GuruMode values your trust and is committed to protecting your privacy and personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA"), the rules framed thereunder, and other applicable Indian laws.
This Privacy Policy ("Policy") explains how Ghibran Vaibodha, Proprietor of GuruMode ("GuruMode", "we", "our", or "us"), collects, uses, stores, shares, and protects information when you access or use the GuruMode Android application, website (https://gurumode.world), and related digital services (collectively, the "Platform").
GuruMode is owned and operated by Ghibran Vaibodha, Proprietor of GuruMode.
This Policy is written for the current MVP release. The current MVP is a free learning product for students in Grades 5, 6, 7 and 8. It does not include payment, subscription, in-app purchase, Razorpay, Google Play Billing, third-party advertising, student chat, student social features, student public profiles, or student free-text messaging. If GuruMode adds any of these features in a future version, this Policy will be updated before that feature is used, and any required parent/legal guardian consent will be obtained.
For privacy, safety, support, or data-related questions, contact: support.gurumode@gmail.com
By registering or using the Platform, the parent or legal guardian acknowledges this Policy. If you do not agree, please discontinue use of the Platform and contact support.gurumode@gmail.com to request deletion of any data already collected.
This Policy is a privacy notice that explains our data practices. It is provided together with, but is separate from, the consent GuruMode obtains from the parent or legal guardian at registration. If GuruMode introduces materially new processing, it will provide an updated notice and obtain fresh parental consent where required before that processing begins.
GuruMode is designed for students in Grades 5, 6, 7 and 8 and is used through a parent-controlled account. Registration is completed by the parent or legal guardian using the parent's mobile number and OTP verification. The OTP, mobile number, account controls, and deletion controls are intended for the parent or legal guardian, not for the student-facing learning experience.
The parent or legal guardian is the account holder and the Data Principal for the parent's own account and contact information. The student is the individual to whom the learner-profile and learning-interaction data relate. For personal data relating to a child, the term "Data Principal" includes the child's parent or lawful guardian acting on the child's behalf, in accordance with the DPDPA. GuruMode obtains verifiable parental consent before creating or using the student profile.
GuruMode does not knowingly allow a student to independently register, provide a phone number, verify OTP, make payments, purchase subscriptions, or manage the account. If we become aware that personal data was collected from a student without valid parental consent, we will take reasonable steps to delete such data.
GuruMode applies the same child-safety protections to all student users in Grades 5, 6, 7 and 8, including students who may fall into different child age bands under applicable laws or Google Play target-audience categories.
The student display name is used only inside the parent-controlled account and student learning experience. It is not shown publicly, searchable by other users, or used for student-to-student interaction.
When a parent or legal guardian registers or uses the Platform, we may collect:
When the Platform is accessed, we may automatically collect limited technical and usage information, including:
GuruMode does not use the Android Advertising ID, Android ID, or App Set ID, and does not use any installation, session, or diagnostic identifier for advertising, ads measurement, retargeting, or commercial profiling. Identifiers are used only for the operational purposes described in this Policy.
GuruMode is designed with child safety as a core requirement. In the current MVP, we do not collect:
GuruMode does not request the Android AD_ID permission for the child-facing MVP and does not use advertising identifiers for student users.
Support request attachments: When a parent or legal guardian contacts support through the app, they may optionally attach up to five images or videos (maximum 50 MB each) using the device's system photo picker, to help us resolve their request. The app accesses only the specific image or video selected by the parent through the system picker, and uploads the selected file to GuruMode's secure support storage. Attachments are retained as part of the support and account record for record-keeping. A parent or legal guardian may request deletion of their support attachments at any time by contacting support.gurumode@gmail.com, and GuruMode will delete or anonymise them on verified request, subject to any longer retention required for security, dispute resolution, or legal compliance. Access is restricted to authorised support and technical personnel. These attachments are used solely to handle the support request and are not used for advertising, profiling, model or AI training, or any unrelated purpose. Parents are asked not to include sensitive personal information about the child in support attachments unless strictly necessary.
We collect and process personal data only for lawful and necessary purposes connected to the current MVP, including:
GuruMode does not use personal data for third-party advertising, targeted internet-based marketing, ads measurement, retargeting, commercial resale, or profiling for sale. No advertising is displayed to students.
The current MVP is free. GuruMode does not collect payment information, does not process subscriptions, does not display payment screens to students, and does not use Razorpay, Google Play Billing, or any other payment gateway in the current MVP.
If GuruMode introduces paid plans, subscriptions, in-app purchases, or payment processing in a future release, the feature will be parent-facing only, the Policy will be updated before the feature is used, and the implementation will follow applicable platform rules and law.
GuruMode sends parent-facing WhatsApp messages to the parent or legal guardian's registered, OTP-verified mobile number. WhatsApp messaging is enabled when the parent registers, and the parent may turn it off at any time from the in-app WhatsApp settings or by contacting support.gurumode@gmail.com. Messages fall into categories: (a) account and service messages; (b) learning updates and reminders, such as a welcome message, weekly progress digest, milestone celebrations, and a daily habit reminder, which are enabled by default; and (c) behaviour-based nudges, such as streak reminders and learning-support alerts, which remain off until the parent explicitly enables each one. GuruMode minimises learner information included in WhatsApp messages, does not send WhatsApp messages to students, and provides no WhatsApp messaging inside the student learning experience.
WhatsApp messages are delivered through Gallabox, operating on the Meta WhatsApp Business Platform, using pre-approved message templates. In delivering these messages, the provider and Meta may process the parent's mobile number, message content, and delivery status in order to operate the service. Meta and Gallabox may technically process replies within the WhatsApp service, but GuruMode does not ingest, store, or use those replies in the GuruMode application or backend. When the parent turns off WhatsApp communication, GuruMode stops sending WhatsApp messages to that number; essential account or security communications may continue through other available channels, such as in-app notices, SMS, or email, where necessary. GuruMode keeps operational records of WhatsApp enrolment, opt-out status, selected message categories, and message delivery status in order to operate the service and honour opt-out requests.
The current MVP does not include student chat, voice chat, social feeds, student-to-student messaging, public comments, searchable student profiles, public leaderboards, or open student-generated text communication.
Student learning interaction data, including accuracy rates, response patterns, hint usage, retry behaviour, time spent, streaks, stars, chapter progress, and adaptive signals, is processed to power the Platform's adaptive learning experience.
This data is used to personalise the student's learning path, identify areas where the student may need extra help, improve content quality, and show progress to the parent or legal guardian through parent-facing surfaces where available.
GuruMode may use aggregated or anonymised learning data internally for product improvement, content quality analysis, crash reduction, learning-outcome analysis, and research into learning effectiveness. Aggregated or anonymised data does not identify an individual parent or student.
To prepare parent-facing WhatsApp progress narratives, GuruMode uses automated language-generation technology provided by a third-party AI provider (Anthropic, the Claude API). The provider receives the learner's display name and selected learning evidence (such as a completed topic or milestone) to generate a short qualitative narrative for the parent, and does not receive XP, point totals, streak-day counts, accuracy percentages, or detailed answer history. The provider processes this data only to generate the narrative on GuruMode's instructions, does not use it to train its models, and does not use it for its own purposes.
GuruMode currently uses the following operational providers and disclosed recipients to operate the Platform:
Each provider processes only the data necessary for its stated function: Supabase processes account, profile, learning, support, and first-party operational-event records; the OTP/SMS provider processes the parent mobile number and OTP-delivery metadata; Firebase Cloud Messaging processes the push token and notification-delivery metadata; and the AI language-generation provider (Anthropic, the Claude API) processes the learner's display name and selected learning evidence to generate the parent-facing progress narrative. Supabase, the OTP/SMS provider, Firebase Cloud Messaging, Gallabox, and the AI language-generation provider process data to provide contracted operational services on GuruMode's behalf, on GuruMode's instructions, and do not use it for their own purposes. Meta Platforms receives WhatsApp data (the parent mobile number, approved message content, and delivery metadata) through the WhatsApp Business Platform and may process certain information under its own applicable terms, as described in Sections 7.3 and 9.
GuruMode does not permit service providers to use student data for their own advertising, ads measurement, retargeting, profiling for commercial resale, or unrelated purposes.
GuruMode reviews third-party APIs and SDKs used in the student-facing MVP for child-safety suitability and removes or disables SDKs that are not appropriate for child-directed or child-inclusive services.
GuruMode does not use any third-party advertising, attribution, cross-app tracking, analytics, or crash-reporting SDK. Product analytics are first-party and stored in GuruMode's own backend, and crash and stability information is limited to the aggregate reports provided by Google Play.
To deliver WhatsApp messages, GuruMode shares the parent's mobile number and message content with Meta Platforms through the WhatsApp Business Platform (via Gallabox). Meta processes this information under its own WhatsApp Business Terms and privacy policy, may process it in the United States or other countries, and may use certain service-usage information for its own purposes as described in those terms. This sharing is solely to provide the WhatsApp messaging feature and is not a sale of personal data.
We may disclose personal information when required by applicable law, regulation, court order, governmental authority, or where necessary to protect the rights, property, or safety of GuruMode, users, or the public.
GuruMode does not sell, rent, lease, or trade personal data for money or other valuable consideration. Except for the operational disclosures described in Section 7.1 - including the transfer of WhatsApp data to Meta for delivery and related service processing - GuruMode does not disclose personal data to unrelated third parties and does not show third-party advertising to students.
GuruMode's current MVP includes the following child-safety protections:
User data is stored securely in cloud-based infrastructure in accordance with applicable Indian data protection laws and reasonable security practices.
Data location and cross-border processing: GuruMode's primary backend, database, and storage are hosted in India (Supabase, Mumbai region), and personal data is stored and processed in India. Certain communication providers, including Google/Firebase Cloud Messaging and Gallabox on the Meta WhatsApp Business Platform, may process limited notification or communication data in jurisdictions outside India. This may include the FCM token, notification-delivery metadata, the parent's mobile number, approved WhatsApp message content, and delivery status. The AI language-generation provider (Anthropic) may process the learner's display name and selected learning evidence outside India, for example in the United States. Where data is processed outside India, GuruMode takes reasonable steps to ensure protection consistent with the DPDPA and applicable law.
We retain personal information only as long as necessary to provide the Platform, maintain account records, support the parent, improve safety and reliability, comply with legal obligations, resolve disputes, and enforce agreements.
Parent account data is retained while the account is active. Student learning interaction data is retained for the duration of the active account and for a reasonable period thereafter, where needed for account restoration, support, security, or legal purposes.
Upon verified account deletion, personal identifiers will be deleted or anonymised from active systems within 30 days, subject to legal, security, backup, fraud-prevention, dispute-resolution, or regulatory retention obligations. Backup copies may take longer to expire through normal backup rotation, but they are not used for active product operation.
Parents or legal guardians may request account deletion and associated data deletion through any of the following:
Before deleting an account, GuruMode may verify that the request comes from the registered parent or legal guardian. After verification, GuruMode will delete or anonymise personal data associated with the account, except records that must be retained for legal, security, fraud-prevention, dispute-resolution, tax, accounting, or regulatory purposes.
Deleting the parent account may permanently remove the student's learning profile, learning progress, stars, streaks, reports, and related learning history.
Where personal data has been shared with processors, service providers, or other disclosed recipients, including Supabase, Gallabox, and Meta, as applicable, GuruMode will take reasonable steps to extend the deletion or anonymisation request to those recipients, subject to their technical capabilities and applicable retention obligations.
We implement reasonable technical and organisational security measures to protect personal data, including TLS/SSL encryption for data in transit, access controls, restricted backend access, secure cloud storage, logging, monitoring, and periodic security review.
No method of transmission or storage is completely secure. In the event of a personal data breach that is likely to cause harm to Data Principals, GuruMode will notify affected users and the Data Protection Board of India in accordance with applicable DPDPA obligations.
The Platform and associated website may use cookies, local storage, device storage, or equivalent technologies to maintain session state, remember preferences, improve performance, protect account security, debug crashes, and collect limited usage analytics.
This data is used for service operation, security, debugging, crash reduction, and product improvement. It is not used for third-party advertising to students, ads measurement, retargeting, or commercial profiling.
Parents may manage browser cookies through browser settings. Disabling some storage mechanisms may affect login, session continuity, or Platform functionality.
As a Data Principal under the DPDPA, the registered parent or legal guardian may have the following rights in relation to personal data held by GuruMode:
Parents or legal guardians may exercise these rights by contacting support.gurumode@gmail.com. We will endeavour to respond to verified data rights requests within 30 days of receipt. Complex or high-volume requests may require additional time, and we will notify you where appropriate.
The Platform relies on the infrastructure, authentication, OTP/SMS, notification, WhatsApp, and support providers identified in Section 7.1. GuruMode does not include a third-party analytics or crash-reporting SDK in the current Android MVP. GuruMode is not responsible for the independent privacy practices of third-party providers outside our control, and we encourage parents to review the privacy policies of relevant service providers where applicable.
The current MVP does not include student-facing external links, social media login, third-party advertising, payment gateway links, student-facing WhatsApp messaging, public student profiles, public comments, or student-to-student messaging. If future versions add third-party links or integrations, they will be reviewed for child safety before release and disclosed as required.
GuruMode may modify or update this Policy from time to time to reflect changes in law, technology, Platform features, or business operations.
Where material changes are made, GuruMode will publish the updated Policy on the Platform with a revised effective date and will endeavour to notify registered parents through the Platform or by email where appropriate.
Where an updated Policy involves materially new processing of personal data, GuruMode will seek fresh verifiable parental consent before that new processing begins. If you do not agree to an updated Policy, you may stop using the Platform and request account deletion.
GuruMode uses reasonable safeguards to protect personal data, but users are advised to secure their own devices, use safe networks, and avoid sharing OTPs or account access with unauthorised persons. GuruMode is not responsible for loss or compromise caused by a user's own device insecurity, shared OTPs, unauthorised access to the user's device, or unsafe network use, except where required by applicable law.
This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and rules framed thereunder. All disputes arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts at Chennai, Tamil Nadu, India.
For questions, concerns, data access requests, deletion requests, or grievances relating to this Policy or the processing of personal data, please contact:
Grievance Officer / Privacy Contact
GuruMode
Owner / Operator: Ghibran Vaibodha, Proprietor of GuruMode
Email: support.gurumode@gmail.com
Website: https://gurumode.world
Business Address: 9/11 Duraisamy Street, Natesan Nagar, 2nd Main Road, Virugambakkam, Chennai - 600092, Tamil Nadu, India
We are committed to addressing data-related grievances promptly and in accordance with applicable Indian law.