Privacy Policy

Last updated: 25 July 2026 Effective date: 30 May 2026

This Privacy Policy explains how Wize Tech Pte Ltd, a private limited company incorporated in the Republic of Singapore (ACRA), operating the Guruvice platform ("Guruvice", "we", "us", "our"), collects, uses, discloses, transfers, retains, and protects your personal information when you use our mobile applications, web services, AI assistant (delivered via Telegram), and related services (collectively, the "Services").

We are committed to protecting your privacy and complying with the data protection laws applicable in the jurisdictions where we operate, including the Singapore Personal Data Protection Act 2012 ("PDPA"), the UK General Data Protection Regulation ("UK GDPR") and UK Data Protection Act 2018, the California Consumer Privacy Act/California Privacy Rights Act ("CCPA/CPRA"), and the India Digital Personal Data Protection Act 2023 ("DPDP Act").

By using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Privacy Policy, please do not use the Services.


1. Who We Are

The data controller (in EEA/UK terminology), "business" (CCPA terminology), "data fiduciary" (DPDP Act terminology), and organisation responsible for your personal data under the PDPA is:

Wize Tech Pte Ltd 421 Clement Ave 1, #40-371 Singapore 120421 Registered in Singapore (ACRA)

For privacy-related queries: privacy@guruvice.com Data Protection Officer: dpo@guruvice.com General contact: contact@guruvice.com


2. Information We Collect

We collect personal information in the following categories:

2.1 Account Information

When you register for Guruvice, we collect:

2.2 Guru/Expert Profile Information

If you register as a Guru/Expert, we additionally collect:

2.3 Payment Information

When you make or receive payments through the Services, we collect:

Card numbers, full bank account numbers, CVV codes, and one-time passwords are NEVER stored on our servers. All such sensitive payment data is handled directly by our PCI-DSS-compliant payment processors (see Section 4.1).

We currently use Stripe, Inc. as our primary card-payment processor. As we expand into our launch markets, we will additionally integrate Apple Pay (Apple Inc.), Google Pay (Google LLC), Wise Payments Ltd (for international payouts), PayNow (the Singapore real-time payments rail), and Unified Payments Interface ("UPI") (the India real-time payments rail). All such processors are independently regulated and have their own privacy notices.

2.4 Service Usage Data

We collect information about how you use the Services:

2.5 Audio and Video Session Data

Live audio and video sessions are delivered via our real-time communications partner Agora.io. We do not record sessions by default. If session recording is enabled (with the consent of all participants, where required by law), recordings are stored encrypted on our infrastructure and accessible only to the participants and our authorised personnel for safety and quality-assurance purposes.

Session and attendance metadata is always logged, whether or not a session is recorded. This includes the scheduled and actual start and end times, the participant list, the duration, and per-participant attendance information — the times you join and leave the call, any reconnections, and whether you were present. We use this to determine whether a session took place, to bill it correctly, to apply our no-show and reliability rules, and to resolve disputes. This is presence and timing information only — it does not include the audio or video content of your call, which we do not record by default.

2.6 Device and Technical Information

We automatically collect:

2.7 Approximate Location Information

We may infer your approximate location (typically city or region level) from your IP address. We do this for fraud prevention, regulatory compliance, currency selection, and to show locally relevant content. We do not collect precise GPS location unless you explicitly grant the relevant permission for a specific feature that requires it.

2.8 Telegram Bot Integration Data (Optional)

If you choose to connect the Guruvice AI Assistant (delivered via Telegram), we collect and store:

If you use the Assistant's question-answering feature, the free-text questions you send are processed to generate an answer (see Section 9.4) and are not stored in content form — we retain only anonymous metadata about them.

We do not read your Telegram conversations with anyone other than the Guruvice AI Assistant itself. We do not access your contact list, group memberships, or any other Telegram data outside the direct conversation with our bot. Telegram itself processes all messages according to its own privacy policy at telegram.org/privacy.

You can disconnect the bot at any time by sending /stop to the Guruvice AI Assistant in Telegram. When you disconnect, we delete the link between your Telegram user ID and your Guruvice account.

2.9 Google Calendar Integration Data (Optional)

If you choose to connect your Google Calendar, Guruvice keeps your schedule in sync using both read and write access to your calendar events — writing your Guruvice bookings onto your calendar, and reading your events so the Guruvice AI Assistant (via Telegram) can flag conflicts in your daily brief. The following applies:

OAuth scopes requested:

What we store:

What we do NOT store:

How we use the calendar data:

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

You can revoke our access to your Google Calendar at any time by:

When you revoke access, we permanently delete the stored refresh token within seven (7) days.

2.10 Cookies and Similar Technologies

Our web services use cookies and similar technologies (such as local storage and session storage) for authentication, security, preferences, and analytics. You can control cookies through your browser settings; refusing certain cookies may impair the functionality of the Services. Our mobile applications use the equivalent platform-provided mechanisms (such as AsyncStorage on React Native) for similar purposes.

We do not use third-party advertising cookies or trackers.


3. How We Use Your Information

We use your personal information for the following purposes, supported by the lawful bases listed in Section 3.6 below:

3.1 To Provide the Services

3.2 To Communicate With You

3.3 To Maintain Safety and Integrity

3.4 To Improve the Services

3.5 To Comply With Law

3.6 Lawful Bases (UK/EEA)

Where the UK GDPR applies to you, we rely on the following lawful bases:

3.7 What We Do NOT Do


4. How We Share Your Information

We share personal information only as described below:

4.1 Service Providers

We engage trusted third-party service providers to operate parts of the Services. They are contractually obligated to use your information only as necessary to perform services for us, to keep it confidential, and to apply appropriate security measures. Our principal service providers include:

ProviderServicePrimary processing location
Amazon Web Services, Inc.Cloud infrastructure, data storage, identity management (Cognito), encryption (KMS)Singapore (ap-southeast-1), with sub-processors in other AWS regions for specific functions
Stripe, Inc.Card payment processingUnited States, with global processing
Apple Pay (Apple Inc.) — plannedCard payment processing for iOS usersUnited States and Ireland
Google Pay (Google LLC) — plannedCard payment processing for Android usersUnited States and Ireland
Wise Payments LtdplannedInternational payouts to GurusUnited Kingdom and various jurisdictions
PayNow (Association of Banks in Singapore) — plannedSingapore real-time payments railSingapore
NPCI (Unified Payments Interface)plannedIndia real-time payments railIndia
Agora.ioReal-time audio/video session deliveryGlobal edge network
Google LLC (Calendar API) — for users who opt inCalendar event read and write — syncing your Guruvice bookings to your calendar, plus event reads for the AI Assistant's conflict detectionUnited States and Ireland
Google LLC (Gemini API) — for users who opt inAI-assisted question answering — generating answers to your free-text questions to the AI Assistant, grounded in our public FAQUnited States and Ireland
Telegram FZ-LLCfor users who opt inAI Assistant message deliveryVarious jurisdictions
Sentry, Inc.Error and crash reporting (data minimised)United States and Germany

This list is not exhaustive and may be updated as we change service providers. Material changes will be reflected in updates to this Privacy Policy.

4.2 Other Users

Limited information from your profile is shown to other users for the purpose of operating the marketplace:

We do not disclose your email address, phone number, billing details, or other contact information to other users except as you choose to share them through in-app messaging.

4.3 Compliance With Law, Protection of Rights

We may disclose personal information to:

4.4 Business Transfers

If we are involved in a merger, acquisition, asset sale, bankruptcy, or similar transaction, personal information may be transferred as part of that transaction. We will notify you of any such transfer (for example, by email or by a prominent notice on the Services) and explain any change in how your information is handled, including your rights to opt out where applicable.

4.5 With Your Consent

We may share your personal information with others when you have given us specific consent to do so.


5. International Data Transfers

We are based in Singapore, and our primary data processing infrastructure is located in the AWS Asia Pacific (Singapore) region. However, given the global nature of the internet and our service providers, your personal information may be transferred to, stored in, and processed in countries other than the one you are located in, including the United States, the European Union, the United Kingdom, India, and elsewhere.

Where we transfer personal information out of Singapore, the United Kingdom, the European Economic Area, or other regions with data export restrictions, we rely on appropriate safeguards, which may include:

You may obtain a copy of the safeguards we use by contacting privacy@guruvice.com.


6. Data Retention

We retain personal information only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Typical retention periods are:

CategoryRetention period
Active account informationWhile your account is open
Account information after a deletion requestAccount deactivated immediately; personal data permanently purged after a 30-day grace period, except where longer retention is required by law (see Section 6.1)
Reviews you received as a Guru, after account deletionRetained in anonymised form (detached from your identity) to preserve ratings integrity
Session records and metadata3 years from the date of the session
Webinar records and metadata3 years from the date of the webinar
Payment and transaction records7 years (to satisfy Singapore tax and accounting record-keeping requirements)
Demerit point history12 months
In-app messages1 year from the date of the message
Support tickets and correspondence3 years from closure
Server logs and security event logsUp to 12 months
Marketing communication preferencesUntil you opt out, plus a reasonable record of having done so
Telegram bot link dataUntil you disconnect (/stop), then deleted within 24 hours; or upon account deletion
Google Calendar refresh tokenUntil you revoke (via /stop, /disconnect_calendar, or Google Account settings), then deleted within 7 days
Google Calendar event contentNot stored; fetched live and discarded after each use

After the retention period ends, we will either delete or irreversibly anonymise your personal information. Where complete deletion is technically impossible (for example, data in encrypted, append-only backup archives), we will isolate the data from further processing and apply industry-standard practices to ensure it is securely destroyed at the end of the backup cycle.

6.1 Deleting Your Account

You can delete your Guruvice account and personal data at any time, directly in the app: open Settings → Delete Account and confirm. (You can also request deletion by emailing privacy@guruvice.com; full step-by-step instructions are on our dedicated Delete Your Account page.)


7. Your Privacy Rights

You have the following rights with respect to your personal information. The specific rights available to you depend on the jurisdiction whose laws apply, but we extend most of these rights to all users as a matter of policy, regardless of where you live.

7.1 Universal Rights (All Users)

7.2 Singapore Personal Data Protection Act (PDPA)

If you are a resident of Singapore, the PDPA provides you with the following statutory rights:

You may exercise these rights by contacting our Data Protection Officer at dpo@guruvice.com. We will respond to verifiable requests within thirty (30) days, as required by the PDPA.

7.3 European Economic Area and United Kingdom (UK GDPR)

If you are in the United Kingdom, you have the following rights under the UK GDPR, in addition to the universal rights above:

7.4 California Residents (CCPA / CPRA)

If you are a resident of California, you have the following rights under the CCPA and CPRA, in addition to the universal rights above:

To exercise these rights, contact privacy@guruvice.com. We will verify your request by reference to information already in our records.

Categories of personal information collected (CCPA disclosure)

Within the preceding 12 months, we have collected the following categories of personal information defined by the CCPA:

We collect these for the business purposes described in Section 3.

7.5 India Residents (DPDP Act 2023)

If you are a resident of India, you have the following rights as a "Data Principal" under the DPDP Act, in addition to the universal rights above:

We act as a Data Fiduciary under the DPDP Act and process your personal data for the purpose to which you have given consent or for legitimate uses recognised under the Act.

7.6 How to Exercise Your Rights

To exercise any of these rights, please contact:

We may need to verify your identity before responding to your request, which may require us to ask for additional information. We will respond to verifiable requests within the period required by the law applicable to you:

If you are not satisfied with our response, you may lodge a complaint with the data protection authority in your jurisdiction:


8. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, loss, or destruction. Our security measures include:

No system is perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security. If you become aware of a security issue affecting the Services, please contact us immediately at privacy@guruvice.com.


9. The Guruvice AI Assistant

The Guruvice AI Assistant is an optional service delivered through Telegram. Today, account linking and the daily brief are live; other proactive reminders are planned. When you opt in, the Assistant can:

Guruvice does not integrate WhatsApp as a messaging or data-processing channel. Any WhatsApp links on Guruvice are ordinary support or share links and do not give us access to your WhatsApp account or messages.

9.1 Linking the Assistant

You can link the Assistant to your Guruvice account by sending the /start command in our Telegram bot together with a single-use link code issued to you from within the Guruvice app. The link code is valid for a limited time (typically 10 minutes) and expires after a single use.

9.2 What the Assistant Accesses

The Assistant accesses only the data it strictly needs:

The Assistant does not access:

9.3 Disconnecting

You can disconnect the Assistant at any time:

Disconnecting the Assistant deletes the link between your Guruvice account and your Telegram user ID. Disconnecting the Google Calendar integration deletes our stored OAuth refresh token. Either action takes effect immediately for new operations and is fully propagated within 24 hours.

9.4 AI-Assisted Question Answering

When you send a free-text question to the Assistant, the text of your question is sent to our AI provider, Google LLC, through the Gemini API, so it can generate an answer grounded in our public Frequently Asked Questions. We send only the text you type. We do not send your name, contact details, Guruvice account identifier, calendar events, session or booking data, payment information, or any other personal data alongside your question.

Google processes your question under the Gemini API terms. Because we use Google's paid Gemini API tier, Google does not use your questions or the generated answers to train or improve its models.

We do not store the content of your questions or the Assistant's answers. We retain only anonymous operational metadata — such as the message length, the detected question category, which FAQ entries were matched, and the length of the response — to monitor quality and prevent abuse.

This use of the Gemini API is separate from, and does not involve, any Google Calendar data: the Assistant sends only your typed question against our public FAQ, never your calendar events or the identity/OAuth data described in Section 2.9 and Section 9.5.

Please do not include sensitive personal information in your messages to the Assistant.

9.5 Google API Services User Data Policy

Guruvice's use of information received from Google APIs, including the Google Calendar API and the Google OpenID Connect identity service, adheres to the Google API Services User Data Policy, including the Limited Use requirements. This section summarises that adherence with respect to each scope we request:

(a) https://www.googleapis.com/auth/calendar.events. This read/write scope is used for two purposes: (i) write — to create, update, and remove events on your calendar that correspond to your Guruvice bookings (session and webinar sync), writing only your own Guruvice booking information and never altering your other events; and (ii) read — to detect schedule conflicts between your Guruvice sessions and your other Google Calendar events and surface them in your daily Telegram brief. Events we read for conflict detection are read and discarded in memory (not persisted), are not shown in the app, are not transmitted to any third party, and are not used for advertising or any secondary purpose.

(b) openid. This scope is consumed only at the moment of the OAuth handshake to confirm that you authorised the calendar connection from your Google account. The OpenID Connect identity token (id_token) issued by Google during this handshake is used only to derive the email claim addressed in (c) below. No other claim from the id_token is persisted.

(c) email (via https://www.googleapis.com/auth/userinfo.email). Your Google account email address, extracted from the id_token's email claim, is persisted in our database for the sole purpose of identifying which Google account is associated with each connected calendar. This identification supports our planned multi-calendar feature, in which a single user may connect more than one Google calendar. The email address is not transmitted to any third party, is not used for marketing or advertising, is not subjected to human review except as strictly necessary for security, abuse prevention, or compliance with applicable law, and is deleted when you disconnect via the /stop or /disconnect_calendar command in Telegram.

We do not transfer Google user data to any third party. We do not use Google user data to serve advertisements, including retargeting, personalised, or interest-based advertising. We do not allow humans to read your Google user data, with the limited exceptions of: (a) obtaining your specific consent to do so, (b) actions necessary for security purposes such as investigating abuse, (c) compliance with applicable law, or (d) operations on data that has been aggregated and anonymised. All Google user data at rest in our systems is protected by encryption at rest, and refresh tokens are additionally encrypted under a customer-managed encryption key.


10. Children's Privacy

The Services are intended for users who are eighteen (18) years of age or older. We do not knowingly collect personal information from children under 18. If you are under 18, do not use the Services and do not provide any personal information to us.

If you believe we have collected information from a person under 18, please contact us at privacy@guruvice.com and we will take steps to delete the information promptly.


11. Marketing Communications

We may send you transactional messages (account notifications, booking confirmations, payment receipts, security alerts) and, where you have not opted out, occasional service updates and marketing communications about Guruvice features and offerings.

You can opt out of marketing communications at any time by:

We do not share your contact information with third-party marketers.


12. Third-Party Links

The Services may contain links to third-party websites, services, or applications that we do not control. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third party you interact with through the Services.


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, applicable law, or for other operational reasons. When we make material changes, we will:

Your continued use of the Services after the effective date of any change constitutes your acceptance of the updated Privacy Policy. If you do not agree to the change, you should stop using the Services and may exercise your rights under Section 7.

Changelog

DateSummary of changes
25 July 2026Made per-participant attendance metadata explicit in Section 2.5: alongside session-level metadata, we log each participant's join and leave times, reconnections, and presence, and use them to determine whether a session took place, to bill it, to apply the no-show and reliability rules, and to resolve disputes. Clarified that this is presence and timing information only and does not include call audio or video content.
9 July 2026Disclosed AI-assisted question answering in the Guruvice AI Assistant: free-text questions you send are processed by Google's Gemini API (paid tier — not used for model training) to generate answers grounded in our public FAQ. Only the question text is sent (no profile, calendar, session, or payment data); question and answer content is not stored, only anonymous metadata. Added Google (Gemini API) to the Section 4.1 sub-processor list, added Section 9.4, and updated Sections 2.8 and 9.
5 July 2026Corrected the Google Calendar integration description to reflect read and write access: Guruvice writes your bookings to your calendar (session/webinar sync) and reads your events for conflict detection in the Telegram brief. Removed the previous, inaccurate read-only characterisation of the calendar scope. Clarified that calendar reads feed the Telegram brief only (not shown in-app) and that tokens are encrypted; noted the daily brief and account linking are live while other reminders are planned; and clarified that WhatsApp is not an integrated channel.
5 July 2026Documented the in-app account-deletion flow (Settings → Delete Account): commitment gating, immediate deactivation with a 30-day grace period before permanent purge, and anonymised retention of reviews received as a Guru. Added Section 6.1 and cross-linked the dedicated Delete Your Account page.
30 May 2026Comprehensive update for the launch of the Guruvice AI Assistant (Telegram delivery) and the optional Google Calendar integration. Added multi-jurisdictional rights sections for Singapore PDPA, UK GDPR, California CCPA/CPRA, and India DPDP Act. Disclosed planned payment processors (Apple Pay, Google Pay, Wise, PayNow, UPI). Made retention periods explicit. Added Google API Services User Data Policy adherence statement.
20 February 2026Prior version (in-app).

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:

Wize Tech Pte Ltd (operating as Guruvice) 421 Clement Ave 1, #40-371 Singapore 120421

We aim to acknowledge all privacy queries within 5 business days and to substantively respond within the statutory periods set out in Section 7.6.


This Privacy Policy is provided in English. If we publish translations, the English version will prevail in the event of any inconsistency.