How Tondo handles your information
Privacy Policy
How Tondo handles your information
Information we process
Tondo creates a random user identifier and session credential. We link settings, reputation, votes, saved or muted posts, moderation history, posts, replies, chats and media to that anonymous identifier. You do not need to provide a real name, email address or phone number for the standard experience.
Support and contact messages
When you use Contact Us, your support message is linked to your anonymous user ID and is visible to authorized Tondo admins for support and safety. The message may include any details you voluntarily enter. Do not include passwords, payment information or other sensitive data.
Device security and bans
To prevent repeat abuse, Tondo can associate a hashed app-installation identifier, verification keys, platform security results and moderation records with your anonymous accounts. Apple DeviceCheck and App Attest, or Google Play Integrity and device recall, may verify the app and remember an abuse flag across reinstalls or device resets. These security records are separate from usage analytics and may remain after account deletion while needed to enforce a ban. Provider tokens stored by Tondo are encrypted and expire. You can contact Tondo support to appeal a device ban, including if ownership of the phone has changed.
Location
With permission, Tondo processes precise coordinates when you browse nearby content or create a post or comment. Coordinates are stored with posts and comments, post accuracy may also be stored, viewer coordinates may be sent to our service at six-decimal precision to calculate distance, and Google Maps receives coordinates to determine a vicinity or region. Exact coordinates are not shown to other users.
Public content and private chats
Posts, replies, community media and share previews can be public. Direct messages and attachments are restricted to participants but are not end-to-end encrypted. A recipient can see the first request message before accepting the chat.
Media safety checks
Before a public photo or video is posted, Tondo’s self-hosted NSFWJS service may process the photo or sampled video frames to detect explicit sexual content. Cloudflare Stream temporarily processes public-post videos to prepare private frame samples. Rejected media is not placed in public storage.
Offline chat storage
Tondo stores an encrypted copy of recently synchronized chat messages and thread details on your device so you can read them without internet access. Chat attachments may also be stored in the app’s protected local storage, limited to 100 MB. Local copies are removed when a synchronized deletion is received, when you delete the conversation, or when you delete your profile.
Live streams
When you go live, Tondo sends the video and audio you choose to broadcast to Cloudflare Stream. We associate the stream title, status, approximate location label and technical delivery information with your anonymous identifier. Live comments are stored with the stream and the anonymous identifier that posted them. Live video is visible to viewers and may be recorded for service operation, safety and abuse review for up to 30 days.
Live gifts and earnings payouts
Apple or Google processes Tondo Coin purchases. Tondo stores the product, platform, transaction identifier, verification status, coin-wallet ledger, gifts sent or received, live-gift earnings, referral rewards and payout status to prevent fraud and operate the consolidated earnings wallet. If you request an earnings payout, we also store the Mobile Money network, number and account name you provide. Authorized administrators can review these payout details to process the payment. Tondo does not receive your full payment-card details.
Referral rewards
When referral rewards are enabled, Tondo stores your personal invite code, referral-link visits, the destination platform and country, the anonymous accounts linked by a qualified referral, and a cash reward ledger. Android may provide the referral parameters through Google Play after installation; iPhone users enter the visible invite code. Tondo stores a one-way app-installation identifier to prevent repeat rewards after an account is reset. We do not use an advertising identifier or device fingerprint for referrals. Unclaimed referral-link records are deleted after 90 days.
Usage analytics and community reminders
Tondo automatically collects usage analytics. Google Analytics receives app and device information, a random app-instance identifier, country, language, screen visits, install campaigns, feature actions and store purchase metadata. We do not send post or chat text, search terms, precise coordinates, contact details or payment credentials to Analytics. Advertising identifiers and advertising personalization are disabled. Tondo also receives limited activity summaries linked to your anonymous account, app language and time-zone offset to measure usage and choose occasional community reminders after inactivity. Activity profiles and reminder records expire after 90 days; aggregate event counts are kept for up to 400 days. Community reminders can be turned off under Settings > Notifications. This does not turn off usage analytics.
Notifications and diagnostics
We store Firebase Cloud Messaging tokens and preferences to send notifications. Google receives notification tokens and payloads. Firebase Crashlytics may receive your anonymous identifier, app and device information, crash reports, diagnostics, stack traces, build mode and authentication or suspension status. Cloudflare may process IP addresses and request metadata to deliver and secure the service.
How information is used
We use information to provide nearby posts, chats, media, notifications and account controls; rank trending content; calculate reputation; investigate reports; moderate abuse; maintain reliability; prevent fraud; and meet legal obligations.
Service providers
We use Cloudflare for app delivery, databases, media storage and video processing; Google Firebase for push messaging, usage analytics and crash diagnostics; and Google Maps for vicinity lookup. These providers process information under their own terms and privacy commitments.
Advertising
Tondo does not sell personal data, use the Android Advertising ID, serve targeted advertising or track your activity across other companies’ apps and websites. Tondo does not collect a phone number for the standard anonymous experience.
Retention and deletion
Open support or contact messages are kept while needed. Resolved or closed messages are deleted from active systems after 180 days. Delete your profile from Settings to remove its active account data, associated contact messages, posts, replies, chats and uploaded media. Media deletion may finish asynchronously, and cached public media or share previews may remain temporarily. Limited security, audit and provider records may remain as described in this policy, including in logs or backups or where needed for fraud prevention, legal compliance or backup integrity.
Your controls
You can manage device permissions, notification categories, message requests and muted posts; delete content where offered; end or delete chats; report content; and delete your profile.
Security and children
We use encrypted network connections and access controls, but no service can guarantee absolute security. Tondo is an 18+ community and is not available to children.
Contact
Tondo is provided by GoApps Ltd. For privacy questions, safety reports or deletion assistance, email info@goapps.com.gh.
