in.gogig.executor (“gOGig Executor”, “the app”). Effective 12 August 2026. Last updated 23 September 2026.gOGig Executor is a work app for field executors. You pick up a branding campaign, go to the site, capture photo or video proof that you were there, and submit it. Everything the app collects exists to make that proof verifiable and to pay you for it. There is no advertising in this app and no advertising identifier. The app does measure how it is used (see “App usage measurement” in section 1), but that measurement is about the app, not about you, and it is never used to profile or advertise to you.
| Data | Why | When |
|---|---|---|
| Phone number | It is your login. Sign-in is a one-time password (OTP) sent to it. | At sign-in |
| Name, role, executor ID | Identifies whose work a submission is, and who gets paid for it. | Returned by our server after sign-in |
| Precise location (GPS) | Checks you are inside the task’s geofence, and is written into each capture as proof of place. | Only while a capture or task screen is open |
| Photos and videos you capture | They are the deliverable: the proof of the completed task. | When you take them in the app |
| Audio | Only as the sound track of a video you record. The app never records audio on its own. | While recording a video |
| Capture metadata | Time, GPS coordinates and accuracy, camera direction, zoom, torch, device make and model, Android version, time zone, whether the device clock is network-set, and the app build. All of it is written into each file so a disputed capture can answer questions on its own. | At capture and at upload |
| Task answers | The form fields of the task you complete. What these are is set by the campaign: for example a shop name, a vehicle’s registration number, a measurement, or a survey the client asked for. | On submission |
| App usage measurement | Counts of how the app is used: that a task was submitted (with its campaign, the kind of campaign, whether it went up straight away or later from the upload queue, and how many files it had), that a task was saved on the phone to upload later, that a task could not be uploaded (with the kind of failure), that you signed in, which screens of the app were opened, and, for camera tasks, how many shots you took and how many you retook. It tells us how much work is being submitted, on which app versions, where uploads get stuck and which campaigns are hard to photograph. It carries no name, phone number, executor ID, location, or image. What Firebase records alongside it is set out below. | After a task is successfully submitted |
| App and device diagnostics | App version, device make and model, Android version, screen size, locale, network type, free disk space, battery and power-save state, how many uploads are queued, and recent app logs. Your name and account ID are attached, so support can tell whose phone a report came from without having to ask. | When you send a problem report, and automatically after a crash or an upload that could not be sent (see section 5) |
The app requests precise location because a task is a claim that you were at a particular place. The coordinate is used to check the task’s geofence and is embedded in the photo or video you capture.
The app does not request background location. It cannot read your location when it is closed or in the background. Android’s background location permission is not declared in the app at all. Location is read only while you have a capture or task screen open.
Two things turn a coordinate into something readable, and both are worth naming. The app asks Android’s own geocoding service to turn your coordinate into an area name (“Bank More, Dhanbad”) for the line shown on the camera screen; on most handsets that service is provided by Google. And when a task shows you a map of a geofence you are outside, the map’s tiles are fetched from OpenStreetMap’s public tile servers, which necessarily see your device’s IP address and which part of the world you are looking at. Neither receives your name, your phone number or your captures.
Signing in needs only your mobile number and the code sent to it. Everything else on your profile, meaning your name, a profile photo and your date of birth, is optional, added by you from the Profile screen, and stored with your account so the people who assign and review your work can see who did it. The photo is one you pick through Android’s photo picker, which gives the app that one image and nothing else from your gallery.
The app opens the camera to capture task proof. It does not browse, read, or upload your photo gallery, and it does not declare the Android media-read permissions that would let it. Only files you capture for a task are uploaded.
GPS Cam, which the app offers on its home screen, is a camera for your own use. Each photo is stamped with the gOGig logo, the address, coordinates, accuracy, date and time, the direction the camera faced, a Plus Code worked out on the phone, a small map of the spot, and any note you type, and saved to your phone’s gallery in Pictures/gOGig GPS Cam. Those photos are not uploaded and are not sent to us; the only things that leave the phone are the address lookup and the map thumbnail’s tiles from OpenStreetMap, both described under location above. On Android 9 and older, adding a photo to the gallery needs Android’s storage-write permission, which the app declares for those versions only and uses only for that. It still does not read your gallery.
Some campaigns ask the app to read a number off the photo for you, such as a vehicle registration plate or a serial code on a board, instead of making you type it. When that happens the photo, with the coordinate and the job type, is sent to our detection service at detection.gogig.in, which returns the text it read. It is an assist and it can be overruled: if the read is wrong or the service cannot be reached, you type the value in and the task submits exactly as it would have.
Sign-in is restricted to a number your handset’s own SIM answers to, so that an account cannot be signed into from somebody else’s phone. To offer you that number the app reads the numbers on the SIMs in the device, which is what the phone permission is for. That read stays on the device: nothing about your SIMs, your slots or your carrier is sent to us or stored. The only number that leaves the phone is the one you pick and sign in with.
Auto-filling the OTP uses Google Play Services’ SMS User Consent API. Play Services watches for a single incoming message containing a code and shows you a prompt; only if you tap it does the app see that one message. The app does not hold any SMS permission and cannot read your messages.
The measurement in the table is sent through Google Analytics for Firebase as a short list of events: a task submitted, a task saved to upload later, a task that could not be uploaded, a sign-in, a screen opened, and, after a camera task is accepted, the number of shots taken and retaken. Each carries at most a campaign id, the kind of campaign, the task’s id on our server, a count, a failure kind, or the name of a screen in the app. None carries a name, phone number, executor ID, GPS coordinate, or image.
Alongside it, Firebase records what it records for every app that uses it: that the app was opened, updated or removed, how long a session lasted, and the device model, Android version, app version and language it happened on. It also derives an approximate region, at country level, from the IP address the request arrives on. That is not the GPS location the app reads for a task; the coordinate on a capture is never sent to Firebase.
To join those records together Firebase generates an app-instance ID: a random number belonging to this installation of this app. It is not your advertising ID, not your Android ID, and not tied to your name or your phone number. The app switches the first two off by name. It is reset if you clear the app’s data or reinstall it, and it cannot be switched off while the measurement runs at all. This policy says so rather than claiming a measurement that leaves no trace.
None of it is used to advertise to you, to build an audience, or to follow you into another app. Ad-personalisation signals are switched off at the same place. It answers operational questions: how many tasks are being submitted and on which app versions, where uploads get stuck, which parts of the app are used, and which campaigns are hard to photograph, so the app and the instructions can be fixed.
The app also asks Firebase Remote Config, about once an hour, for one setting: the oldest app version still allowed to run, so a version with a known fault can be retired without waiting for everyone to update. That request carries a Firebase installation ID (a random number for this installation, reset on reinstall), the app’s own id and version, and the phone’s language and country setting. It carries nothing about you or your tasks.
We do not sell, rent, or trade your personal information. We disclose it only in these cases:
When you send a problem report from the app’s menu, it carries the app’s recent log lines together with the device and queue facts listed in section 1, so that support can act on it without a phone call. Anything that looks like a login token or an inline image is stripped out of those logs before they are sent.
Every report says who it came from. Your name, your account ID and your role are attached to it, the ones already held on your device from when you signed in. A report that nobody can trace back to an executor cannot be answered, and the alternative was support guessing from a campaign name in the logs. It is the same information the app already sends when you submit work, and it is used to answer the problem, not for anything else.
Three things are reported without being asked for. If the app closes unexpectedly, it writes the error and the log lines around it to a file on your device and sends that file the next time it has a network, then deletes it. If a completed task cannot be uploaded, whether from no signal, a full phone, or a server that refuses it, the app files one report about that failure on its own, so that work stuck on a phone is something we find out about rather than something you have to tell us. The same goes for a capture the phone could not encrypt before queuing it: that report names the task and the file, not what is in it. And if your phone reports a location that Android marks as simulated, from a mock-location or “fake GPS” app, the app refuses the reading, tells you so on screen, and files a report about it. That report carries the coordinate the other app claimed, because a location that was refused is the only evidence that it was.
Repeats of any of the three are counted and sent as one report rather than one per attempt.
You can withdraw the camera, location or phone permission at any time in Android Settings. The app will keep working, but tasks that need a verified place or a capture cannot be completed without them, because that verification is what the task is.
You can also ask us to:
Delete it yourself: dashboard.gogig.in/delete-account. Sign in with the phone number on your account, confirm, and the request is filed without anybody having to read an email. The same page is linked from About inside the app.
Or write to us: email support@gogig.in with the subject “Delete my account”, from the email address on your account or naming your registered phone number. We verify the request against your registered number.
Either way, what is deleted is the same: your account, your profile details, and your submitted captures. Anything still waiting on your phone goes with the app when you uninstall it, unless you choose “Keep app data” on the uninstall screen.
gOGig Executor is a work app for adults engaged as field executors. It is not directed at children and we do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.
If this policy changes, the updated version is posted at this address with a new “last updated” date. Material changes to what we collect or why will be communicated in the app before they take effect.
Questions, requests, or grievances about your data:
Email: support@gogig.in
Website: www.gogig.in
in.gogig.executor · Privacy policy, last updated 23 September 2026.