Privacy Policy

Effective date: 21 July 2026  ·  Last updated: 21 July 2026

This Privacy Policy is published in accordance with Rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and describes how Gonu AI handles personal data under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.

Gonu AI ("Gonu AI", "we", "us" or "our") is a sole proprietorship established under the laws of India, operating the Gonu AI platform — the Gonu Worker desktop AI agent, Gonu Video, Gonu Music, and the associated web application and APIs (together, the "Services"). This document is an electronic record generated by a computer system under the Information Technology Act, 2000 and does not require any physical or digital signature.

For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") we act as a Data Fiduciary in respect of the personal data you provide, and you are a Data Principal. By using the Services you confirm that you have read and understood this Policy.

1. The laws this Policy is built on

We process personal data in accordance with the following Indian laws, as amended from time to time:

  • Constitution of India, Article 21 — the right to privacy as a fundamental right, recognised by the Supreme Court in K. S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
  • Digital Personal Data Protection Act, 2023 — in particular Sections 4 to 10 (grounds for processing, notice, consent and the duties of a Data Fiduciary), Sections 11 to 15 (rights and duties of a Data Principal), Section 16 (transfer of personal data outside India) and Section 33 read with the Schedule (penalties of up to ₹250 crore).
  • Digital Personal Data Protection Rules, 2025 — notified on 14 November 2025, including Rule 6 (reasonable security safeguards), Rule 7 (intimation of a personal data breach), Rule 8 (retention and erasure) and Rule 10 (verifiable consent for children). Substantive obligations are being phased in and become fully enforceable on 13 May 2027; we have chosen to align with them from today.
  • Information Technology Act, 2000 — Section 43A (compensation for failure to protect data), Section 72A (punishment for disclosure of information in breach of a lawful contract), Section 79 (intermediary liability) and Section 10A (validity of electronic contracts).
  • SPDI Rules, 2011 — the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including Rule 4 (publication of this Policy), Rule 5 (collection and consent), Rule 6 (disclosure), Rule 7 (transfer) and Rule 8 (reasonable security practices).
  • IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — Rule 3(1) (publication of policies and prohibited content) and Rule 3(2) (Grievance Officer and redressal timelines).

2. Personal data we collect

2.1 Account data

Your name, email address, password hash, profile photo (if provided), organisation name and role. Collected under Section 6 of the DPDP Act on the basis of your consent, to create and operate your account.

2.2 Workspace and agent data

When you use Gonu Worker, the prompts you write, the tasks you run, file paths and file contents you explicitly grant the agent access to, terminal output, and the resulting agent transcripts. Gonu Worker only reads the folder you select. It does not scan your disk.

2.3 Audio and transcription data

Where you use voice or meeting features, audio is processed to produce a transcript. Audio is processed in real time and is not retained after transcription unless you explicitly save the session. You are solely responsible for obtaining the consent of every other participant before recording or transcribing any conversation.

2.4 Generated content

Media you create through Gonu Video and Gonu Music, along with the prompts and parameters used to generate it, so that it can be delivered to and stored in your library.

2.5 Payment data

Subscription payments are processed by our payment gateway partner (Razorpay Software Private Limited), which is regulated by the Reserve Bank of India under the Payment and Settlement Systems Act, 2007. We receive only the transaction identifier, amount, status, and the last four digits and network of the instrument. We never receive or store your full card number, CVV, UPI PIN or net-banking credentials.

2.6 Device and usage information

IP address, device and operating-system identifiers, browser type, application version, referring URLs, pages and features used, crash reports and diagnostic logs — used to keep the Services secure, reliable and performant.

2.7 Sensitive personal data or information (SPDI)

We do not deliberately collect passwords in plain text, financial instrument details, physical or mental health records, sexual orientation, medical records or biometric information as defined in Rule 3 of the SPDI Rules, 2011. Please do not submit such information to the Services. If you do so voluntarily, it will be handled under this Policy and you may ask us to erase it at any time.

2.8 Google account data (optional)

If you sign in with Google or connect a Google account, we access only what you approve in the OAuth consent screen:

  • Profile: name, email address and profile picture — for account creation and display.
  • Calendar (read-only): upcoming events — shown on your dashboard only. We never create, modify or delete events.
  • Gmail (read-only): subject lines and sender names of relevant emails — to surface them on your dashboard. We do not read message bodies, send mail or modify anything.

You can disconnect Google access at any time from your account settings, which immediately revokes our token.

3. Google API Services User Data Policy

Gonu AI's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request only the Google data needed for the features described above.
  • We do not use Google user data for advertising.
  • We do not sell Google user data to any third party.
  • We do not use Google user data for any unrelated purpose.
  • No human reads your Google user data unless (a) you give explicit consent, (b) it is necessary for security, (c) it is required by law, or (d) the data has been aggregated and anonymised for internal operations.
  • Google user data is never used to train any AI or machine-learning model.

4. Why we process your data — lawful grounds

Section 4 of the DPDP Act permits processing only for a lawful purpose, either with your consent or for a "certain legitimate use". Our grounds are:

  • Your consent (Section 6): to create your account, run agent tasks, generate media, transcribe audio, connect Google services, and send product communications.
  • Voluntarily provided data for a specified purpose (Section 7(a)): data you hand us for support, feedback or a specific request.
  • Compliance with law (Section 7(b) and 7(g)): tax records under the Income Tax Act, 1961 and the CGST Act, 2017; and responses to lawful orders from a court or authority.

We do not sell your personal data. We do not use your workspace content, prompts, code or generated media to train foundation models, and we do not share it with model providers for training.

5. Notice, consent and withdrawal

In line with Section 5 of the DPDP Act, every request for consent is presented in clear and plain language, itemises the personal data sought and the purpose, and tells you how to withdraw consent and how to complain to the Data Protection Board of India. On request, the notice will be made available in English or any language listed in the Eighth Schedule to the Constitution of India.

Under Section 6(4) to 6(6), you may withdraw consent at any time, with the same ease with which it was given — from Settings → Privacy or by writing to our Grievance Officer. Withdrawal does not affect the lawfulness of processing done before it, and once you withdraw we will cease processing and erase the relevant data within a reasonable period unless a law requires us to retain it.

6. Who we share data with

We do not sell personal data and do not share it with advertisers or data brokers. We disclose data only in these circumstances:

  • Data Processors: cloud hosting, database, email delivery, error monitoring, payment processing and AI model providers engaged under a written contract as required by Section 8(2) of the DPDP Act. They may process personal data only on our documented instructions.
  • AI model providers: your prompts and the context you supply are sent to the model you select in order to generate a response. These providers act on our instructions and are contractually barred from using your content for training.
  • Legal compliance: where disclosure is required under Section 7(g) or Section 17(1)(c) of the DPDP Act, Section 91 of the Bharatiya Nagarik Suraksha Sanhita, 2023, or any order of a court or a competent authority.
  • Business transfer: in a merger, acquisition or sale of assets, subject to the transferee being bound by obligations no less protective than this Policy. You will be notified before your data is transferred.
  • With your consent: any other disclosure you specifically authorise.

7. Transfer of personal data outside India

Some of our infrastructure and AI model providers operate outside India. Such transfers are made under Section 16 of the DPDP Act read with Rule 15 of the DPDP Rules, 2025, which permit transfer to any country other than one restricted by the Central Government by notification, and subject to any conditions the Government may specify. Transfers are protected by contractual safeguards and encryption in transit, and we will stop transferring to any territory that the Central Government subsequently restricts.

8. Security safeguards

As required by Section 8(5) of the DPDP Act, Rule 6 of the DPDP Rules, 2025, Section 43A of the IT Act, 2000 and Rule 8 of the SPDI Rules, 2011, we maintain reasonable security practices, including:

  • Encryption: AES-256 at rest and TLS 1.2 or higher in transit; secrets and third-party tokens are additionally encrypted at the application layer.
  • Access control: role-based access on a need-to-know basis, with multi-factor authentication for administrative accounts.
  • Logging and monitoring: access logs are retained to detect and investigate unauthorised access, as contemplated by Rule 6 of the DPDP Rules, 2025.
  • Resilience: encrypted backups and documented restoration procedures.
  • Contractual controls: every processor is bound by confidentiality and security obligations.

No system is perfectly secure. You are responsible for keeping your credentials confidential and for the security of the device on which Gonu Worker runs.

9. Personal data breach — what we will do

If a personal data breach occurs, then in accordance with Section 8(6) of the DPDP Act read with Rule 7 of the DPDP Rules, 2025 we will:

  • inform every affected Data Principal without delay, describing the nature, extent and timing of the breach, its likely consequences, the steps we have taken to mitigate it, and the safety measures you should take; and
  • notify the Data Protection Board of India without delay, and furnish detailed particulars within 72 hours of becoming aware of the breach (or such longer period as the Board allows).

10. How long we keep your data

Under Section 8(7) of the DPDP Act read with Rule 8 of the DPDP Rules, 2025, we erase personal data once the purpose for which it was collected is no longer being served, unless retention is required by law. In practice:

  • Account data: kept while your account is active, and erased within 90 days of account deletion.
  • Agent transcripts and generated media: kept until you delete them, or until account deletion.
  • Audio: not retained after transcription unless you save the session.
  • Logs and traffic data: retained for at least one year as contemplated by Rule 8 of the DPDP Rules, 2025, then erased.
  • Invoices and tax records: retained for eight years as required by the Income Tax Act, 1961 and the CGST Act, 2017. These survive account deletion because the law requires it.

11. Your rights as a Data Principal

Chapter III of the DPDP Act gives you the following rights, exercisable free of charge from your account settings or by writing to our Grievance Officer:

  • Right to access information (Section 11): a summary of the personal data we process, the processing activities undertaken, and the identities of every Data Fiduciary and Data Processor with whom it has been shared.
  • Right to correction, completion, updating and erasure (Section 12): have inaccurate data corrected, incomplete data completed, and your data erased where consent is withdrawn or the purpose is exhausted.
  • Right of grievance redressal (Section 13): a readily available means of complaint, which we must answer before you approach the Data Protection Board.
  • Right to nominate (Section 14): nominate another individual to exercise your rights in the event of your death or incapacity. Write to the Grievance Officer to record a nomination.
  • Right to data portability: export your data in a machine-readable format from Settings → Data Export.
  • Right to withdraw consent (Section 6(4)): as described in clause 5 above.

We respond to rights requests within 30 days. We may ask you to verify your identity before acting, to make sure we do not disclose your data to someone else.

12. Your duties as a Data Principal

Section 15 of the DPDP Act places duties on you as well. You must comply with applicable law when exercising your rights, must not impersonate another person while providing personal data, must not suppress material information, must not register a false or frivolous grievance, and must furnish only verifiably authentic information when seeking correction or erasure. Breach of these duties can attract a penalty of up to ₹10,000 under the Schedule to the DPDP Act.

13. Children and persons with a guardian

Under Section 2(f) of the DPDP Act a "child" is any individual below eighteen years of age. The Services are not directed at children. We do not knowingly process the personal data of a child, or of a person with a disability who has a lawful guardian, without verifiable consent from the parent or guardian as required by Section 9 read with Rule 10 of the DPDP Rules, 2025.

We do not undertake tracking, behavioural monitoring or targeted advertising directed at children — this is prohibited by Section 9(3). If we learn that a child has created an account without verifiable parental consent, we will suspend it and erase the associated data promptly. Parents and guardians may write to our Grievance Officer at any time.

14. Grievance Officer

In compliance with Section 13 of the DPDP Act, Rule 5(9) of the SPDI Rules, 2011 and Rule 3(2) of the IT Rules, 2021, the following officer has been designated to address your grievances regarding this Policy or the processing of your personal data:

Grievance Officer & Data Protection Contact
Gonu AI (Sole Proprietorship)
Email: support@gonu-ai.com
Subject line: Grievance — Privacy
Jurisdiction of operation: New Delhi, India

Our timelines: we acknowledge every complaint within 24 hours and dispose of it within 15 days as required by Rule 3(2)(a) of the IT Rules, 2021 — and in any event within one month as required by Rule 5(9) of the SPDI Rules, 2011. Requests to remove content in the nature of impersonation or non-consensual imagery are actioned within 24 hours under Rule 3(2)(b).

15. Escalation to the Data Protection Board of India

If you are not satisfied with our response, you may complain to the Data Protection Board of India constituted under Chapter V of the DPDP Act. Section 13(3) requires you to exhaust the grievance route above before approaching the Board. The Board may inquire into a breach and impose monetary penalties of up to ₹250 crore under Section 33 read with the Schedule. You may also pursue remedies under Section 43A or Section 72A of the IT Act, 2000.

16. Cookies and similar technologies

The website uses strictly necessary cookies for authentication and security, and optional analytics cookies that are set only with your consent. You can change your choice at any time. Full details are in our Cookie Policy.

17. Changes to this Policy

We may amend this Policy to reflect changes in law or in our Services. Material changes will be posted on this page with a revised effective date and, where they affect the basis on which we process your data, communicated to you by email at least 7 days in advance. Where a change requires fresh consent under the DPDP Act, we will ask for it rather than assume it.

18. Contact us

For any question about this Policy, your personal data, or to exercise any right described above:

Gonu AI
support@gonu-ai.com
See also our Terms of Service.

This Policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts at New Delhi, without prejudice to your right as a consumer to approach the appropriate District, State or National Consumer Disputes Redressal Commission under the Consumer Protection Act, 2019, or to complain to the Data Protection Board of India.