES-256-GCM).
  • You can disconnect and wipe all data from the UI at any time.

Quick start (Docker)

cp .env.example .env      # then fill in the values
docker compose up -d

Open http://localhost:3000. See docs/SETUP-GOOGLE-OAUTH.md for creating your Google OAuth client (required once; takes ~5 minutes).

Development

npm install
cp .env.example .env      # set ADMIN_PASSWORD (8+ chars) and ENCRYPTION_KEY
docker compose up -d db   # Postgres only
npm run dev

Database migrations run automatically on startup. After changing src/db/schema.ts, run npm run db:generate and commit the new file in drizzle/. Other scripts: npm test, npm run typecheck, npm run lint. To also run the database integration tests, create an empty Postgres database and set TEST_DATABASE_URL to it before npm test (they're skipped otherwise).

Stack

Next.js (App Router) · TypeScript · Tailwind CSS · PostgreSQL (Drizzle ORM) · Docker

Disclaimer

Ghost-Hub is for managing your own accounts and identifiers. Do not use the shadow-profile scanner on other people.

License

MIT

Install Ghost-Hub on Unraid in a few clicks.

Find Ghost-Hub in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for Ghost-Hub Review the template variables and paths Click Install

Requirements

Requires a PostgreSQL container (e.g. postgres:17). Set DATABASE_URL to point at it.

Related apps

Explore more like this

Explore all

Details

Repository
allornothing/ghost-hub:latest
Last Updated2026-10-04
First Seen2026-10-04

Runtime arguments

Web UI
http://[IP]:[PORT:3000]/
Network
bridge
Shell
sh
Privileged
false

Template configuration

WebUI PortPorttcp

Web interface port

Target
3000
Default
3000
Value
3000
App URLVariable

URL you reach Ghost-Hub at. Used to build the Google OAuth redirect URI (APP_URL/api/auth/google/callback).

Target
APP_URL
Default
http://[IP]:3000
Value
http://[IP]:3000
Admin PasswordVariable

Password for the web UI login.

Target
ADMIN_PASSWORD
Encryption KeyVariable

32-byte base64 key that encrypts your OAuth tokens at rest. Generate with: openssl rand -base64 32. Losing it means reconnecting your inbox.

Target
ENCRYPTION_KEY
Database URLVariable

PostgreSQL connection string for your Postgres container.

Target
DATABASE_URL
Default
postgres://ghosthub:password@[IP]:5432/ghosthub
Value
postgres://ghosthub:password@[IP]:5432/ghosthub
Google Client IDVariable

From your own Google Cloud OAuth client (see docs/SETUP-GOOGLE-OAUTH.md in the project).

Target
GOOGLE_CLIENT_ID
Google Client SecretVariable

Secret for your Google OAuth client.

Target
GOOGLE_CLIENT_SECRET
HIBP API KeyVariable

Optional. Have I Been Pwned API key for per-email breach lookups. Without it, services are matched against HIBP's free public breach list.

Target
HIBP_API_KEY