GLongP

Privacy Policy

Last updated: 2026-10-07 · G'LongP Technology Corp

GLongP is an end-to-end encrypted messaging and calling app. This policy describes exactly what the app stores on your device, what it sends to our servers, and which third parties are involved. It reflects how the app actually works, feature by feature.

The short version. Your recovery phrase and the keys derived from it never leave your device. Message and call content is end-to-end encrypted — our relay server passes ciphertext it cannot read. We do not use any advertising or analytics SDK, and we do not sell data.

1. Your account identity

When you first open GLongP, the app generates a 12-word recovery phrase on your device. Everything else is derived from it: your account address, the key that encrypts your messages, and the keys that encrypt your local database and vault. We never receive the phrase, and we cannot regenerate it for you.

Your account address is a text identifier such as glp1…. It is what other people add to reach you, and what our relay uses to route messages — nothing more.

2. Data stored only on your device

If you uninstall the app or lose the device without your recovery phrase, this data is unrecoverable. We cannot restore it for you, because we never had it.

3. Data sent to our servers

DataWhyRetention
Account address Route messages and calls to youWhile the account is in use
Display name and public key Shown to people you add as contactsWhile the account is in use
Push tokens (Apple / Firebase) Deliver call and message notifications when the app is closed Until replaced or you delete your account
Encrypted message content Relayed to the recipient Queued only while the recipient is offline, deleted on delivery or after at most 30 days
Encrypted photos and files Downloaded by the recipient Deleted after at most 30 days
Group name, group ID and member list Group membership managementUntil the group is dissolved
Reports you file about other users (your address, the reported address, reason, note) Review abuse reports within 24 hoursUntil the report is resolved
IP address Rate limiting to block abuse such as floodingNot stored with your account
Online / offline presence Show contacts whether you are reachableNot stored after disconnect

What our servers cannot see

Private messages, group messages, shared photos and files are encrypted on your device with a key that only you and the recipient hold. Voice and video calls are peer-to-peer and encrypted (DTLS-SRTP). Our servers relay the encrypted bytes and the signalling needed to set up a call; they cannot decrypt the content.

Our servers can necessarily see metadata: which addresses exchange messages, when, and approximate sizes. We do not use this for profiling.

4. Third parties

ServiceWhat it receivesWhen
Apple Push Notification servicePush token, encrypted notification payload Incoming calls and messages (iOS)
Google Firebase Cloud MessagingPush token, notification payload Incoming calls and messages (Android)
Our relay / TURN serverIP address, encrypted call media Only when a direct device-to-device connection is not possible

We do not embed advertising networks, analytics SDKs or social media trackers.

5. Device permissions

The app requests no location permission of its own and does not collect your location. A system library may declare one; we do not read or transmit it.

6. What we do not do

7. Your choices

In the app, Profile → Delete account wipes your device and deletes your server-side data (push tokens, queued messages, public key, uploaded files and group memberships) in one step. You can also email us — see Delete Your Data. You can revoke camera, microphone, photo and notification permissions in system settings; the related features stop working but the rest of the app continues.

8. Children

GLongP is not directed at children under 13, and we do not knowingly collect data from them.

9. Changes and contact

Material changes will be published on this page with a new date. Questions or requests: glongptech@gmail.com.

Chính sách quyền riêng tư

Cập nhật: 2026-10-07 · G'LongP Technology Corp

GLongP là ứng dụng nhắn tin và gọi thoại/video mã hoá đầu-cuối. Chính sách này mô tả đúng những gì ứng dụng lưu trên máy bạn, những gì gửi lên máy chủ, và các bên thứ ba liên quan.

Tóm tắt. Cụm từ khôi phục và các khoá dẫn xuất từ nó không bao giờ rời khỏi máy bạn. Nội dung tin nhắn và cuộc gọi được mã hoá đầu-cuối — máy chủ chỉ chuyển tiếp dữ liệu đã mã hoá và không đọc được. Chúng tôi không dùng SDK quảng cáo hay phân tích hành vi, và không bán dữ liệu.

1. Danh tính tài khoản

Lần đầu mở GLongP, ứng dụng sinh cụm từ khôi phục 12 từ ngay trên máy bạn. Mọi thứ khác dẫn xuất từ nó: địa chỉ tài khoản, khoá mã hoá tin nhắn, và khoá mã hoá cơ sở dữ liệu cùng kho tài liệu cục bộ. Chúng tôi không bao giờ nhận cụm từ này và không tạo lại được cho bạn.

Địa chỉ tài khoản là một chuỗi dạng glp1… — người khác dùng nó để kết bạn với bạn, và máy chủ dùng nó để định tuyến tin nhắn. Chỉ vậy.

2. Dữ liệu chỉ nằm trên máy bạn

Gỡ ứng dụng hoặc mất máy mà không có cụm từ khôi phục thì dữ liệu này không thể lấy lại. Chúng tôi không khôi phục được, vì chưa từng có nó.

3. Dữ liệu gửi lên máy chủ

Dữ liệuMục đíchThời gian lưu
Địa chỉ tài khoảnĐịnh tuyến tin nhắn, cuộc gọi Trong thời gian còn dùng
Tên hiển thị và khoá công khaiHiển thị cho người bạn kết bạn Trong thời gian còn dùng
Token thông báo đẩy (Apple / Firebase) Báo cuộc gọi, tin nhắn khi ứng dụng đã đóngTới khi thay hoặc xoá tài khoản
Nội dung tin nhắn đã mã hoáChuyển tiếp tới người nhận Chỉ xếp hàng khi người nhận offline, xoá khi đã giao hoặc sau tối đa 30 ngày
Ảnh và tệp đã mã hoáĐể người nhận tải về Xoá sau tối đa 30 ngày
Tên nhóm, mã nhóm, danh sách thành viênQuản lý nhómTới khi giải tán nhóm
Báo cáo vi phạm bạn gửi (địa chỉ của bạn, địa chỉ bị báo cáo, lý do, ghi chú) Xem xét báo cáo trong 24 giờTới khi xử lý xong
Địa chỉ IPGiới hạn tần suất để chặn lạm dụng như gửi dồn dập Không lưu kèm tài khoản
Trạng thái online/offlineCho biết bạn có đang trực tuyếnKhông lưu sau khi ngắt

Máy chủ không thấy được gì

Tin nhắn riêng, tin nhắn nhóm, ảnh và tệp được mã hoá ngay trên máy bạn bằng khoá chỉ bạn và người nhận có. Cuộc gọi đi trực tiếp giữa hai máy và được mã hoá (DTLS-SRTP). Máy chủ chỉ chuyển tiếp dữ liệu đã mã hoá.

Máy chủ buộc phải thấy siêu dữ liệu: địa chỉ nào trao đổi với địa chỉ nào, vào lúc nào, kích thước xấp xỉ. Chúng tôi không dùng dữ liệu này để lập hồ sơ người dùng.

4. Bên thứ ba

Dịch vụ đẩy thông báo của Apple và Google nhận token thiết bị và nội dung thông báo. Khi hai máy không kết nối trực tiếp được với nhau, máy chủ chuyển tiếp (TURN) của chúng tôi nhận địa chỉ IP và dữ liệu cuộc gọi đã mã hoá.

Chúng tôi không nhúng mạng quảng cáo, SDK phân tích hay trình theo dõi mạng xã hội.

5. Quyền trên thiết bị

Ứng dụng không thu thập vị trí của bạn.

6. Chúng tôi không làm gì

7. Quyền của bạn

Trong ứng dụng, Cá nhân → Xoá tài khoản sẽ xoá sạch dữ liệu trên máy và xoá dữ liệu phía máy chủ (push token, tin nhắn còn chờ, khoá công khai, tệp đã tải lên, tư cách thành viên nhóm) trong một bước. Bạn cũng có thể gửi email — xem Xoá dữ liệu.

8. Trẻ em

GLongP không hướng tới trẻ em dưới 13 tuổi và chúng tôi không cố ý thu thập dữ liệu của các em.

9. Thay đổi và liên hệ

Mọi thay đổi quan trọng sẽ đăng tại trang này kèm ngày mới. Liên hệ: glongptech@gmail.com.