← Back to GongLah
廣東話普通话EnglishFilipino

Privacy and data handling

In short: after pressing Record, you can choose live Browser mode or API High Accuracy mode. Browser mode needs no account and GongLah does not independently save or upload that recording. API mode sends only the audio recorded in that session to the speech model and returns the result to the same editor.

Speech recognition

GongLah uses the browser Web Speech API, not a speech model operated by GongLah. On first use, browser languages may suggest Cantonese, Mandarin, English, or Filipino, and you can always choose manually. GongLah does not infer language from your IP address. Audio processing location and retention are determined by the browser, operating system, or recognition provider.

Audio, microphone checks, and long recordings

Live Browser recordings and the 10-second microphone check do not create, save, or upload an audio file. API High Accuracy mode and Accuracy Lab are separate, clearly labelled exceptions.

During recording, GongLah may request a Screen Wake Lock to keep the display awake. Battery saving, system limits, locking the device, or moving to another app can still pause recognition. Background recording while locked cannot be guaranteed.

API High Accuracy transcription

Audio is uploaded only after you press Record and actively choose API High Accuracy mode. GongLah does not provide an audio-file upload control. The audio recorded in that session is temporarily placed in private Cloudflare R2 and sent to the OpenRouter speech model. Do not record customer data, passwords, financial, medical, or confidential content.

Temporary audio is deleted after success or permanent failure; interrupted jobs are cleared within 24 hours. The transcript, model, status, minute usage, and provider-reported cost remain linked to the current anonymous or signed-in account. Failed provider requests refund reserved minutes. The result returns to the same editor.

Credits, payments, and order records

Once payments open, only signed-in accounts can buy API minutes. Stripe hosts the payment page; GongLah does not receive or store full card numbers. GongLah stores the pack, amount, minutes, order state, Stripe checkout reference, and credit ledger to post credits once, issue refunds, and resolve disputes. Purchase controls remain disabled until the payment channel is configured.

AI editing, Clear, and translation

During long Browser recordings and Cantonese API High Accuracy recordings, GongLah can send short, finalized text segments and the selected language profile to the production organizer to improve punctuation, sentences, and paragraphs incrementally. Microphone audio and changing interim text are not sent. After API mode stops and the final section is transcribed, the completed incremental result becomes available first; the complete text is then sent once more to the organizer in the background for full-context Natural polish. Clear and English versions are generated only when first requested.

Ordinary Browser recordings are not sent to speech models; API High Accuracy mode and the continuing-consent Accuracy Lab are clearly marked exceptions. Results remain in the current browser unless you enable account sync. Editing requests do not create a separate account chat history.

Anonymous analytics and the accuracy benchmark

GongLah records limited anonymous events such as page views, microphone-test completion, recording-duration bands, editing, Copy, sharing, and referral outcomes. To measure one visit from its entry page through the first Copy, the browser creates a random session code in sessionStorage and submits it with a coarse acquisition channel, entry path, and sanitized UTM source and campaign. The code is not reused after that tab session and is not linked to an account, cookie, or cross-site identity. Aggregate events are retained for up to three months. Events exclude spoken or typed text, audio, microphone names, names, email addresses, and persistent device identifiers. Front-end events are not sent when Do Not Track is enabled.

The public Cantonese benchmark compares fixed phrases and recognized text on your device. Anonymous aggregate reporting can be disabled before the test. If enabled, only the sample version, score, difference count, reference length, completion time, coarse device/browser type, and recognition language are submitted—never recognized text. Group averages appear only after at least three tests.

Invite-only Accuracy Lab

Accuracy Lab is off by default and is limited to signed-in participants with a valid invite. Joining takes one clear consent. The system then assigns and adjusts internal sampling intensity automatically, so participants do not need to understand or choose a mode for each recording and are not prompted clip by clip. Skip this recording, pause, and leave-and-delete remain available.

An eligible recording may briefly create audio in browser memory. Audio that is not selected or is abandoned stays on the device and is deleted immediately. Only a system-selected clip that reaches Copy is uploaded. Do not dictate customer data, passwords, financial, medical, or confidential information. Audio goes only to the listed ASR providers; organizer models never receive audio.

Selected private audio and temporary text remain in restricted Cloudflare R2 for at most seven days. During that period they stay linked to the signed-in account and sample so leave-and-delete can remove them. After raw data is deleted, only de-identified error metrics remain—never the audio or transcript.

The system automatically compares multiple ASR outputs with the Browser transcript. Only a strict agreeing majority above the confidence threshold becomes an Auto-Verified reference; everything else is quarantined. Participants do not need to replay audio. Gold remains reserved for a complete, explicit internal human audit.

Personal learning and anonymous short corrections

When you correct a short term and successfully Copy, GongLah can add the confirmed form to the personal glossary for that language. Repeating the same short correction twice in one workspace can also create an immediate session-only hint without a review dialog. Undoing an automatic change within 30 seconds removes that local hint until it is reconfirmed. Ordinary insertions, full-passage pastes, and AI passage rewrites are not short-term learning data. The personal glossary stays in the browser unless sync is enabled.

Guests can share short corrections anonymously by default and can turn this off at any time; signed-in accounts are asked separately once. Copying unchanged text contributes only an aggregate success count; copying Original instead of Natural contributes only a version-preference count. Short-pair submissions omit cookies, account IDs, audio, full text, sentence context, and contact details, and filter email, phone, URL, address, high-entropy identifiers, instruction-like text, and oversized content. The browser creates a random contributor-day code for evidence diversity; it rotates the next day and is not a persistent identity.

Correction signals use explainable weights, source diversity, conflict thresholds, and a small holdout. Unedited copies alone can never activate a replacement. Site rules require at least three confirmations from two contributor-day groups with no conflicts before holdout; community rules require broader multi-day evidence. Stale, undone, or repeatedly rejected rules are downgraded, blocked, or rolled back. GongLah does not directly alter the browser speech model.

On-device text, settings, and backups

  • Without sync, text, segments, versions, glossaries, language, and preferences stay in the current browser. localStorage and an IndexedDB recovery checkpoint reduce accidental loss after a refresh or interruption.
  • Daily characters, tokens, and time saved are on-device estimates, not Cloudflare billing usage.
  • You can export and import a JSON backup without an account.
  • Clearing browser site data or clearing content in GongLah removes the corresponding on-device data.

Optional account sync

  • Sync is off by default and uploads a workspace only after you choose Google, an email code, or a passkey sign-in.
  • Sync includes text, segments, versions, glossaries, language, and preferences. It excludes audio, microphone content or names, and on-device usage totals.
  • Account records, sessions, passkey public credentials, and workspaces are stored in Cloudflare D1. GongLah never receives biometric data or a Google password. Email codes are temporarily stored as hashes, expire after about five minutes, and are delivered through Resend.
  • If both the device and cloud changed, automatic overwrite pauses so you can merge, keep this device, or use the cloud copy.
  • You can sign out or delete the cloud account at any time. This does not automatically delete text held on the device.

Hosting, network data, and your controls

The site, Workers AI, and optional sync database are hosted by Cloudflare. Cloudflare may process IP addresses, request times, and general device/browser information for operations and security. The correction API uses connection IPs only for short-lived rate limiting and does not store them with corrections. You can refuse microphone permission, use GongLah without installation or sign-in, turn off anonymous improvement, clear local content, export a backup, and delete the cloud account. Company devices remain subject to company policy.

Contact and support

Questions, bug reports, or account-data deletion requests: email info@gonglah.com. We reply within 2 business days.

Read the full help guide→

Updated August 15, 2026