The short version
This policy covers Gao on the web and the Gao app. Gao on the web and the Gao app are one product with one identity model and one set of capabilities. What is available to you at a given moment can still differ — by platform, by how far a feature has been rolled out, by whether you are online, by permissions you have granted, by any subscription you have connected, and by whether a capability is ready. Where availability differs, the parts of this policy that depend on that feature do not yet apply to you.
Gao keeps some things on your device, some things on our servers, and sends a small, specific set of things to services you or we connect. This policy is organised that way.
On your device. Your Work. Your My World — the people, memories and events in your private record. Your preferences. And, in the app, your wallet's keys. We do not receive any of it, and we cannot read it, restore it or delete it for you.
On our servers. Your Gao ID and your session. The public World — places, businesses, events, communities, profiles. Anything you post or send. Records of requests you make to an AI model. And files you upload.
Sent to others, when you use the feature that needs it. The Gao ID service that issues your identity. An AI provider, when you ask a question. Map and media services. Your wallet's connection infrastructure.
We are not going to tell you "everything stays on your device", because your identity, the World and your messages could not work that way. We are also not going to tell you Gao stores everything, because your Work and My World genuinely do not leave your device unless you ask them to.
Your device
What is stored there
Work — your objectives, work items, notes, references and routines. My World — the people, relationships, memories, events and sources in your private record, including any photos or files you attach to a memory. Preferences and cached data so Gao opens quickly. In the app: your wallet's private key and recovery material, protected by your device's secure storage.
What we receive from it
Nothing, in ordinary use. Creating, editing, archiving and searching your Work and My World happen on your device, and there is no background sync.
Two things are worth naming exactly:
- Connected intelligence. A bounded part of your Work, and anything from My World you pick, is sent when you ask for it. Section 5 says what.
- Work from before Gao moved Work onto the device. Those earlier records were kept on our servers. Gao copies them onto your device once and never writes back, but the copy on our servers is still there; deleting your Gao App account removes it, and nothing else does.
Anything you upload is a separate matter, in section 3.6.
What that means for you
This is real privacy, and it has a real consequence: you are the only backup.
- If you clear the app's data, sign out of your device account, switch device, or lose the device, that data is gone. We cannot bring it back.
- We cannot produce it in response to a legal request, because we do not have it.
- Anyone who can unlock your device or use your browser profile can reach it.
- Gao is separated by account: signing in with a different Gao ID opens that identity's own separate store on this device. It will be empty if that identity has nothing stored here yet.
Please export your Work and My World from time to time. Section 9 explains how.
Deleting it
Work: archiving an item hides it; the record stays on your device. My World: forgetting a record genuinely destroys its content and every earlier version of it, along with any files only that record used. Everything: you can delete the whole local store from your device.
Our servers
Your account
Your Gao ID, the public wallet address you sign in with, and your account details: display name, profile photo, short bio, city, Gao domain name, trust level and badges, and your visibility and location settings.
We do not collect an email address, a phone number or a password. Gao has no sign-in that asks for one, so we hold nothing that would let us reach you outside Gao — no address to email, no number to text. Inside Gao we can reach you: notices appear in the product and in your Activity. If you want to reach us, the addresses are in section 17.
Your sessions
Each time you sign in, and each time your session is quietly renewed, we record a scrambled form of your session token, your IP address and a description of the device or browser you signed in from, along with timestamps. We use this to keep you signed in, let you end sessions, and detect abuse.
Signing out ends every session on every device.
Being straightforward about retention: session records expire after 90 days, and a routine exists to remove expired ones, but it does not currently run on a schedule, so a record can outlive its expiry.
The Gao ID service that issues your identity handles this more carefully than we do: it keeps only a shortened version of your IP address and a scrambled description of your device. One exception works the other way: its abuse-prevention counters record your full IP address before you sign in, and the routine that clears them is currently switched off.
Your profile and what you publish
Your profile, and a separate work profile if you create one — headline, biography, industry, skills, work history, education, languages, salary expectations, portfolio link and location. Both are public by default. Businesses, events and communities you create hold what you enter, including contact details and addresses you choose to publish.
Your profile picture is public, is served without requiring anyone to sign in, and is cached for a long time. We do not currently strip location and camera information from images before publishing them, so please remove that information before uploading a photo, and note there is no way to delete a profile picture once uploaded — only replace it.
What you post and send
Posts, comments and reactions; reviews; direct messages; kisses; time capsules; signals and offers; follows and saved items; notifications.
Two things you should know:
- Messages are not end-to-end encrypted — a direct message and a message in an event or circle are the same in this respect. They are stored on our servers as ordinary text and are technically readable by us. The notice we create for the recipient keeps the first 100 characters of the message as well. Please do not use Gao messages for anything that needs to be confidential from us. There is currently no way to delete a message.
- Kisses record where both the sender and the recipient were. Time capsules record a location too.
Location
We store your exact coordinates. The approximate area other people see is applied when your location is *shown*, not when it is stored.
Coordinates are stored for: your account, your work profile, each check-in you make, kisses, time capsules, signals you attach a location to, gift-card redemptions, and the venues of businesses and events you publish. Over time, your check-ins are a record of places you have been.
Who can see your location:
| Your setting | A stranger or someone signed out | Someone you both follow, or share a community with | You |
|---|---|---|---|
| Off, or sharing expired | nothing | nothing | exact |
| Approximate *(the default)* | about a 1 km area | about a 1 km area — never exact | exact |
| Exact | about a 1 km area | exact | exact |
| Friends | nothing | exact, for a mutual follow | exact |
| Communities | nothing | exact, for a shared community | exact |
| Not set | nothing | nothing | exact |
If you give an event organiser a location grant, that event's authorised attendees can see your exact position while it lasts. Venues you publish for an active business or event are treated as public places.
How we get it: only from your device's location service, with your device's own permission prompt. We never work out your location from your IP address. The World map asks for permission as soon as you open it; you can refuse, and Gao still works.
On your device: your last position is kept at full precision, and nothing currently removes it — including signing out. Clearing Gao's data removes it.
Files you upload
Files you upload for posts, profile pictures and reviews, and files you attach to your Work, are stored on our servers. Uploaded files are not deleted — there is currently no deletion path, so a file stays even after the post that used it is removed, and deleting your Gao App account does not remove it either. This does not apply to files attached to a My World memory, which never leave your device.
AI requests
See section 5.
Safety records
If you block or mute someone, we store that. If you report someone, we store the report — the subject, the reason you chose, and anything you wrote.
Points, gift cards, bookings and check-ins
Your Gao Points balance and how it changed; gift cards you hold or issue, including any message and where a redemption happened; bookings including any note you added; check-ins with their location.
What we do not collect
- No analytics. Gao includes no analytics or product-tracking software of its own — no Google Analytics, no equivalent. Section 4.2 describes telemetry sent by the wallet component, which is not ours.
- No crash reporting or session replay.
- No advertising, and no advertising or tracking cookies.
- No email or text messages — we hold no address or number and cannot send one.
- No tracking pixels or social-media widgets. The only embedded third-party content is the video player on the Live surface.
- We never receive your camera feed. Two features use your camera — the try-on page and the gift-card scanner — and both process the video entirely on your device. Only a scanned code is sent.
- We never receive your wallet's private key or recovery phrase, on any platform.
- We never receive your fingerprint or face data. Where the app uses biometrics to authorise wallet use, that check happens on your device, by your device.
Services we connect to
The Gao ID service
Signing in sends your wallet address, the network it is on, the sign-in message and your signature to the Gao ID service, which issues and holds your identity. It also holds organisations and memberships, which are keyed to Gao identities — an invitation never contains an email address, and you cannot invite someone who does not already have a Gao ID.
That service also offers a lookup that will create an identity record for a wallet address it has not seen before, without anyone signing in. It grants no access to anything, but it does mean a record can be created for a public address by someone other than its owner.
Your wallet's connection infrastructure
In the app, your wallet lives on your device: the key stays there and signing happens there, and this path does not use the WalletConnect infrastructure described next. Using Gao still involves Gao's own services, and anything that reaches a blockchain network involves that network.
On the web, connecting a mobile wallet uses WalletConnect infrastructure operated by Reown. Your browser then contacts their services, which see your IP address and connection details.
To be exact about telemetry: the wallet component we include on the web sends its own usage information to its vendor by default, and we have not switched that off. It runs whenever that component loads. We do not operate analytics ourselves — this is a third-party component reporting to its own vendor, and what it reports is defined by that vendor, not by us.
Address lookup
When you type an address into a business, event, community or signal form, your browser or app sends that text directly to OpenStreetMap's public address service, which sees your IP address and what you typed. One feature also sends coordinates there to look up a city name.
AI providers
See section 5.
Images and assets
Placeholder images for events come from an image service, which sees your IP address. The try-on feature downloads its hand-tracking model from a content network when you start the camera — no image or video is sent there. A mapping service is used only if global place search is enabled; it is currently off.
Services our servers use
Our AI provider (section 5); market-data and news sources for the Live widget, which receive nothing about you; and our hosting provider, which processes all traffic to Gao.
Intelligence and AI
The full version is in the AI and Connected Intelligence Notice. This is the data part.
Some of it never leaves your device
Searching your Work and My World, and structured questions about your own records — what you are owed, what conflicts, when you last saw someone — run entirely on your device. No model, no network, and what you type is not sent anywhere.
One search box does not mean one request. Results from your Work and My World are found on your device and merged there. Only the public part of a search — places, people, businesses, events — reaches our servers, and it never carries anything from your Work or My World.
Ask Gao
Ask Gao helps you find public things. Your question goes to our servers, which send it to an AI model we operate under our own account, along with whether your location is known and a list of candidate public businesses and events. Our provider for this is currently Anthropic.
It never receives anything from your Work or My World.
Connected intelligence
To use the Studio conversation you connect your own AI provider subscription, signing in with that provider directly, in that provider's own software on your own computer through the Gao Local Companion — a small program you install and pair with your Gao ID.
What is sent: a bounded slice of your Work — at most 10 objectives, 25 work items and 5 notes, with titles up to 200 characters and note text up to 1,200 characters — together with your message. Opening the Studio conversation sends that slice once so we can check it and show you exactly what would go; that copy is not stored.
You may also choose, for one message at a time, to include specific people, memories and events from My World. Their names, and memory titles and text, are then included. This is off unless you choose it; a record you have marked as staying on your device is never included even if you select it; and memories are marked that way by default.
Gao shows you what will be sent before you send it.
Where it goes: your device → our servers → temporary storage for at most 15 minutes, deleted on delivery → the Gao Local Companion on your own computer → your provider's own software → your provider. Your computer asks our servers for the work over a connection it opens itself; we never connect to your computer, and only the computer that proves it holds the key the work was written for receives it.
What we keep
| Your message | The model's answer | |
|---|---|---|
| An ordinary request | Stored on our servers, with no automatic expiry | Stored on our servers, with no automatic expiry |
| A request that includes My World content | Not stored — held briefly, then deleted | Not stored — the same |
Which one applies is decided by our servers from the request itself. Neither you nor anything on your device can switch it on or off.
For every request we also keep a record with no content in it: how much was included, a fingerprint, which provider ran it, and what happened.
The Companion on your computer reports the answer to our servers. For an ordinary request that report is the copy we keep; for a request that includes My World content it passes through temporary storage for at most 15 minutes and is deleted when your device receives it.
How long these are kept is set out in full in the [AI and Connected Intelligence Notice](/ai), section 6.4 — the request, the answer, the copy held while it is delivered, and what disconnecting a provider, deleting a conversation or deleting your Gao App account do to each. In short: an ordinary request and its answer are kept for as long as your Gao App account exists and are deleted with it; nothing expires them earlier.
None of this applies to the parts of Studio that run on your device — searching your own records and structured questions about them produce nothing for us to keep, because nothing is sent.
Your provider sign-in
Your provider's own software runs on your own computer, through the Gao Local Companion, and signs in to your provider there. Gao never holds your provider sign-in. It is not sent to our servers, our own code does not read, copy or export it, and our records have no place to put a provider password, key or session.
What our servers hold about a request is what you asked, the boundary the software was allowed to run under, and — for an ordinary request — the answer, as set out in 5.4. Your computer has to be on while your provider answers; we never run your provider's software for you.
Disconnecting a provider is something you do in your provider's software on your computer. There is nothing on our side to remove.
Storage on your device and in your browser
The Cookie and Local Storage Notice covers this in full: the small number of cookies needed to sign you in and keep your account secure; local storage for your last position, recent searches and preferences; the database holding your Work and My World; and, in the app, your device's secure storage for wallet material.
Why we use your information
| Purpose | What we use |
|---|---|
| Signing you in and keeping you signed in | Gao ID, wallet address, session records including IP and device description |
| Showing you the World, and you to it | Profile, what you publish, location at the precision your setting allows |
| Delivering messages and notifications | Message content, participants, notification records |
| Answering with AI | Your question, and what section 5 describes |
| Preventing abuse and keeping Gao secure | IP address, session records, abuse counters, block/mute/report records |
| Operating and fixing Gao | Error logs |
| Meeting legal obligations | Whatever the obligation requires |
We do not use your information for advertising, for commercial profiling, or for automated decisions that have legal or similarly significant effects on you.
Who can see your information
Other people, according to your visibility settings and the location table in 3.5. Anyone on the internet, for anything public — several things are public by default, and your profile picture is public regardless. The services in section 4. Anyone we are legally required to disclose to — and we can only disclose what we hold, which excludes what is on your device. A successor, if the business is reorganised or sold, on notice.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Your choices
| You want to | How, today |
|---|---|
| Stop sharing your location | Set location sharing to Off, or refuse the permission |
| Change who sees your profile | Public, communities-only or private, in settings |
| Change who sees something you posted | Set its visibility |
| End your sessions | Sign out — this ends every session on every device |
| Get a copy of your Work and My World | Export from Gao; it works without a network connection |
| Delete your Work or My World | Forget individual My World records, or delete the whole local store |
| Delete a post, comment, reaction, event or signal | Delete it in Gao |
| Stop seeing someone | Block or mute them |
| Delete your Gao App account | In the Gao app: Me › Delete Gao App account — or write to privacy@gao.global. What it deletes, what it keeps with your name removed, and what it does not touch is set out on the account-deletion page |
| Delete other content | Not available in Gao today. Write to privacy@gao.global |
We would rather be plain than imply a control we have not built. Deleting your Gao App account is the one account control that exists. It deletes the account Gao keeps for you and the information listed on the account-deletion page; it keeps records that other people depend on — a business, event or community you created, a booking or gift card a business holds, a message you sent into a conversation — with your name and identity removed; and it keeps the record of the deletion request itself, so that a repeated request is recognised. It does not delete your Gao ID. Gao ID is your permanent identity across Gao products: the service that issues it keeps your identity, your wallet binding and your Gao ID profile, and removes only what it holds for this product — your Gao App profile there and your notifications. Signing in again later gives you a new, empty Gao App account under the same Gao ID; the deleted information does not come back. There is no export of the information on our servers, and several kinds of content cannot be deleted one at a time. Requests to privacy@gao.global are handled by hand.
Note that archiving Work, forgetting a My World record, disconnecting an AI provider and removing a wallet from your device are all different from deleting your Gao App account — and all five are different from deleting your Gao ID, which Gao does not offer.
How long we keep things
| How long | |
|---|---|
| Your Gao App account | Until you delete it, in the app or by request; the record of the deletion request is kept |
| Your Gao ID | Kept — it is your permanent identity across Gao products and is not deleted with a Gao App account |
| Session records, including IP and device description | 90-day expiry; removal is not currently scheduled |
| Identity-service session records | Kept after being revoked |
| Pre-sign-in abuse counters containing full IP addresses | Clearing is currently switched off |
| AI request text held in transit | At most 15 minutes |
| AI request and answer, ordinary requests | Until you delete your Gao App account; no automatic expiry is set before then — the full position is in the AI and Connected Intelligence Notice |
| Records with no content in them | Kept until you delete your Gao App account |
| What you post | Until you delete it, or delete your Gao App account; otherwise kept |
| Uploaded files | Kept — no deletion path exists, and deleting your Gao App account does not remove them |
| Profile pictures | Kept — one on your Gao ID stays with your Gao ID, and an uploaded picture file stays like any uploaded file; there is no way to delete one, only replace it |
| Work and My World on your device | Entirely up to you |
Where no period is given, it is because Gao does not currently enforce one, and we will not imply otherwise.
Security
Session tokens are stored only in scrambled form and delivered so that page scripts cannot read them. We protect against other sites acting as you, and limit request rates. Signing in relies on a wallet signature rather than a password we could lose. In the app, wallet keys are held in your device's secure storage and, where you enable it, released only after a device check such as a fingerprint or face check — which happens on your device and is never sent to us. Requests to a connected AI provider run on your own computer; our servers hand that work only to the computer that proves it holds the key the work was written for.
No service is completely secure, and we do not claim Gao is.
Where your information is processed
Gao runs on a global network, and the services in section 4 operate internationally.
Children
Gao is not intended for children under 13 years old. We do not knowingly collect information from children under that age. Contact privacy@gao.global if you believe we have.
Your rights
Depending on where you live, you may have rights to see, correct, delete, restrict or object to our use of your information, and to receive a copy of it.
Please read this together with section 9. Several of those rights have no button in Gao today; some — such as deleting what is on your device — we could not carry out even if you asked, because we do not have it. Deleting your Gao App account can be carried out in the app or by request (section 9); deleting your Gao ID cannot, because Gao ID is your permanent identity across Gao products. Other requests go to privacy@gao.global.
App stores
If you install the Gao app, the app store you use has its own relationship with you and its own privacy practices. We also provide the store with the disclosures it requires about what Gao collects.
Changes
The date this policy was last updated is shown at the top of this page, and its effective date will be shown there once it is published as the effective policy. Material changes will be announced in Gao. We cannot email you, because we hold no address.
Contact
Toii Social LLC, a Delaware Limited Liability Company · Delaware, United States · privacy@gao.global