GuruMode
  • How it works
  • Why it works
  • Founder
  • Curriculum
  • FAQ
  • Blog
Try GuruMode

Privacy Policy

Effective Date: July 2026  |  Platform: https://gurumode.world and the GuruMode Android application

Owner / Operator: Ghibran Vaibodha, Proprietor of GuruMode.

1. Introduction

GuruMode values your trust and is committed to protecting your privacy and personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA"), the rules framed thereunder, and other applicable Indian laws.

This Privacy Policy ("Policy") explains how Ghibran Vaibodha, Proprietor of GuruMode ("GuruMode", "we", "our", or "us"), collects, uses, stores, shares, and protects information when you access or use the GuruMode Android application, website (https://gurumode.world), and related digital services (collectively, the "Platform").

GuruMode is owned and operated by Ghibran Vaibodha, Proprietor of GuruMode.

This Policy is written for the current MVP release. The current MVP is a free learning product for students in Grades 5, 6, 7 and 8. It does not include payment, subscription, in-app purchase, Razorpay, Google Play Billing, third-party advertising, student chat, student social features, student public profiles, or student free-text messaging. If GuruMode adds any of these features in a future version, this Policy will be updated before that feature is used, and any required parent/legal guardian consent will be obtained.

For privacy, safety, support, or data-related questions, contact: support.gurumode@gmail.com

By registering or using the Platform, the parent or legal guardian acknowledges this Policy. If you do not agree, please discontinue use of the Platform and contact support.gurumode@gmail.com to request deletion of any data already collected.

This Policy is a privacy notice that explains our data practices. It is provided together with, but is separate from, the consent GuruMode obtains from the parent or legal guardian at registration. If GuruMode introduces materially new processing, it will provide an updated notice and obtain fresh parental consent where required before that processing begins.

2. Who Registers and Who Uses the Platform

GuruMode is designed for students in Grades 5, 6, 7 and 8 and is used through a parent-controlled account. Registration is completed by the parent or legal guardian using the parent's mobile number and OTP verification. The OTP, mobile number, account controls, and deletion controls are intended for the parent or legal guardian, not for the student-facing learning experience.

The parent or legal guardian is the account holder and the Data Principal for the parent's own account and contact information. The student is the individual to whom the learner-profile and learning-interaction data relate. For personal data relating to a child, the term "Data Principal" includes the child's parent or lawful guardian acting on the child's behalf, in accordance with the DPDPA. GuruMode obtains verifiable parental consent before creating or using the student profile.

GuruMode does not knowingly allow a student to independently register, provide a phone number, verify OTP, make payments, purchase subscriptions, or manage the account. If we become aware that personal data was collected from a student without valid parental consent, we will take reasonable steps to delete such data.

GuruMode applies the same child-safety protections to all student users in Grades 5, 6, 7 and 8, including students who may fall into different child age bands under applicable laws or Google Play target-audience categories.

The student display name is used only inside the parent-controlled account and student learning experience. It is not shown publicly, searchable by other users, or used for student-to-student interaction.

3. Information We Collect

3.1 Information Provided by the Parent or Legal Guardian

When a parent or legal guardian registers or uses the Platform, we may collect:

  • Parent or legal guardian name, where provided
  • Parent or legal guardian mobile number for OTP-based account registration and login
  • Parent or legal guardian email address. It is required in the under-13 parental-notice flow and may be optional in other registration flows
  • Student first name or display name - we do not require the student's surname
  • Student grade level: Grade 5, Grade 6, Grade 7, or Grade 8
  • Account preferences, notification and WhatsApp communication preferences, and support communication history
  • Any images, screenshots, or videos that the parent or legal guardian voluntarily chooses to attach to an in-app support request
  • The support-request topic and free-text message that the parent or legal guardian voluntarily submits through the in-app support form.

3.2 Information Collected Automatically

When the Platform is accessed, we may automatically collect limited technical and usage information, including:

  • Device type, Android OS version, and application version
  • IP address in server logs for security, abuse prevention, and service reliability. GuruMode does not infer, derive, or store geographic location from the IP address, and does not collect GPS or precise location
  • In-app learning interaction data such as missions attempted, responses submitted, hints used, time spent per screen, stars earned, streaks, retries, chapter progress, and adaptive learning signals
  • Session logs and feature-usage events recorded in GuruMode's own backend as first-party product analytics, used to operate and improve the Platform; GuruMode does not use a third-party analytics or crash-reporting SDK
  • A push-notification token and app-instance identifier from Firebase Cloud Messaging, used only to route notifications to the parent-controlled device, together with system-generated session or security identifiers used only for authentication, abuse prevention, and service reliability
  • System-generated Supabase authentication account identifiers and internal parent-profile and learner-profile identifiers used to associate authorised accounts with profiles, sessions, learning progress, preferences, and account records.

GuruMode does not use the Android Advertising ID, Android ID, or App Set ID, and does not use any installation, session, or diagnostic identifier for advertising, ads measurement, retargeting, or commercial profiling. Identifiers are used only for the operational purposes described in this Policy.

3.3 Information We Do Not Ordinarily Request or Collect

GuruMode is designed with child safety as a core requirement. In the current MVP, we do not collect:

  • Payment information, card details, UPI credentials, billing details, subscription records, or transaction references
  • Photographs, videos, audio recordings, voice recordings, or biometric data relating to the student, other than an image or video that the parent or legal guardian voluntarily attaches to a support request as described below
  • Student surname, school name, home address, precise location, GPS location, or live location
  • Student chat messages, student-to-student messages, public comments, social posts, public profile content, or open free-text communication
  • Student contacts, phonebook, SMS, call log, camera, microphone, or Bluetooth data, and background or bulk access to device storage
  • Social media profile information, social media login data, or third-party account information
  • Android Advertising ID (AAID), IMEI, IMSI, SIM serial, build serial, MAC address, BSSID, SSID, or device phone number from TelephonyManager for child/student use

GuruMode does not request the Android AD_ID permission for the child-facing MVP and does not use advertising identifiers for student users.

Support request attachments: When a parent or legal guardian contacts support through the app, they may optionally attach up to five images or videos (maximum 50 MB each) using the device's system photo picker, to help us resolve their request. The app accesses only the specific image or video selected by the parent through the system picker, and uploads the selected file to GuruMode's secure support storage. Attachments are retained as part of the support and account record for record-keeping. A parent or legal guardian may request deletion of their support attachments at any time by contacting support.gurumode@gmail.com, and GuruMode will delete or anonymise them on verified request, subject to any longer retention required for security, dispute resolution, or legal compliance. Access is restricted to authorised support and technical personnel. These attachments are used solely to handle the support request and are not used for advertising, profiling, model or AI training, or any unrelated purpose. Parents are asked not to include sensitive personal information about the child in support attachments unless strictly necessary.

4. Purpose of Data Collection and Use

We collect and process personal data only for lawful and necessary purposes connected to the current MVP, including:

  • To authenticate the parent or legal guardian and create or access the parent-controlled account
  • To activate the student's learning profile after parental consent
  • To deliver personalised, adaptive learning missions based on the student's performance, accuracy, speed, retry patterns, and hint usage
  • To show student learning progress, chapter progress, streaks, stars, and related learning feedback inside the Platform
  • To generate learning progress summaries or reports inside the parent-facing area of the Platform, where available
  • To maintain platform safety, prevent abuse, detect fraud or misuse, debug crashes, and improve reliability
  • To respond to parent support requests and account/data deletion requests, including any images or videos that the parent voluntarily attaches to a support request
  • To send the parent or legal guardian service and transactional messages, learning and streak reminders, daily habit prompts, and account or progress updates, including by push notification and by WhatsApp, with opt-out available
  • To comply with legal, security, and regulatory obligations under Indian law

GuruMode does not use personal data for third-party advertising, targeted internet-based marketing, ads measurement, retargeting, commercial resale, or profiling for sale. No advertising is displayed to students.

5. Current MVP Feature Status and Exclusions

5.1 No Payment or Subscription in the Current MVP

The current MVP is free. GuruMode does not collect payment information, does not process subscriptions, does not display payment screens to students, and does not use Razorpay, Google Play Billing, or any other payment gateway in the current MVP.

If GuruMode introduces paid plans, subscriptions, in-app purchases, or payment processing in a future release, the feature will be parent-facing only, the Policy will be updated before the feature is used, and the implementation will follow applicable platform rules and law.

5.2 WhatsApp Communication

GuruMode sends parent-facing WhatsApp messages to the parent or legal guardian's registered, OTP-verified mobile number. WhatsApp messaging is enabled when the parent registers, and the parent may turn it off at any time from the in-app WhatsApp settings or by contacting support.gurumode@gmail.com. Messages fall into categories: (a) account and service messages; (b) learning updates and reminders, such as a welcome message, weekly progress digest, milestone celebrations, and a daily habit reminder, which are enabled by default; and (c) behaviour-based nudges, such as streak reminders and learning-support alerts, which remain off until the parent explicitly enables each one. GuruMode minimises learner information included in WhatsApp messages, does not send WhatsApp messages to students, and provides no WhatsApp messaging inside the student learning experience.

WhatsApp messages are delivered through Gallabox, operating on the Meta WhatsApp Business Platform, using pre-approved message templates. In delivering these messages, the provider and Meta may process the parent's mobile number, message content, and delivery status in order to operate the service. Meta and Gallabox may technically process replies within the WhatsApp service, but GuruMode does not ingest, store, or use those replies in the GuruMode application or backend. When the parent turns off WhatsApp communication, GuruMode stops sending WhatsApp messages to that number; essential account or security communications may continue through other available channels, such as in-app notices, SMS, or email, where necessary. GuruMode keeps operational records of WhatsApp enrolment, opt-out status, selected message categories, and message delivery status in order to operate the service and honour opt-out requests.

5.3 No Student Social, Chat, or Public Communication in the Current MVP

The current MVP does not include student chat, voice chat, social feeds, student-to-student messaging, public comments, searchable student profiles, public leaderboards, or open student-generated text communication.

6. Content and Learning Data

Student learning interaction data, including accuracy rates, response patterns, hint usage, retry behaviour, time spent, streaks, stars, chapter progress, and adaptive signals, is processed to power the Platform's adaptive learning experience.

This data is used to personalise the student's learning path, identify areas where the student may need extra help, improve content quality, and show progress to the parent or legal guardian through parent-facing surfaces where available.

GuruMode may use aggregated or anonymised learning data internally for product improvement, content quality analysis, crash reduction, learning-outcome analysis, and research into learning effectiveness. Aggregated or anonymised data does not identify an individual parent or student.

To prepare parent-facing WhatsApp progress narratives, GuruMode uses automated language-generation technology provided by a third-party AI provider (Anthropic, the Claude API). The provider receives the learner's display name and selected learning evidence (such as a completed topic or milestone) to generate a short qualitative narrative for the parent, and does not receive XP, point totals, streak-day counts, accuracy percentages, or detailed answer history. The provider processes this data only to generate the narrative on GuruMode's instructions, does not use it to train its models, and does not use it for its own purposes.

7. Data Sharing and Disclosure

7.1 Operational Providers and Other Recipients

GuruMode currently uses the following operational providers and disclosed recipients to operate the Platform:

  • Cloud backend and infrastructure provider (Supabase), hosted in India (Mumbai region), used to operate authentication, database, serverless backend functions, storage, and service reliability
  • OTP/SMS delivery providers used only to deliver parent login or registration OTPs
  • Push notification delivery through Firebase Cloud Messaging (Google) and Google Play Services, used only to send account, learning, reminder, and habit notifications to the parent-controlled device, and not for advertising or ads measurement
  • WhatsApp Business messaging provider (Gallabox), operating on the Meta WhatsApp Business Platform, used only to deliver parent-facing WhatsApp messages, learning updates, and reminders to the parent or legal guardian's registered mobile number; the provider and Meta may process the mobile number, message content, and delivery status for this purpose
  • Hosting, CDN, email, or support tools used for service delivery and parent support

Each provider processes only the data necessary for its stated function: Supabase processes account, profile, learning, support, and first-party operational-event records; the OTP/SMS provider processes the parent mobile number and OTP-delivery metadata; Firebase Cloud Messaging processes the push token and notification-delivery metadata; and the AI language-generation provider (Anthropic, the Claude API) processes the learner's display name and selected learning evidence to generate the parent-facing progress narrative. Supabase, the OTP/SMS provider, Firebase Cloud Messaging, Gallabox, and the AI language-generation provider process data to provide contracted operational services on GuruMode's behalf, on GuruMode's instructions, and do not use it for their own purposes. Meta Platforms receives WhatsApp data (the parent mobile number, approved message content, and delivery metadata) through the WhatsApp Business Platform and may process certain information under its own applicable terms, as described in Sections 7.3 and 9.

GuruMode does not permit service providers to use student data for their own advertising, ads measurement, retargeting, profiling for commercial resale, or unrelated purposes.

GuruMode reviews third-party APIs and SDKs used in the student-facing MVP for child-safety suitability and removes or disables SDKs that are not appropriate for child-directed or child-inclusive services.

GuruMode does not use any third-party advertising, attribution, cross-app tracking, analytics, or crash-reporting SDK. Product analytics are first-party and stored in GuruMode's own backend, and crash and stability information is limited to the aggregate reports provided by Google Play.

To deliver WhatsApp messages, GuruMode shares the parent's mobile number and message content with Meta Platforms through the WhatsApp Business Platform (via Gallabox). Meta processes this information under its own WhatsApp Business Terms and privacy policy, may process it in the United States or other countries, and may use certain service-usage information for its own purposes as described in those terms. This sharing is solely to provide the WhatsApp messaging feature and is not a sale of personal data.

7.2 Legal Disclosures

We may disclose personal information when required by applicable law, regulation, court order, governmental authority, or where necessary to protect the rights, property, or safety of GuruMode, users, or the public.

7.3 What We Do Not Do

GuruMode does not sell, rent, lease, or trade personal data for money or other valuable consideration. Except for the operational disclosures described in Section 7.1 - including the transfer of WhatsApp data to Meta for delivery and related service processing - GuruMode does not disclose personal data to unrelated third parties and does not show third-party advertising to students.

8. Child Safety and Student Experience

GuruMode's current MVP includes the following child-safety protections:

  • Student-facing screens do not show OTP, parent mobile number, payment, billing, subscription, upgrade, checkout, or account deletion controls
  • Registration, consent, account management, and deletion are parent-controlled
  • No chat, voice chat, student social feed, student messaging, public comments, public student profile, or open free-text communication is available to the student
  • Only a first name or display name is used for the student profile, and it is not public or searchable
  • No student surname, school name, precise location, photograph, audio, video, or biometric data is required
  • No third-party advertising is displayed to students
  • Student learning interaction data is used to personalise learning and improve the product, not for commercial resale, third-party advertising, retargeting, or ads measurement
  • Parental consent is obtained before a student profile is created and used
  • The current MVP does not include student-facing external links, social media login, payment gateway links, WhatsApp messaging links, or third-party advertising links

9. Storage and Retention of Data

User data is stored securely in cloud-based infrastructure in accordance with applicable Indian data protection laws and reasonable security practices.

Data location and cross-border processing: GuruMode's primary backend, database, and storage are hosted in India (Supabase, Mumbai region), and personal data is stored and processed in India. Certain communication providers, including Google/Firebase Cloud Messaging and Gallabox on the Meta WhatsApp Business Platform, may process limited notification or communication data in jurisdictions outside India. This may include the FCM token, notification-delivery metadata, the parent's mobile number, approved WhatsApp message content, and delivery status. The AI language-generation provider (Anthropic) may process the learner's display name and selected learning evidence outside India, for example in the United States. Where data is processed outside India, GuruMode takes reasonable steps to ensure protection consistent with the DPDPA and applicable law.

We retain personal information only as long as necessary to provide the Platform, maintain account records, support the parent, improve safety and reliability, comply with legal obligations, resolve disputes, and enforce agreements.

Parent account data is retained while the account is active. Student learning interaction data is retained for the duration of the active account and for a reasonable period thereafter, where needed for account restoration, support, security, or legal purposes.

Upon verified account deletion, personal identifiers will be deleted or anonymised from active systems within 30 days, subject to legal, security, backup, fraud-prevention, dispute-resolution, or regulatory retention obligations. Backup copies may take longer to expire through normal backup rotation, but they are not used for active product operation.

10. Account Deletion and Data Deletion

Parents or legal guardians may request account deletion and associated data deletion through any of the following:

  • Inside the app: Profile → Parental controls → Delete Profile
  • Outside the app: https://gurumode.world/delete-account
  • By email: support.gurumode@gmail.com

Before deleting an account, GuruMode may verify that the request comes from the registered parent or legal guardian. After verification, GuruMode will delete or anonymise personal data associated with the account, except records that must be retained for legal, security, fraud-prevention, dispute-resolution, tax, accounting, or regulatory purposes.

Deleting the parent account may permanently remove the student's learning profile, learning progress, stars, streaks, reports, and related learning history.

Where personal data has been shared with processors, service providers, or other disclosed recipients, including Supabase, Gallabox, and Meta, as applicable, GuruMode will take reasonable steps to extend the deletion or anonymisation request to those recipients, subject to their technical capabilities and applicable retention obligations.

11. Security Measures

We implement reasonable technical and organisational security measures to protect personal data, including TLS/SSL encryption for data in transit, access controls, restricted backend access, secure cloud storage, logging, monitoring, and periodic security review.

No method of transmission or storage is completely secure. In the event of a personal data breach that is likely to cause harm to Data Principals, GuruMode will notify affected users and the Data Protection Board of India in accordance with applicable DPDPA obligations.

12. Cookies, Local Storage, and Analytics

The Platform and associated website may use cookies, local storage, device storage, or equivalent technologies to maintain session state, remember preferences, improve performance, protect account security, debug crashes, and collect limited usage analytics.

This data is used for service operation, security, debugging, crash reduction, and product improvement. It is not used for third-party advertising to students, ads measurement, retargeting, or commercial profiling.

Parents may manage browser cookies through browser settings. Disabling some storage mechanisms may affect login, session continuity, or Platform functionality.

13. Your Rights Under the DPDPA

As a Data Principal under the DPDPA, the registered parent or legal guardian may have the following rights in relation to personal data held by GuruMode:

  • Right of Access: To obtain a summary of personal data held by GuruMode and the purposes for which it is processed
  • Right to Correction: To request correction of inaccurate, incomplete, or outdated personal data
  • Right to Erasure: To request deletion of personal data where the purpose for which it was collected is no longer being served, subject to applicable retention obligations
  • Right to Grievance Redressal: To have grievances related to data processing addressed in a timely and effective manner
  • Right to Withdraw Consent: To withdraw consent for non-essential processing, without affecting lawful processing already carried out before withdrawal
  • Right to Nominate: To nominate another individual to exercise these rights in the event of death or incapacity, where applicable

Parents or legal guardians may exercise these rights by contacting support.gurumode@gmail.com. We will endeavour to respond to verified data rights requests within 30 days of receipt. Complex or high-volume requests may require additional time, and we will notify you where appropriate.

14. Third-Party Links and Services

The Platform relies on the infrastructure, authentication, OTP/SMS, notification, WhatsApp, and support providers identified in Section 7.1. GuruMode does not include a third-party analytics or crash-reporting SDK in the current Android MVP. GuruMode is not responsible for the independent privacy practices of third-party providers outside our control, and we encourage parents to review the privacy policies of relevant service providers where applicable.

The current MVP does not include student-facing external links, social media login, third-party advertising, payment gateway links, student-facing WhatsApp messaging, public student profiles, public comments, or student-to-student messaging. If future versions add third-party links or integrations, they will be reviewed for child safety before release and disclosed as required.

15. Changes to This Policy

GuruMode may modify or update this Policy from time to time to reflect changes in law, technology, Platform features, or business operations.

Where material changes are made, GuruMode will publish the updated Policy on the Platform with a revised effective date and will endeavour to notify registered parents through the Platform or by email where appropriate.

Where an updated Policy involves materially new processing of personal data, GuruMode will seek fresh verifiable parental consent before that new processing begins. If you do not agree to an updated Policy, you may stop using the Platform and request account deletion.

16. Disclaimer

GuruMode uses reasonable safeguards to protect personal data, but users are advised to secure their own devices, use safe networks, and avoid sharing OTPs or account access with unauthorised persons. GuruMode is not responsible for loss or compromise caused by a user's own device insecurity, shared OTPs, unauthorised access to the user's device, or unsafe network use, except where required by applicable law.

17. Governing Law and Jurisdiction

This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and rules framed thereunder. All disputes arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts at Chennai, Tamil Nadu, India.

18. Contact and Grievance Redressal

For questions, concerns, data access requests, deletion requests, or grievances relating to this Policy or the processing of personal data, please contact:

Grievance Officer / Privacy Contact
GuruMode
Owner / Operator: Ghibran Vaibodha, Proprietor of GuruMode
Email: support.gurumode@gmail.com
Website: https://gurumode.world
Business Address: 9/11 Duraisamy Street, Natesan Nagar, 2nd Main Road, Virugambakkam, Chennai - 600092, Tamil Nadu, India

We are committed to addressing data-related grievances promptly and in accordance with applicable Indian law.

© 2026 GuruMode. Owned and operated by Ghibran Vaibodha, Proprietor of GuruMode. https://gurumode.world
GuruMode Privacy Policy - Free MVP for Grades 5, 6, 7 and 8 - Updated July 2026
GuruMode

GuruMode is owned and operated by Ghibran Vaibodha, trading as GuruMode.
Learning that adapts.

App

  • Try GuruMode
  • How it works
  • Curriculum
  • Download on Play Store

Company

  • Founder
  • Schools
  • Blog
  • Contact

Legal

  • Terms & Conditions
  • Privacy Policy
  • Request Account Deletion
© 2026 GuruMode. Owned and operated by Ghibran Vaibodha, Proprietor of GuruMode. All rights reserved.
support.gurumode@gmail.com +91 91763 73040