GLO / PRIVACY

Privacy Policy

01 / Official GLO service

1. Account information

Google sign-in supplies your Google subject identifier, email and display name. GLO stores those fields to identify your account and associate sessions with it. GLO does not receive your Google password. Login tokens are stored as hashes in the service database.

2. Session, network and operational data

The service processes source IP addresses, selected game, relay assignment, session identifiers and timestamps, expiry and session state. Operational metrics can include session and gameplay duration, transferred bytes, relay latency, capacity, errors and security events. These support routing, session enforcement, troubleshooting, capacity planning and abuse prevention.

Relays necessarily process the game packets they forward and their destination addresses. Routing only supported game traffic is not a promise of anonymity or of zero logging. GLO does not route all of your browsing traffic through the game relay.

3. Cookies and browser storage

The account website uses a Secure, HttpOnly login cookie and an anti-forgery cookie/token. Browser storage remembers language, theme and asset refresh state. The administrator panel stores its access token and expiry in localStorage; signing out removes those local credentials. Clearing browser data removes local preferences and may require another sign-in.

4. Advertising

GLO does not inspect or collect routed game traffic for advertising purposes.

5. Session configs and encryption

The generic desktop client receives a short-lived config containing relay details, a relay public key, a game profile and a signed grant. It does not receive the website’s Google login credential or web session token. Treat a config as a secret: someone with an unused config may be able to redeem it.

The client-to-relay tunnel uses encryption. Protection from relay to game server depends on the game’s own protocol. This does not provide end-to-end encryption between you and the game beyond what the game itself supports.

6. Providers and international routing

Google processes sign-in requests, Cloudflare delivers or protects the website/API where configured, and hosting/network providers carry traffic and host service systems. Those providers process data under their own terms and roles. Relays in other regions may process your game traffic outside your country. A route shown on the homepage is not a promise of data residency.

When Turnstile is enabled, Cloudflare processes verification challenges and related browser or network signals for protected service actions, including sign-in and requests for a new session config.

Google Privacy Policy ↗ · Cloudflare Privacy Policy ↗

7. Retention and account requests

Expired login challenges and expired or revoked login records are eligible for periodic cleanup. Non-operator service accounts may be automatically deleted after the configured inactivity period (3 days by default); deleting an inactive account invalidates its sign-in sessions and live account state, so a returning user signs up again as a new account. Historical operational analytics are stored separately from live account identity and may remain as aggregate or de-identified statistics after the account is deleted. Infrastructure logs and backups can have different lifetimes; signing out by itself does not delete your account.

You can stop using the service and request access, correction or deletion through the official contact below. Identity verification may be needed; some records may need to be retained for security, disputes or applicable legal duties. Requests and exceptions must be assessed by the operator.

02 / Open source and independent relays

8. Who processes self-hosted traffic

Reading, downloading or building source code does not itself create an official GLO service account. Requests to a source-code host are subject to that host’s policy. If you use an independent relay or modified client, its operator controls its logging, security and retention practices. This official service policy does not cover that operator.

An open-source license grants software rights; it is not a privacy certification. Review the code, build source and policies of the relay you choose. An OSS client connecting to official GLO infrastructure is still covered by the official-service section for data that infrastructure processes.

Contact & requests

Use the official support contact to ask about these terms or request access, correction or deletion of your account data. Do not publish session configs, tokens or personal data in public issues.

The operator has not published a support contact on this site yet.