1. Scope
This Privacy Policy explains how Gaurify collects, uses, stores, and protects personal data when you use Gaurify OS. We act as the data fiduciary/controller for account and business data, and as a processor for the content you upload to run your projects.
2. What we collect
Account data: your name, email, phone (if provided), role, and organization. For editors and team members we also collect onboarding details you provide (skills, experience, portfolio, availability, payment details, emergency contact, and identity-verification documents).
Project data: briefs, notes, footage and files you upload, links you paste, comments, revisions, and delivery history.
Financial data: invoices, amounts, payment references, and payout details. We do not store full card numbers; card processing, where used, is handled by third-party processors.
Technical data: sign-in events, IP address and user-agent (including at the moment you accept our agreements), device/push-subscription tokens if you enable notifications, and audit logs of significant actions.
3. How we use it
To provide the service (run your projects, produce and deliver work, issue invoices); to authenticate you and secure the Platform; to notify you about your projects; to meet legal, tax, and accounting obligations; and to improve reliability. We do not sell your personal data.
4. Where your data lives (sub-processors)
We use trusted providers to run the Platform, each processing data on our behalf only as needed for its function, under its own security and privacy commitments: Supabase (database, authentication, and file storage), Vercel (application hosting), Cloudflare R2 (storage of delivered files), Brevo (transactional email), Google (Calendar and Drive, only if you connect them), Razorpay and PayPal (payment processing), and Meta/WhatsApp (only if your studio uses WhatsApp messaging, which sends the phone numbers and message content involved to Meta).
Gaurify Flow, our AI assistant, additionally uses AI providers (which may include Groq, OpenRouter, and Anthropic) and, for questions about the public web, the Brave Search API. What these receive is described in the next section.
Data may be processed in regions outside India (including the United States), under appropriate safeguards. A current sub-processor list and a Data Processing Agreement are available on request at hello@gaurifyhq.com.
4a. Gaurify Flow (the AI assistant)
When you use Gaurify Flow, we send the work information you ask about — such as your project titles, statuses and deadlines, invoice figures, and the message you are drafting — to an AI provider so it can generate your answer. This is always scoped to what you are already allowed to see on the Platform: Flow runs on your own permissions, never crosses between tenants, and keeps our client/editor identity separation intact.
We do NOT send your stored files or video content, your password, or full payment-card numbers to the AI. We use AI providers under terms that do not permit them to use your content to train their models. For a question that needs current public-web information, Flow may send a short search query (not your workspace data) to the Brave Search API.
Gaurify Flow can be turned off for your organisation. Because AI providers may operate outside India, this processing may involve a cross-border transfer under the safeguards described above.
5. Identity masking
To protect both clients and editors, the Platform deliberately separates identities: clients never see which editor worked on their project, and editors never see the client's identity. We process the minimum personal data needed on each side of that boundary.
6. Retention
We keep personal and project data for as long as your account is active and as needed to provide the service, then per our Data Retention Policy. Financial records are kept as long as tax and accounting law requires. Audit logs are retained for security and dispute resolution.
7. Your rights (India DPDP Act, 2023)
If you are in India, the Digital Personal Data Protection Act, 2023 gives you, as a Data Principal, the following rights over the personal data we hold as Data Fiduciary:
Right to access: a summary of the personal data we process about you and the processing activities involved.
Right to correction and erasure: to have inaccurate or incomplete data corrected or updated, and to have your personal data erased when it is no longer needed for the purpose it was collected for or as the law requires.
Right to withdraw consent: where we rely on your consent, you may withdraw it at any time; withdrawing is as easy as giving it, and does not affect processing already carried out.
Right of grievance redressal: a readily available means to raise a concern with us (see the next section) before approaching the Data Protection Board.
Right to nominate: to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these, contact hello@gaurifyhq.com. We will verify your identity before acting and respond within the timelines the law prescribes. Some data must be retained where the law requires it (for example, tax and accounting records); where relevant law such as the GDPR also applies, equivalent rights are honoured.
7a. Grievance redressal and the Data Protection Board
If you have a concern about how your personal data is handled, write to our Grievance Officer at hello@gaurifyhq.com. We will acknowledge your grievance and work to resolve it within the period prescribed under the DPDP Act and its rules.
If you are not satisfied with our response, or we do not respond in time, you may escalate your complaint to the Data Protection Board of India, the authority established under the DPDP Act, in the manner it prescribes.
8. Security and breach notification
We protect data with row-level database security, encrypted transport, encryption of sensitive fields at rest, access controls by role, and audit logging. See our Security Policy.
No system is perfectly secure. In the event of a personal-data breach, we will notify each affected Data Principal and the Data Protection Board of India, without undue delay and in the manner required by the DPDP Act and its rules, describing what happened, the likely consequences, and the steps we are taking and you can take in response.
9. The mobile apps
Gaurify OS is also available as apps for Android and iOS. They talk to the same service and are covered by everything above; this section describes what is different because the software is running on your own phone.
On the device we store your signed-in session and your workspace's appearance settings. The session is held in the platform's own encrypted store, the Android Keystore or the iOS Keychain, and is removed when you sign out. Nothing else about your projects is kept on the device after you close the app.
If you turn on biometric unlock, the check is performed by Android or iOS and never by us. We are told only whether the unlock succeeded. Your fingerprint or face data never leaves your device, is never sent to us, and we could not read it if it were.
The Android app requests three permissions and no others: internet access, network-state (to tell "offline" from "failed"), and biometric (only if you enable unlock). It asks for no location, contacts, camera, microphone, or file-system access beyond the files you deliberately choose to upload.
The apps contain no advertising, no analytics or tracking SDK, and no crash-reporting SDK. We do not collect an advertising identifier, we do not track you across other companies' apps or websites, and no data from the apps is sold or shared for advertising.
To delete your account and the personal data we hold for it, write to hello@gaurifyhq.com from your account's email address. This applies whether you signed up on the web or in an app, and is the same right described in section 7.
10. Contact
Data-protection questions and requests: hello@gaurifyhq.com. General legal contact: hello@gaurifyhq.com.