Privacy Policy
Effective August 18, 2026
Gus is an AI-powered college companion that helps students record lectures, organize notes, manage schedules, and study more effectively. Gus is operated by TenBid Ventures LLC ("TenBid", "we", "us", or "our"). This Privacy Policy explains how we collect, use, and protect your personal information when you use our service at meetgus.app.
By using Gus, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use our service.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and school affiliation. If you sign up using Google or Facebook, we receive your name and email from that provider.
Content You Provide
This includes lecture recordings and transcriptions, notes, course information, schedule data, flashcards, study group messages, shared files, and task lists. You control what content you upload and share.
AI Interaction Data
When you use AI-powered features (study assistant, flashcard generation, quiz generation, lecture summarization, document scanning, study podcasts), the content you submit is sent to third-party AI providers to generate responses. We store the generated outputs (summaries, flashcards, quiz questions) as part of your account.
We also keep an internal log of AI requests, which includes the text sent to the model and the text it returned, together with token counts and cost. We use this log to monitor spend, debug incorrect output, and improve prompts. It is not used for advertising and is not sold.
Email Sent to Your Gus Address
Each account is issued a personal inbound email address. Messages you send or forward to that address, including attachments, are received on our behalf by Resend, stored with your account, and passed to the AI provider so Gus can act on them.
Usage & Session Data
We use cookies to keep you signed in and to remember a small amount of context between visits. See Section 5 for the full list. If you arrive through a campus ambassador or referral link, we record which link you came from along with your user agent and a hashed form of your IP address, so we can credit the referrer.
We also record a page view each time you open a page of our public website or of the signed-in web app, so we can see which pages people read and which links and ads actually bring people to Gus. Each record holds the page path with any identifiers in it replaced by a placeholder, the two random cookie values described in Section 5, whether it was the first page of the visit, your account identifier if you are signed in, and the response status. For the first page of a visit we also record the hostname of the site that linked to us, any campaign tags on the link (utm_source, utm_medium, utm_campaign), and an advertising click identifier if one was present. From your browser's user agent we derive and keep only a device class (mobile, tablet or desktop), a browser name, and an operating-system name.
We deliberately do not store your IP address, any hashed or otherwise scrambled form of it, or the raw user agent string. If you go on to create an account, the page views already recorded against your visitor cookie in the previous 30 days are linked to that account, so we can tell which visit brought you in.
This measurement is our own and stays on our own servers. It is not sent to Google Analytics or to any other analytics or advertising company; it is read only by us, in our internal dashboard. It does not run inside the Gus iOS or Android apps.
Advertising Measurement
We advertise Gus on TikTok. If you reach our public website by clicking one of those ads, TikTok adds a click identifier to the link, and we store it in a first-party cookie for up to 7 days so we can tell that your visit came from that ad. Our public marketing pages and our signup page also load TikTok's measurement pixel, which sets its own cookie and tells TikTok that the page was viewed.
If you then create an account, we tell TikTok that a signup happened, so we can measure which ads work. That report includes the click identifier, your IP address and browser details, and your email address in a hashed (irreversibly scrambled) form, never your name, your school, or anything you store in Gus. We send this report only when you actually arrived by way of TikTok; if you found Gus some other way, nothing about your signup is sent to TikTok.
Our public marketing pages and our signup page also load a pixel from AdRoll, a retargeting service. It sets its own cookie and tells AdRoll that the page was viewed, together with your IP address and browser details, so that AdRoll can show you a Gus ad on other websites afterwards. We do not send AdRoll anything about your account, and it never learns whether you signed up.
This advertising measurement runs only on the public website. It does not run inside the Gus iOS or Android apps, and it does not run on any signed-in page of the product. TikTok and AdRoll are the only advertising networks we use. Our analytics are first-party: the data stays on our own servers and is never sent to Google Analytics or any other third-party analytics product.
2. How We Use Your Information
- Provide and operate the Gus service, including all study tools
- Process your content through AI services to generate study materials
- Transcribe and summarize your lecture recordings
- Enable study group communication and file sharing
- Send transactional emails (password resets, study group invitations)
- Maintain and improve the service
3. Third-Party Services
We use the following third-party services to operate Gus. Your data is shared with them only as needed to provide specific features.
Every provider listed here is bound by a written agreement that requires them to protect your data to the same standard set out in this policy, to use it only to perform the service we asked for, and not to use it to train their own models or to advertise to you. There are two exceptions, and we call them out plainly: TikTok and AdRoll, listed under "Advertising measurement" below, are advertising companies and do use what they receive for their own advertising purposes. That is why they never see anything beyond the public-website signals described there: no notes, recordings, coursework, or anything else you store in Gus.
AI processing
Nothing in this section happens until you have seen the in-app notice naming these services and given permission. You can withdraw that permission at any time under Settings → Privacy → AI features; the AI features then switch off and we stop sending your content. The rest of Gus keeps working.
- OpenRouter: routes our AI requests to a model provider. The content you submit to AI features passes through OpenRouter on its way to the model.
- Google (Gemini and Gemma models): the AI models behind study chat, flashcard and quiz generation, syllabus parsing, document scanning, and lecture summarization. Your submitted content is processed by Google to generate these responses.
- Other model hosts: For some requests OpenRouter selects among several hosting providers based on availability and speed, rather than a single fixed provider. This means a request may be served by a host we do not name in advance.
- OpenAI: generates text embeddings used for content search and relevance.
- Rev.ai and RunPod: transcribe lecture audio into text. Audio is transmitted for processing.
- Google Text-to-Speech: generates the audio for AI study podcasts from text we send it.
Accounts, email and payments
- Google & Facebook: If you use social login, these providers share your name and email with us to authenticate your account. We do not access any other data from your Google or Facebook accounts.
- Resend: delivers our outbound email and receives inbound email sent to your Gus address.
- Stripe: processes payments made on the web. We send Stripe your name, email, and account identifier. Card details are entered on Stripe's own checkout page and are never received or stored by us.
- Apple and Google Play: process subscriptions purchased inside our iOS and Android apps, and tell us whether a subscription is active. We send them only an opaque per-account identifier. Payment details are handled entirely by the app store.
- Apple Push Notification service and Google Firebase Cloud Messaging: deliver push notifications to your device. We send them a device token and the notification text.
Advertising measurement
- TikTok: measures whether our TikTok ads lead to signups. On our public marketing and signup pages, TikTok's pixel runs in your browser and receives your IP address, browser details, the page you are on, and its own cookie. If you signed up after arriving from TikTok, our server additionally sends TikTok a "registration completed" report containing the ad click identifier and your email address in hashed form. TikTok uses data for its own advertising purposes as well as ours, which is why it is confined to the public site. See "Advertising Measurement" in Section 1.
- AdRoll: shows Gus ads to people who have visited our public website. On our public marketing and signup pages, AdRoll's pixel runs in your browser and receives your IP address, browser details, the page you are on, and its own cookie. Nothing about your account or your signup is sent to AdRoll. Like TikTok, AdRoll uses what it receives for its own advertising purposes, and it is confined to the public site. See "Advertising Measurement" in Section 1.
Loaded by your browser
These services receive your IP address and browser details because your device requests files from them directly when a Gus page loads:
- Google Fonts and jsDelivr: serve fonts and JavaScript libraries used by the interface.
- Google or Facebook: only if you signed in with one of them and kept the profile picture from that account. The picture is loaded from their servers when it is displayed. Uploading your own picture in settings replaces it.
We do not use Gravatar. Profile pictures come only from what you upload or from the account you signed in with; if you have neither, Gus draws your initial instead. Your email address is never sent to a third party to fetch an image.
Document text extraction runs on our own servers and is not a third-party transfer.
4. Data Sharing
We do not sell your personal information, and we do not share it with data brokers.
Your data is shared only in these circumstances:
- With the third-party service providers listed above, solely to operate Gus
- With TikTok, strictly for advertising measurement and strictly as described in Section 1 and Section 3: the fact that a signup happened, the ad click identifier, and a hashed email address, and only when you reached us through TikTok. Under California law this limited disclosure counts as "sharing for cross-context behavioral advertising", and you can opt out of it (see Section 9)
- With AdRoll, strictly through its pixel on our public marketing and signup pages as described in Section 1 and Section 3: the fact that a page was viewed, your IP address, and browser details. Under California law this also counts as "sharing for cross-context behavioral advertising", and you can opt out of it (see Section 9)
- With other members of study groups you join (messages, files, and tasks you share within a group are visible to group members)
- If required by law, such as in response to a valid legal process
5. Cookies & Sessions
Gus sets the following first-party cookies.
- Session: keeps you signed in. HttpOnly, Secure in production, persistent — it keeps you signed in until you sign out, and is renewed each time you use Gus (it lapses only after 400 days without any activity, the longest a browser will keep a cookie). The cookie holds only a session identifier; the session itself is stored server-side.
- Referral attribution: If you arrive through a campus ambassador or referral link, records which link you came from so the referrer can be credited. Lasts up to 30 days.
- Invitation and pilot context: remembers a study-group invitation or campus pilot you followed, so it still applies after you sign up.
- App context: records that you are using the iOS or Android app rather than a browser, so the interface adapts.
- Sign-in-with-Apple state: a short-lived value used to protect the Apple login flow against cross-site request forgery.
- Analytics visitor: a random identifier that lets us count a reader who comes back as one person rather than several, without knowing who that person is. HttpOnly, SameSite=Lax, and lasts about 13 months.
- Analytics visit: a random identifier that groups the pages you read in a single sitting, so we can see where a visit started and where it went next. HttpOnly, SameSite=Lax, and expires 30 minutes after your last page view.
- Advertising click identifier: set only if you arrive on our public website from a TikTok ad. Records TikTok's identifier for that click so a resulting signup can be attributed to the ad. HttpOnly, and expires after 7 days or as soon as it has been used, whichever comes first. Not set for visitors who did not come from an ad.
Two third-party cookies are also set, one by TikTok's measurement pixel and one by AdRoll's retargeting pixel, when you visit our public marketing or signup pages. See "Advertising Measurement" in Section 1. No third-party cookies are set on signed-in pages of the product, or in the Gus iOS and Android apps.
The referral cookie is used for attribution (that is, to work out which referrer to credit) and is recorded together with the user agent and a hashed IP address. The analytics visitor and visit cookies are used to count page views and to follow one visit from page to page, as described in Section 1. All three are first-party only: they are not shared with an advertising network and are not used to profile you or to target ads.
We also store a theme preference (light/dark mode) in your browser's local storage. Our analytics are first-party: the data stays on our own servers and is never sent to Google Analytics or any other third-party analytics product.
6. Data Retention
- Account data (name, email, school) is retained while your account is active.
- Content (notes, lectures, recordings, flashcards) is retained while your account is active. You can delete individual items at any time.
- Study group content (messages, files, tasks) remains in the group even if you leave. Group owners can delete group content.
- Billing records (subscription status, purchase and payment identifiers, invoices) are retained after cancellation as required for tax and accounting purposes. We never hold your card details.
- Analytics page views: the individual page-view rows described in Section 1 are deleted after 90 days. What we keep beyond that is aggregate daily counts only, with no visitor, visit or account identifiers in them.
- Deleted accounts: when you delete your account, personal data is removed or anonymized within 30 days. Your profile and the content tied to it are deleted. Entries in our internal AI request log are anonymized: they are unlinked from your account and the text you submitted is erased, leaving only non-identifying figures such as model name, token counts and cost. Analytics page views are unlinked from your account as well: the account identifier on each row is cleared, and what remains holds no identifier that points to a person. Billing records are retained as described above. Encrypted backups may retain data for up to 90 days for disaster recovery before being purged.
7. Your Rights
You have the right to:
- Access your personal data: you can view and download your content within the app
- Correct your personal data: you can update your name, email, school, and timezone in settings
- Delete your personal data: you can delete individual content items or your entire account
- Request data export: contact us to receive a copy of your data
To exercise these rights or if you have questions, email us at privacy@meetgus.app.
How to delete your Gus account
You can delete your account yourself, from any device, without contacting us:
- Sign in to Gus at meetgus.app, or in the Gus app for iOS or Android.
- Open Settings from the menu under your profile picture.
- Scroll to Delete account.
- Choose Permanently delete account and confirm.
If you can no longer sign in, email privacy@meetgus.app from the address on the account and we will delete it for you.
What is deleted: your profile, and the content tied to it: notes, lecture recordings and transcriptions, flashcards, quizzes, tasks, schedule and course data. Entries in our internal AI request log are anonymized: unlinked from your account, with the submitted text erased.
What is kept, and for how long: billing records (subscription status, purchase and payment identifiers, invoices) are retained after cancellation as required for tax and accounting purposes. Messages, files and tasks you shared into a study group remain visible to that group. Deletion completes within 30 days; encrypted backups may retain data for up to a further 90 days before being purged. See Data Retention above.
8. Education Records
Gus is a student-facing tool. We are not an agent of your school or university, and we do not receive education records directly from educational institutions. The content you upload to Gus (notes, recordings, etc.) is provided by you and managed by you.
For students at U.S. institutions, your school's FERPA obligations do not extend to content you voluntarily store in Gus. For students at Canadian institutions, the equivalent provincial education records and freedom-of-information statutes (e.g., Ontario's FIPPA, BC's FIPPA, Alberta's FOIP) similarly apply to records held by your school, not to content you choose to store with us.
If your institution integrates with Gus in the future, we will enter into appropriate data protection agreements and update this policy accordingly.
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know: you can request details about the personal information we collect and how it is used
- Right to Delete: you can request deletion of your personal information
- Right to Correct: you can request correction of inaccurate personal information
- Right to Opt-Out: we do not sell your personal information. We do share a limited signal with TikTok for advertising measurement and with AdRoll for retargeting, as described in Sections 1, 3 and 4, which California law treats as "sharing for cross-context behavioral advertising". To opt out, email privacy@meetgus.app and we will exclude your account. Blocking the TikTok and AdRoll pixels in your browser, or using the Gus iOS or Android app (where they never run), also prevents it. You can also opt out of AdRoll directly at app.adroll.com/optout
- Right to Non-Discrimination: we will not treat you differently for exercising your privacy rights
To submit a CCPA request, email privacy@meetgus.app. We will respond within 45 days.
10. Canadian Privacy Rights (PIPEDA)
If you are located in Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle your personal information. We commit to:
- Meaningful consent: you knowingly consent to our collection and use of your data when you create an account and upload content
- Limiting collection: we collect only what is necessary to provide Gus's features
- Accuracy: you can update your account information at any time in settings
- Access and correction: you can view, export, and correct your personal data, as described in Section 7
- Safeguards: see Section 11 (Data Security) for the protections we apply
- Breach notification: If a breach poses real risk of significant harm, we will notify you and report to the Office of the Privacy Commissioner of Canada as required
- Complaints: to file a privacy complaint, email privacy@meetgus.app. You also have the right to contact the Office of the Privacy Commissioner of Canada.
Quebec residents: Gus is not currently available to students at Quebec institutions. We are not yet equipped to comply with Quebec's Law 25 (including its French-language and Privacy Impact Assessment requirements). When we expand to Quebec, we will update this policy and notify users.
11. Cross-Border Data Transfers
Gus is operated from the United States. If you access Gus from outside the U.S. (including from Canada), your personal information will be transferred to, stored in, and processed in the U.S. The third-party service providers listed in Section 3 may also process your data in the U.S. or other jurisdictions where they operate; because some AI requests are routed to whichever model host is available at the time, the specific country of processing for those requests can vary. By using Gus, you acknowledge that this cross-border transfer takes place. We use contractual and technical safeguards to protect your data wherever it is processed.
12. Children's Privacy
Gus is designed for college and university students. You must be at least 13 years old to create an account. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
13. Data Security
We take reasonable measures to protect your data:
- Passwords are hashed using bcrypt with a high work factor
- All traffic is encrypted with HTTPS in production
- Session cookies are HttpOnly and Secure
- Sessions are stored server-side in an encrypted database
- OAuth login uses industry-standard CSRF protection
No system is perfectly secure. If we discover a breach affecting your data, we will notify you promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice in the app. The "Effective" date at the top of this page indicates when the policy was last revised. Continued use of Gus after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at privacy@meetgus.app.