Guidra Privacy Policy
Last updated: July 31, 2026
Our approach to privacy
We are leaders too. We have hopes, fears, ambitions, doubts, dreams, and challenges that we may not be ready to share publicly.
We believe every leader has a right to privacy, especially when reflecting on deeply personal things such as their Journal, goals, relationships, challenges, and sense of direction. Guidra is designed around that belief.
Content you would reasonably expect to remain private in Guidra, including your Journal, goals, reflections, private messages, and support messages, is encrypted on your device before it is stored with us.
Because this content is encrypted on your device, Guidra cannot decrypt, search, or read the plaintext from our backend systems. We do not have a general internal tool, administrator feature, or hidden “snooping button” that lets our team view it. If you lose your Privacy Key permanently, we cannot recover that encrypted content because we do not have the ability to decrypt it.
Private by design. Yours by default. Shared only when you choose, or where this policy explains a narrow safety or legal exception.
We do not, and will not, sell your personal information, your private content, or access to your identity.
Guidra is building a valuable business by creating an experience useful enough that people choose to pay for premium features, and by introducing members to transformational programs, coaching, communities, or services that may genuinely support their growth. Where we receive compensation for a recommendation, partnership, or program introduction, we will make that clear. We will not share your private Guidra content with those partners unless you choose to share it or ask us to do so.
Guidra does not use advertising SDKs, cross-app tracking, or data brokers.
The rest of this policy explains what information Guidra collects, what content is encrypted, when information may be shared with service providers, and how you can delete your account.
1. Who we are
Guidra is owned and operated by The Andrew Bull Companies Ltd, a company incorporated and registered in England and Wales with company number 09455235 (“Guidra”, “we”, “us”, or “our”).
The Andrew Bull Companies Ltd is registered with the UK Information Commissioner’s Office (ICO) as a data controller.
Contact:
- Email: hello@bullcompanies.com
- Registered office: The Andrew Bull Companies Ltd, 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, W1T 6EB, GB
- Account deletion request page: https://guidra.one/data-deletion/
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use the Guidra mobile app and related services.
2. Summary
Guidra is designed as a private reflection, planning, growth, community, and coaching app.
- We do not and will not sell personal information, private content, or access to your identity.
- We do not use advertising SDKs, cross-app tracking, or data brokers.
- Guidra’s business model is paid product value and clearly disclosed transformational programs, not selling user data.
- User-generated free text is encrypted on your device before it is stored on our backend, except for fields you intentionally publish, such as your Community Profile.
- We collect account, device, activity, notification, profile, support, safety, and app-functionality data needed to operate Guidra.
- If you choose Apple or Google sign-in, we receive authentication information from that provider to create or access your Guidra account.
- You can delete your account in the app under Account -> Delete Account. You can also request deletion at https://guidra.one/data-deletion/.
3. Information we collect
Account and authentication information
We collect information needed to create, authenticate, secure, and manage your account, including:
- your email address
- your Guidra user ID
- your display name, if you add one
- session and authentication tokens
- account creation and update timestamps
- sign-in provider information
If you sign in by email, we use your email address to send passwordless magic links and manage your session.
If you sign in with Google, Google provides us with an identity token and may provide your email address, name, and profile photo. We use this to sign you in through Supabase Auth and may use the name and photo to seed your Guidra profile.
If you sign in with Apple, Apple provides us with an identity token and, depending on your Apple choices and whether it is your first sign-in, may provide your name and email address. If you choose Hide My Email, we receive Apple’s private relay email address rather than your personal email address.
We do not receive your Apple or Google account password.
Profile and public community information
You may add profile information such as:
- display name
- Community Profile full name
- role or title
- organisation
- city
- positioning statement
- profile image
- selected public Bridge titles
Your Community Profile is user-controlled. Some fields, such as organisation and city, include visibility controls. If you publish a Community Profile, the fields you choose to show may be visible to other Guidra members according to the community feature design.
Guidra does not request device location permission. If you add a city to your profile, it is information you type manually.
Private planning, reflection, and growth content
Guidra lets you create personal and shared content, including:
- Values
- Bridges, challenges, strategies, and actions
- Horizons and intentions
- Rituals, habits, and completion records
- journal entries
- daily and period reviews
- growth assignments and progress
- community applications, messages, comments, and responses
- coaching workspace messages and shared context
- support tickets, support replies, and bug reports
User-generated free text in these areas is encrypted client-side before it is stored on our backend unless this policy says otherwise. Examples include journal titles and bodies, Bridge titles and descriptions, action titles, Horizon meaning and intention text, review reflections, community messages, application answers, support ticket message content, and report evidence.
We still store structured metadata needed to operate the app, such as user IDs, object IDs, dates, timestamps, statuses, membership records, sort order, completion state, due dates, counts, schedule settings, notification settings, and encryption key IDs.
Wellbeing and activity metrics
Guidra includes optional structured wellbeing and activity metrics that support reflection and insights. These may include:
- sleep duration
- hydration logs
- distance or movement quantity logs
- repetitions
- focus time
- nutrition or meal counts if used
- daily metric targets
- completion counts, streaks, and progress percentages
- daily or period review alignment and emotional tone selections
These metrics are for personal reflection and app insights. Guidra is not a medical, diagnostic, fitness, or emergency service.
Programmes, coaching, events, and retreats
If you register for, apply to, purchase, or attend a Guidra programme, coaching offer, challenge, cohort, workshop, live event, retreat, or paid community, we may collect information needed to deliver and manage that experience, such as:
- registration, application, attendance, and access status
- programme, coaching, Circle, event, retreat, or cohort selections
- payment status, invoice, receipt, refund, and entitlement metadata
- intake answers, preferences, goals, and operational notes
- dietary, accessibility, travel, emergency-contact, or accommodation details where relevant to an in-person experience
- attendance records, participation notes, and support or safeguarding records where needed to operate the experience safely
Where these experiences involve private free text inside Guidra, that content follows the encryption rules described in this policy. Some operational details, such as attendance, access status, payment status, and logistics preferences, may be stored as structured metadata so we can deliver the experience.
Event photography, video, podcasts, and media appearances
Guidra events, retreats, workshops, and community experiences may include photography, video, audio, testimonials, interviews, podcasts, or other media capture for publicity, marketing, editorial, training, or community materials.
We will not deliberately feature you as a named speaker, guest, testimonial, or primary subject in published media without actively seeking your permission. Where general event photography or filming is taking place, we will aim to make this clear through event information, signage, or verbal notices. You have the right to tell us that you do not want to be featured, and we will take reasonable steps to respect that choice.
If you agree to appear in a podcast, interview, case study, testimonial, photograph, video, or other media piece, we may process your name, voice, image, likeness, biography, role, organisation, story, and the content of that appearance for the agreed purpose.
Device, security, and notification information
We collect and store information needed to keep your account secure and operate notifications, including:
- a Guidra-generated device identifier for each app install
- device registration status, first seen and last seen timestamps, and revocation status
- push notification tokens
- notification delivery status and scheduling metadata
- device audit events
- local session and query state
- security and encryption setup status
The app may store certain data locally on your device, including Supabase session data, theme preference, notification token cache, local notification scheduling references, selected chat/community context, and encrypted-data access material.
Your User Master Key is generated on your device and stored in the device Keychain or Keystore. It is not sent to Guidra in plaintext. Your Privacy Key is user-held recovery material. Guidra stores wrapped recovery and data-encryption-key material so you can restore encrypted access, but we do not store the plaintext Privacy Key.
If you use Face ID, Touch ID, or another device unlock method to protect local access, biometric checks are handled by your device operating system. Guidra does not receive or store your biometric template.
If you enable push notifications, Guidra registers a push token with our backend and uses Apple Push Notification service, Google/Firebase Cloud Messaging, and Expo notification services as applicable. Notification payloads should use safe operational copy and must not include decrypted private free text.
Photos, camera, and files
Guidra asks for camera or photo library permission only when you choose to take or upload an image, such as:
- a Community Profile image
- an editorial image, if you have editorial/admin access
- a support screenshot attachment
Images you select or take may be uploaded and stored through our image service provider. We do not access your full photo library for unrelated purposes.
Before support screenshot upload, the app warns you not to include journal text, messages, payment details, security codes, personal data, or other sensitive material.
Payment and billing information
If you buy a subscription, programme, coaching offer, event, retreat, paid community, or other paid Guidra experience, payment processing may be handled by app store payment platforms or payment processors such as RevenueCat, Apple, Google, Stripe, PayPal, or Wise.
Guidra does not directly store full payment card numbers. Payment processors and app store platforms handle payment method details. We may store or receive payment status, product, subscription, invoice, receipt, refund, entitlement, tax, fraud-prevention, and transaction metadata needed to provide paid features, support billing questions, keep accounts accurate, prevent abuse, and meet legal, tax, accounting, and platform obligations.
Support, reports, and trust and safety
If you contact support or submit a report, we collect the information needed to respond, investigate, and maintain platform integrity, including:
- support ticket category, severity, status, assigned support user, and routing metadata
- app version, build number, platform, operating system version, device model, source route, and stable internal identifiers
- encrypted support messages, bug details, screenshots, and support replies
- trust and safety report metadata
- encrypted evidence bundles
- moderation case records, actions, appeals, reviewer assignments, audit logs, and access logs
Report evidence and reviewer notes that contain user-generated or sensitive free text are encrypted for scoped review. Reviewer access is intended to be role-based, limited, and auditable.
Technical and usage information
When you use Guidra, our app, backend, and service providers may process technical information such as:
- IP address and request metadata
- device type, operating system, and app version
- network and error information
- diagnostics needed to debug support requests or app issues
- app activity events such as inbox state, acknowledgement state, delivery state, and feature usage needed to operate the service
Guidra does not include third-party advertising SDKs or behavioral advertising tracking.
Guidra does not request contacts, microphone, calendar, or precise device location permission.
Website forms, cookies, and similar technologies
When you use the Guidra website, submit a website form, join a waitlist, request support, or request data deletion, we may collect the information you provide and technical information needed to receive, route, secure, and respond to that request.
The Guidra website and our service providers may use cookies, local storage, server logs, form security tools, spam-prevention signals, or similar technologies for essential site operation, security, form submission, preference storage, performance, and diagnostics. We do not use these technologies for cross-app tracking or behavioral advertising.
If we later introduce optional analytics, marketing cookies, or remarketing technologies, we will update our website notices and consent choices where required.
4. How we use information
We use information to:
- create, authenticate, and manage your account
- provide app features, sync data, and restore access across devices
- encrypt, decrypt, save, and display your content on authorized devices
- personalize app timing, reminders, Today views, and insight surfaces
- operate community, coaching, publishing, support, and trust and safety features
- send magic links, account/security messages, service notifications, and optional push notifications
- respond to support requests and bug reports
- enforce community standards and investigate safety issues
- prevent fraud, abuse, unauthorized access, and security incidents
- maintain, debug, analyze, and improve Guidra
- comply with legal, regulatory, platform, tax, accounting, and safety obligations
We use personal information for the purposes described in this policy and for compatible purposes needed to provide, protect, improve, or comply with obligations relating to Guidra. We will not use information collected for one context, such as support or account deletion, to send marketing unless you have consented or the law allows it.
We do not use your encrypted private content for advertising, and we do not build advertising profiles from your Guidra activity.
Marketing and mailing lists
Guidra may offer optional newsletters, product updates, event invitations, challenge updates, community announcements, programme information, or other marketing communications.
We will not automatically add you to a marketing mailing list just because you create an account, contact support, request data deletion, or make an unrelated purchase. Where marketing consent is required, we will ask for it. You can unsubscribe from marketing emails using the unsubscribe link in the message or by contacting us.
We may still send required service, transactional, account, security, billing, support, safety, or legal messages even if you opt out of marketing.
5. Structured analytics, AI, and insights
Guidra can generate some insights without using AI and without reading private free-text content. We may use structured, non-free-text signals and aggregated metrics to understand app use and behaviour patterns, such as:
- how many days in a row you have used or “shown up” in the app
- action, habit, ritual, ritual-step, review, assignment, or resource completion rates
- whether actions, rituals, or reviews were completed on particular dates
- intention-setting frequency and review alignment scores
- time-of-day, schedule, due-date, reminder, and completion patterns
- sleep, hydration, movement, focus-time, or other structured wellbeing metrics you choose to enter
- counts, percentages, streaks, windows, and trend direction over bounded periods
These structured analytics are used to operate Guidra, show progress, power basic and advanced insights, improve feature quality, and help you notice patterns. They are not the same as AI analysis of your private writing.
Guidra’s structured insights should use facts such as completions, counts, dates, categories, selected options, and scores. They should not require raw journal text, private Bridge text, message bodies, or other decrypted user-generated free text.
Private content AI analysis is allowed only when you explicitly request it. In that case:
- your device decrypts the selected content locally
- the selected content may be sent to an AI service for that request
- plaintext AI request payloads should not be persisted by Guidra
- AI results that are stored in Guidra are treated as sensitive and encrypted
Guidra does not silently scan encrypted journal or message content in the background for AI analysis.
6. How encryption works
Guidra uses client-side encryption for user-generated free text.
In simplified terms:
- your device generates a User Master Key
- your device uses encryption keys to encrypt private content before upload
- the backend stores ciphertext envelopes, key identifiers, and wrapped key material
- plaintext User Master Keys, Data Encryption Keys, and Privacy Keys are not stored in Guidra’s backend
- decryption happens on authorized devices that have the required local key material or a valid recovery flow
Approved plaintext exceptions are limited to:
- public Community Profile fields that you intentionally manage for display
- selected public Bridge title snapshots you choose to show on your Community Profile
- concise conversation title/subtitle metadata used for operations, membership management, moderation routing, and report response
- non-sensitive editorial and publishing metadata such as categories, schedules, placements, and status labels
- structured app metadata needed for functionality, security, and analytics
Encryption protects against many backend, storage, and insider-access risks, but it cannot protect content on a compromised or unlocked device, content you share with another person who saves it, screenshots, or content already decrypted by authorized participants.
If you lose your Privacy Key and no active trusted device can restore or re-wrap your keys, Guidra may not be able to recover older encrypted content for you.
7. When we disclose information
We disclose information only as needed to operate, protect, and provide Guidra:
- Service providers: companies that process data for hosting, authentication, database services, backend services, image hosting, push notifications, email delivery, website forms, spam prevention, payment processing, AI processing when requested, support operations, and security monitoring. These may include Supabase, Cloudinary, Expo, Apple, Google/Firebase, email delivery providers configured by Guidra, website form providers, payment providers, AI gateway providers, and AI model providers used only for explicit AI requests.
- Sign-in providers: Apple and Google process information when you choose their sign-in methods. We send their identity token to our authentication provider to establish your Guidra session.
- Push providers: Apple, Google/Firebase, and Expo process notification tokens and delivery data as needed to deliver notifications.
- Image providers: profile, support, and editorial images may be uploaded to and served through an image hosting provider.
- Community and coaching participants: content you publish or share in community, coaching, or shared workspaces is visible to the people authorized for that space.
- Reviewers and moderators: authorized reviewers may access scoped encrypted evidence or application content when needed for community review, support, reports, enforcement, appeals, safeguarding, or legal/safety obligations.
- Legal and safety: we may disclose information if required by law, legal process, platform rules, or to protect rights, safety, security, and service integrity.
- Business transfers: if Guidra is involved in a merger, acquisition, financing, reorganization, or asset transfer, information may be transferred subject to appropriate protections.
Guidra does not and will not sell your personal information, private content, or access to your identity. We do not share personal information with data brokers or for cross-context behavioral advertising.
Current third-party providers and processors
The main third-party providers we use to operate Guidra are listed below. The exact data processed depends on which features you use.
| Provider | Purpose | Information processed |
|---|---|---|
| Supabase | Authentication, database, backend data storage, session management, and local development email capture | Account identifiers, email address, authentication/session data, structured app records, encrypted private content, device records, access and security metadata |
| Google Cloud Platform, including Cloud Run and Cloud Scheduler | Hosting the Guidra API, scheduled backend jobs, infrastructure logs, and operational runtime services | API requests, IP/request metadata, route and diagnostic logs, scheduled-job metadata, backend operational data |
| Expo and EAS | Mobile build/update infrastructure and Expo push notification delivery | App/project identifiers, device and push tokens, notification delivery data, build/update metadata, crash or diagnostic information generated by the platform services we enable |
| Apple | Sign in with Apple, Apple Push Notification service, iOS app distribution, TestFlight/App Store services, and device platform services | Apple identity tokens when you choose Apple sign-in, Apple private relay email if selected, push notification routing data, app install/distribution metadata |
| Google and Firebase | Google Sign-In, Firebase/Google push notification infrastructure, Android app services, and Google Play services where applicable | Google identity tokens when you choose Google sign-in, email/name/profile photo where provided by Google, Firebase/FCM push routing data, app install/distribution metadata |
| Cloudinary | Image upload, image hosting, image transformation, and media delivery | Images you choose to upload, image metadata, provider public IDs, transformed delivery URLs, and related upload/delivery metadata |
| Loops | Email delivery for hosted authentication email and future Guidra email categories where enabled | Email address, email delivery metadata, template variables needed to send service or product email, and subscription/consent status where applicable |
| Google Workspace / Gmail | Internal business email, inbound contact handling, support routing, and operational communications | Email address, name, message content, request details, attachments you choose to send, and related email metadata |
| Proton | Internal business email, privacy-focused mailbox migration, support routing, and operational communications where enabled | Email address, name, message content, request details, attachments you choose to send, and related email metadata |
| Slack | Internal operational alerts, team notifications, support/contact triage, and incident or workflow coordination where enabled | Alert content, request summaries, names or email addresses if included in the alert, internal team messages, and related notification metadata |
| FormSpark | Website contact, support, waitlist, and data-deletion request forms | Form submissions you choose to send through the Guidra website, such as name, email address, message content, request type, platform, and form metadata |
| Botpoison | Website form spam and abuse prevention | Form submission metadata, technical request data, and spam-prevention signals for forms submitted through the Guidra website |
| RevenueCat | Mobile subscription management, purchase state syncing, entitlement events, and restore-purchase support | Guidra user identifier, app/platform identifiers, subscription status, purchase/renewal/refund/cancellation events, product identifiers, and related billing metadata |
| Apple and Google payment platforms | App Store and Google Play in-app purchase processing, subscription billing, receipts, refunds, and store account management | Store account and payment information handled by Apple or Google, purchase receipts, transaction identifiers, subscription status, refund/cancellation metadata, and store-region/tax information where applicable |
| Stripe | Payment processing for subscriptions, programmes, coaching, events, invoices, refunds, and related commercial transactions where enabled | Contact and billing details, payment method details, transaction records, subscription status, invoice data, tax information, fraud-prevention signals, and related payment metadata |
| PayPal | Payment processing for programmes, coaching, events, invoices, refunds, or other commercial transactions where enabled | PayPal account details, contact and billing details, transaction records, payment status, refund/dispute metadata, and related payment metadata |
| Wise | Bank transfer, international payment, payout, refund, or invoice-payment processing where enabled | Contact and billing details, bank/payment account details, transfer records, payout/refund data, currency and transaction metadata, and compliance information needed to process payments |
| Requesty | EU AI gateway and model routing for Guidra AI features when you explicitly request AI processing | AI request inputs and outputs, routing metadata, usage metrics, technical logs, and provider-routing information, subject to the configured Requesty EU processing path |
| OpenAI and other selected AI model providers | AI model inference for Guidra AI features when routed through Requesty or another approved AI processing path | The content you explicitly submit for AI analysis, model inputs and outputs, technical metadata, and usage data needed to provide and secure the AI service |
We do not currently use third-party advertising SDKs, cross-app tracking providers, data brokers, or behavioral advertising networks.
We intend to use EU-focused AI routing where available. Where an AI gateway routes a request to a selected model provider, that model provider may also process the request for the limited purpose of returning the AI result.
8. Your choices and controls
You can:
- update your display name and Community Profile information
- choose whether to publish your Community Profile
- choose whether organisation and city appear on your Community Profile
- remove your profile image
- choose whether to share selected Bridge titles on your Community Profile
- enable or disable push notifications through your device settings and in-app preferences where available
- delete individual journal entries and other app objects where the app provides deletion controls
- sign out of your account
- remove local encrypted data from a device
- delete your account
- contact us to request access, correction, export, restriction, objection, or deletion, depending on your location and applicable law
Deleting the app from your device does not automatically delete your Guidra account or server-side data.
9. Account deletion and data deletion
You can initiate account deletion in the app:
Account -> Delete Account
You can also request account deletion outside the app at:
https://guidra.one/data-deletion/
When you delete your account, Guidra deletes or anonymizes account data and associated app data that we are not required or permitted to retain. Account deletion also clears local encrypted data and local notification schedules for that account on the device where you initiated deletion.
Some information may be retained where necessary or permitted for:
- legal obligations
- tax, accounting, billing, or transaction records
- security and fraud prevention
- trust and safety investigations
- safeguarding concerns
- moderation appeals
- audit logs
- dispute resolution
- enforcing our terms and community standards
User-facing deletion from a community or shared surface may not remove bounded evidence bundles, audit records, legal/safeguarding holds, or moderation records. Shared content already decrypted by authorized participants cannot be cryptographically erased from their devices.
If you used Sign in with Apple, account deletion includes revoking associated Sign in with Apple tokens where required and technically available.
10. Retention
We keep personal information for as long as needed to provide Guidra, maintain your account, meet legal obligations, resolve disputes, enforce agreements, protect safety, and maintain security.
Examples:
- account and profile records are generally kept while your account exists
- encrypted private content is generally kept while your account exists or until you delete it, subject to shared-space and safety retention rules
- notification tokens are kept while needed to send notifications and are removed or cleared when you sign out or revoke device access where possible
- support, trust and safety, moderation, appeal, audit, legal, and safeguarding records may be retained after content is edited, deleted, hidden, or removed from ordinary view
- local data remains on your device until you sign out, remove device data, delete the account, uninstall the app, or clear device storage, depending on the data type
11. Security
We use technical and organizational safeguards designed to protect information, including:
- encryption in transit
- client-side encryption for private free text
- OS secure storage for local encryption keys
- role-based access controls
- scoped reviewer and support keys for sensitive review workflows
- audit logs for sensitive access paths
- session locking and local device trust controls
- limits on plaintext in logs, analytics, push notifications, and inbox payloads
No system is perfectly secure. You are responsible for keeping your device, account, and Privacy Key safe.
12. International transfers
Guidra and our service providers may process information in countries other than where you live. Where required, we use appropriate safeguards for international transfers.
13. Legal bases for UK and EEA users
Where UK or EEA data protection law applies, we rely on the following legal bases:
- Contract: to provide Guidra, authenticate you, sync content, manage your account, and deliver requested features.
- Consent: for optional permissions such as push notifications, camera/photo access, and user-triggered AI analysis where consent is required.
- Legitimate interests: to secure, maintain, debug, improve, and protect Guidra, prevent abuse, and operate support and trust and safety workflows.
- Legal obligation: to comply with applicable laws, valid legal requests, tax/accounting obligations, platform obligations, and safety obligations.
You may have rights to access, correct, delete, restrict, transfer, or object to processing of your personal information. You may also have the right to withdraw consent where processing is based on consent. To exercise these rights, contact hello@bullcompanies.com.
If you are in the UK, you also have the right to complain to the Information Commissioner’s Office. We would appreciate the chance to respond to your concern first, but you are not required to contact us before contacting the ICO.
14. California and other US privacy rights
Depending on where you live, you may have rights to know, access, correct, delete, or obtain a copy of personal information, and to opt out of certain sales, sharing, or targeted advertising.
Guidra does not and will not sell personal information, and we do not share personal information for cross-context behavioral advertising.
To exercise rights available to you, contact hello@bullcompanies.com or use https://guidra.one/data-deletion/ for account deletion.
15. Children
Guidra is intended only for users aged 18 or over. We do not knowingly collect personal information from anyone under 18. If you believe that a person under 18 has provided personal information to Guidra, please contact hello@bullcompanies.com.
16. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice in the app or by another appropriate method. The “Last updated” date shows when this policy was most recently changed.