Cookie Policy
Effective date: 01.07.2026 | Version: 1.0
1. About this Cookie Policy
This Cookie Policy explains how GURU NETWORK S.R.L. ("we", "us", "our") uses cookies on our website guruvpn.com and SDK-based identifiers or similar technologies in connection with Guru VPN mobile applications. It supplements our Privacy Policy and should be read together with the Privacy Policy, No-Logs Policy, Terms of Service, Fair Usage Policy, Acceptable Use Policy, Transparency Report & Warrant Canary, and, where relevant, Refund Policy.
Cookies are primarily website/browser technologies. Mobile applications do not normally use browser cookies in the same way as websites; instead, they may use SDK-based identifiers, platform identifiers, local app storage, push tokens, subscription identifiers, attribution identifiers, crash/diagnostic identifiers, and similar app technologies.
For clarity, cookies and SDK-based identifiers are not used to log VPN traffic content, the content of communications, traffic payloads, full URLs, page content, detailed browsing histories, users' real source IP addresses in connection logs, source-IP-linked VPN activity logs, or user-linked DNS query records.
Some third-party SDKs, analytics, attribution, payment, app-store, crash reporting, push notification, security, or advertising providers may process technical identifiers, device or network information, and IP address information in their own systems according to their own privacy notices and contractual terms. This does not expand Guru VPN's no-logs commitment or create VPN activity logs where such logs are not collected under our ordinary technical architecture.
2. What cookies and SDK-based identifiers are
A cookie is a small file or similar browser storage technology that may contain an identifier and is stored by a web browser. A session cookie usually expires when the browser session ends. A persistent cookie may remain until its expiration date or until the user deletes it.
SDK-based identifiers are identifiers or tokens generated or processed by mobile platforms, mobile operating systems, or third-party SDKs. Examples may include IDFA/GAID where available and permitted, Firebase identifiers, RevenueCat identifiers, AppsFlyer or other attribution identifiers where implemented, device tokens for push notifications, crash reporting identifiers, and subscription or purchase verification identifiers. SDK-based identifiers are not browser cookies.
3. Categories of cookies, SDK identifiers and similar technologies we may use
The categories below apply only where the relevant feature, website component, app SDK, or third-party integration is implemented and enabled for the applicable region, platform, plan, or user consent status. A more detailed cookie and SDK inventory may be provided on the Cookie and SDK Inventory page or upon request to privacy@guruvpn.com.
3.1. Essential / Strictly necessary website cookies and technical app storage
Purpose: Enable core website and service functionality, such as authenticated sessions, secure payment flows, CSRF protection, consent records, correct routing via CDN/WAF, security checks, and delivery of essential website resources. In mobile apps, equivalent technical functions may rely on local app storage, platform APIs, or technical app identifiers rather than browser cookies.
Retention: Session-only or for the period necessary to support the feature; "remember me" or similar security/session features may last up to approximately 30 days unless configured otherwise.
Legal basis: Consent is not required where the technology is strictly necessary to provide the website, app, account, payment, security, or requested service functionality, but transparency is required.
If blocked or disabled: login, account access, payment flows, security checks, consent preferences, or core website/app functionality may not work correctly.
Examples: session IDs, authentication tokens, CSRF tokens, consent-state cookies, secure payment or routing cookies.
No-logs limitation: These technologies do not log VPN traffic content, browsing histories, full URLs, page content, source-IP-linked VPN activity logs, or user-linked DNS query records.
3.2. Functional cookies and app preference identifiers
Purpose: Remember user choices and preferences, such as language, region, theme, interface settings, cookie preferences, and last-used non-sensitive options. On mobile apps, similar preferences may be stored through local app storage or app settings rather than browser cookies.
Retention: From the session duration to approximately 1 year, depending on the feature and user choice.
Legal basis: Legitimate interests or consent, depending on the jurisdiction, technology, and privacy impact. Where required, we request consent and allow withdrawal.
If blocked or disabled: preferences may not persist and the service experience may be less convenient.
Examples: language preference, theme preference, consent flags, preference-center settings.
No-logs limitation: Functional technologies are not used to reconstruct users' VPN activity or browsing behavior.
3.3. Performance, diagnostics and analytics cookies / SDK identifiers
Purpose: Measure website and app performance, reliability, crash events, error rates, aggregated feature usage, conversion funnels, and product performance so we can troubleshoot and improve the Service. Website analytics may use cookies; mobile analytics and crash reporting may use SDK-based identifiers.
Retention: Usually 24 hours to 24 months, depending on the provider configuration and the purpose. Crash and diagnostic records may be retained for the periods described in the Privacy Policy or provider terms.
Legal basis: Consent where required, particularly in the EU/UK for non-essential analytics cookies or mobile tracking. Aggregated, anonymised, or strictly necessary diagnostics may be processed based on legitimate interests or performance of contract where permitted.
If blocked or disabled: we may receive less diagnostic and performance information, which can limit troubleshooting and product improvement.
Examples: Google Analytics, Firebase/Crashlytics, Sentry, Amplitude, Plausible, or similar analytics and diagnostic tools where implemented.
No-logs limitation: Analytics and diagnostics must not be used to log traffic content, communications content, full URLs, page content, detailed browsing histories, source-IP-linked VPN activity logs, or user-linked DNS query records.
3.4. Advertising, marketing and attribution cookies / SDK identifiers
Purpose: Where implemented and where required consent has been obtained, measure marketing campaigns, attribute installs or conversions, manage affiliate or referral campaigns, and, where applicable, support advertising or retargeting. Mobile attribution may involve advertising identifiers such as IDFA/GAID or SDK-specific attribution identifiers, subject to platform rules.
Retention: Vendor-dependent, typically from a few days to up to 24 months unless a shorter period is configured or required by law.
Legal basis: Explicit consent where required. On iOS, App Tracking Transparency rules may apply. On Android, advertising ID and platform consent rules may apply. Profiling or targeted advertising requires clear disclosures and opt-out or withdrawal mechanisms where required.
If blocked or disabled: marketing attribution and personalized advertising may be limited or unavailable, but core paid VPN functionality should remain available unless a specific feature depends on the identifier.
Examples: advertising pixels, campaign identifiers, affiliate identifiers, attribution identifiers, AppsFlyer or similar attribution tools, and advertising IDs where implemented.
No-logs limitation: Advertising and attribution technologies must not be used to create VPN traffic-content logs, browsing histories, full URL logs, source-IP-linked VPN activity logs, or user-linked DNS histories.
3.5. Security and anti-fraud cookies / identifiers
Purpose: Protect accounts, payment flows, forms, infrastructure, and the Service against automated attacks, fraud, abuse, suspicious signups, credential attacks, and bot activity. These technologies may support CAPTCHA, rate-limiting, payment-risk checks, device risk signals, and infrastructure security.
Retention: Session-only to several months, depending on the provider configuration, risk event, and documented security purpose.
Legal basis: Legitimate interests in security, fraud prevention, and service integrity, subject to necessity, proportionality, and applicable law. Consent may be required for non-essential third-party tracking elements in some jurisdictions.
If blocked or disabled: some forms, payment flows, account changes, or security checks may fail or require additional verification.
Examples: CAPTCHA tokens, fraud-prevention identifiers, secure routing cookies, WAF/CDN security cookies, payment-risk identifiers where implemented.
No-logs limitation: These technologies are for website, account, payment, app, and infrastructure security. They do not involve full traffic-content monitoring, routine inspection of user communications, maintaining browsing histories, or user-linked DNS logging.
3.6. Third-party and embedded content cookies
Purpose: Where we embed third-party content, such as videos, maps, support widgets, app-store widgets, or similar tools, those providers may set cookies or collect technical identifiers when the content loads or when you interact with it.
Retention: Determined by the relevant third party and its configuration.
Legal basis: Depends on the provider and cookie type. Non-essential third-party cookies typically require consent before being set, especially in the EU/UK.
If blocked or disabled: embedded content may not load or may require additional consent before activation.
Examples: video, map, support, app-store, or social content cookies where such features are implemented.
No-logs limitation: Third-party embedded content must not be treated as Guru VPN VPN-activity logging. The provider's own processing is governed by its own privacy/cookie notice.
3.7. Social login, sharing and social media cookies
Purpose: Where implemented, support social login, sharing features, or limited social interaction features. Social providers may set cookies or process identifiers according to their own privacy notices and platform rules.
Retention: Vendor-dependent and subject to the relevant provider's settings.
Legal basis: Consent is required for tracking, targeting, or cross-site social analytics where applicable. Social login may also involve authentication and security processing necessary for the requested login flow.
If blocked or disabled: social login or sharing features may be unavailable or may require additional steps.
Examples: social login or sharing cookies/identifiers where implemented; we avoid listing specific social providers unless actually integrated.
No-logs limitation: Social cookies are not used by Guru VPN to maintain VPN traffic-content logs, browsing histories, source-IP-linked VPN activity logs, or user-linked DNS histories.
3.8. Application / SDK identifiers (mobile and in-app)
Purpose: In mobile apps, SDKs and platform identifiers may be used for subscription management and restoration, purchase verification, install attribution, push notifications, crash reporting, diagnostics, in-app analytics, fraud prevention, and app functionality. They may help connect signals from the device, app store, billing provider, subscription provider, push provider, or analytics provider to maintain the correct account or subscription state.
Retention: Vendor-defined and purpose-dependent. Technical subscription, billing, crash, diagnostic, push, and analytics records are retained according to the Privacy Policy, provider terms, consent status, app-store rules, and applicable deletion workflows.
Legal basis: Performance of contract or legitimate interests for technical subscription, purchase verification, billing, security, crash reporting, and service reliability where permitted; consent for advertising, attribution, tracking, or analytics where required by law or platform rules.
If blocked or disabled: subscription restoration, purchase verification, push notifications, install attribution, crash reporting, or analytics may be limited or unavailable depending on the identifier disabled.
Examples: RevenueCat IDs, Firebase IDs, IDFA/GAID, AppsFlyer or similar attribution identifiers where implemented, OneSignal push tokens, crash reporting identifiers, and app-store purchase identifiers.
No-logs limitation: SDK identifiers are not browser cookies and are not used to log traffic content, communications content, full URLs, page content, source-IP-linked VPN activity logs, or user-linked DNS query records.
3.9. Consent and preference management cookies / identifiers
Purpose: Store or recall your privacy choices, such as accepted/rejected categories, region-specific consent state, withdrawal status, and the policy version shown to you. This prevents repeated consent prompts and supports compliance documentation.
Retention: Typically 6 months to 2 years, unless a shorter period is configured or required by law.
Legal basis: Necessary for compliance with consent and documentation obligations and/or legitimate interests in maintaining privacy preferences.
If blocked or disabled: you may be asked to provide cookie or SDK choices more often, and your settings may not persist.
Examples: cookie_consent, consent_settings, opt_out, preference-center identifiers.
No-logs limitation: Consent records should be minimized and, where possible, stored through pseudonymous consent identifiers rather than unnecessary direct identifiers.
4. How we manage consent and third-party technologies
Where required, we use a consent banner or preference center that separates categories such as Essential, Functional, Analytics, Advertising/Attribution, Security, and Third-party/Embedded content.
Non-essential cookies and SDK-based tracking are not enabled unless the required consent has been obtained. Pre-ticked boxes should not be used where consent is required.
You can withdraw or change consent through the cookie banner, preference center, in-app settings, device settings, or by contacting privacy@guruvpn.com, depending on the technology and platform.
We keep minimized consent records or pseudonymous consent identifiers showing what choices were made, when, and which policy version was shown. We avoid storing more personal data than necessary for consent documentation.
We maintain and periodically review a cookie/SDK inventory, including names, provider/domain, category, purpose, retention, and recipients where applicable. The inventory should be updated after material website, app, SDK, or vendor changes.
Where we rely on legitimate interests for security, fraud prevention, or necessary diagnostics, we document necessity, proportionality, and safeguards where required.
Where third-party providers process data on our behalf, we apply appropriate contractual safeguards, including data processing terms where required. Where providers act independently, their own privacy/cookie notices also apply.
5. Third-party services and processors that may set cookies or process SDK identifiers
Depending on integration, region, platform, consent status, and user settings, the following categories of third parties may set cookies or process SDK-based identifiers through the website, mobile apps, checkout flows, or related services:
Analytics and diagnostics: Google Analytics, Firebase/Crashlytics, Sentry, Amplitude, Plausible, or similar providers where implemented.
Subscription management and billing: RevenueCat, Stripe, Apple App Store, Google Play, and related checkout or purchase-verification systems where implemented.
Push notifications: OneSignal or platform push notification services where implemented.
Attribution, advertising, and affiliate measurement: AppsFlyer or selected advertising/affiliate partners where implemented and only where required consent or platform permission has been obtained.
Security and anti-fraud: reCAPTCHA, WAF/CDN security tools, payment-risk tools, or other bot/fraud prevention providers where implemented.
Embedded content and social features: video, map, support widget, social login, or sharing providers where those features are actually implemented.
This list is illustrative and should be kept aligned with the actual cookie and SDK inventory. For a complete and up-to-date list of third parties that may set cookies or process SDK identifiers through the Service, contact privacy@guruvpn.com.
Third-party cookies and SDK processing are governed by the relevant providers' own privacy and cookie notices. Where required, we disclose such providers, obtain consent, and apply contractual safeguards. We are not responsible for a third party's independent processing outside our control, but we will take reasonable steps required by applicable law for providers used in connection with our Service.
6. How to manage, disable or delete cookies and SDK-based identifiers
6.1. Web browser
You can block or delete cookies through your browser settings, including Chrome, Firefox, Safari, Edge, or other browsers.
You can use our cookie banner or preference center, where presented, to accept, reject, or change choices for non-essential cookies such as analytics, advertising, or third-party content cookies.
You may disable non-essential cookies at any time. Blocking essential cookies may affect login, payment, security, consent preferences, or core website functionality.
6.2. Mobile applications
Mobile apps do not use browser cookies in the same way as websites. They may use SDK-based identifiers such as IDFA/GAID, Firebase IDs, RevenueCat IDs, attribution identifiers, push tokens, crash reporting identifiers, and similar app technologies.
Use in-app settings, iOS App Tracking Transparency and device settings, Android advertising ID/app settings, app permissions, or notification settings to manage analytics, marketing, SDK-based tracking, and push notifications where available.
Uninstalling the app removes local app storage from the device. However, server-side SDK identifiers, billing records, app-store records, analytics records, crash logs, push-token records, backups, or provider-held records may remain for the periods described in the Privacy Policy, provider terms, or applicable law.
To request deletion or anonymisation of cookie-derived data, SDK identifiers, or provider-held records, contact privacy@guruvpn.com. We will handle such requests as described in the Privacy Policy and applicable provider deletion workflows.
7. Retention, deletion and limitations
Cookie and SDK retention depends on the category, purpose, provider configuration, user consent status, legal basis, and applicable retention rules. Non-essential cookies and SDK-based tracking should not be retained longer than necessary for the disclosed purpose.
Where a cookie, SDK identifier, or provider-held record contains or is linked to Personal Data, retention and deletion are governed by the Privacy Policy, No-Logs Policy, provider terms, applicable law, and documented security, abuse-prevention, billing, lawful-request, legal-claims, accounting, or backup requirements.
Deletion or anonymisation may be limited where data is held by third-party providers, app stores, payment processors, analytics providers, crash reporting providers, push notification providers, advertising or attribution partners, backups, security records, or legal/accounting systems. Where possible and legally required, we will submit deletion or anonymisation requests to providers and record the outcome.
8. Children
The Service is not intended for persons under 18. We do not knowingly use cookies or SDK-based identifiers to collect Personal Data from children under 18. If you believe we have collected data from a child, contact privacy@guruvpn.com or support@guruvpn.com.
9. Changes to this Cookie Policy
We may update this Cookie Policy from time to time. Material changes will be posted with a new effective date and, where appropriate, notified to users through the Service or other reasonable means. Continued use after publication of changes constitutes acceptance of the updated Policy to the extent permitted by applicable law.
10. Cross-references
This Cookie Policy should be read together with our Privacy Policy, No-Logs Policy, Terms of Service, Fair Usage Policy, Acceptable Use Policy, Transparency Report & Warrant Canary, and, where relevant, Refund Policy. Where cookie or SDK processing involves third parties, their own privacy/cookie notices and platform rules may also apply.
11. Contact information and requests
For questions about this Cookie Policy, to withdraw consent, to request deletion or anonymisation of cookie-derived data or SDK identifiers, or to ask for the current cookie/SDK inventory, contact: privacy@guruvpn.com or support@guruvpn.com.
For requests involving third-party providers, we will, where possible and legally required, submit deletion or anonymisation requests on your behalf or provide instructions for contacting the relevant provider directly. We will document the outcome where required.
Last updated: 01.07.2026