All apps · 0 apps
Ghost-Hub
Docker app from allornothing's Repository
Overview
Readme
View on GitHubGhost-Hub
A self-hosted digital-footprint cleaner. Connect your inbox, discover every account you've ever signed up for, see what's breached, and clean up — on your own hardware, with your own OAuth credentials. Your email never goes to a third-party service.
Status: early development. See docs/PLAN.md for the roadmap.
What it does
- Connect — Gmail via Google OAuth (read-only). Outlook is planned.
- Scan — finds services from sign-up, welcome, verification and receipt emails; optionally searches the web for "shadow profiles" under your email, phone or username. Everything is checked against breach data.
- Dashboard — accounts grouped by service, risk-scored, with breach flags and newsletter detection.
- Act — deletion guides, review-first bulk newsletter unsubscribe. Nothing happens without your approval.
Privacy model
- Self-hosted: runs on your machine or Unraid server. No hosted backend, no telemetry.
- Raw email content is processed in memory and never written to disk. Only derived facts are stored (service domain, first/last seen, message count, category, unsubscribe link).
- OAuth refresh tokens are encrypted at rest (AES-256-GCM).
- You can disconnect and wipe all data from the UI at any time.
Quick start (Docker)
cp .env.example .env # then fill in the values
docker compose up -d
Open http://localhost:3000. See docs/SETUP-GOOGLE-OAUTH.md for creating your Google OAuth client (required once; takes ~5 minutes).
Development
npm install
cp .env.example .env # set ADMIN_PASSWORD (8+ chars) and ENCRYPTION_KEY
docker compose up -d db # Postgres only
npm run dev
Database migrations run automatically on startup. After changing src/db/schema.ts, run
npm run db:generate and commit the new file in drizzle/. Other scripts: npm test,
npm run typecheck, npm run lint. To also run the database integration tests, create an empty Postgres
database and set TEST_DATABASE_URL to it before npm test (they're skipped otherwise).
Stack
Next.js (App Router) · TypeScript · Tailwind CSS · PostgreSQL (Drizzle ORM) · Docker
Disclaimer
Ghost-Hub is for managing your own accounts and identifiers. Do not use the shadow-profile scanner on other people.
License
MIT
Install Ghost-Hub on Unraid in a few clicks.
Find Ghost-Hub in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.
Requirements
Categories
Related apps
Explore more like this
Explore allDetails
allornothing/ghost-hub:latestRuntime arguments
- Web UI
http://[IP]:[PORT:3000]/- Network
bridge- Shell
sh- Privileged
- false
Template configuration
Web interface port
- Target
- 3000
- Default
- 3000
- Value
- 3000
URL you reach Ghost-Hub at. Used to build the Google OAuth redirect URI (APP_URL/api/auth/google/callback).
- Target
- APP_URL
- Default
- http://[IP]:3000
- Value
- http://[IP]:3000
Password for the web UI login.
- Target
- ADMIN_PASSWORD
32-byte base64 key that encrypts your OAuth tokens at rest. Generate with: openssl rand -base64 32. Losing it means reconnecting your inbox.
- Target
- ENCRYPTION_KEY
PostgreSQL connection string for your Postgres container.
- Target
- DATABASE_URL
- Default
- postgres://ghosthub:password@[IP]:5432/ghosthub
- Value
- postgres://ghosthub:password@[IP]:5432/ghosthub
From your own Google Cloud OAuth client (see docs/SETUP-GOOGLE-OAUTH.md in the project).
- Target
- GOOGLE_CLIENT_ID
Secret for your Google OAuth client.
- Target
- GOOGLE_CLIENT_SECRET
Optional. Have I Been Pwned API key for per-email breach lookups. Without it, services are matched against HIBP's free public breach list.
- Target
- HIBP_API_KEY