Privacy Policy
Effective date: 10 June 2026 · Last updated: 30 June 2026
Who We Are
GoGuru is a mobile application built for private tutors in Sri Lanka. It helps tutors manage their students, track payments, schedule classes, and communicate with parents.
GoGuru is operated by Savith Herath ("we", "us", "our"). Our contact email is [email protected].
Data protection contact: For all data protection enquiries — including access, correction, and deletion requests — contact [email protected] with the subject "Data Protection Request." We aim to respond within 30 days; if your request is complex or we need to verify your identity, we will let you know and may take up to 60 days to complete it (Sri Lanka PDPA Art. 13).
What This Policy Covers
This Privacy Policy explains:
- What personal data GoGuru collects
- Why we collect it
- How we use and store it
- Who we share it with
- Where it is stored
- Your rights as a user or data subject
- How to contact us with questions or requests
This policy applies to all users of the GoGuru mobile application and the GoGuru website (gogurulk.app), collectively referred to as "the Service."
By using GoGuru, you agree to the collection and use of information as described in this policy.
The People Whose Data We Handle
GoGuru involves three types of people:
Tutors — adults who create a GoGuru account to manage their tuition business. Tutors are the primary users of the app and are directly responsible for the data they enter.
Parents — adults who are invited by a tutor to access the parent portal. Parents can view their child's schedule, payment status, and contact the tutor.
Students — individuals (which may include minors under 18) whose data is entered into the app by tutors. Students do not have a GoGuru account and do not interact with the app directly.
Data We Collect
Data you give us directly
Tutor account data:
- Full name
- Email address
- Phone number
- WhatsApp number
- City / location
- Subjects taught
- Profile photo (optional)
- Password (stored as a secure hash — we never store your plain-text password)
Student data (entered by tutors):
- Student name
- Subject
- Phone number
- Parent's phone number
- Monthly fee or per-class rate
- Payment deadline day
- Billing type (monthly or per-class)
- Notes (optional)
Session and attendance data (entered by tutors):
- Class dates and times
- Session duration
- Attendance status per student (Attended, No-Show, Cancelled)
- Session notes (optional)
Payment data (entered by tutors):
- Payment amount
- Payment date
- Payment method (cash or bank transfer)
- Payment reference (optional)
- Notes (optional)
Parent account data (entered by parents on signup via invite):
- Full name
- Email address
- Password (stored as a secure hash)
Onboarding data:
- Tutor's teaching availability
- Tuition name or brand (optional)
- Billing preferences
Data we collect automatically
Authentication data:
- Session tokens (stored encrypted on your device using iOS Keychain or Android EncryptedSharedPreferences)
- Login timestamps
- Device type (iOS or Android)
Usage data:
- App feature usage patterns (aggregated, not linked to individual identity)
- Error logs (stripped of personal data before storage)
Data we do NOT collect
- We do not collect location data beyond the city field you provide
- We do not access your contacts, camera, or microphone (unless you explicitly share a photo)
- We do not collect financial account details (bank account numbers, card numbers)
- We do not run advertising trackers, advertising SDKs, or behavioural-profiling cookies. We use one privacy-friendly product analytics tool (PostHog) for aggregated event tracking — see the "Third Parties" section below for full details.
- We do not sell your data to anyone, ever
Why We Collect This Data
We collect and process personal data for the following purposes:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your tutor account | Name, email, phone, password | Contract — necessary to provide the service |
| Displaying student records to the tutor who created them | Student names, fees, attendance | Legitimate interest of the tutor |
| Displaying child's data to the linked parent | Student schedule, payment status | Consent — parent accepts the tutor's invite |
| Processing and displaying payment records | Payment amounts, dates, method | Contract — core feature of the service |
| Sending you account-related emails (password reset, verification) | Email address | Contract — necessary to maintain account access |
| Improving the app and fixing bugs | Aggregated usage patterns, error logs | Legitimate interest — improving service quality |
| Communicating with you about GoGuru | Email address | Legitimate interest / consent |
We do not use your data for advertising, profiling, or any purpose beyond what is listed above.
Controller arrangement for student data: For student data entered by tutors, GoGuru and the tutor act as joint controllers. Tutors determine which students' information is entered and what details are recorded. GoGuru determines the technical means by which that data is stored, secured, retained, and deleted. Both parties bear responsibility for ensuring this processing is lawful. This arrangement is governed by these Terms and the GoGuru Terms of Service.
Automated decision-making: GoGuru does not use automated decision-making or profiling that produces legal or similarly significant effects on any user or data subject. All decisions within the app (payment status, attendance records, balance calculations) are based solely on data you enter manually. No algorithmic or AI-based decisions are made about you or your students.
Data About Students (Including Minors)
GoGuru stores data about students on behalf of tutors. Many students are minors under the age of 18.
GoGuru does not directly collect data from students or minors. All student data is entered by the tutor, who has an existing professional relationship with the student and their family.
Tutors are responsible for ensuring they have appropriate consent from students (or their parents/guardians) to store student information in GoGuru. By using GoGuru, tutors confirm that they are entitled to store the student information they enter.
Parents who are invited to the parent portal give explicit consent when they accept the invite and complete signup. The parent portal gives parents visibility into their own child's data — they cannot see any other student's information.
Data minimisation for students: We only store what is necessary for the tutor to manage the tutoring relationship. Student data is not used for any purpose beyond displaying it to the tutor and (if invited) the student's parent.
If you are a parent and wish to have your child's data removed from GoGuru, please contact us at [email protected]. We will work with the relevant tutor to action your request as quickly as possible, typically within 30 days of receipt.
How We Store and Protect Your Data
Storage location: All GoGuru data is stored in Supabase, a managed database platform. Your data is hosted on Amazon Web Services (AWS) infrastructure managed by Supabase. AWS maintains industry-standard ISO 27001 and SOC 2 Type II certifications across its regions. The specific region your data is stored in depends on the Supabase project configuration in effect at the time you signed up.
Encryption in transit: Data transmitted between your device and our servers is encrypted using industry-standard TLS (HTTPS). Our app and website do not accept unencrypted connections.
Encryption at rest: Data stored in Supabase is encrypted at rest using Supabase's standard AES-256 disk-level encryption.
On-device security: Your GoGuru session token is stored using iOS Keychain (on iPhone) or Android EncryptedSharedPreferences (on Android). These are the most secure on-device storage mechanisms available on each platform. Your session is never stored in plain text.
Row-Level Security: GoGuru's database is configured with Row-Level Security (RLS) policies designed to ensure that each tutor can only access their own data — a tutor cannot read another tutor's students, payments, or sessions. We test these policies regularly but cannot guarantee that no misconfiguration could ever occur; if you believe you have accessed data that does not belong to you, please report it immediately at [email protected] with the subject "Security Report."
Access controls: Savith Herath (the operator) has administrative access to the GoGuru database. As a managed cloud platform, Supabase and its infrastructure provider (AWS) also have technical access to the underlying systems as sub-processors. This access is governed by Supabase's own security policies, data processing agreements, and ISO 27001 / SOC 2 Type II certifications. No other third parties have access to your data.
Passwords: Passwords are never stored in plain text. They are hashed using bcrypt through Supabase Auth before being stored. We cannot read your password.
Third Parties We Share Data With
GoGuru uses a small number of trusted third-party services to operate. We do not sell or share your data for advertising purposes.
Supabase (supabase.com)
- Role: Database, authentication, and backend infrastructure
- Data shared: All app data (tutor profiles, students, payments, sessions)
- Location: AWS Tokyo (ap-northeast-1)
- Privacy policy: https://supabase.com/privacy
Google (for Google Sign-In)
- Role: Optional authentication provider
- Data shared: Your Google account email and name, only if you choose to sign in with Google
- Google's privacy policy: https://policies.google.com/privacy
Expo / EAS (expo.dev)
- Role: App build and distribution platform; also handles delivery of push notification tokens between the GoGuru app and Apple Push Notification Service (APNs) / Firebase Cloud Messaging (FCM)
- Data shared: App binary, and — for users who grant notification permission — an anonymised device push token (an opaque string that lets us send notifications to the device; it does not identify the user). The push token is stored on the user's profile row in Supabase and used solely to dispatch class reminders and morning summaries. No notification content passes through Expo's servers in plaintext beyond what is needed to relay the message to APNs/FCM.
- Privacy policy: https://expo.dev/privacy
PostHog (posthog.com)
- Role: Product analytics — captures aggregated, event-level usage data (e.g. "a student was added," "a payment was logged," "a reminder was sent") so we can understand which features tutors actually use and improve them.
- Data shared: Event names with a small set of non-identifying properties (e.g. billing type "monthly" vs "per-class," payment method "cash" vs "bank transfer"). Once you sign in, we associate events with your Supabase user ID and your email address so we can de-duplicate the same person across sessions and contact you about service issues if needed. We do NOT send your students' names, students' phone numbers, students' payment amounts, message content, attendance details, or any other personal data about you or your students to PostHog.
- Location: PostHog US cloud (us.i.posthog.com)
- You can opt out of analytics at any time by emailing [email protected] with the subject "Analytics Opt-Out."
- Privacy policy: https://posthog.com/privacy
WhatsApp (Meta)
- Role: GoGuru opens WhatsApp to allow tutors to send payment reminders
- Data shared: GoGuru does not share any data with WhatsApp. The tutor's device opens WhatsApp independently. GoGuru pre-fills a message template but does not send messages itself, does not access the tutor's WhatsApp contacts, and has no integration with the WhatsApp API.
- See the "WhatsApp Reminders" section below for full details.
Apple App Store / Google Play Store
- Role: App distribution
- Data shared: App usage metrics as required by store policies
- Apple privacy policy: https://www.apple.com/privacy/
- Google privacy policy: https://policies.google.com/privacy
We do not use Google Analytics, Facebook Pixel, Mixpanel, Amplitude, advertising SDKs, or behavioural-profiling trackers inside the GoGuru app. The only analytics tool we use is PostHog, described above — and we only send it aggregated event names, never your personal data or your students' data.
WhatsApp Reminders — Important Disclaimer
GoGuru includes a feature that allows tutors to send payment reminders to students via WhatsApp.
How it works: When a tutor taps "Send Reminder" in GoGuru, the app opens the tutor's personal WhatsApp application with a pre-written message. The tutor reviews the message and taps "Send" inside WhatsApp. GoGuru has no involvement beyond opening WhatsApp with the pre-filled text.
What GoGuru does NOT do:
- GoGuru does not send WhatsApp messages automatically or on anyone's behalf
- GoGuru does not access the tutor's WhatsApp account, contacts, or message history
- GoGuru does not integrate with the WhatsApp Business API
- GoGuru does not store the content of any WhatsApp messages sent
Tutor responsibility: Tutors are solely responsible for the messages they choose to send via WhatsApp. By using the reminder feature, tutors confirm that they have the recipient's consent to be contacted on WhatsApp and that the message content is accurate and appropriate.
WhatsApp terms: Tutors must comply with WhatsApp's Terms of Service when using the reminder feature. GoGuru is not responsible for any action taken by WhatsApp or Meta against a tutor's account as a result of messages sent.
Data Retention
We retain your data for as long as your account is active. If you delete your account, we will permanently delete all associated data within 30 days, including:
- Your tutor profile
- All student records you created
- All payment records
- All session and attendance records
- All parent links associated with your students
Exception: We may retain anonymised, aggregated usage statistics (which cannot identify you) indefinitely for product improvement purposes.
After account deletion, data may persist in our managed database provider's encrypted backups for the duration of the provider's standard backup retention window (typically up to 30 days) before being purged. During this period, the data is not accessible through the app and is only used for disaster recovery purposes.
Your Rights
Under Sri Lanka's Personal Data Protection Act (No. 9 of 2022) and applicable international data protection law, you have the following rights:
Right to access: You can request a copy of all personal data we hold about you. Email [email protected] with the subject "Data Export Request" and we will provide it within 30 days.
Right to rectification: You can correct inaccurate data directly in the app (edit your profile, update student records) or contact us to make corrections.
Right to erasure: You can delete your account and all associated data from within the app (Profile → Settings → Delete Account). You can also email us at [email protected] to request deletion.
Right to data portability: You can request an export of your data. Email [email protected] with the subject "Data Export Request" and we will provide it in a structured format within 30 days.
Right to restrict processing: You can contact us to request that we restrict how we process your data while a complaint is being investigated.
Right to object: You can object to processing based on legitimate interests by contacting us at [email protected].
Rights relating to your child's data: If you are a parent and wish to access, correct, or delete data relating to your child stored in GoGuru, contact us at [email protected]. We will respond within 14 days.
Right to lodge a complaint: You have the right to lodge a complaint with the relevant data protection supervisory authority. In Sri Lanka, this is the Data Protection Authority of Sri Lanka (DASL), established under the Personal Data Protection Act No. 9 of 2022. If you are based in the EU or UK, you may also lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your national DPA in the EU). We would appreciate the opportunity to address your concern directly before you contact a regulator — please email us first at [email protected].
To exercise any of these rights, email [email protected] with the subject line "Privacy Request — [type of request]." We will respond within 30 days. We may ask you to verify your identity before processing the request.
Data Breaches
In the unlikely event of a data breach that affects your personal data, we will:
- Investigate and contain the breach as quickly as possible
- Notify affected users by email within 72 hours of becoming aware of the breach
- Notify the relevant data protection authority as required by law
- Provide a clear explanation of what data was affected, what we have done, and what you should do
Cookies and Tracking
The GoGuru mobile app does not use cookies.
The GoGuru website (gogurulk.app) uses only essential technical cookies necessary for the site to function. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
Waitlist data: If you submit your email address via the waitlist form on our website, we store your email address solely to notify you when GoGuru launches. We will not send you marketing emails beyond the launch notification unless you explicitly opt in. Waitlist emails are stored on a dedicated server and are deleted within 90 days of GoGuru's public launch. You can request removal from the waitlist at any time by emailing [email protected] with the subject "Remove from waitlist."
GoGuru Tutors Directory
gogurulk.app/tutors is a public directory of private tutors ("GoGuru Tutors"). Tutor profiles on the directory display the tutor's name, subjects taught, general teaching area (town level only — never a street address), grades covered, fees, years of experience, a short bio, and a WhatsApp contact button.
- Two kinds of listings: Claimed profiles are created or confirmed by the tutor themselves through our sign-up form. Unclaimed profiles are created by us from the tutor's own public advertisement (for example, a tuition ad the tutor placed on a public classifieds site), republishing only the professional details the tutor chose to advertise publicly — name, subjects, fees, teaching area, and the contact number they published for enquiries. Unclaimed profiles are clearly labelled as such, state their source, and carry a prominent link for the tutor to claim, correct, or remove the profile. We process this professional contact data on the basis of legitimate interest in helping students find tutors who are actively advertising, and we honour objections immediately.
- Updates and removal: A tutor can claim, correct, or remove their profile — claimed or unclaimed — at any time, free, by emailing [email protected] or using the claim link on their profile. We action removal requests promptly (within 72 hours), though search engines may take additional time to drop already-indexed pages.
- Reviews: Reviews are submitted through our review form and published with a general descriptor (e.g. "Parent of Grade 10 student"), not the reviewer's name, unless the reviewer explicitly asks to be named. We only publish genuine reviews — never fabricated ones.
- Contact privacy: Tutors' phone numbers are never displayed as text on the directory. Contact happens through a WhatsApp link the tutor has consented to.
- Analytics: The directory may use PostHog, a privacy-focused analytics tool, to count page views and button clicks (e.g. how many visitors contacted a tutor). This measures aggregate usage and is not used to build advertising profiles.
Children's Privacy
GoGuru is designed for use by adults (tutors and parents). The app is not directed at children and we do not knowingly collect personal information directly from minors. Under Sri Lankan law, a minor is any person under 18. Under GDPR (applicable to EU/UK users), the threshold for independent consent is 16.
Student data (which may include data about minors) is entered by tutors, who have an existing professional relationship with the student and their family. See the "Data About Students" section above for full details.
If you believe we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at [email protected] and we will delete the data promptly.
International Data Transfers
Your data is stored on servers located in Tokyo, Japan (AWS ap-northeast-1). If you are based in Sri Lanka, this means your data is transferred internationally when you use GoGuru.
AWS Tokyo maintains robust data protection standards including ISO 27001 certification. All data is encrypted in transit and at rest. The transfer is necessary to provide the GoGuru service.
← Back to home