Acceptance of Terms
By accessing, downloading, installing, or using any component of the GhostPay Mesh platform — including its website, mobile applications, SDKs, APIs, protocol libraries, and all associated documentation (collectively, the "Service") — you acknowledge that you have read, understood, and agree to be legally bound by these Terms of Use.
If you are accessing the Service on behalf of a legal entity, you represent and warrant that you have full authority to bind that entity. If you do not agree to these Terms in their entirety, you must immediately cease using the Service.
What is GhostPay Mesh
GhostPay Mesh is an offline-capable cryptographic settlement infrastructure protocol. It enables the creation, transfer, and synchronization of Cryptographic Settlement Promises (CSPs/PLCs) without requiring a continuous internet connection.
CSPs and PLCs are cryptographic technical objects — data structures signed by cryptographic keys. They are not currency, not deposits, not electronic money instruments, not financial instruments, and not guarantees of automatic financial settlement.
Nature of the Technology Service
GhostPay Mesh provides exclusively a technology infrastructure service. It is not a financial service, financial product, or regulated financial activity.
- Provides cryptographic protocol software, libraries, SDKs, APIs, and documentation.
- Enables on-device generation and management of cryptographic key pairs.
- Enables offline-first creation, signing, and peer-to-peer transfer of CSPs/PLCs.
- Enables synchronization with regulated settlement partners when connectivity is restored.
- Does not hold, store, manage, or custody any monetary funds on behalf of any user.
- Any settlement is performed exclusively by third-party regulated partners.
What GhostPay Mesh Is NOT
GhostPay Mesh is expressly not any of the following:
- Not a bank — Not a bank, savings institution, credit union, or deposit-taking institution.
- Not a payment institution — Not a PSP, payment facilitator, or payment institution under Lei 12.865/2013 or equivalent.
- Not an electronic money issuer — Does not issue e-money or any electronic value storage instrument.
- Not a financial custodian — Does not hold or manage user funds in custody at any time.
- Not a cryptocurrency exchange — Does not operate a marketplace or trading platform for digital assets.
- Not an investment product — Nothing constitutes a security, derivative, or regulated financial instrument.
- Not a custodial wallet — Does not hold monetary value on behalf of users.
- Not a regulated financial service provider — Holds no banking, payment institution, or e-money license in any jurisdiction.
Permitted Use
GhostPay Mesh grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Service for lawful purposes, including:
- Integrating the protocol into your own applications, in compliance with applicable API/SDK terms.
- Creating, receiving, and managing CSPs/PLCs for coordinating settlement obligations between consenting parties.
- Testing and evaluating the protocol in non-production environments.
- Accessing documentation, specifications, and technical resources.
All use must comply with applicable laws and regulations in your jurisdiction.
Prohibited Use
You must not use the Service for any of the following. Violation may result in immediate suspension and legal reporting:
- Money laundering — Concealing proceeds of criminal activity in violation of Lei 9.613/1998, FATF recommendations, or equivalent law.
- Terrorism financing — Using the Service to finance terrorism or terrorist organizations.
- Fraud — Facilitating or concealing fraud, identity theft, or any dishonest scheme.
- Circumventing KYC/AML — Evading KYC/AML requirements of regulated settlement partners including ASAAS.
- Unauthorized resale — Commercially exploiting any Service component without written authorization.
- Illegal activities — Illegal gambling, weapons trafficking, drug trafficking, human trafficking, or other criminal activity.
- System interference — Reverse-engineering, decompiling, or interfering with security mechanisms.
- Misrepresentation — Representing CSPs/PLCs as money, bank deposits, or guaranteed financial instruments.
- Sanctions violations — Violating economic sanctions administered by OFAC, the EU, the UN, or Brazilian authorities.
User Responsibilities
You are solely responsible for:
- Compliance with local law — Including financial regulations, tax obligations, and data protection law.
- Accurate information — Providing accurate data to GhostPay Mesh and regulated settlement partners for KYC/AML purposes.
- Key management — Generating, storing, protecting, and backing up your cryptographic private keys. GhostPay Mesh has no access and cannot recover them.
- Device security — Protecting devices against unauthorized access, malware, and physical theft.
- Authorization — Ensuring proper authorization before creating or accepting CSPs/PLCs on behalf of third parties.
- Tax obligations — Understanding and fulfilling any tax obligations arising from activities conducted using the Service.
Private Keys, Certificates, Backups and Loss of Access
GhostPay Mesh is a self-custody cryptographic protocol. Cryptographic keys are generated on your device and remain under your exclusive control at all times.
- GhostPay Mesh does not have access to your private keys at any time.
- GhostPay Mesh cannot recover your private keys or device credentials if lost, destroyed, forgotten, or compromised.
- Loss of private keys means permanent loss of ability to sign or authorize associated CSPs/PLCs.
- You are solely responsible for creating and maintaining secure backups of key material.
- Compromise of private keys (e.g., via malware or device theft) may result in unauthorized CSP/PLC use that GhostPay Mesh cannot reverse.
Offline Mode Risks
You acknowledge the inherent risks of the offline-capable architecture:
- Connectivity failures — CSPs/PLCs may fail to synchronize or settle if connectivity cannot be restored before expiration.
- Synchronization delays — Delays may cause CSPs/PLCs to expire without settlement.
- Expiration — Each CSP/PLC has a defined TTL. Expired CSPs/PLCs cannot be settled.
- Double-spend prevention — Cryptographic mechanisms require network synchronization. Submitting the same CSP/PLC through multiple channels may result in rejection.
- No guarantee of settlement — Creation of a CSP/PLC does not guarantee financial settlement.
Third-Party Integrations and Regulated Partners
- ASAAS as settlement partner — Financial settlement (Pix, Boleto) is executed exclusively by ASAAS Gestão Financeira Instituição de Pagamento S.A., regulated by Banco Central do Brasil. ASAAS's own terms and KYC/AML requirements apply.
- Third-party terms apply — Your use of settlement features is subject to ASAAS's terms. GhostPay Mesh is not a party to your settlement transaction with ASAAS.
- No liability for partner failures — GhostPay Mesh is not responsible for any failure, error, delay, or refusal by ASAAS or any other regulated settlement partner.
- Compliance requirements — Regulated partners may require identity verification and KYC/AML information as a condition of settlement.
No Financial, Legal, Tax or Investment Advice
Nothing in the Service, its documentation, or any communication from GhostPay Mesh constitutes financial advice, legal advice, tax advice, investment advice, or any recommendation to buy, sell, hold, or transfer any asset.
GhostPay Mesh is a technology protocol. Consult qualified, licensed professionals in your jurisdiction for financial, legal, tax, and investment guidance.
Beta / Experimental Technology Disclaimer
GhostPay Mesh is in active development. Components may be designated as "beta," "experimental," or pre-production software. Beta software may contain bugs that could result in data loss or failure to settle CSPs/PLCs.
- GhostPay Mesh does not guarantee uptime, availability, or uninterrupted service.
- The Service is not recommended for production-critical applications where settlement failure could cause significant financial loss without an alternative mechanism.
- Protocol specifications, APIs, and data formats may change without prior notice.
Limitation of Liability
To the maximum extent permitted by applicable law, GhostPay Mesh and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, CSPs/PLCs, or failure to settle.
GhostPay Mesh's total aggregate liability shall not exceed the greater of: (a) fees paid by you in the 12 months preceding the event, or (b) BRL 100.00.
Disclaimer of Warranties
The Service is provided "AS IS" and "AS AVAILABLE" without any warranty, express or implied, including warranties of merchantability, fitness for a particular purpose, uninterrupted service, error-free operation, or successful settlement of any CSP/PLC.
Indemnification
You agree to defend, indemnify, and hold harmless GhostPay Mesh and its affiliates from any claims, liabilities, damages, and expenses (including attorneys' fees) arising from your violation of these Terms, misuse of the Service, violation of applicable law, or any CSP/PLC transaction you initiate.
Intellectual Property
All content, software, code, protocol specifications, trademarks, and intellectual property available through the Service are the exclusive property of GhostPay Mesh or its licensors. No provision of these Terms transfers any intellectual property ownership to you.
Suspension or Restriction of Use
GhostPay Mesh may, at its sole discretion, suspend or terminate your access to the Service without prior notice for breach of these Terms, suspected illegal activity, fraud, AML/KYC concerns, technical necessity, or regulatory requirement. GhostPay Mesh shall not be liable for any resulting damages.
Changes to These Terms
GhostPay Mesh may modify these Terms at any time. Updated Terms will be published with a revised "Last updated" date. For material changes, we will provide at least 14 days' notice. Continued use of the Service after the effective date constitutes acceptance of the revised Terms.
Governing Law and Jurisdiction
These Terms are governed by the laws of the Federative Republic of Brazil. Disputes shall be resolved by the courts of São Paulo, Brazil, unless mandatory consumer protection law in your jurisdiction requires otherwise.
Contact
For questions or notices related to these Terms:
GhostPay Mesh
contact@ghostpaymesh.com
Alameda Rio Negro, N° 503 — Sala Comercial 2011, Alphaville Industrial, Barueri — SP — 06454-000 — Brazil
Minors and Age Restrictions
The Service is intended solely for persons aged 18 years or older (or the age of legal majority in the applicable jurisdiction). GhostPay Mesh does not knowingly collect data from or permit use by minors. If you are a minor, you must not use the Service. If a parent or guardian becomes aware that a minor has registered without consent, they should contact us at contact@ghostpaymesh.com for account deletion.
Brazilian Data Protection Law (LGPD — Lei 13.709/2018)
GhostPay Mesh processes personal data in accordance with Lei Geral de Proteção de Dados (LGPD — Lei 13.709/2018). The legal bases for processing may include: consent (Art. 7, I), performance of a contract (Art. 7, V), compliance with a legal obligation (Art. 7, II), and legitimate interest (Art. 7, IX), depending on the specific processing activity.
Data subjects have the following rights under LGPD (Art. 18): confirmation of the existence of processing; access to data; correction of incomplete or inaccurate data; anonymization, blocking or deletion of unnecessary data; portability; deletion of data processed with consent; information about third parties with whom data is shared; information about the right to deny consent and consequences; and revocation of consent. To exercise these rights, contact contact@ghostpaymesh.com.
The Data Protection Officer (DPO/Encarregado) designated under LGPD can be reached at contact@ghostpaymesh.com.
Marco Civil da Internet (Lei 12.965/2014)
GhostPay Mesh complies with the Brazilian Internet Civil Framework (Lei 12.965/2014 — Marco Civil da Internet) and its Decree No. 8.771/2016. Connection logs and access logs to applications are retained as required by applicable law (Art. 13 and Art. 15). GhostPay Mesh may disclose such records in response to lawful court orders or competent authority requests, in accordance with Article 10 and 22 of the Marco Civil da Internet.
Anti-Money Laundering Compliance (Lei 9.613/1998 / COAF)
GhostPay Mesh is a technology infrastructure protocol, not a financial institution. Financial settlement is performed exclusively by ASAAS Gestão Financeira Instituição de Pagamento S.A., which bears primary AML/KYC obligations as a regulated payment institution under supervision of Banco Central do Brasil and COAF (Conselho de Controle de Atividades Financeiras).
GhostPay Mesh cooperates fully with competent authorities and provides cryptographic audit records and metadata as required by law. Use of the Service to conceal the origin of illicit funds or evade AML requirements is strictly prohibited and will result in immediate suspension and reporting to competent authorities, including COAF and law enforcement.
Regulatory Framework Reference
The following regulatory instruments are relevant to the context in which GhostPay Mesh operates and to the obligations of its regulated settlement partner (ASAAS):
- Lei 12.865/2013 — Regulates payment institutions and arrangements in Brazil (basis for ASAAS's authorization).
- Resolução BCB 80/2021 — BACEN rules on payment institutions; applies to ASAAS as the regulated partner.
- Lei 9.613/1998 / COAF — Brazilian Anti-Money Laundering Law; obligations held by ASAAS as the regulated institution.
- Lei 13.709/2018 (LGPD) — Brazilian General Data Protection Law; applies to GhostPay Mesh's minimal data processing.
- Lei 12.965/2014 (Marco Civil) — Brazilian Internet Civil Framework; governs data retention obligations for internet applications.
- Lei 14.478/2022 — Brazilian framework for virtual asset service providers; classification of GhostPay Mesh as a technology protocol, not a VASP, is maintained based on its non-custodial, non-exchange nature.
Force Majeure
GhostPay Mesh shall not be liable for any delay or failure in performance resulting from causes beyond its reasonable control, including but not limited to: acts of God, natural disasters, governmental actions, cyberattacks, infrastructure outages by third parties, Internet service provider failures, pandemic, or war. The affected party will notify the other party promptly and use reasonable efforts to mitigate the impact.
Severability and Entire Agreement
If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. These Terms constitute the entire agreement between you and GhostPay Mesh with respect to the Service and supersede all prior agreements, representations, or understandings on the same subject matter.