Privacy
Plain-language privacy policy.
No dark patterns.
This page is the complete answer to "what does Viably do with my data?" — plain language, no buried clauses. We update it whenever something material changes, and post a release note when we do.
For the technical retention windows and collection-level detail, see /security, which mirrors the same retention contracts the database actually enforces.
What we collect
Only what's needed to make the app work for you. Each item below is editable in-app, exportable on request, and deletable.
Account & profile
Email, hashed password (bcrypt, 12 rounds), display name, timezone, household composition (adult/child counts only — no names, dates of birth, or relationships).
Financial inputs you enter
Workplace records, pay rules, shifts, bills, debts, goals, ZIP code(s), and other financial data you explicitly add. This is the data we exist to crunch — without it the app does nothing.
Optional connected-bank data
If bank aggregation is configured and you choose Plaid, Viably stores an encrypted provider access token and institution/item metadata. On an explicit sync, we store the derived eligible checking/savings cash total and account counts — never your bank login.
Authentication metadata
Per-device session records (IP, user-agent, last-seen) so you can review and revoke them from /settings/security. Optional TOTP secret and/or registered passkey credentials.
Audit log (security events)
Login attempts, MFA enrollments, password changes, billing transitions, account deletion. Retained 365 days for security review (you can request your full log via support).
What we never collect
The list below is a commitment, not a default. Verify in your browser devtools Network tab — we don't load any third-party tracking scripts.
- Names, ages, or relationships of household members.
- Government identifiers (SSN, ITIN, driver license).
- Bank login credentials. Optional bank connection runs through Plaid's consent flow; Viably never receives or stores your bank username or password.
- Browsing history outside the Viably app.
- Third-party tracking pixels (no Facebook, no LinkedIn, no Quora — verify in your devtools Network tab).
- Cross-site tracking cookies. Auth cookies are first-party, HttpOnly, Secure, and SameSite=None for supported app domains.
- Behavioural advertising signals. We do not advertise on your data.
Service providers and subprocessors
These services may process data only for the role shown and only when the corresponding feature is used or deployment integration is configured. Optional and conditional services stay listed here so the policy does not hide them when disabled. We do not sell, rent, or trade your data.
Stripe
Privacy policy →Payment processing only.
Email, billing address (if you provide one), and Stripe customer ID. Stripe-hosted Checkout collects card details directly; Viably does not receive or store your card number.
Retention: Stripe retains provider records under its policy; Viably retains the customer/subscription reference through account deletion and any required financial-ledger period.
Disclosure effective 2026-07-14
Resend
Privacy policy →Transactional email delivery.
Email address and the rendered verification, password-reset, or billing message. Viably does not operate a bulk marketing list.
Retention: Delivery metadata follows the configured provider account policy; Viably keeps only the related application/security event under its documented retention class.
Disclosure effective 2026-07-14
Google OAuth (optional)
Privacy policy →Optional sign-in, only when you choose Google.
Your Google email and the OAuth-scoped user information Google shares. Viably does not request Drive, Calendar, or Gmail scopes.
Retention: OAuth-derived account identity remains until disconnect or account deletion; individual application sessions expire under the authentication retention policy.
Disclosure effective 2026-07-14
Cloudflare
Privacy policy →CDN, request transit, and DDoS protection when used by the deployment.
IP address, user-agent, request URL, and network/security metadata needed to deliver and protect the service.
Retention: Edge and security-log retention is controlled by the active deployment plan and Cloudflare policy; Viably does not import those raw logs into product financial state.
Disclosure effective 2026-07-14
Plaid (optional)
Privacy policy →Optional, user-initiated bank connection and balance sync.
Plaid handles bank login credentials and the account, balance, or transaction permissions shown in its consent flow. Viably stores an encrypted provider access token plus institution/item metadata and currently retrieves eligible deposit-account balances only when you explicitly sync. Viably does not receive or store your bank username or password.
Retention: The encrypted provider token and item metadata remain only while connected or while a confirmed provider-revocation retry is pending, then are deleted.
Disclosure effective 2026-07-14
Sentry (when configured)
Privacy policy →Error and sampled performance monitoring when a Sentry DSN is configured.
Error messages and stack traces, request URLs, browser/device context, and sampled performance diagnostics. Viably scrubs cookies, auth headers, email, and known token/financial fields before browser events are sent; browser Session Replay is disabled.
Retention: Sanitized event retention follows the configured Sentry project period; disabling the DSN stops new browser events.
Disclosure effective 2026-07-14
Emergent LLM gateway (when configured)
Privacy policy →Optional AI processing for OCR, Scenario Lab, and changelog summaries when an Emergent key is configured.
The document content or prompt needed for the feature you invoke. OCR and Scenario Lab inputs can contain financial information; Viably does not send bank login credentials.
Retention: Provider-side processing and logs follow the configured Emergent account terms; Viably retains feature inputs and results only under the applicable application retention class.
Disclosure effective 2026-07-14
Google AI / Gemini (when configured)
Privacy policy →Optional direct AI processing for OCR and Scenario Lab when a Gemini key is configured.
The document content or scenario prompt needed for the feature you invoke. Those inputs can contain financial information; Viably does not send bank login credentials.
Retention: Production requires a paid Gemini service and reviewed data-processing terms; provider logging and retention follow those paid-service terms. Viably retains feature inputs and results only under the applicable application retention class.
Disclosure effective 2026-07-14
Groq (when configured)
Privacy policy →Optional direct AI processing for Scenario Lab when a Groq key is configured.
The scenario prompt and financial context needed to produce the answer you request. Viably does not send bank login credentials.
Retention: Provider-side processing and logs follow the configured Groq account terms; Viably retains scenario inputs and results only under the applicable application retention class.
Disclosure effective 2026-07-14
Railway (when used for hosting)
Privacy policy →Application, database, cache, and network hosting for Railway deployments.
Encrypted application traffic, stored product and ledger records, and operational metadata needed to run and protect the deployed service.
Retention: Hosted data follows Viably's application retention and backup schedules; Railway infrastructure metadata follows the active account and provider policy.
Disclosure effective 2026-07-14
Amazon S3 (when selected)
Privacy policy →Optional S3-compatible object storage for uploaded documents and generated exports.
Encrypted document/export objects, object keys, content type, size, and storage access metadata.
Retention: Objects follow Viably's document, export, deletion, and backup schedules; provider operational metadata follows the configured AWS account policy.
Disclosure effective 2026-07-14
Cloudflare R2 (when selected)
Privacy policy →Optional S3-compatible object storage for uploaded documents and generated exports.
Encrypted document/export objects, object keys, content type, size, and storage access metadata.
Retention: Objects follow Viably's document, export, deletion, and backup schedules; provider operational metadata follows the configured Cloudflare account policy.
Disclosure effective 2026-07-14
Google Cloud Storage (when selected)
Privacy policy →Optional S3-compatible object storage for uploaded documents and generated exports.
Encrypted document/export objects, object keys, content type, size, and storage access metadata.
Retention: Objects follow Viably's document, export, deletion, and backup schedules; provider operational metadata follows the configured Google Cloud account policy.
Disclosure effective 2026-07-14
Firebase Cloud Messaging (when configured)
Privacy policy →Optional native push delivery for Android and iOS through Firebase Cloud Messaging. On iOS, Firebase routes delivery through Apple Push Notification service (APNs).
Device push token, notification payload, application identifiers, and delivery metadata needed to route a native notification.
Retention: Viably retains an encrypted device token until it is revoked, becomes stale, or the account is deleted; provider delivery metadata follows Firebase policy.
Disclosure effective 2026-07-14
Apple (when mobile billing or iOS push is configured)
Privacy policy →Optional App Store purchase-receipt verification and APNs transport for iOS notifications routed through Firebase Cloud Messaging. Viably does not currently operate a direct APNs client.
For billing: App Store receipt, product and transaction identifiers, bundle ID, and application account-binding metadata. For iOS push: device token, notification payload, application identifiers, and delivery metadata needed by APNs.
Retention: Viably retains the verified entitlement and ledger record under its billing retention class, and an encrypted device token until it is revoked, becomes stale, or the account is deleted; Apple's receipt, push-delivery, and operational metadata follow Apple policy.
Disclosure effective 2026-07-14
Google Play (when mobile billing is configured)
Privacy policy →Optional Google Play purchase-token verification.
Purchase token, product and order identifiers, package name, and application account-binding metadata needed to validate a purchase.
Retention: Viably retains the verified entitlement and ledger record under its billing retention class; Google's receipt and operational metadata follow Google policy.
Disclosure effective 2026-07-14
Browser or OS push service (when enabled)
Privacy policy →Optional standards-based notification delivery through the service selected by your browser or operating system.
Push subscription endpoint, public encryption keys, encrypted notification payload, and delivery metadata. The endpoint determines whether Google, Mozilla, Apple, or Microsoft routes the message.
Retention: Viably retains the encrypted subscription until it is revoked, becomes stale, or the account is deleted; provider delivery metadata follows the selected browser or OS provider's policy.
Disclosure effective 2026-07-14
How long we keep things
Most data either auto-deletes on a schedule (TTL) or sticks around until you delete your account. Engineering enforces these at the database layer — see /security.
| Data | Retention |
|---|---|
| Audit logs (security events) | 365 days, then auto-deleted. |
| In-app notifications | 90 days, then auto-deleted (30 days post-dismissal if you dismiss earlier). |
| Marketing-funnel analytics | 90 days, anonymous (visitor_id is a client-generated UUID, not your account). |
| Auth artifacts (OTP codes, password reset, MFA challenges) | 5 minutes to 1 hour depending on the artifact. |
| Brute-force lockout state | 1 hour after the lockout fires. |
| Session records | 24 hours (default) or 30 days (if you check 'remember me'). |
| Account & financial data you enter | Indefinite while your account is active — deleted on account deletion. |
| Payment-transaction ledger | Retained per accounting requirements + mirrored by Stripe. |
Your rights
Whether or not your jurisdiction (GDPR, CCPA, PIPEDA, etc.) requires it, you can do all of the following with one click in-app or one email to support.
Export your data
Request a full export of every record we hold about you (JSON + CSV bundle). 5-business-day turnaround.
Delete your account
Settings → Security → Delete account. Cascading hard delete: every personal record removed within seconds. Audit-log entries are preserved (anonymised) for the 365-day security window, then auto-purged.
Correct your data
All financial fields are user-editable in-app. For account email/billing details, contact support.
Opt out of analytics
Toggle in Settings → Privacy disables landing-funnel telemetry on your device. (The collection auto-purges in 90 days regardless.)
Need to delete your data right now?
If you have an account: go to Settings → Security → Delete account— the cascade runs immediately.
If you don't have an account but think we have data on you (e.g. you submitted feedback or signed up and never confirmed), email privacy@viably.tech with the email you used and we'll delete it within 5 business days.
Children
Viably is not directed at children under 16 and we do not knowingly collect data from them. If you believe we have, email privacy@viably.tech and we'll delete it.
International transfers
If a deployment processes data in the United States, access from outside the US may transfer data there. Applicable region, network, storage, provider encryption, and retention controls are deployment-specific; controlled evidence is maintained separately and is not asserted by this page.
Changes to this policy
We post material changes 30 days in advance via in-app notification and an entry in our public release notes. Minor edits (typo fixes, link updates, restructuring without changing substance) we just commit and update the effective date.
Contact
Questions about this policy or about your specific data: privacy@viably.tech. Security incidents: security@viably.tech.
Trust, then verify
The privacy commitment is real.
The product is too.
Run your audit Free. No credit card. Account creation requires only an email.