GuruFrame GURUFRAME Account
Home Beta Program About Android App Partners Client Login

DRAFT — Under Legal Review

This document has not yet been reviewed by legal counsel. Do not publish until approved.

Privacy Policy

GuruFrame LLC
Effective Date: July 22, 2026
Last Updated: July 26, 2026

GuruFrame LLC ("GuruFrame," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our services, applications, website, client portal, and related offerings (the "Service").

1. Information We Collect

We may collect the following types of information when you use the Service:

  • Account information (name, email, company, billing details)
  • Device and technical information (device type, OS, IP address, Tailscale node information when enabled)
  • API keys and credentials that you voluntarily enter and sync
  • Usage data and logs related to the Service
  • Communications you send us
  • Content you process through the Service (e.g., voice input, prompts, email metadata when you connect Microsoft 365)

2. How We Use Information

We use the information we collect to provide, maintain, secure, and improve the Service, process payments, communicate with you, and comply with applicable law.

3. AI Processing — Local vs Cloud

  • When you choose local models (e.g., Ollama), your data remains on the infrastructure you control.
  • When you choose cloud models (Anthropic Claude, xAI Grok, etc.), your inputs and relevant context are sent to those providers under their own terms and privacy policies.
  • We clearly indicate in the product when a model sends data to third parties.

4. API Keys and Credentials

  • Keys are first stored locally on your device.
  • Keys are transmitted to your chosen destination (Home Server, Virtual Server, or other devices) only when you explicitly initiate a manual sync.
  • After sync, keys are stored encrypted in your dedicated environment and in our systems only as needed to provide the Service.

5. Password and Credential Protection

GuruFrame never stores your third-party service passwords. All integrations (Microsoft 365, Salesforce, Google Workspace, etc.) use industry-standard OAuth 2.0 authorization — you authenticate directly with the service provider, and GuruFrame receives a secure token, not your password.

  • Your GuruFrame portal login password is hashed using PBKDF2-SHA256 with a unique salt before storage. The raw password is never stored and cannot be retrieved — not by our systems, not by our staff, not by our AI assistant.
  • Passwords and credentials are never included in emails, exports, reports, session logs, AI conversation summaries, or any output that leaves your local environment.
  • If a connected service requires re-authentication (e.g., after you change a password with the service provider), you re-authorize through the provider's own OAuth screen — you never re-enter the service password into GuruFrame.
  • AI assistants operating within GuruFrame are programmatically prohibited from echoing, storing, or transmitting passwords encountered during conversation. If a password is spoken aloud or typed, the system acknowledges receipt without repeating or logging the credential.
  • These protections are enforced at the architecture level — they are not optional settings and cannot be overridden by users, administrators, or AI models.

6. Dedicated Virtual Machine Architecture

Each client receives their own dedicated virtual machine or isolated environment. Client environments are not shared at the compute level with other clients.

Certain management, portal, billing, and support systems are shared and protected by access controls.

7. Tailscale

Tailscale is used only with your explicit consent. We support client-owned Tailscale tailnets. You control your devices and can request removal at any time.

8. Data Sharing

We do not sell your personal information. We share information only with:

  • Service providers (e.g., Stripe, Cloudflare, Microsoft, Anthropic, xAI, Tailscale) necessary to operate the Service
  • Professional advisors and authorities when required by law
  • Successors in the event of a business transfer

9. Data Retention and Deletion

We retain information only as long as needed to provide the Service and meet legal obligations. Upon account termination or verified request, we will delete or de-identify personal data and credentials in accordance with our retention schedule, subject to legal requirements.

10. Security

We use encryption in transit and at rest, access controls, and dedicated virtual machines per client to protect your data.

No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

11. Your Rights

Depending on your location, you may have rights to access, correct, delete, or export your data, or object to certain processing. Contact us to exercise these rights.

12. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children.

13. Changes

We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email. Continued use of the Service after changes constitutes acceptance.

14. Contact

GuruFrame LLC
Georgia, United States
Email: ryan@guruframe.ai
Website: https://guruframe.ai