Privacy
The news.gemboss.ai website (GemCommunity News). Updated 2026-10-03.
What the website sends and receives
- Briefing: the website fetches the list of stories from community.gemboss.ai. If you connected an account, the request carries your token so member-only parts are included.
- Search: when you type two or more characters in the search box, the text you typed is sent to community.gemboss.ai to search the whole community, with your token if you connected an account.
- Saved stories: if you connected an account, stories you star are synced to your account so they show up on your other devices; on the first connect, the list saved in the browser is merged into your account.
- Extension: the page asks the GemCommunity News extension (if you have it) whether it is there; the extension only answers yes and its version number.
- Images: cover images and images inside a story can live on other servers (the community image store, or the story's original site). Your browser then loads them from that server, which sees your IP address, as with any image on the web. If this browser is signed in to community.gemboss.ai, every image loaded from community.gemboss.ai (covers, images inside stories) carries the community sign-in cookie: your browser sends it on its own, as when you open the community site itself. Inside the WeChat app the page may load WeChat's sharing script (res.wx.qq.com) so the share card shows correctly.
Anonymous counts
The events below are sent to the community server (gemcommunity.gemboss.ai). Each event holds only these fields:
e- The event name (table below).
page- The page type: the briefing, a story, or the extension install page; not the page address.
dev- Phone or computer.
lang- The language the page is showing.
tz- Your browser time zone, so the server can infer the country. The time zone is not stored.
via- The channel of a shared link (for example WhatsApp), or the channel you pick in the share dialog.
ref- Only on page opens: the referral source group (for example Google or ChatGPT). The previous page address is not sent.
mode- Only on extension install invites: where the invite showed, or which button was pressed.
The events:
visit- Opening the briefing, a story, or the extension install page (other pages, such as the archive or this one, send nothing)
invite_shown- An extension install invite is shown
invite_click- Clicking a button in the install invite
installed_seen- The first time this browser sees the extension is installed
share_open- Opening the share dialog
share_pick- Picking a share channel
qr_show- Opening the QR code to read on a phone
connect_start- Pressing sign in
connect_done- Finishing sign in
The server turns the time zone into a country code and drops the time zone, then only adds one to that day's counter for exactly the fields above: no cookies, no IP address or browser identification string stored, nothing tied to an account, so the counts cannot be joined into one person's journey. Your IP address is kept in the server's memory to limit floods: it is never written to disk or a database, and it is gone when the server restarts. The hosting provider may log it in ordinary request logs.
Google Analytics
Our server sends each event above to Google Analytics (Google LLC) for reporting. Every event carries its own random number that Google requires; events are grouped by minute, sent in shuffled order, and carry only the start of that minute as their time. So Google gets no ID that joins the events to each other or to you. Google receives the event name and the fields above, except the time zone: it gets the country code the server inferred instead. The sending happens from our server: the page has no Google Analytics code, sets no Google cookies, and Google does not receive your IP address through this.
Story reads
When you open a story in the reader, the website sends that story's ID and the language the reader is showing (Vietnamese, English or Chinese) to the community; if you reach the end, it sends that too. The server stores each read as a timestamped row. If you connected an account, the row is linked to it: that is your reading history in the community. If not, it is linked to a code made from your IP address, browser and the date with a secret key: the code changes every day and cannot be turned back into your IP, but reads on the same day share a code. To delete reading history linked to your account, email the address under Contact.
Stored in your browser
In your browser, on this device only (localStorage unless marked sessionStorage):
gcn:gcn.token- A session token, only if you connect an account.
gcn:gcn.feed- The last briefing fetched, so the page shows text at once; if you connected an account it includes your name and member-only parts.
gcn:gcn.theme- Light or dark theme.
gcn:gcn.lang- The language you picked.
gcn:gcn.rate- How many times and on how many days you opened it (for the extension rating prompt; the website does not show that prompt).
gcn:gcn.saved- Stories you starred, up to 200.
gcn:gcn.savedSync- The sync state of saved stories with your account.
gcn:gcn.welcomed- When you closed the welcome note shown after install (if any).
gcn:gcn.invite- Whether you clicked or postponed the extension install invite.
gcn:gcn.seenInstalled- Whether this browser was already reported as having the extension (yes/no).
gcn:connect.state- During sign in (sessionStorage, cleared when the tab closes): a code that blocks forged sign-ins.
gcn:connect.back- During sign in (sessionStorage): the page to return to.
gcn:connect.done- After sign in (sessionStorage): a marker so "finished sign in" is counted once.
Beyond what the sections above describe (sending, counting, reads, sign in), none of this leaves your browser. Clearing this site's data in your browser removes all of it.
Sign in
Connecting your GemCommunity account stores a token in this browser. Signing out from the account menu revokes that token on the server.
Chrome extension
The GemCommunity News extension has its own policy at community.gemboss.ai/ext/privacy.
Contact
Questions about this page or your data, or requests to delete data: email chris.chimen@gmail.com.