GuruVPN Privacy Policy
Guru VPN is a modern virtual private network service designed to ensure the security and anonymity of users while surfing the internet. It effectively protects data and personal information from unauthorized access, offering a reliable solution for those who value privacy in the digital world.
Guru VPN processes your personal data and acts as a data controller in accordance with privacy laws, including the General Data Protection Regulation ( GDPR ).
This Privacy Policy explains how GURU NETWORK S.R.L. ("Company", "we", "us", "our") collects, uses, stores, discloses, and otherwise processes Personal Data in connection with the Guru VPN service (website: guruvpn.com, mobile applications). By accessing or using the Service you acknowledge that you have read and accept this Policy.
By continuing to use our Website and/or Services, you accept the terms of this Privacy Policy. We strongly urge you to refrain from using our Services and Websites if you do not agree with this Privacy Policy or any of its provisions.
Controller: GURU NETWORK S.R.L. (legal name: GURU NETWORK S.R.L., registration no.: J2025060746006, CUI/VAT ID 523197202, registered address: Bucureşti, Sectorul 3, Str. Nerva Traian, Nr. 27-33, br. 6, Scara B, Etaj 1, Post code 031044, Romania).
Privacy contact email: privacy@guruvpn.com; general support: support@guruvpn.com.
1. Processing of your data
Guru VPN follows a no-logs approach to the content of your VPN traffic. We do not monitor, inspect, or store the content of communications, traffic payloads, full URLs, page content, or detailed browsing histories. Where limited operational data is processed to operate, secure, troubleshoot, bill for, improve, and lawfully administer the Service, it is described in this Policy and kept minimized.
No-logs does not mean that Guru VPN collects no data at all. Guru VPN may process limited account, subscription, billing, diagnostics, security, service metadata, user-linked connection logs, registered-device limit status, DNS technical logs, analytics/SDK data, cookies for the website, push notification data, and support data where necessary for the purposes described in this Policy.
To make sure our VPN service operates effectively, our systems may retain limited user-linked connection logs showing that a user account or registered device connected to a particular VPN server, together with connection timestamps available under the current architecture and connection status indicators, such as whether traffic was detected for connection-success and service-reliability metrics. We do not store users' real source IP addresses in connection logs, do not associate source IP addresses with user accounts, and do not keep records of the websites you visit.
2. Categories of Personal Data We Collect
We collect a limited amount of personal data that may directly or indirectly identify you while you use our Services. This information is essential for delivering our Services effectively, enhancing user experience, optimizing functionalities, and ensuring compliance with legal obligations. We are deeply committed to protecting your privacy and managing your personal data with the utmost responsibility and care.
We collect the following categories of Personal Data to operate and maintain the Service:
- Account information: email address (required for most users; optional for demo iOS accounts), username or display name if provided, account creation date and subscription status, signup method (OTP or OAuth via Apple/Google).
- Authentication and security metadata: login attempts, one‑time password (OTP) metadata, device identifiers used for authentication.
- Payment and billing metadata: transaction identifiers, receipts, billing name/email, subscription IDs managed through Stripe and RevenueCat. We do not store full card numbers (PAN) on our servers; card processing is handled by payment providers.
- Connection logs: VPN server identifiers and connection timestamps (connection start/end times). These are recorded in our primary database.
- DNS logs: Domain names you resolve, timestamps, and your source IP address. These are stored in Google Cloud BigQuery (USA) for up to 7 days to enable security filtering and performance improvements. We do not log the full URLs or content of your traffic.
- Crash and diagnostic data: crash reports, stack traces and other diagnostic telemetry stored in Firebase (and Sentry where applicable).
- Analytics and usage metrics: event data and aggregated metrics sent to analytics providers (e.g., Firebase/Google Analytics, Amplitude, Plausible, AppsFlyer).
- Push notification data: device tokens and related metadata processed via OneSignal.
- Support communications: email, in‑app support messages, and related ticket logs.
3. Data We Do Not Collect
We do not collect or retain full traffic payloads, the content of communications, detailed browsing histories or page content. The only network‑level metadata we retain are the connection logs and DNS records noted above.
4. Purposes and Legal Bases for Processing
We process Personal Data for the following purposes and on these legal grounds, as applicable:
- To provide and administer the Service and fulfill contractual obligations to users (performance of a contract).
- To maintain security, detect and prevent fraud, abuse and attacks, and to ensure service reliability (legitimate interests).
- To comply with applicable laws and respond to lawful requests from public authorities (legal obligation).
- Where applicable, on the basis of the user’s consent - for optional features such as certain analytics or marketing communications.
5. Current Logging, Storage Locations and Retention Practices
-
Connection logs: limited user-linked connection logs stored in our primary database hosted on DigitalOcean (Amsterdam, NL). These logs may show that a user account or registered device connected to a particular VPN server, together with connection timestamps available under the current architecture and connection status indicators, such as whether traffic was detected for connection-success and service-reliability metrics. We do not store users' real source IP addresses in connection logs, do not associate source IP addresses with user accounts, and do not use these logs to maintain browsing histories, traffic content, full URLs, page content, user-linked DNS query logs, or communications content. Connection logs are retained by default for 30 days and may be retained for up to 6 months where necessary and documented for security, billing, incident investigation, lawful-request handling, or the establishment, exercise, or defence of legal claims. After the retention period expires, the logs are deleted, anonymised, or aggregated so that longer-term connection-rate metrics do not remain user-identifiable unless a documented legal or security reason requires otherwise
-
DNS logs: DNS technical logs may consist of domain names resolved through the Service and timestamps. They may be collected through third-party DNS servers and/or Guru VPN's resolver and stored in Google Cloud / BigQuery (United States) for up to 7 days to enable security filtering and performance improvements. Under the current ordinary architecture, these logs are anonymised or de-linked from users before storage or use, are not associated with user accounts, registered devices, or users' real source IP addresses, and do not allow us to identify which user or device made a particular DNS request. In specific cases (e.g., investigation of abuse or security incidents), DNS technical logs may be retained for up to 30 days with strict access controls; any retention beyond 30 days requires documented legal or security justification and supervisory oversight. We do not log full URLs, page content, traffic payloads, or the content of your communications.
-
Security / IDS/IPS alerts and abuse signals: limited network-level security signals, configured signatures, pattern-based alerts, infrastructure signals, and external abuse reports may be processed to protect the Service and investigate abuse. Alerts may include technical indicators and internal device identifiers that may allow Guru VPN to associate a security event with an account or device where necessary. IDS/IPS alerts do not constitute full traffic-content monitoring, and packets or traffic payloads are not retained as user activity logs.
-
Registered-device status: registered-device limit status may be processed to enforce plan limits, currently up to four (4) registered devices unless the applicable plan states otherwise. Device limits are based on devices linked to an account, not on simultaneous connection counts
-
Crash and diagnostic logs: crash reports and diagnostic telemetry are stored in Firebase (and Sentry where applicable). By default, these logs are retained for 90 days. If longer retention is necessary for ongoing debugging of recurring issues, we may retain anonymized logs for up to 12 months with documented justification and restricted access.
-
Billing and payment records: transactional metadata and receipts are processed and retained by Stripe and RevenueCat under their policies; we keep only necessary metadata or references in our systems.
-
Analytics data and aggregates: analytics events and aggregated/pseudonymised metrics are stored with analytics providers and in BigQuery as configured per provider.
-
Push tokens: device tokens and push metadata are stored/processed via OneSignal.
-
Backups and exports: managed DB backups and scheduled exports to BigQuery or other analytics stores may preserve records beyond the lifecycle of data in the primary DB; provider backup retention policies apply.
6. Account Deletion - Procedure and Limitations
When a user deletes their account via the application or dashboard, we overwrite/zero personal fields (including email) in the primary database and mark the account as deleted. This operation removes Personal Data from our primary operational store.
However, copies and exports previously written to BigQuery and data retained by third‑party processors (Stripe, RevenueCat, Amplitude, Firebase, OneSignal, etc.) are not automatically purged by the primary DB deletion operation and remain subject to the retention and deletion policies of those providers.
If you request removal of data stored by third parties, contact privacy@guruvpn.com. We will use commercially reasonable efforts to submit deletion requests via available APIs and will document the outcome. If a provider cannot delete data, we will inform you of the applicable retention period.
7. Disclosure and Use by Third‑Party Processors
We engage processors to provide infrastructure, analytics, payments, monitoring and other services. Principal processors include (but are not limited to): DigitalOcean, Google Cloud / BigQuery, Stripe, RevenueCat, Firebase, Sentry, Amplitude, Plausible, AppsFlyer, OneSignal, and various VPN hosting providers (Vultr, Inferno, M247, Timeweb, etc.). All processors operate under contractual Data Processing Agreements (DPAs). For transfers outside the EEA we apply appropriate safeguards (adequacy decisions, Standard Contractual Clauses or equivalent mechanisms).
8. International Transfers of Personal Data
The information we collect, as outlined in this Privacy Policy, may be stored and processed in any country where we have infrastructure or collaborate with other service providers. We thoroughly assess all international data transfers and apply suitable
measures to safeguard your personal data in line with this Privacy Policy. Please be aware that we utilize standard contractual clauses endorsed by the European Commission (available here) for transferring your personal data from the EEA to other countries.
9. Security Measures and Operational Controls
We maintain administrative, technical and physical safeguards proportional to the sensitivity of the data processed:
- TLS encryption in transit for communications with our services.
- Encryption at rest where supported by provider platforms.
- Least‑privilege, role‑based access controls, and mandatory MFA for staff.
- Logging of administrative and privileged access, with periodic reviews.
- Regular vulnerability scanning and scheduled penetration testing.
We do our best to protect your information and privacy, but we cannot guarantee 100% security for the data you disclose on the Internet. By using the Services, you expressly acknowledge and agree that we cannot guarantee the security of any data you provide or that we receive through the Services, and that any general information, other information, or information obtained from you through the Website or Services is provided by you at your own risk.
10. Analytics, Machine Learning and Automated Processing
We utilise analytics providers and may run analytics on aggregated or pseudonymised data for service improvements. Any use of machine learning models involving personal data will be minimized, properly documented, and supported by an appropriate legal basis. We do not undertake automated decision‑making with legal or similarly significant effects without explicit safeguards.
11. Marketing Communications and Push Notifications
With user consent where required, we may send marketing messages via email and push notifications. Users can opt out of marketing emails via unsubscribe links and can disable push notifications via device settings or app controls. Push tokens are managed through OneSignal.
12. Cookies and Tracking Technologies
Our website may use cookies, pixels, web beacons, and similar web technologies to enhance, secure, measure, and improve the Website and Services. You may be able to manage or disable cookies through your browser or the controls described in our Cookie Policy; doing so may limit some website functionality.
Mobile applications do not use browser cookies in the same way as websites. Mobile apps may use SDK-based identifiers, such as IDFA/GAID, Firebase IDs, RevenueCat IDs, attribution identifiers, push notification tokens, and similar mobile identifiers, as described in this Policy and applicable in-app settings. The Cookie Policy applies primarily to website cookies and similar web technologies.
13. Data Subject Rights and How to Exercise Them
Subject to applicable law, you may have rights to access, rectify, erase, restrict processing, object to processing, request data portability, and withdraw consent. To exercise these rights, contact privacy@guruvpn.com or support@guruvpn.com. We will verify your identity and respond within statutory timelines. Note that some copies (e.g., backups, third‑party provider holdings) may persist for a period after deletion requests.
| Right | Description |
|---|---|
| Right of access | You can access or obtain a copy of your personal data by contacting us. |
| Right to transfer | You may object to the processing of your personal data, ask us to restrict its processing, or request the portability of your personal data, if technically feasible. |
| Right to correction | You may request that inaccurate personal data be corrected and that incomplete personal data be completed (depending on the nature of its collection and use). |
| Right to destruction | The right to erasure of your personal data specified in paragraph 6, unless required to do so by applicable law or where we have a legal basis for retaining certain personal data. |
| Right to withdraw consent | If we collected and processed your personal data with your consent, you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing prior to your withdrawal, nor will it affect the processing of your personal data carried out on lawful processing grounds other than consent. |
| Right to object | You may object to our processing of your personal data that is carried out on the basis of our legitimate interests. |
| Right to file a complaint | If you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office . In EU countries, you have the right to lodge a complaint with the relevant supervisory authority . |
14. Retention Summary - Current Operational Choices
-
Connection logs (VPN server identifiers + timestamps):
- Location: DigitalOcean, Amsterdam (Netherlands).
- Retention: default 30 days; up to 6 months with documented justification (incident investigation, law enforcement).
- Legal basis: legitimate interests (security) or performance of a contract.
- Safeguards: automatic deletion; anonymization/pseudonymization; encryption at rest; least privilege access; access logging.
-
DNS logs (domains + timestamps + real user IP):
- Location: Google BigQuery (USA).
- Retention: default 7 days; up to 30 days if operationally necessary; beyond 30 days only for legal/investigative reasons (up to 6–12 months when warranted).
- Legal basis: legitimate interests (abuse prevention) or consent.
- Safeguards: IP pseudonymization/removal where possible; encryption in transit and at rest; strict access controls and audit.
-
Crash and diagnostic logs (Firebase / Sentry):
- Location: Firebase (Google) and Sentry (cloud providers; may be located in various jurisdictions including the USA).
- Retention: 90 days default; up to 12 months if justified for long‑term debugging.
- Legal basis: performance of a contract / legitimate interests (service reliability).
- Safeguards: strip personal identifiers where possible; data minimization; encryption; role‑based access.
-
Billing/payment metadata:
- Location: Stripe, RevenueCat (payment providers, typically international/USA) and limited local metadata.
- Retention: per applicable tax/financial law (typically 3–7 years). Local auxiliary metadata deleted when no longer required unless law requires retention.
- Legal basis: legal obligations / performance of a contract.
- Safeguards: DPA with providers, encryption, role‑based access, data minimization.
-
Analytics & aggregated metrics:
- Location: Google BigQuery (USA) and analytics providers.
- Retention: fully anonymized/aggregated data may be retained indefinitely; personal/pseudonymized analytics data: typically 3–24 months depending on purpose.
- Legal basis: legitimate interests or consent.
- Safeguards: aggregation, anonymization, retention schedules, access control.
-
Backups and exports:
- Location: in provider infrastructures (including DigitalOcean and cloud services).
- Retention: per provider backup policy (recommended 30–90 days). Backups containing deleted primary records will be flagged for deletion/rotation per retention policy. Extended retention must be documented.
- Legal basis: technical necessity for recovery.
- Safeguards: encrypted backups, access controls, deleted‑record marking.
15. Children’s Privacy
The Service is not intended for children under 18. We do not knowingly collect Personal Data from minors.
We do not offer our services to individuals who are under the age of 18, and we do not intentionally collect their personal information. If you are under 18, we kindly ask that you refrain from sharing any personal details with us. In the event that we find out we have received personal information from someone under 18, we will promptly delete it. If you suspect we may have such information, please contact us at @guruvpn.com for removal.
16. Changes to this Policy
We may update this Privacy Policy; material changes will be published with an updated effective date and, where appropriate, notified to users.
17. Complaints and Supervisory Authorities
If you believe our processing violates applicable data protection law, contact privacy@guruvpn.com. You may also lodge a complaint with a competent supervisory authority in your jurisdiction.
18. Internal Documentation and Auditability
This public Policy is supported by a non‑public Internal Data Protection Policy that contains: detailed data inventories, data flows, retention justifications, processor DPAs, deletion workflows, DPIA summaries, templates for deletion/SAR requests, and operational guidance for engineering and legal teams.
Guru VPN's infrastructure and data practices are reviewed through internal audits and, where applicable, independent third-party assessments. These evaluations help verify that Guru VPN does not retain traffic content, communications content, detailed browsing histories, full URLs, page content, source-IP-linked VPN activity logs, or user-linked DNS histories, and that any limited operational records remain aligned with this Policy, the No-Logs Policy, and the Transparency Report & Warrant Canary.
19. Transparency and Known Limitations
Current practice and known limitations: user-linked connection logs, DNS technical logs, crash/diagnostic logs, analytics data, backups, exports, and processor-held records are subject to the retention periods and limitations described in this Policy. Primary operational records should be deleted, anonymised, or aggregated when the applicable retention period expires, but backups, exports, BigQuery datasets, billing systems, app-store records, analytics/SDK provider systems, and other third-party processor systems may retain copies until their own retention or deletion workflows run. Users seeking deletion from third-party processors should contact privacy@guruvpn.com; we will submit deletion requests where provider APIs/policies permit and will record these actions.
How to Contact Us
For privacy inquiries, data subject requests or complaints, contact: privacy@guruvpn.com or support@guruvpn.com. For formal legal or law enforcement requests, please use: support@guruvpn.com or privacy@guruvpn.com.
Last updated: 01.07.2026