Privacy Policy
Last updated: 1 August 2026
GuruSetu is currently a teacher-training prototype. This working notice describes how the current build handles data and requires legal review before a public launch.
What the prototype stores
The public directory is open to everyone. Signing in and using member features creates records in GuruSetu’s configured database.
- Sign-in data: GuruSetu uses your email address to send a one-time code through Resend. During sign-in, the address is held in a short-lived, HTTP-only cookie. The application database stores keyed cryptographic values derived from the address; its schema has no plain-text email field.
- Profile data: If you complete onboarding, GuruSetu stores your display name, role, institution if supplied, time zone and leaderboard choice.
- Learning data: The site stores lesson notes, flashcards added to Review, review history, video progress, reactions, points, streak activity and badges.
- Community data: Comments, replies and deletion timestamps are stored with the lesson and your account identifier.
- Abuse prevention data: Sign-in and API rate limits use derived identifiers. The application database has no plain-text IP-address field. A hosting provider may keep separate request logs under the settings of that deployment.
The current prototype has no advertising or visitor-analytics service.
How the data is used
The stored data supports the feature that produced it: signing you in, saving notes, scheduling flashcard reviews, recording progress, running the points system, showing comments and building the leaderboard for members who opt in. It is also used to limit repeated sign-in and write requests.
What other people can see
- Your lesson notes and review history are returned only to your signed-in session through the current interface.
- Signed-in members can see your display name and comments. Your email address stays private.
- Signed-in members can see reaction totals. Individual reaction choices stay private.
- The leaderboard is off by default. If you opt in, it displays your name, level and points for the current 30-day window. Your institution, role, notes and email address stay private.
Keep private and sensitive information out of display names and comments.
Cookies, local storage and outside services
GuruSetu uses secure, HTTP-only cookies for the one-time-code flow and the signed-in session. The sign-in code expires after 10 minutes. If you leave Remember me off, the cookie has no persistent expiry and the server expires the session after eight hours. If you select Remember me, the cookie and server-side session expire after 30 days. Signing out revokes either type of session immediately. The site also keeps your light or dark theme choice in browser local storage.
Resend processes the destination email address to deliver sign-in codes. Lesson videos use YouTube’s privacy-enhanced embed domain, and the player loads YouTube code when a member opens a video. YouTube and the publishers of linked resources handle requests under their own terms and privacy practices.
Retention and your choices
Expired sign-in challenges and sessions are cleaned from the application database as the service runs. Profile and learning records otherwise remain in the configured database until they are removed. A formal retention schedule is pending for this prototype.
You can:
- opt in to or out of the leaderboard from your profile;
- edit or delete a lesson note;
- remove a flashcard or reaction;
- delete your own comment through the available interface;
- download one note or export all notes as a ZIP file; and
- sign out to revoke the current session.
Account-deletion requests currently go through email. To ask for a copy, correction or deletion of account data, contact hello@neeldhara.email. The operator of each deployed instance handles requests concerning that instance.
Security and changes
The prototype uses access controls, bounded sessions, request checks and rate limits. Security risk remains, so keep confidential records outside this prototype.
This notice may change as the product, hosting setup or data practices change. The date at the top will be updated when that happens.
Questions about this notice can be sent to hello@neeldhara.email.

