Skip to content

RA 10173 · RA 10175

Privacy policy and telemetry notice

Effective September 1, 2026. Written to comply with Republic Act No. 10173 (Data Privacy Act of 2012) and Republic Act No. 10175 (Cybercrime Prevention Act of 2012).

  • End-to-end encryption

    Messages and tasks are client-side encrypted using ECDH and AES-GCM. Plaintext never touches servers.

  • Store-and-forward

    Encrypted messages are purged from server storage immediately once delivery receipts are acknowledged.

  • 180-day retention floor

    Traffic telemetry is strictly maintained for 180 days pursuant to RA 10175 Section 13 statutory mandate.

01

Sub-processor and telemetry disclosures

To maintain system integrity, tamper-evident security audit logs and traffic telemetry are processed using Cloudflare D1 (APAC location hint) and cold-archived to Cloudflare R2. Audit records include timestamp, actor identifier, action type, IP address, user-agent string, and contextual event metadata.

02

Statutory retention and storage limitation

In accordance with Section 13 of Republic Act No. 10175 (Cybercrime Prevention Act of 2012), traffic telemetry must be preserved for a minimum period of six (6) months (180 days). Under Section 11 of Republic Act No. 10173 (Data Privacy Act of 2012), personal data is not retained longer than necessary. Telemetry exceeding 180 days is automatically compressed into encrypted, tamper-evident NDJSON archives and securely removed from operational databases.

03

Data subject rights (RA 10173 §16)

Users possess the statutory right to request access, rectification, and erasure of their personal information. When an account erasure request is processed pursuant to Section 16(e), personal identifiers in account databases are permanently sanitized, and historical telemetry across connected databases is scrubbed of direct actor linkages.

To make a request, email support@glgspace.com.

04

Security measures and immutability

Operational audit trails are governed by database triggers that strictly prohibit ad-hoc UPDATE or DELETE operations. The append-only design guarantees evidential integrity for Data Protection Officer (DPO) and National Privacy Commission compliance inspections.

05

Third-party AI sub-processors

Your encrypted chat messages, tasks, and files are never sent to any AI sub-processor. End-to-end encryption (Section 1) means we could not send that content even if we wanted to, since our servers never hold the decryption keys. The two features below are the only places this product sends any text to a third-party AI provider, and each runs only when a user explicitly triggers it, never in the background, and never on messages marked confidential.

Fleet dispatch notepad (/fleet)

Sub-processor: Google, LLC (Gemini API). What is sent: the raw dispatch schedule text you paste into the notepad: truck plates, crew and client names, delivery addresses. This is operational routing data you type in for parsing, not a chat message. Production traffic is restricted to a billing-enabled, paid-tier API key; under Google’s paid-tier terms, submitted content is not used to train or improve its models. Every submission is individually logged as a compliance audit event. If AI parsing is unavailable, the same text is parsed entirely on your device instead.

AI meeting summary

Sub-processor: Cloudflare, Inc. (Workers AI). What is sent: the call transcript and speaker names, only when a user requests an AI-generated summary after a call ends. Cloudflare’s Workers AI is private by default: prompts and completions are not used to train any model and are not retained beyond generating the response. The generated summary is delivered back to you as a draft for review. It is never written to our servers automatically; it is sent only if and when you choose to send it, through the same end-to-end encrypted pipeline as any other message.

In short: information you choose to run through these AI features is transmitted securely (TLS in transit), used solely to generate the requested result, is not retained by the sub-processor beyond that request, and is not used to train their models under the terms above. Nothing reaches either provider unless you explicitly initiate the action.