1. What this covers
This notice explains, in plain terms, how content and data move through Gaurify OS so you know exactly what happens to what you upload.
2. Footage and files
Raw footage, final deliverables, and business documents you upload are stored in our secured Supabase storage bucket and are accessible only to Gaurify staff and the specific editor assigned to your project, enforced by database row-level security.
Links you paste (Google Drive, Dropbox, WeTransfer, etc.) are stored as references so the team can retrieve your footage; we do not copy the linked content unless needed to produce your work.
3. How email is used
Transactional emails (sign-in links, project updates, invoices) are sent via Brevo. We do not send marketing email through the Platform without a separate opt-in.
4. Notifications
If you enable push notifications, we store a device subscription token to deliver alerts about your projects. You can disable this at any time in your browser or device settings.
5. Access controls
Every request is authorized server-side by role, and the database enforces isolation so one client can never read another client's data, and editors only see projects assigned to them. Significant actions are recorded in an audit log.
6. Sub-processors and AI
We rely on the sub-processors listed in our Privacy Policy (§4): Supabase, Vercel, Cloudflare R2, Brevo, Google, Razorpay, PayPal, and — only if used — Meta/WhatsApp. Delivered files are stored in Cloudflare R2 or Supabase storage; payment card details are handled by Razorpay/PayPal and never stored by us.
Gaurify Flow, our AI assistant, sends the work information you ask about (scoped to what you are permitted to see, and never your stored files, password, or full card numbers) to an AI provider to generate answers, under terms that prohibit training on your content, and may send a public-web search query to Brave. See Privacy Policy §4a. Flow can be turned off for your organisation.