Legal

Privacy Policy

Last updated: August 20, 2026

This Privacy Policy applies to the Gullivr AI mobile application, website at https://gullivr.ai, APIs, and related services (collectively, the "Services").

This Privacy Policy explains how Gullivr AI Technologies Private Limited ("Gullivr," "we," "our," or "us") collects, uses, discloses, stores, and otherwise processes personal information in connection with the Services. It also explains your choices and rights. Where a particular processing activity requires consent, we request that consent separately.

Important AI Privacy Notice

Gullivr AI uses third-party AI and generative-media providers. Depending on the feature you use, prompts, messages, images, files, videos, and related request content may be transmitted to OpenRouter and/or model providers including OpenAI, Google Gemini, xAI (Grok), and fal.ai. Gullivr presents an in-app disclosure and requests permission before covered personal data is sent to third-party AI services where consent is required.

1.Personal Information We Collect

The information we collect depends on the features you use, the permissions you grant, and how you interact with Gullivr AI.

1.1 Information You Provide

  • Account information. Name, email address, phone number, profile image, account identifier, and account preferences that you provide or that an authorized sign-in provider returns to us.
  • User Content. Prompts, messages, conversations, text, images, videos, files, attachments, itinerary details, travel preferences, references, seller or business enquiry details, and other content you type, upload, select, or submit.
  • Generated Content. AI-generated text, images, videos, and associated metadata that we process to return results, maintain requested history, troubleshoot, and support the Service.
  • Support and communications. Information you provide when contacting support, including name, contact details, message content, screenshots, and device or diagnostic details you choose to share.
  • Payments and wallet top-ups. Limited transaction information such as amount, order or transaction identifier, payment status, wallet-credit status, receipts, and fraud or verification metadata. Full payment card details are handled by the applicable payment processor and are not stored by Gullivr.

1.2 Information We Collect Automatically

  • Device and technical information. Device model, operating system and version, app version, language, time zone, IP address, network information, push-notification token, device or app identifiers, crash logs, error logs, and related diagnostics.
  • Usage and analytics information. Session identifiers, feature interactions, screens viewed, buttons or actions used, generation type, request status, timestamps, performance information, and events used to measure enquiries, conversions, and product use.
  • Approximate location. A general country or region derived from IP address for security, localization, availability, or analytics. Gullivr does not collect precise GPS location unless a feature clearly requests it and you grant the relevant device permission.
  • Cookies, SDKs, and similar technologies. On our website and in the app, we may use local storage, SDKs, cookies, and similar technologies for authentication, preferences, security, analytics, diagnostics, and performance.

1.3 Information We Receive from Third Parties

  • Google Sign-In. If you choose Sign in with Google, Google may provide information you authorize, such as your name, email address, profile image, and Google account identifier. We use this information to authenticate and link your Gullivr account. We do not receive your Google password.
  • Sign in with Apple. If you choose Sign in with Apple, Apple may provide your name (typically at first authorization), email address or Apple private relay email address, and an Apple account identifier. We use this information to authenticate and link your Gullivr account. We do not receive your Apple ID password.
  • Payment providers. For wallet top-ups, Cashfree Payments may return payment status, transaction identifiers, order references, and related payment metadata needed to credit your Gullivr wallet, reconcile transactions, prevent fraud, and handle support. App-store purchases, if offered, may similarly provide limited transaction metadata.
  • Analytics, security, and infrastructure providers. Providers may return aggregated analytics, diagnostic information, fraud or abuse signals, delivery status, and service-related metadata generated while operating Gullivr.

2.AI Features and Third-Party AI Data Sharing

Gullivr uses third-party AI and generative-media services to provide text, image, and video features. Depending on the feature or model selected, content you submit may be sent through Gullivr's backend to one or more of the providers below.

2.1 Data That May Be Sent to AI Providers

  • Prompts, messages, chat content, and instructions you submit.
  • Images you upload or select for analysis, editing, or image generation.
  • Video inputs, reference images, or other media you submit for video generation.
  • Files, attachments, itinerary details, templates, or other content you intentionally include in a request.
  • Technical request metadata reasonably necessary to route, secure, process, and return the AI request.
  • AI outputs or generation results where needed to deliver, continue, or troubleshoot the requested feature.

User Content can contain personal information about you or another person if you include such information in a prompt, file, image, video, or other input. Gullivr does not intentionally attach your account password to AI requests.

2.2 AI and Generative-Media Providers We Use

ProviderPurposeData that may be sent
OpenRouter, Inc.Routes certain AI requests to selected model providers.Prompts, messages, images, files, attachments, technical request metadata, and related AI inputs/outputs as needed for the requested feature.
OpenAIText and/or image AI features using OpenAI models.Content included in the relevant request, such as prompts, messages, images, files, and request metadata.
Google / GeminiText and/or image AI features using Gemini models.Content included in the relevant request, such as prompts, messages, images, files, and request metadata.
xAI / GrokText and/or image AI features using Grok models.Content included in the relevant request, such as prompts, messages, images, files, and request metadata.
fal.ai (Features & Labels, Inc.)Video generation and other generative-media processing.Prompts, reference images, video inputs, media files, and request metadata needed to generate the requested media.

If OpenRouter automatic routing, provider fallback, or fal.ai routing uses an additional underlying model provider, Gullivr will update this Policy and the applicable in-app disclosure when required before covered personal data is sent to that provider.

2.3 Permission Before AI Sharing

Before covered personal data is sent to a third-party AI service where consent is required, Gullivr presents an in-app disclosure identifying the relevant provider(s), the categories of data that may be sent, and the purpose of the sharing. The disclosure may be contextual to the feature. For example, video-generation consent may identify fal.ai when the user first uses a video feature.

If you decline, Gullivr will not send the covered data for that request, and the affected AI feature may be unavailable. You may withdraw consent for future AI sharing by contacting us at legal@gullivr.ai. If Gullivr provides an in-app privacy control for withdrawal, you may also use that control. Withdrawal does not affect processing that lawfully occurred before consent was withdrawn.

2.4 Provider Processing, Retention, and Protection

Third-party AI providers process information under their own contracts, privacy notices, data-processing terms, security practices, and provider-specific retention or abuse-monitoring rules. Provider practices may vary by model, route, account configuration, and feature. Gullivr uses contractual and technical safeguards where appropriate and encourages users not to submit information that is unnecessary for the request, particularly highly sensitive information.

2.5 AI Output and Accuracy

AI-generated content is produced by probabilistic machine-learning systems and may be incomplete, inaccurate, inappropriate, or outdated. Verify important information independently before relying on it, especially for medical, legal, financial, safety-critical, or other high-impact decisions.

3.How We Use Personal Information

  • Provide and operate the Services. Create and manage accounts, authenticate users, process AI requests, generate text/images/videos, maintain requested history, process wallet credits and purchases, and provide core functionality.
  • Personalize and improve the experience. Remember preferences, understand feature usage, improve user flows, evaluate performance, and develop or test features.
  • Analytics and business enquiry tracking. Measure feature interactions, service quality, seller enquiries, conversions, and product performance. Analytics events may include seller contact identifiers such as seller WhatsApp numbers or seller email addresses where those identifiers are part of an enquiry event.
  • Security and abuse prevention. Detect fraud, spam, abuse, unauthorized access, policy violations, malicious activity, and technical threats.
  • Customer support and communications. Respond to questions, troubleshoot issues, provide account or service notices, and communicate about transactions or service changes.
  • Legal and compliance. Comply with applicable law, valid legal requests, accounting or tax requirements, resolve disputes, and enforce our terms.

4.How We Share Personal Information

We do not sell personal information for money. We disclose information only as described in this Policy and as necessary to operate, secure, support, and improve the Services or comply with law.

  • AI and model-routing providers. OpenRouter, OpenAI, Google/Gemini, xAI/Grok, fal.ai, and any other model provider disclosed to you before covered AI data is shared.
  • Authentication providers. Google and Apple when you choose their sign-in services.
  • Payments. Cashfree Payments India Private Limited for wallet top-ups and payment processing; Apple App Store or Google Play where applicable for platform purchases or subscriptions.
  • Analytics and diagnostics. PostHog and Google Firebase, depending on enabled features and configuration.
  • Infrastructure and security. Hosting, cloud, storage, communications, security, anti-abuse, and support providers that process information as needed to perform services for Gullivr.
  • Legal and safety. Courts, regulators, law enforcement, or other parties when disclosure is required by law or reasonably necessary to protect rights, security, users, or the public.
  • Business transfers. A buyer, investor, successor, or professional adviser in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to appropriate safeguards.

4.1 Third-Party Privacy Policies

  • OpenRouter Privacy Policy
  • OpenAI Privacy Policy
  • Google Privacy Policy
  • xAI Privacy Policy
  • fal.ai Privacy Policy
  • PostHog Privacy Policy
  • Google Firebase / Google Privacy
  • Cashfree Payments Privacy Policy
  • Apple Privacy Policy

5.Third-Party Authentication

5.1 Google Sign-In

When you choose Google Sign-In, authentication is performed by Google. Gullivr may receive the account information you authorize, such as name, email address, profile image, and an account identifier. We do not receive your Google password. Google processes information according to its own privacy terms and your Google account settings.

5.2 Sign in with Apple

When you choose Sign in with Apple, authentication is performed by Apple. Gullivr may receive your name, email address or Apple private relay address, and a unique Apple account identifier, subject to your choices and Apple's sign-in flow. We do not receive your Apple ID password.

5.3 Account Linking and Security

We use authentication information to create or link your Gullivr account, maintain login sessions, prevent unauthorized access, and support account security and recovery.

6.Analytics, Session Replay, Diagnostics, and Notifications

6.1 PostHog Analytics and Session Replay

Gullivr uses PostHog for product analytics and session replay. Depending on the current app configuration, PostHog may process product usage events, session and device metadata, feature interaction information, and screen-session recordings used for debugging and product improvement.

Where session replay is enabled without text or image masking, recordings may capture screen content visible during a session, including text entered or displayed and images shown in the app. Gullivr uses these recordings for product improvement, quality analysis, and debugging, not for cross-context behavioral advertising.

Gullivr may associate PostHog analytics with account-related identifiers and contact information, including user ID, name, email address, and phone number, where configured for support, diagnostics, or product analysis. Analytics events may also include seller contact identifiers such as seller WhatsApp number or seller email address when those values are included in a business-enquiry event.

We recommend minimizing capture of sensitive information in analytics and session replay. Gullivr may change its masking and sampling configuration over time to reduce data collection while preserving debugging and product-quality needs.

6.2 Google Firebase

Gullivr may use Google Firebase services such as Cloud Messaging, Crashlytics, Analytics, Remote Config, or related infrastructure. Depending on which Firebase products are enabled, Firebase may process device identifiers, app-instance identifiers, push tokens, crash data, diagnostics, usage information, IP addresses, and similar technical information.

6.3 Cookies, SDKs, and Similar Technologies

Our website and mobile app may use cookies, SDKs, local storage, and similar technologies for authentication, security, preferences, analytics, diagnostics, notifications, and performance. Where applicable law requires consent for non-essential tracking technologies, we request that consent before using them.

7.Payments, Wallet Top-Ups, and Subscriptions

Wallet top-ups in Gullivr are processed by Cashfree Payments India Private Limited ("Cashfree"). When you initiate a top-up, Cashfree may display its payment interface or webview and process the payment method you choose. Cashfree may collect and process payment information, billing or transaction details, device or fraud-prevention information, and other information necessary to complete the payment under its own privacy policy and applicable law.

Gullivr may receive limited information from Cashfree, such as order ID, transaction ID, payment status, amount, timestamp, failure reason, or related metadata required to credit your wallet, reconcile payments, handle refunds or support, prevent fraud, and comply with financial recordkeeping. Gullivr does not store your full payment card number or card security code.

If Gullivr offers subscriptions or purchases through Apple App Store or Google Play, the applicable platform may process the payment and provide Gullivr with limited transaction, receipt, subscription, renewal, and product metadata. Platform cancellation and refund rules may apply to those purchases.

8.Face ID, Touch ID, and Device Authentication

Where your device supports biometric authentication and you choose to use it, Gullivr may request Face ID, Touch ID, or another operating-system authentication method to help confirm sensitive actions such as payment authentication. Biometric templates and biometric matching are handled by the operating system and device security hardware. Gullivr does not receive, store, or transmit your Face ID or Touch ID biometric template to Gullivr servers or to third-party service providers.

Your device may display a system permission or authentication prompt. You can manage biometric authentication through your device settings. If you do not use biometric authentication, an alternative device-supported authentication method may be available depending on the feature.

9.Information Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, authentication, encryption in transit, logging, monitoring, secure development practices, vendor review, and payment-security controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10.Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain account functionality, process transactions, comply with legal and financial requirements, resolve disputes, prevent fraud or abuse, enforce agreements, and protect security. Retention periods vary depending on the type of data, feature used, legal obligations, and whether you maintain an active account.

AI providers, analytics providers, payment providers, and other service providers may apply their own retention periods to information they process. Those periods may depend on the product, contract, provider configuration, abuse-monitoring requirements, and applicable law. See Section 4.1 for provider-specific privacy notices.

When you request account deletion, we will delete or de-identify personal information that we are not required or permitted to retain, subject to reasonable technical limitations, backup cycles, transaction recordkeeping, fraud prevention, dispute resolution, and applicable law.

11.International Data Transfers

Gullivr and its service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers, such as contractual protections or other lawful transfer mechanisms.

12.Your Privacy Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or obtain a portable copy of personal information; object to or restrict certain processing; withdraw consent where processing is based on consent; and exercise other rights provided by applicable law.

12.1 AI Data-Sharing Consent

You may decline permission when Gullivr asks to share covered personal data with a third-party AI provider. To withdraw consent for future AI sharing, contact us at legal@gullivr.ai. If an in-app privacy control for AI consent is available, you may also use that control. Declining or withdrawing consent may make features that require third-party AI processing unavailable.

12.2 Authentication and Device Permissions

You can manage Google account permissions, Sign in with Apple permissions, notifications, Face ID / Touch ID, and other device permissions through the applicable provider or device settings.

12.3 Account Deletion

You may request deletion of your Gullivr account from the in-app account or privacy settings, if available (Settings > Account > Delete Account), or by contacting us at legal@gullivr.ai or team@gullivr.ai.

13.Additional U.S. Privacy Disclosures

Depending on how you use Gullivr, we may process categories of personal information that include identifiers and contact information; internet or electronic network activity; device and technical information; commercial and transaction information; approximate geolocation derived from IP address; customer or user content; communications; and inferences or analytics derived from use of the Services.

We disclose these categories to the provider and recipient categories described in this Policy for the business purposes described here. We do not sell personal information for money. We do not use personal information for cross-context behavioral advertising unless separately disclosed and an applicable opt-out mechanism is provided where required by law.

Residents of certain U.S. states may have rights to know, access, correct, delete, or obtain a portable copy of personal information and may have additional opt-out or appeal rights. Submit requests using the contact methods in Section 17.

14.EEA, United Kingdom, Switzerland, India, and Other Jurisdictions

Where data-protection law requires a legal basis for processing, our legal bases may include performance of a contract, legitimate interests in operating and securing the Services, consent where requested, and compliance with legal obligations. Depending on your jurisdiction, you may have rights of access, correction, erasure, restriction, portability, objection, withdrawal of consent, grievance redressal, nomination, or complaint to a competent authority, subject to applicable law.

In India, you may contact our Grievance Officer, Amitesh Kumar Maurya, at legal@gullivr.ai, under the Digital Personal Data Protection Act, 2023. If your concern is not resolved, you may approach the Data Protection Board of India.

15.Children's Privacy

The Services are not directed to children under 13, or to children below the minimum age required to consent to the processing of personal information in their jurisdiction without parental authorization. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information to Gullivr in violation of law, please contact us so we can investigate and take appropriate action.

16.Third-Party Websites and Services

The Services may contain links to, integrations with, or sharing options for third-party websites, apps, payment interfaces, authentication services, or AI providers. When you interact directly with a third party, that third party may process information under its own privacy policy and terms. This Privacy Policy does not control independent third-party processing outside Gullivr's role or instructions.

17.Contact Us

We may need to verify your identity before completing certain privacy requests. We will respond within the period required by applicable law.

18.Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our Services, providers, technology, legal requirements, or business practices. We will update the "Last Updated" date when we make changes. If a change materially affects how we collect, use, or share personal information, we will provide additional notice or request consent where required by law.

20.Privacy Transparency Summary

CategoryExamplesLinked to account?Primary recipients / use
Contact InformationName, email, phoneYesGullivr; Google/Apple auth; PostHog where configured
IdentifiersUser ID, device/app identifiersYesAuthentication, analytics, diagnostics
Usage DataFeature interactions, session dataYesGullivr; PostHog; Firebase
DiagnosticsCrash and error logsUsually not necessarilyGullivr; Firebase; support providers
User ContentMessages, images, files, videosYes / may contain personal dataAI providers and Gullivr as described in Section 2
Financial / Transaction DataPayment status, order IDs, wallet creditsYesCashfree Payments; Gullivr; app stores where applicable
Seller Enquiry DataSeller WhatsApp/email in enquiry eventsMay relate to seller/accountGullivr analytics; PostHog where configured
Approximate LocationCountry/region derived from IPMay be associatedSecurity, localization, analytics

21.App Store Privacy Disclosure Alignment

For App Store Connect privacy disclosures, Gullivr reviews its current code and service configuration before each release. Based on the practices described in this Policy, the following categories are expected to be relevant. The final App Store Connect answers must match the exact production build and Apple's current definitions.

CategoryDataLinked to Identity?Used for Tracking?
Contact InfoName, email, phoneYesNo
IdentifiersUser ID, device/app identifiersYesNo
Usage DataFeature interactions, session and replay dataYesNo
DiagnosticsCrash logs, error logsNo / depends on configurationNo
User ContentMessages, images, files, videosYesNo
Financial InfoPurchase history, wallet credits, transaction metadataYesNo

Gullivr does not currently describe collection of precise location, device contacts, health/fitness data, or browsing history in this Policy. If the production app begins collecting any of those categories, both this Policy and the App Store privacy disclosures will be updated before release.