Skip to content
Gudru

Privacy Policy

Last updated: 4 October 2026

Gudru ("we", "our") respects the privacy of you and your children. This policy explains what data we collect, how we use it, and how we protect it - with particular care for the fact that a child never provides personal information of their own to use Gudru.

1. Who We Are

Gudru is a mastery-based mathematics learning application designed for primary school children. The app is primarily aimed at the Lithuanian market and runs on iOS and Android.

2. What Data We Collect

Website Visitors

  • -Your email address, if you sign up on gudru.app to be notified at launch - kept until launch, then deleted.

Parent Accounts

  • -Google account email address and name (via Google Sign-In)
  • -Family profile display name
  • -Children's profile names (not real names - only the nicknames you choose)
  • -A push-notification token for your own device, if you allow notifications - so worksheet reminders and alerts can reach you; deleted when you sign out or delete your account.

Children's Profiles

  • -A nickname (the name entered by the parent)
  • -The child's school grade (required - used to choose the starting level)
  • -Mathematics level and progress data (task accuracy, speed, streak)
  • -Pairing code usage (one-time - invalidated after the profile is linked)
  • -Daily activity date (day only - not time) for streak tracking
  • -A push-notification token for the child's device, if you (the parent) enable notifications for them.

What We Never Collect From Your Child

  • -Your child's real name or surname
  • -Your child's email address, phone number, or any other contact details
  • -Your child's location
  • -Photos, video, or audio recordings of your child
  • -Advertising identifiers, and no third-party advertising or tracking SDKs of any kind - this holds for the parent side of the app too, not only your child's.

3. How We Use Your Data

  • -To save and sync task results across devices
  • -To display progress indicators (streak, level) inside the app
  • -For the parent dashboard (in-app) - to review your child's statistics
  • -For the technical operation of the app - no advertising, no profiling, no selling.

4. Analytics and Measurement

We want to know where students get stuck so we can keep improving Gudru's lessons for every family - that is the only reason we ever measure app usage. On your own device, as a parent, you can choose to share anonymous usage data, an opt-in you can turn on or off at any time from your dashboard (section 10). This is off until you turn it on, and it never runs at all on a device that holds a child's profile, in any consent state, because that removes the whole device from analytics regardless of your choice. When it is on, we use Firebase Analytics (Google) to collect thirteen specific in-app events - such as completing a worksheet or advancing a level - plus what the Firebase Analytics SDK collects automatically: a pseudonymous device identifier, general device model and OS version, approximate region, and app-open/session timing. Google keeps this event data for approximately two months by default; turning the toggle off, or deleting your account, stops any further collection immediately but does not retroactively erase events already sent before that point.

  • -It never runs on a device signed in as a child, in any consent state
  • -It never includes your child's name, nickname, or any other identifying detail
  • -We use no advertising SDKs and no advertising identifiers, with or without your consent
  • -We never sell or share this data, and we never use it to track you across other apps or websites.

5. Children's Data Protection

Children never create their own account. A profile is created and controlled entirely by a parent who has signed in with their own Google account; the child never provides an email address, age, or any other personal information to sign up, and Firebase's security rules prevent a child's device from creating, renaming, or removing a profile on its own. In Lithuania, a child aged 14 or older may otherwise consent to an information-society service in their own right under GDPR Article 8 - Gudru's design exceeds that by keeping every profile under a parent's control regardless of the child's age. This also aligns with the parental-control principle behind the US COPPA rule, which sets its own threshold at under 13, even though Gudru is not marketed in the United States. We do not independently verify a parent's identity beyond their Google account; if you believe a child profile was created without a parent's involvement, contact us at privacy@gudru.app.

6. How Data Is Stored, and Who Processes It

We store and process your data using the services listed below; each, except iCloud Mail and Gmail described below, acts only on our instructions, as our data processor, and none may use your data for its own purposes. Google, Vercel and Apple are all headquartered in the United States and process some of this data outside the European Economic Area as well as inside it; that transfer is required to run under a mechanism recognised by EU law, and we have not yet completed the Data Processing Agreements confirming which mechanism (such as the Standard Contractual Clauses, or the EU-US Data Privacy Framework) covers every processor below - this section will name it precisely once that work is finished. Vercel Web Analytics, specifically, sets no cookies and identifies a visit only by a hash of the request that is discarded after 24 hours, so it cannot recognise the same visitor from one day to the next. The gudru.app website separately sets its own NEXT_LOCALE cookie, which stores only your language choice (Lithuanian or English) for up to a year, so a returning visit shows you the language you last chose - it identifies no one and is never sent to any third party.

  • -Firebase Auth (Google) - your Google account email and display name, used to sign you in
  • -Cloud Firestore (Google, hosted in Warsaw, EU) - everything described in section 2, stored in our database
  • -Cloud Functions (Google, hosted in Belgium, EU) - the same data, processed by our backend logic such as account deletion, pairing codes, and subscription checks
  • -Firestore backups (Google) - a daily encrypted copy of the database, kept for 60 days for disaster recovery only
  • -Firebase Analytics (Google) - anonymous usage events, only from a parent's own device and only if you opt in (section 4)
  • -Firebase Crashlytics (Google) - crash reports and non-fatal error logs, device model, OS version, and a per-install identifier, from every device including a child's, so we can fix problems before they affect your child's session
  • -Firebase Cloud Messaging (Google) - your device's push-notification token, if notifications are enabled
  • -Firebase Remote Config (Google) - a request carrying your app installation's identity, used to safely roll out feature changes
  • -Firebase App Check (Google) - an attestation token proving requests come from our real app, not a script or a forged client. On gudru.app the same check is Google reCAPTCHA Enterprise, and it starts only when you submit the launch signup form: your browser then loads reCAPTCHA from Google (and may contact Google again to renew the check while the page stays open), which receives your IP address and browser details to tell a person from an automated script. In our own test it stored a _GRECAPTCHA cookie from google.com (valid for about six months), a _grecaptcha entry in this site's local storage, and two Firebase databases (App Check and heartbeat) in the browser; other browsers may differ
  • -RevenueCat - your purchase and subscription status, linked to your account, to manage your subscription across devices
  • -iCloud Mail (Apple) - the email service for gudru.app addresses, on a standard Apple account under Apple's own terms rather than a data processing agreement with us: when you sign up for launch notifications, a copy of your email address is sent to our info@gudru.app address; every email you send us, for example to privacy@gudru.app, arrives there; and our internal service alerts, which carry only account identifiers, go there too. Mail to these addresses is forwarded to a standard Gmail inbox (Google) that we read, under Google's own terms
  • -Vercel (hosting, Frankfurt, EU) - standard web server request logs for gudru.app
  • -Vercel Web Analytics - anonymous, cookieless website visit data for gudru.app.

7. Security Measures

  • -All communications are encrypted via HTTPS / TLS
  • -Firebase security rules ensure only an authenticated parent can access their family's data
  • -Children's profiles have no Firebase Auth accounts - they can only read and write through a verified family pairing, never directly
  • -Firebase App Check is active on every build, verifying that requests come from our genuine app before Firestore or our backend functions process them.

8. Data Retention and Deletion

  • -We keep encrypted daily backups of our database for 60 days, for disaster recovery only - data erased from our live database can still exist in these backups until they finish rotating out, which takes up to 60 days, and backups are never used for any other purpose
  • -Removing a single child's profile: the child's profile data (the nickname entered by the parent, learning progress, task history) is kept for 7 days so you can undo the removal from the parent dashboard - after 7 days it is erased from our live database and follows the 60-day backup rotation above
  • -Deleting the entire family account: deletion is scheduled with a 7-day grace period during which you can cancel - once it proceeds, ALL family data (parent account, every child's profile, progress and task history) is erased from our live database at once, including any removed child profile still inside its own 7-day window, and follows the same 60-day backup rotation
  • -We retain personal data only for as long as it is needed to provide the service
  • -One record is the exception: a minimal deletion-audit entry (who requested deletion, when, why, and which signals were checked) is written before your account is erased and is kept afterward, so we can answer a legal request or resolve a dispute about a deletion. It never contains your child's name, progress, or task data - only the fact and circumstances of the deletion itself, and it is the one record that outlives the account it describes.

10. Your Rights (GDPR)

You have the right to: access your data; correct inaccurate data; erasure (right to be forgotten); restrict processing; object to processing based on legitimate interest; data portability; and withdraw consent at any time for anything based on it (section 9), without affecting the lawfulness of processing carried out before your withdrawal. To exercise these rights, contact us at: privacy@gudru.app. We will respond within 30 days.

11. Changes to This Policy

We will notify you of material changes to this policy via in-app notice or email (to parents). Continued use after the effective date constitutes acceptance of the revised policy.

12. Contact

For privacy questions: privacy@gudru.app