1. Scope
This Privacy Policy explains how Gaurify collects, uses, stores, and protects personal data when you use Gaurify OS. We act as the data fiduciary/controller for account and business data, and as a processor for the content you upload to run your projects.
2. What we collect
Account data: your name, email, phone (if provided), role, and organization. For editors and team members we also collect onboarding details you provide (skills, experience, portfolio, availability, payment details, emergency contact, and identity-verification documents).
Project data: briefs, notes, footage and files you upload, links you paste, comments, revisions, and delivery history.
Financial data: invoices, amounts, payment references, and payout details. We do not store full card numbers; card processing, where used, is handled by third-party processors.
Technical data: sign-in events, IP address and user-agent (including at the moment you accept our agreements), device/push-subscription tokens if you enable notifications, and audit logs of significant actions.
3. How we use it
To provide the service (run your projects, produce and deliver work, issue invoices); to authenticate you and secure the Platform; to notify you about your projects; to meet legal, tax, and accounting obligations; and to improve reliability. We do not sell your personal data.
4. Where your data lives (sub-processors)
We use trusted infrastructure providers to run the Platform: Supabase (database, authentication, and file storage), Google Calendar (meetings), Brevo (transactional email), and Vercel (application hosting). These providers process data on our behalf under their own security and privacy commitments. Data may be processed in regions outside India, with appropriate safeguards.
5. Identity masking
To protect both clients and editors, the Platform deliberately separates identities: clients never see which editor worked on their project, and editors never see the client's identity. We process the minimum personal data needed on each side of that boundary.
6. Retention
We keep personal and project data for as long as your account is active and as needed to provide the service, then per our Data Retention Policy. Financial records are kept as long as tax and accounting law requires. Audit logs are retained for security and dispute resolution.
7. Your rights
Subject to applicable law (including India's Digital Personal Data Protection Act, 2023, and, where relevant, the GDPR), you may request access to, correction of, or deletion of your personal data, and you may withdraw consent. To exercise these rights, contact hello@gaurifyhq.com. We will verify your identity before acting. Some data must be retained where the law requires it (for example, tax records).
8. Security
We protect data with row-level database security, encrypted transport, encryption of sensitive fields at rest, access controls by role, and audit logging. See our Security Policy. No system is perfectly secure; we will notify affected users and authorities of a personal-data breach as required by law.
9. The mobile apps
Gaurify OS is also available as apps for Android and iOS. They talk to the same service and are covered by everything above; this section describes what is different because the software is running on your own phone.
On the device we store your signed-in session and your workspace's appearance settings. The session is held in the platform's own encrypted store — the Android Keystore or the iOS Keychain — and is removed when you sign out. Nothing else about your projects is kept on the device after you close the app.
If you turn on biometric unlock, the check is performed by Android or iOS and never by us. We are told only whether the unlock succeeded. Your fingerprint or face data never leaves your device, is never sent to us, and we could not read it if it were.
The Android app requests three permissions and no others: internet access, network-state (to tell "offline" from "failed"), and biometric (only if you enable unlock). It asks for no location, contacts, camera, microphone, or file-system access beyond the files you deliberately choose to upload.
The apps contain no advertising, no analytics or tracking SDK, and no crash-reporting SDK. We do not collect an advertising identifier, we do not track you across other companies' apps or websites, and no data from the apps is sold or shared for advertising.
To delete your account and the personal data we hold for it, write to hello@gaurifyhq.com from your account's email address. This applies whether you signed up on the web or in an app, and is the same right described in section 7.
10. Contact
Data-protection questions and requests: hello@gaurifyhq.com. General legal contact: hello@gaurifyhq.com.