Security & privacy

Security and privacy in plain language

See how account protection, message privacy, QR login, linked sessions, and active-device control are handled across Alolo Chat and Alolo Chat Web.

Account protection

The web experience starts from the phone. Instead of a separate web password flow, the mobile app approves browser sessions with QR linking.

Message privacy

Read receipts, typing indicators, last seen visibility, and notification controls remain user-facing settings rather than hidden assumptions.

Linked device awareness

Sessions stay persistent for convenience, but they are still treated as separate linked surfaces that can be ended when needed.

Session continuity

The web app keeps the session alive so users can continue where they left off, while preserving a clear logout path.

Security & privacy

How QR login works

Sign-in starts on your phone. A temporary code and approval in the app link this browser to your account.

  1. 1. Generate a secure pairing

    The browser asks for a short-lived pairing request and displays it as a QR code.

  2. 2. Scan from the app

    Inside the profile screen, the mobile app opens a dedicated computer-login scanner and reads the pairing data.

  3. 3. Approve the browser session

    The app confirms the QR request against the real Alolo Chat account and the browser session becomes active.

Security & privacy

Session principles

End a session whenever you need

Log out on the web, or end the browser session from linked devices in your app.

Keys stay in your browser

Web encryption keys are created in your browser. Some older messages may only be accessible on your phone.

Use a device you trust

Link your own devices and log out after using a shared computer. Do not approve a pairing code sent by someone else.