GComm Privacy Policy
Applies to the GComm mobile application (com.pesystems.gcomm) for Android and iOS.
Effective 4 September 2026. Published by PE Systems LLC.
The short version
GComm is a private chat application for a team. It talks to one server — the one whose address you type in when you set it up, normally run by your own employer or organisation. It contacts nothing else.
There are no accounts, no advertising, no analytics, and no third-party software development kits of any kind. PE Systems LLC does not operate the server you connect to, does not receive your messages, and does not collect any information about you from this app.
The contents of your messages and the files you send are encrypted before they leave your phone and are decrypted only by the people you sent them to. The server that carries them cannot read them.
Who this policy is about
GComm is sold as software that an organisation installs and runs for itself. The GComm server is operated by whoever deployed it — typically your employer — not by PE Systems LLC. That distinction matters throughout this document:
- PE Systems LLC writes and distributes the application. We receive no data from it. We have no server that the app contacts, and there is no way for us to see who uses it or what they say.
- Your server operator runs the machine your phone connects to. They control that machine, its logs, and how long it keeps them. If you want to know their retention practices, ask them; this policy describes what the software does, not what they choose to do with it.
Information stored on your device
Setup asks for a handful of things, and they are kept in the operating system's own preference storage, private to the app:
| What | Why it is kept |
|---|---|
| Display name | The name your colleagues see beside your messages. It defaults to your device's name and you can change it to anything. |
| Server address and port | Where to connect. You or your administrator supply this. |
| Shared passphrase | Proves to the server that you are allowed in, and derives the key that encrypts messages. It never leaves the device — see How messages are protected below. |
| Colour, font and text size | How your messages appear to everyone reading them. |
| An installation identifier | A random value generated on first run so that a restart is recognised as the same installation. It is not derived from your device, your hardware, or you, and reinstalling produces a new one. |
The conversation itself is held in memory only while the app is running. GComm on mobile keeps no chat database, so closing the app discards the transcript on that device.
Files you receive are written to your Downloads folder, where they are ordinary files belonging to you. Files you are about to send, and content shared into GComm from another app, are copied into the app's private cache first so they can be transferred.
Information sent to the server
When you connect, the server is told:
- your display name, your chosen colour, your installation identifier, and the app version;
- a cryptographic proof that you know the shared passphrase — the passphrase itself is never transmitted;
- whether you are currently online or away, so colleagues can see who is available.
The server also observes the IP address your connection arrives from, as every internet server necessarily does. The app does not report your address, look it up, or send it anywhere; the server reads it from the connection and can show it in the list of who is online, which is a feature of the product for troubleshooting connectivity within a team.
GComm sends nothing else. In particular it does not transmit your contacts, your location, your device identifiers, an advertising ID, your other installed applications, or any usage or diagnostic telemetry.
How messages are protected
The connection to the server uses TLS. On top of that, the contents of everything intended for another person — chat messages and the files attached to them — are encrypted on your device with AES-GCM, using a key derived from your team's shared passphrase, and are decrypted only on the devices of the people receiving them. The server relays that traffic without being able to read it.
Two honest limits are worth stating plainly:
- Who is online is visible to the server; what was said is not. Display names, presence and connection addresses have to be readable for the server to route anything at all, so they are.
- The key is shared by the whole team. This protects your conversation from the server operator and from anyone on the network in between. It does not, and is not intended to, keep messages private from other members of your own group — anyone who has the passphrase can join and read what is sent.
The server holds connections in memory and does not store messages. There is no message archive on the server and no offline queue, so a message sent to someone who is not connected is simply not delivered rather than being retained.
Third parties
There are none. The mobile app contains no advertising networks, no analytics or crash reporting services, no social media kits, and no third-party libraries that make network requests of their own. It sends data to exactly one destination: the server address you entered.
We do not sell, rent, trade, or share your information with anyone, because we do not have it.
Permissions the app requests
| Permission | What it is for |
|---|---|
| Internet Network state |
Connecting to your server and noticing when the network comes and goes. |
| Notifications | Telling you a message has arrived while you are in another app, and displaying the notice Android requires while the connection is held open. Declining costs you the alerts and nothing else. |
| Foreground service (special use) |
Keeping the connection to your server open while GComm is in the background, so messages still arrive. Android shows a permanent notice whenever this is running, and it stops when you swipe the app away. |
| Storage (Android 9 and older only) |
Saving a received file into your Downloads folder. On Android 10 and later this needs no permission and none is requested. |
GComm does not request access to your location, camera, microphone, contacts, calendar, call logs, SMS messages, or health data, and it does not read your photo library. Files are attached either through the system file picker or through the share sheet of another app, both of which hand GComm one specific file that you chose.
Accounts and deletion
GComm has no user accounts. There is nothing to register, no profile stored anywhere, and consequently no account for us to delete on request.
To remove everything the app keeps, uninstall it. That deletes the settings described above, the installation identifier, and the app's cache. Files already saved into your Downloads folder remain, because they are your files; delete them as you would any other download. If you want your display name removed from your organisation's server logs, that is a request for your server operator, not for us.
Children
GComm is a workplace tool. It is not directed at children, is not designed or marketed for anyone under 13, and we do not knowingly collect information from children.
Security
Beyond the encryption described above, the app verifies the identity of the server it connects to by pinning that server's certificate the first time it sees it, so a later attempt to impersonate your server is refused rather than silently accepted.
No system is perfect, and this one depends on the shared passphrase being treated as a secret. Anyone who obtains it can join your team's conversation and read what is sent to it.
Changes to this policy
If this policy changes, the revised version will be posted at this address with a new effective date. Material changes will also be noted in the app's release notes on Google Play.
Contact
Questions about this policy or about GComm's handling of data can be sent to ecklerpa@pesystemsllc.com.
PE Systems LLC
pesystemsllc.com