GuruVPN Privacy Policy
Guru VPN is a modern virtual private network service designed to ensure the security and anonymity of users while surfing the internet. It effectively protects data and personal information from unauthorized access, offering a reliable solution for those who value privacy in the digital world.
Guru VPN processes your personal data and acts as a data controller in accordance with privacy laws, including the General Data Protection Regulation ( GDPR ).
This Privacy Policy explains how GURU NETWORK S.R.L. ("Company", "we", "us", "our") collects, uses, stores, discloses, and otherwise processes Personal Data in connection with the Guru VPN service (website: guruvpn.com, mobile applications). This Policy provides information about our processing; where consent is required, we request it separately.
If you do not agree to processing that is necessary to provide the Service, you should not use the Website or Services. Optional processing choices, including consent where applicable, can be managed or withdrawn as described in this Policy and the relevant settings.
Controller: GURU NETWORK S.R.L., registration no.: J2025060746006, CUI: 52319720, VAT ID: RO52319720, registered address: Strada Nerva Traian, Nr. 27-33, Bloc 6, Scara B, Etaj 1, Sectorul 3, București 031044, Romania.
Privacy contact email: privacy@guruvpn.com; general support: support@guruvpn.com.
1. Processing of your data
Our no-logs commitment concerns the content carried through the VPN tunnel: we do not retain communications content, traffic payloads, full URLs or page content. It does not mean that no connection activity, IP addresses or DNS requests are recorded. User-linked connection metadata, IP-bearing analytics events and DNS request records are described below and in the No-Logs Policy.
We process account, subscription, billing, authentication, security, registered-device, support, website cookie, mobile SDK, analytics and push-notification data. We also retain connection records and DNS request records. The purposes, retention practices and deletion limitations differ by category, as set out in this Policy.
Our primary database retains connection records showing that an account or registered device connected to a VPN server. A record may contain an internal account or registered-device reference, a VPN server identifier, a connection start timestamp and an available connection-status indicator, such as whether traffic was detected for connection-success metrics. The Vpn Connection Sessions table does not record a connection end timestamp or the user's real source IP address. Separately, Amplitude receives VPN connection events and IP addresses associated with analytics identifiers; those events are also exported to BigQuery. The absence of IP addresses from the primary connection table does not apply to those analytics records.
2. Categories of Personal Data We Collect
The categories below include data that may directly or indirectly identify you. The purpose, legal basis, retention and available choices differ by category; optional analytics and retained DNS records should not be treated as data essential for every core VPN function.
The following categories are processed in connection with the Service:
- Account information: email address (required for most users; optional for demo iOS accounts), username or display name if provided, account creation date, subscription status, signup method (OTP or OAuth via Apple/Google), and a randomly generated account identifier (UID). The UID is created at registration and is used to associate records with the account; a new registration receives a new UID.
- Authentication and security metadata: login attempts, one‑time password (OTP) metadata, device identifiers used for authentication.
- Payment and billing metadata: transaction identifiers, receipts, billing name/email, subscription IDs managed through Stripe and RevenueCat. We do not store full card numbers (PAN) on our servers; card processing is handled by payment providers.
- Connection records: an internal account or registered-device reference, VPN server identifier, connection start timestamp and an available connection-status indicator, stored in the primary database. This table does not include a connection end timestamp or real source IP address. Separate analytics events may record the start and end of a VPN connection, as described below.
- DNS request records: requested domain names, timestamps, query protocol and type, DNS query identifier, request size, response duration, VPN server hostname and service/log type. Records from our DNS resolver are stored in the logging system and exported to Google BigQuery in the United States. The DNS record format contains no user/account ID, device ID, connection ID or real source IP field. These are records of DNS requests, not merely aggregate domain counts. We do not use this dataset to identify which user made a request or for an active operational purpose.
- Connection diagnostics: on rare occasions, connection attempts and failures are collected manually for troubleshooting over a period of up to one day, reviewed for the individual case and deleted immediately after analysis. These diagnostic logs are not collected automatically. The collection window is distinct from the time at which analysis is completed.
- Analytics and usage data: Amplitude receives events relating to VPN connections, including start/end events, user_id, device_id, session_id, IP address and device or approximate location information. An event may contain the original IP before the VPN connection is established or the VPN exit IP after connection. The original IP is also visible to the VPN server as part of providing the connection. Analytics and measurement services include Firebase/Google Analytics, Amplitude, Plausible, AppsFlyer, Singular and Keitaro where integrated. Event, session, campaign, conversion, subscription and payment datasets are exported to BigQuery as described below.
- Push notification data: device tokens and related technical metadata processed through Firebase Cloud Messaging and, where applicable, OneSignal.
- Support communications: email, in‑app support messages, and related ticket logs.
3. Data We Do Not Collect
We do not retain VPN traffic payloads, communications content, full URLs or page content as activity logs, and we do not maintain a full browsing history for each user. We do retain domain-level DNS requests, connection metadata and analytics events, including IP addresses, as described in this Policy. A DNS request can reveal a requested domain even though its record has no direct user identifier. We do not monitor, calculate or retain traffic-volume totals for individual users or user accounts.
4. Purposes and Legal Bases for Processing
We process Personal Data only where an applicable legal basis under Article 6 GDPR applies. The basis depends on the purpose and data involved:
- Performance of a contract (Article 6(1)(b) GDPR): to create and administer accounts; authenticate users; provide VPN connections and requested app functions; manage subscriptions, billing, and functional service communications; and provide customer support.
- Legitimate interests (Article 6(1)(f) GDPR): to secure the Service; prevent and investigate fraud, abuse, attacks and service disruption; troubleshoot and improve reliability; protect legal rights; and carry out necessary and proportionate operational analysis where consent is not required. This basis does not automatically justify every retained dataset. The DNS request archive currently has no active operational use, as disclosed below.
- Legal obligations (Article 6(1)(c) GDPR): to comply with tax, accounting, consumer-protection, data-protection, and other applicable legal duties, and to respond to binding lawful requests.
- Consent (Article 6(1)(a) GDPR), where required: for non-essential analytics or tracking, marketing communications, advertising or attribution, and other optional processing. Consent may be withdrawn at any time without affecting processing already carried out lawfully before withdrawal.
5. Current Logging, Storage Locations and Retention Practices
-
Connection records: the primary database and application server are hosted by DigitalOcean in the Netherlands (Amsterdam). The Vpn Connection Sessions table contains the limited fields described above, without an end timestamp or real source IP address. There is no automatic cleanup based on the age of a connection record. The account and its linked connection records are deleted from the primary database through cascade deletion when the account is deleted, without an additional 30-day holding period. Until then, historical records may be queried through Metabase for cohort and connection-rate metrics. Separate analytics events in Amplitude and BigQuery are subject to their own retention and deletion arrangements.
-
DNS request records: The logging system retains the records for 14 days and data is exported from the logging system to BigQuery (United States). BigQuery has no configured fixed expiration period for this archive; records are currently kept while the warehouse service is maintained. The retention period in the logging system does not delete the exported BigQuery copies. The dataset includes domain, time and server information and is not currently used for an active operational purpose, including FUP/AUP enforcement or refund assessment. Although it has no direct user, device, connection or source-IP field, absence of those fields alone does not establish irreversible anonymisation or exclude every possible correlation with other information.
-
Security / IDS/IPS alerts and abuse signals: limited network-level security signals, configured signatures, pattern-based alerts, infrastructure signals and external abuse reports may be processed to protect the Service and investigate abuse. Alerts may include technical indicators and internal device identifiers that permit association with an account or device where necessary. The standard retention period for operational logs is 14 days. Separately retained support, incident or legal-claims records are subject to their own purpose and applicable retention requirements. Packets and traffic payloads are not retained as user activity logs.
-
Registered-device status: registered-device limit status may be processed to enforce plan limits, currently up to four (4) registered devices unless the applicable plan states otherwise. Device limits are based on devices linked to an account, not on a live count of simultaneous connections. Separate VPN start/end analytics events are collected as described above.
-
Connection diagnostics: logs of connection attempts and failures are collected manually only in occasional troubleshooting cases, over a period of up to one day. They are analysed for the individual case and deleted immediately after analysis. This diagnostic collection is not automatic. The ordinary collection of connection and analytics events described elsewhere in this Policy is separate from this manual troubleshooting process.
-
Billing and payment records: Stripe and RevenueCat process transactional metadata and receipts, and Stripe subscription/payment data including customer_id is exported to BigQuery. Account deletion is not currently propagated automatically to Stripe or RevenueCat. Financial, refund and dispute records may remain where required for applicable legal obligations or legal claims; BigQuery exports have the separate retention limitations described below.
-
Analytics and reporting: Metabase runs live queries against the primary database and BigQuery. Its cache stores SQL query text rather than cached query-result datasets. Reports may display cohort or aggregate metrics while the underlying sources retain individual events and identifiers. BigQuery receives the six additional source datasets listed below. These exports have no configured fixed expiration period and are kept while the warehouse service is maintained. This warehouse is not composed solely of anonymous statistics.
-
Push tokens: device tokens and related technical metadata are stored/processed through Firebase Cloud Messaging and, where applicable, OneSignal.
-
Backups and exports: primary database backups are retained for no more than 14 days. VPN servers have no backups. A deleted primary record may remain in a database backup until that backup expires. BigQuery exports are separate datasets, not backups governed by the 14-day database backup cycle; they have no configured fixed expiration period.
6. Account Deletion - Procedure and Limitations
When an account is deleted, the user record, customer profile data and linked records covered by cascade deletion, including primary connection records, are removed from the primary database. The primary database UID is removed with the account. There is no additional 30-day retention requirement or holding period for this operation. A new registration creates a new UID.
Account deletion does not automatically purge all downstream records. Old identifiers and historical records may remain in BigQuery and other subsystems after the associated customer profile data is removed. In the current implementation, account deletion is not automatically sent to Amplitude, Stripe, RevenueCat or Brevo. Removing profile data or issuing a new UID on re-registration does not itself remove old analytics events, exported identifiers or every possible link to a person. We do not describe all remaining records as anonymous or promise that every exported IP address, device/session identifier or payment reference is cleared by account deletion.
To request erasure of remaining Personal Data, including processor-held data and warehouse copies, contact privacy@guruvpn.com. We will assess the request under applicable law, coordinate any required action with relevant service providers and explain any lawful exception to erasure. Provider settings and the absence of automatic deletion do not remove your statutory rights. Erasure requests are handled without undue delay where required by law; the normal one-month response period is not a mandatory period for retaining your data.
7. Disclosure and Use by Third‑Party Processors
Recipients and service providers include DigitalOcean (application and database hosting), Google Cloud / BigQuery (data warehousing), Amplitude and Firebase (analytics), Stripe and RevenueCat (payments and subscriptions), Brevo (communications), Firebase Cloud Messaging and OneSignal (push notifications), and marketing or measurement services such as AppsFlyer, Singular, Keitaro and Plausible where integrated. We also use VPN hosting providers such as Vultr, Inferno, M247 and Timeweb where applicable. A provider may act as our processor or, for some activities, as an independent controller. Processing on our behalf requires appropriate data-processing terms; international transfers are subject to the safeguards described below.
8. International Transfers of Personal Data
The application server and primary database are hosted by DigitalOcean in the Netherlands. BigQuery datasets, including DNS and analytics exports, are stored in the United States. Other service providers may process data in additional countries according to the service and contractual arrangements. A European location for the primary database does not mean that all Service data remains in the EEA.
Transfers of Personal Data outside the EEA require an applicable transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses together with any necessary supplementary safeguards. You may contact privacy@guruvpn.com for information about the safeguards applicable to your data and how to obtain a copy. A provider's location alone does not establish that a particular transfer mechanism applies.
9. Security Measures and Operational Controls
We maintain administrative, technical and physical safeguards proportional to the sensitivity of the data processed:
- TLS encryption in transit for communications with our services.
- Encryption at rest where supported by provider platforms.
- Access to Personal Data and administrative systems is limited to authorized personnel using the permission settings and access controls available in each relevant service. Access rights are assigned according to operational responsibilities and adjusted when roles or needs change.
- Administrative and privileged access is logged and reviewed where the relevant service supports such logging and the control is enabled.
- Regular vulnerability scanning and scheduled penetration testing.
We do our best to protect your information and privacy, but we cannot guarantee 100% security for the data you disclose on the Internet. By using the Services, you expressly acknowledge and agree that we cannot guarantee the security of any data you provide or that we receive through the Services, and that any general information, other information, or information obtained from you through the Website or Services is provided by you at your own risk.
10. Analytics, Machine Learning and Automated Processing
We use analytics to understand Service use, connection success, reliability and product performance, and use campaign, conversion, subscription and payment reporting for the corresponding measurement and administration functions. Analytics may involve individual events, persistent identifiers and IP addresses as well as aggregated reports. A random UID is a pseudonymous identifier, not a guarantee of anonymity. We do not use DNS request records for individual advertising profiles. Any use of machine learning involving Personal Data must be minimised, documented and supported by an appropriate legal basis. We do not undertake automated decision-making with legal or similarly significant effects without explicit safeguards.
11. Marketing Communications and Push Notifications
With user consent where required, we may send marketing messages via email, including through Brevo, and push notifications. Users can opt out of marketing emails via unsubscribe links and disable push notifications via device or available app controls. Push tokens are managed through Firebase Cloud Messaging and, where applicable, OneSignal. Account deletion is not currently propagated automatically to Brevo; unsubscribe and erasure requests are separate from deleting the primary account.
12. Cookies and Tracking Technologies
Our website may use cookies, pixels, web beacons, and similar web technologies to enhance, secure, measure, and improve the Website and Services. You may be able to manage or disable cookies through your browser or the controls described in our Cookie Policy; doing so may limit some website functionality.
Mobile applications use SDK and account identifiers, such as the registration UID, Amplitude user/device/session IDs, Firebase identifiers, RevenueCat IDs, IDFA/GAID where enabled, attribution identifiers and push tokens. Amplitude collects VPN connection events and IP addresses and exports event records to BigQuery. Website cookie controls, mobile tracking permissions and deletion of an account affect different systems; changing one does not by itself erase existing provider-held or exported records. See the Cookie Policy for the available categories of controls.
13. Data Subject Rights and How to Exercise Them
Subject to applicable law, you may have rights to access, rectify, erase, restrict processing, object, request data portability and withdraw consent. Contact privacy@guruvpn.com or support@guruvpn.com. We may verify your identity using proportionate information and will respond within statutory time limits, normally one month, with any permitted extension explained within that period. Primary account deletion, backup expiry and erasure from analytics, warehouse or payment systems are distinct processes. Retention exceptions must have a lawful basis; the limitations described here do not waive your rights.
| Right | Description |
|---|---|
| Right of access | You can access or obtain a copy of your personal data by contacting us. |
| Right to data portability | Where the statutory conditions apply, you may receive the Personal Data you provided in a structured, commonly used and machine-readable format and request transmission to another controller where technically feasible. |
| Right to correction | You may request that inaccurate personal data be corrected and that incomplete personal data be completed (depending on the nature of its collection and use). |
| Right to erasure | You may request erasure where the statutory conditions apply. Any exception, such as a legal obligation or the establishment, exercise or defence of legal claims, must be assessed for the data concerned. Account deletion does not automatically erase every provider-held or exported record. |
| Right to withdraw consent | If we collected and processed your personal data with your consent, you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing prior to your withdrawal, nor will it affect the processing of your personal data carried out on lawful processing grounds other than consent. |
| Right to object | You may object to our processing of your personal data that is carried out on the basis of our legitimate interests. |
| Right to file a complaint | If you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office . In EU countries, you have the right to lodge a complaint with the relevant supervisory authority . |
14. Retention Summary - Current Operational Choices
-
Connection records (internal account or registered-device reference, VPN server identifier, connection start timestamp, and available connection-status indicator; no connection end timestamp or real source IP address):
- Location: DigitalOcean, Amsterdam (Netherlands).
- Retention: no automatic deletion based on record age. Records remain in the primary database until removed with the account through cascade deletion. There is no additional 30-day holding period after account deletion. Metabase queries the available source records live for cohort and connection-rate metrics.
- Purpose and legal basis: operating and troubleshooting the connection under the contract; necessary and proportionate reliability, cohort and connection-rate analysis under legitimate interests where consent is not required. The absence of an age-based cleanup rule is a description of the current implementation, not a requirement to retain every historical record indefinitely.
- Scope: the absence of an end timestamp and source IP applies to the primary Vpn Connection Sessions table. Separate Amplitude and BigQuery events can include VPN connection start/end information, IP addresses and identifiers. Deleting the primary table records does not automatically delete those events.
-
DNS request records:
- Location: the logging system and exported copies in Google BigQuery (United States).
- Retention: 14 days in the logging system; no configured fixed expiration period in BigQuery. BigQuery copies are retained while the warehouse service is maintained and do not expire when source records in the logging system expire.
- Use: the dataset is not currently used for an active operational purpose, FUP/AUP enforcement or refund assessment. Retaining a dataset without active use does not itself establish necessity or a legal basis for any Personal Data within it.
- Scope: records include domain, timestamp, server hostname and technical query fields. There are no direct account, device, connection or source-IP fields in the DNS record format. These field limitations do not constitute a guarantee of irreversible anonymity.
-
Manual connection diagnostics and operational logs:
- Collection: occasional manual troubleshooting of connection attempts and failures, analysed for the individual case. Diagnostic logs are not collected automatically.
- Retention: manual collection takes place over up to one day; collected diagnostic logs are deleted immediately after analysis. Standard operational log retention is 14 days. These periods do not apply to connection records in the primary database or exports in BigQuery.
- Legal basis: performance of a contract for requested troubleshooting, or legitimate interests in necessary and proportionate service reliability and security processing.
- Scope: collecting diagnostic logs for up to one day is not a promise that every support communication or analytics event is erased within 24 hours. Those records follow their respective categories.
-
Billing/payment metadata:
- Location: Stripe, RevenueCat, relevant app stores, necessary records in our systems and Stripe subscription/payment exports in BigQuery (United States).
- Retention: necessary financial records may remain for applicable tax, accounting, refund, dispute or legal-claims requirements. The applicable duration depends on the record and legal obligation. Account deletion is not automatically propagated to Stripe or RevenueCat; BigQuery payment exports have no configured fixed expiration period.
- Legal basis: legal obligations / performance of a contract.
- Safeguards: provider data-processing terms where required, encryption where supported, service-specific access controls, and data minimization.
-
Analytics and measurement data:
- Location: Amplitude, Firebase and other relevant providers, with the source exports described above stored in BigQuery (United States). Metabase provides live reporting over BigQuery and the primary database.
- Retention: the six BigQuery source datasets listed above have no configured fixed expiration period and remain while the warehouse service is maintained. Provider-side retention depends on the relevant service configuration. Account deletion does not currently trigger automatic deletion in Amplitude or a complete purge of warehouse exports. There is no common 14-day, 30-day or 24-month deletion promise for these records.
- Legal basis: consent where required for analytics, attribution or tracking; legitimate interests for necessary and proportionate analysis where permitted. Subscription and payment administration may also rely on contract or legal obligations.
- Scope: Amplitude exports include user_id, device_id, session_id and ip_address; Firebase exports include session_id; Stripe exports include customer_id. Identifiers may remain after removal of associated customer profile data. Such records are not automatically anonymous.
-
Database backups:
- Location: the database hosting infrastructure. There are no VPN-server backups.
- Retention: database backups are retained for no more than 14 days. Deleted primary data may persist until the relevant backup expires. This does not set the retention period for BigQuery exports or records held by other providers.
- Legal basis: legitimate interests in necessary service continuity, security and disaster recovery, subject to applicable data protection requirements.
- Safeguards: access is restricted to authorised personnel using the relevant infrastructure controls. Expiry of a backup is separate from deletion of downstream analytics or payment records.
15. Children’s Privacy
The Service is not intended for children under 18. We do not knowingly collect Personal Data from minors.
We do not offer our services to individuals who are under the age of 18, and we do not intentionally collect their personal information. If you are under 18, we kindly ask that you refrain from sharing any personal details with us. In the event that we find out we have received personal information from someone under 18, we will promptly delete it. If you suspect we may have such information, please contact us at @guruvpn.com for removal.
16. Changes to this Policy
We may update this Privacy Policy; material changes will be published with an updated effective date and, where appropriate, notified to users.
17. Complaints and Supervisory Authorities
If you believe our processing violates applicable data protection law, contact privacy@guruvpn.com. You may also lodge a complaint with a competent supervisory authority in your jurisdiction.
18. Internal Documentation and Auditability
This Policy describes the current processing practices and their limitations. Internal data inventories, provider arrangements, retention decisions and deletion procedures support the administration of data protection obligations; this Policy does not certify that every system has automatic deletion or that every record is anonymous.
Any internal review or independent assessment must consider the actual records described here, including DNS request records and IP-bearing analytics events. The No-Logs Policy is limited in scope and is not a statement that those records do not exist. Any published Transparency Report or Warrant Canary must be read consistently with these disclosures.
19. Transparency and Known Limitations
Current limitations: primary connection records have no age-based cleanup and are deleted with the account; database backups remain for no more than 14 days; retention in the logging system is 14 days; BigQuery exports have no configured fixed expiration. Analytics may retain IP addresses, VPN connection events and old identifiers after primary account deletion. Account deletion is not automatically propagated to Amplitude, Stripe, RevenueCat or Brevo. These limitations remain relevant even when reports are aggregated or direct customer profile data has been removed.
How to Contact Us
For privacy inquiries, data subject requests or complaints, contact: privacy@guruvpn.com or support@guruvpn.com. For formal legal or law enforcement requests, please use: support@guruvpn.com or privacy@guruvpn.com.
Last updated: 01.07.2026