Overview
GuruApps builds mobile apps and digital products. This Privacy Policy explains how GuruApps collects, uses, shares, and protects information when you use our apps, website, subscriptions, advertising-supported features, or support channels.
The exact information handled by a specific app may vary depending on the app's features, your device settings, and the permissions you choose to grant.
App-specific information: Keep or Return · Ringora AI Generation. These sections describe the relevant app’s practices more specifically than the general sections below.
Keep or Return
Keep or Return helps you organise purchases, decide what to keep, share private voting links, remember return deadlines, and record returns and refunds. GuruApps LLC, based in Tbilisi, Georgia, is responsible for the app’s processing of your information. Guest use also creates a backend account for online features and credits; it is not an entirely offline or data-free mode.
Information We Handle and Why
- Purchase and item records: store names, dates, totals, currencies, deadlines, item names, prices, sizes, colours, notes, decisions, and return/refund information you enter. We use these to organise your purchases and show what needs attention. Refund status is your record; we do not connect to your bank or confirm receipt of funds.
- Selected files: receipt photos, imported receipt images or PDF pages, item photos, and profile photos you choose. Receipts can contain names, addresses, order numbers, loyalty identifiers, or partial payment details visible in the document. Only submit content needed for your purchase. The app does not upload your entire photo library.
- Account information: a guest or signed-in account identifier, authentication/session credentials, and, if you use Sign in with Apple, an Apple-provided sign-in identifier and the name you share or add to your profile. The current app requests your name, not your email address, from Apple’s sign-in screen. An email or other information you send to support is handled separately.
- Credits and app purchases: verified Apple transaction identifiers and signed purchase data, product/pack identifiers, account association, delivery and refund/revocation status, credit grants, reservations, debits, balance, and device identifiers used to recover interrupted saves. These records deliver credits, reconcile balances, prevent duplicate grants and fraud, and support purchase issues. Apple processes payment; we do not receive your full payment-card number.
- Sharing and votes: your question, selected items and permitted fields, link status and expiry, votes, structured reasons, and timestamps. We use these to operate private decisions and display results.
- Technical information: network/IP information, device and app versions, language, installation identifiers, notification settings and tokens, operational events, and diagnostics used for security, reliability, notifications, analytics, and support as described below.
Receipt Scanning and OpenAI
When you start online scanning or import a receipt for analysis, the selected receipt pages are prepared as images; embedded PDF text may also be included. They are sent to our SashiDo/Parse backend and then to OpenAI to extract purchase details. This can include personal information visible in the receipt. The result is an editable draft, not a verified retailer policy. Manual entry is available if you prefer not to send a receipt for analysis.
The extraction request does not intentionally include your profile, credit balance, or Apple transaction data as model input. OpenAI also receives technical request metadata. Our extraction flow uses store: false to disable stored Responses API application state; this is not a guarantee of zero retention. OpenAI’s standard abuse-monitoring logs may include inputs and outputs and be retained for up to 30 days, or longer where required for legal or safety reasons. OpenAI states that API data is not used to train its models by default unless the customer opts in. See OpenAI’s API data controls.
The extraction handler processes receipt input to return detected fields rather than creating a permanent AI conversation. Saving the receipt with a purchase is a separate storage action: your saved receipt, extracted fields, and item records can remain on your device and in account sync until deleted. Operational usage and error records support abuse prevention and diagnosis.
Cloud Storage, Sync, and Providers
SashiDo/Parse provides guest and signed-in accounts, purchase-credit records, receipt-request handling, private decisions, and account sync. Cloudflare R2 stores uploaded files such as receipt, item, and profile images for those features. Signing in with Apple allows saved account data and unused credits to be retrieved on your devices. Files remain subject to their account and sharing permissions; making a decision link can make selected content available to link visitors.
Apple provides Sign in with Apple, App Store payment and transaction services, and Apple Push Notification Service. Google Firebase Analytics and Crashlytics support the measurement and diagnostics described below. These providers process information needed to perform their functions; their processing may occur outside your country. General international-processing and security provisions below also apply.
Private Links and Friends Who Vote
Friends can open a voting link without an app or account. The page shows the decision question and selected items, with optional photos, prices, sizes, and notes according to your visibility choices. It does not expose unrelated purchases or your private account credentials. A private link is unlisted, not restricted to named recipients: anyone with an active link, including a forwarded copy, can view the shared information. Use expiry, close, or revoke controls to end future access. Copies or screenshots already saved by others cannot be recalled.
The voting page creates a random browser key in local storage to help prevent repeat voting. The server derives a decision-specific hash for vote deduplication and stores the vote, any selected reasons, and related timestamps. It also handles network information for request security and abuse prevention. The browser key remains until local storage is cleared. It is not a promise of complete anonymity or a way to verify each visitor’s identity.
Analytics, Diagnostics, and Tracking Choices
Keep or Return uses Google Firebase Analytics for app usage and purchase measurement and Crashlytics for crash and error reporting. This can include app-instance/installation identifiers, device and operating-system details, sessions and screen views, feature interactions, counts and durations, credit-purchase transaction information, approximate geography derived from network information, crash traces, and diagnostic context. We use these to understand usage, evaluate receipt and purchase flows, measure app-credit sales, and improve reliability.
Our custom analytics events use categories, counts, and timings rather than receipt contents, item names, store names, photos, personal notes, voting questions, or raw error text. Recording that you saved a retail purchase or confirmed a retail refund is an app interaction, not a claim that GuruApps processed that retail transaction.
The app requests Apple’s App Tracking Transparency permission for advertising measurement. If you allow it, the advertising identifier can be available to the measurement SDK; if you deny it, the app remains usable and iOS restricts access to that identifier. Denying tracking does not disable ordinary app analytics or crash reporting. You can change the tracking choice in iOS Settings → Privacy & Security → Tracking. See Firebase’s privacy and security information for its processing practices.
Camera, Calendar, and Notifications
Camera access is used when you choose to capture receipts or photos. Photo and document pickers provide the content you select. Calendar entries are created when you choose to add and save a return deadline; the app does not upload your existing calendar contents for this feature. Reminders and decision notifications use permission settings, scheduling information, and, for remote delivery, installation/device tokens and Apple’s push service. Notification previews may display purchase or decision details on your lock screen. You can control previews and permissions in iOS Settings.
Retention, Deletion, and Your Choices
Saved purchases, receipts, photos, account records, decisions, and votes are retained to provide your ongoing purchase history, sync, and decision results until you delete the relevant content or account, subject to necessary legal, security, and dispute-related retention. Expiring a voting link ends access through that link; it does not automatically erase the owner’s purchase or decision history. Local files and backups can remain until removed separately.
Use Profile → Edit profile → Delete account to request deletion of a guest or Apple-linked account. Apple-linked deletion may require fresh Apple authentication. This removes the account’s cloud records, private voting links and votes, sync data, stored files, and unused credit balance. Removing local app data or uninstalling the app does not itself request cloud-account deletion. Contact us before deletion if you need help with unused paid credits; deleting an account does not automatically request an Apple refund or reset eligibility for the free allowance.
Deleting the billing account removes its credit balance and transaction history; a non-reversible token marker remains to reject late purchase notifications. Other security, support, or legally required records may be retained where necessary, without continuing your public sharing. Apple keeps purchase records under its own obligations. Account deletion does not automatically erase independent AI-provider logs, analytics/diagnostic records, device backups, or recipients’ copies. OpenAI’s retention is explained above. Firebase states that Crashlytics begins removing crash traces and associated identifiers after 90 days; Analytics retention depends on the service’s retention settings. Contact us about deletion of information we control, including provider-held information where it can be identified.
You can request access, correction, deletion, or information about processing, and exercise other rights available under applicable law, by emailing davit@guru-apps.com. We may need information to verify ownership, especially for a guest account. Do not send passwords or complete card details. See Keep or Return deletion instructions and Keep or Return Terms of Use.
Information You Provide
We may receive information that you choose to send to us, including your name, email address, support messages, screenshots, feedback, business inquiry details, or other content you submit when contacting GuruApps.
Information Collected Automatically
Our apps and website may collect limited technical and usage information, such as device type, operating system version, app version, language, country or region, crash logs, diagnostics, performance data, feature usage, purchase status, and approximate network information such as IP address.
App Permissions and User Content
Some apps may request access to device features such as the camera, photos, files, microphone, notifications, or location when those features are needed for app functionality. We request permission through the operating system, and you can change permissions later in your device settings.
Unless a specific app feature clearly uploads or shares content, content such as photos, files, scans, recordings, or other user-created material is intended to be processed for the feature you choose to use.
Ringora AI Generation
Ringora: Ringtone Maker offers optional photo-to-music generation. When you choose a photo and start a generation, the selected image is uploaded for AI analysis and music creation. This feature uses a persistent anonymous Ringora account to associate your generation requests and purchased credits with you, even if you do not use Community. It does not require an email-and-password account.
For this feature, we process:
- The photo you select from your library or capture with the camera. The app resizes and re-encodes it as a JPEG, removing embedded EXIF and GPS metadata before upload. People, text, locations, and other information visible in the image remain part of the image supplied for analysis.
- Your selected musical style and audio mode, such as instrumental or with lyrics.
- AI-created text, including a title, musical brief, mood, genre, tempo, instruments, generation instructions, and vocal direction or lyrics when applicable.
- The resulting audio and its file type and storage reference.
- Your anonymous account identifier, generation job identifier, creation and start times, expiration time, attempt count, processing status, and error information.
- Purchase and credit information described below, used to authorize generation, prevent duplicate charges, and return credits after failures.
How the Photo Becomes Music
- Ringora's backend (SashiDo/Parse) receives the prepared photo, your selected options, and the authenticated request. It manages the generation job and reserves a credit.
- OpenAI receives the prepared photo, selected style and audio mode, and Ringora's instructions. It analyzes the image and returns a musical brief, title, and, where applicable, generated lyrics. We do not include your Ringora account identifier, Apple purchase records, or credit balance in this AI request.
- Google/Lyria, through the paid Gemini API, receives a separate text-only music request based on that brief, with style, arrangement and timing instructions, and any generated lyrics and vocal direction. Google does not receive the uploaded photo, your Ringora account identifier, or your purchase and credit records in this request. The text may reflect content visible in your photo.
- Cloudflare R2 stores the generated audio privately so Ringora can deliver it to your device using a temporary signed download link. Saving or exporting the result creates a local copy. Publishing it to Community is a separate action.
We use this information to fulfill your request, deliver and recover generation results, manage credits, diagnose failures, and protect the service. AI providers also receive technical request information associated with GuruApps' API connection. The photo-to-music flow does not upload your entire photo library or send your imported audio library to either AI provider.
AI Input and Output Retention
- Uploaded photos and music prompts: Ringora's generation worker processes photos, briefs, and lyrics in memory and does not save them to its backend database or R2 storage. Production request logs redact the uploaded image payload. Operational logs can contain job identifiers, status, and diagnostic errors. Provider retention is described below and is separate from Ringora's storage.
- Pending generation on your device: Ringora keeps the prepared photo and job information in a protected local file excluded from device backups, so you can resume checking an interrupted request. It removes this file after successful import, when a failed, expired, or canceled result is handled, or when you delete your Ringora account. A pending file can remain while a request is unresolved.
- Generated audio on our servers: Download access expires seven days after the generation request is prepared. Production R2 storage has a seven-day lifecycle deletion rule for generated audio. Ringora also deletes expired audio when its status is checked, and deletes stored generation audio during account deletion. Storage deletion may take additional technical processing time.
- Generation records: The account and job identifiers, selected options, short generated title, timestamps, status, file information, and diagnostic errors remain in the backend after the audio download expires. These records do not have an automatic seven-day deletion period. They support request recovery, credit reconciliation, and support, and are removed through account deletion or a verified deletion request, subject to necessary legal and security retention.
- Saved projects and exports: Copies saved on your device remain until you delete them. Deleting a local project does not automatically delete a server-side generation record, a published Community copy, or a copy exported to another app. Device backups and receiving services follow their own retention rules.
AI Provider Retention and Training
OpenAI: Ringora disables stored Responses API application state for its photo-analysis requests. This is not a guarantee of zero retention: OpenAI's standard abuse-monitoring logs may contain inputs, outputs, and related metadata for up to 30 days, with longer retention for legal or safety reasons. OpenAI states that API data is not used to train its models by default unless the customer opts in. See OpenAI's API data controls.
Google/Lyria: Ringora uses a paid Google API project. Google states that paid-service prompts and responses are not used to improve its products. Ringora's music requests use the Interactions API's default storage behavior. Google's documented paid-tier interaction retention is 55 days, or a shorter period configured for the project. This covers the text request and generated response. Google also keeps safety, security, operational, and billing records under its applicable policies. See Google's interaction retention documentation and Gemini API paid-service terms.
Deleting data in Ringora does not automatically erase copies already processed or retained by an AI provider. Those copies remain subject to the provider's retention periods and legal obligations. Contact us about a deletion request so we can address data we control and any available provider deletion process; immediate deletion from every provider system cannot be guaranteed.
AI Purchase and Credit Records
Apple processes purchases of the 3-, 10-, and 25-generation credit packs. Ringora processes the signed transaction and verifies purchase information directly with Apple. This includes transaction and product identifiers, purchase date, quantity, purchase environment, an app-specific account token, and refund or revocation status. The account token links the purchase to your anonymous Ringora account; it is not your Apple Account password or payment-card number.
Our server stores the transaction identifier, associated Ringora account identifier, product, purchased quantity, purchase date, remaining credits, revocation status, and generation identifiers for credit use and returns. We use these records to maintain non-expiring balances, recover unfinished purchase deliveries, handle failed generations, process purchase reversals, and prevent duplicate redemption. Credit records have no automatic time-based expiration or deletion while they support these purposes.
When you delete your Ringora account, its credit balance is cleared, the account association is removed from credit records, and generation-use and credit-return identifiers are removed. A limited transaction record, including its transaction identifier, product, quantity, purchase date, and revoked status, remains to prevent deleted or refunded purchases from being redeemed again and to meet applicable record obligations. Apple retains its own purchase records under its policies. See the Ringora AI credit terms for account recovery and the effect of account deletion on unused credits.
Deleting Ringora AI Data
You can delete local projects in your library. Ringora's account-deletion option in the Community profile also cancels generation jobs, removes their stored audio and job records, clears the pending local generation file, and clears the account's credit balance. To request deletion without using that flow, or to ask about particular AI data, email davit@guru-apps.com. We may need enough information to verify and locate your anonymous account. Uninstalling the app alone does not send a server-data deletion request.
Ringora Community
Ringora includes an optional Community feature where you can create a creator profile and publicly publish ringtone audio that you create. You can use Ringora without creating a traditional email-and-password account. If you use Community or AI generation, Ringora may create a persistent anonymous backend identity to associate your profile, published ringtones, and Community activity with you.
When you use Ringora Community, we may collect and process:
- An anonymous or persistent user or creator identifier.
- Your username or creator name and, where applicable, a display name.
- Your profile or avatar image.
- Ringtone titles and related metadata.
- Ringtone or audio files that you choose to upload and publish.
- Community interaction data, including ringtone usage and "Set Ringtone" interactions.
- Device or push-notification identifiers needed to deliver notifications.
- Analytics, diagnostics, and technical information described elsewhere in this Privacy Policy.
Creator profile information, ringtone titles, metadata, and published ringtone audio may be visible to other Ringora users. Uploaded ringtone files are stored remotely so they can be made available through the Community feed and previewed or used by other users.
Ringora may record interactions with Community ringtones to operate features such as usage counts and creator notifications. For example, a creator may receive a push notification when another user sets or uses the creator's published ringtone. Push notifications are optional, require notification permission, and remain subject to the recipient's device notification settings.
Deleting Ringora Community Data
Ringora creators can use the deletion options available in the app to delete their own published ringtones and their Community creator profile or account. When you delete your Community profile or account through Ringora's deletion flow, we will remove or disassociate your server-side Community profile, content, and associated Community data, where applicable, subject to reasonable technical processing time and any retention required by law.
Ringora's account-deletion flow also removes the AI generation data and clears the credit balance described in Ringora AI Generation. Deleting an individual published ringtone does not delete your account or credit balance.
Deleting a ringtone from Community prevents the original Community upload from remaining available through Ringora, subject to reasonable processing and backup periods. However, if another user already exported, downloaded, or set that ringtone and stored a separate copy on their own device, deleting the original upload cannot necessarily remove that independently stored copy. GuruApps cannot remotely erase ringtone files that another user has already exported or stored independently on their device.
Subscriptions and Purchases
If you purchase a subscription or other in-app purchase, payment is processed by the app store or payment platform. GuruApps does not receive your full payment card number. We may receive purchase-related information needed to unlock paid features, verify entitlement status, prevent fraud, provide support, and maintain business records.
Advertising and Tracking
Some GuruApps apps may show ads. Advertising partners may process information such as device identifiers, advertising identifiers, IP address, coarse location, app interactions, ad views, and diagnostic information to deliver ads, measure ad performance, limit ad frequency, prevent fraud, and comply with their obligations.
Where required, we request your permission before allowing tracking for advertising or advertising measurement. You can manage tracking choices in your device settings. You may still see ads after disabling tracking, but they may be less personalized.
How We Use Information
- To operate, maintain, and improve our apps, website, and services.
- To provide app features, subscriptions, purchase restoration, and customer support.
- To analyze performance, diagnose crashes, fix bugs, and improve reliability.
- To show ads, measure advertising performance, and prevent advertising fraud.
- To communicate important product, support, legal, or security updates.
- To comply with legal obligations and enforce our terms.
Service Providers
We may use third-party service providers acting on behalf of GuruApps to support app stores, payments, subscriptions, advertising, backend and database services, file, audio, and image storage, AI image analysis and music generation, push notifications, analytics, crash reporting, cloud infrastructure, customer support, and other app functionality. These providers may process information as needed to provide their services to us and according to their own privacy policies and the settings available in your app or device.
The infrastructure used for Ringora Community may include providers and products such as SashiDo or Parse for backend and database services, Cloudflare (including R2) for file storage, Firebase for app services such as analytics or crash reporting, and Apple Push Notification Service for push notifications. The specific providers and products we use may change over time as our services evolve. Service providers do not acquire ownership of your Community content merely because they process or store it on our behalf.
When We Share Information
We may share information with service providers that help us operate our apps and business, with advertising partners where ads are used, with app stores and payment platforms for purchases, when required by law, to protect rights and safety, or as part of a business transfer such as a merger, acquisition, or asset sale.
Data Retention
We keep information only as long as reasonably necessary for the purposes described in this policy, including providing services, supporting users, maintaining records, resolving disputes, improving our products, and meeting legal obligations.
Ringora AI photos, prompts, generated audio, generation records, and credit purchases have the specific retention and deletion practices described in Ringora AI Generation above.
Your Choices and Rights
You can stop using an app at any time and may uninstall it to stop future app-based data collection. You can manage app permissions, notifications, and tracking permissions in your device settings. You can also contact us to request access, correction, deletion, or additional information about personal information we may hold, subject to applicable law and verification. For deletion instructions, visit our Data Deletion Instructions page.
Children
GuruApps apps are not intended for children under 13 unless a specific app states otherwise and is designed for that audience. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us so we can take appropriate action.
Security
We use reasonable technical, administrative, and organizational safeguards designed to protect information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
International Processing
GuruApps and our service providers may process information in countries other than your country of residence. Where required, we use appropriate safeguards for international transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date above. Continued use of our apps, website, or services after an update means you accept the updated policy.
Contact
If you have questions, requests, or concerns about this Privacy Policy or your privacy choices, contact us at davit@guru-apps.com.