Privacy Policy
App name: GMSS
Developer: GMSS
Last updated: 26 August 2026
Effective date: 26 August 2026
This Privacy Policy (the “Policy”) explains how the GMSS app and its related services (the “App” or “we”) access, collect, use, store, share, and delete user data and device data. Please read it carefully before using the App. If you do not agree with this Policy, please stop using the App.
This Policy applies to the GMSS Android app published on Google Play (package name: hk.gmss.android) and the accompanying message relay service.
1. Developer information and contact
Developer name: GMSS
App name: GMSS
If you have questions, comments, complaints, or requests about this Policy or our handling of personal information, contact us through the developer email listed on the App’s Google Play store listing. If you received this service through your organization, you may also contact that organization’s administrator.
2. Information we collect
We process data only as needed to provide the App’s features and as you would reasonably expect. The App does not show ads, does not sell personal data, and does not collect contacts, precise or approximate location, photos, microphone audio, SMS, or call logs.
2.1 Account and binding information
The App does not offer public self-registration. Organization administrators generate pairing codes on the GMSS platform. When you scan or paste a pairing code and confirm joining, we process:
- Instance code, user code, group code, and pairing code, used to bind this device to the organization’s service and to route push messages;
- An optional device label, used to identify the device in the admin console.
2.2 Device and push identifiers
- Firebase Cloud Messaging (FCM) registration token: used to deliver notifications to this device;
- Platform type (for example, Android): used for compatibility;
- Last-seen time: used to determine whether the device can still receive messages.
2.3 Message content
Notification titles, bodies, and extra data sent by an organization through GMSS are relayed by our servers and delivered by Google Firebase to this device. The App stores recent messages locally so you can read them in the App. The server keeps send logs (including title, body, target, status, and time) for delivery and troubleshooting.
2.4 Camera
The App requests camera permission only to scan pairing QR codes for binding. Camera frames are processed on-device in real time. We do not upload, store, or share your photos, videos, or camera frames.
2.5 Notification permission
On Android 13 and later, the App requests notification permission so it can show pushes in the system tray. You can turn notifications off at any time in system settings.
2.6 Information we do not collect
- Name, phone number, email, or other identity details you would type in (the App has no such forms);
- Location, contacts, SMS, call logs, photo library, or microphone recordings;
- Advertising ID (AAID) or identifiers used for ad personalization;
- Payment information or government ID numbers.
3. How we use information
Collected information is used only to:
- Bind and unbind devices to organization instances, and manage topic subscriptions;
- Deliver push notifications sent by the organization to bound devices;
- Show message history in the App and send logs in the admin console;
- Protect the service, troubleshoot issues, and prevent abuse;
- Meet legal requirements or valid requests from competent authorities.
We do not use this data for advertising, user profiling, or sale to third parties.
4. How we share information
We do not sell personal or sensitive user data. We share data only in these cases:
- Google Firebase Cloud Messaging (Google LLC): to deliver pushes we provide Google with the FCM token and notification payload. Google processes that data under its own privacy policy;
- The organization that provisioned your service: pairing codes, user codes, and group codes are provided or managed by that organization. It can send messages to its members through the GMSS API and, within its admin rights, view related binding and send records;
- Legal requirements: when required by applicable law, valid legal process, or to protect users and the public.
We do not share your personal data with ad networks, analytics vendors, or data brokers beyond the cases above.
5. Third-party services
The App integrates the following third-party services, which handle data under their own policies:
- Google Firebase Cloud Messaging: for push registration and delivery;
- Google Play services: for app distribution and Google components on the device.
Please also read Google’s privacy policy. We require these services to use data only to provide the relevant features.
6. Data security
We take reasonable administrative and technical measures to protect user data, including:
- Admin access requires sign-in; open APIs are authenticated with instance keys;
- In production, traffic between the client and GMSS servers should use HTTPS;
- The Firebase channel is encrypted by Google;
- Internal access is limited to operating the service and troubleshooting.
No internet transmission or electronic storage is 100% secure. If a security incident may affect your rights, we will notify you as required by applicable law.
7. Retention and deletion
- Device binding data: kept until you unbind or the organization disables the instance, so messages can still be delivered;
- Message send logs: kept for delivery and audit, and cleaned up after a period or as operations require;
- On-device message history: stored on this device and removed if you uninstall the App or clear app data;
- FCM tokens: no longer used after unbind; expired tokens are not used for delivery.
You can Unbind a bound instance on the App’s Instances screen. After unbind, this device will no longer receive that instance’s messages, and we delete the binding between the device and the corresponding account. Unbind is not the same as deleting the organization’s user-code record. To delete organization-side account data, contact the administrator who provisioned the service, or contact us using the details in this Policy. After a valid deletion request, we delete the related user data instead of only freezing the record, except where law requires retention, which we will explain at the time.
8. Your rights
To the extent applicable law allows, you may:
- Read this Policy and the types of data we process;
- Unbind to stop the App from further processing binding and push data on this device;
- Revoke camera or notification permission in system settings; without camera permission you cannot scan to bind, and without notification permission the system tray will not show pushes;
- Request correction or deletion of data about you;
- Ask questions about this Policy.
To exercise these rights, use the contact details in “Developer information and contact”. We will respond within a reasonable time.
9. Children’s privacy
The App is for receiving organization messages. It is not directed at children and is not intended for children under 13 (or a higher age required in your region). We do not knowingly collect children’s personal information. If you believe we collected a child’s personal information by mistake, contact us and we will delete it promptly.
10. Permissions
- Internet: to reach GMSS servers and Firebase for binding, message sync, and push delivery;
- Camera: only to scan pairing QR codes; not used to capture or upload images;
- Notifications: to display push notifications. You may refuse; you can still view messages already synced in the App, if any.
11. Changes to this Policy
We may update this Policy from time to time. The updated Policy will be published on this page and will also be available in the App. For material changes, we will notify you in the App or by other reasonable means. If you continue to use the App after an update, you have read and understood the updated Policy.
12. Other terms
Headings are for convenience only and do not affect meaning. If any clause is held invalid, the remaining clauses still apply. This Policy is interpreted and applied under the laws of the place where the App is provided. If this Policy conflicts with mandatory law, the law controls.
The Chinese and English versions of this Policy are both official texts for Google Play and in-app display. The language you see depends on the language you choose in the App or the language parameter of this page.