Last updated: August 16, 2026
1. Who We Are & Our Role
Viridel is operated as a sole proprietorship by Shiva Kumar Esakki Pandiyan, based in Secunderabad, Telangana, India. For account, authentication, and billing metadata you provide to Viridel, we act as the data controller (Data Fiduciary under India's DPDPA 2023). For finance-record payloads you sync under Viridel Plus, you are the controller and Viridel is the processor — see the DPA.
Grievance Officer. In accordance with Rule 3(1)(a) of the IT Rules 2021 and the DPDPA 2023, our Grievance Officer is Shiva Kumar Esakki Pandiyan, contactable at grievance@viridel.app. General privacy enquiries: privacy@viridel.app. Complaints are acknowledged within 48 hours and resolved within 15 days under the IT Rules (30 days for data-principal requests under the DPDPA).
2. Local-First Architecture
Viridel is local-first. By default, every finance record you create — expenses, budgets, bills, subscriptions, income, savings goals, and money calendar events — is stored only on your device, in your browser's IndexedDB / localStorage or your app's native storage. That content is not transmitted to Viridel's servers. If you never enable cloud sync, there is no server-side copy of those finance records for us to open.
Viridel is local-first: your data is stored on your device (localStorage/IndexedDB). You are solely responsible for backing up your data. We are not liable for data loss from device failure, cleared caches, uninstallation, or OS updates. If you use the optional Plus cloud sync, we make commercially reasonable efforts to secure it but do not guarantee against loss or interruption. Claims about data loss or calculation/reminder errors are also governed by the Terms (Limitation of Liability and Mandatory Arbitration).
Cloud sync is an opt-in paid feature (Viridel Plus). Only when you enable it do those records leave your device. Synced rows are protected by database row-level security so other users cannot read them through the application APIs. We do not browse customer sync data in ordinary operations; exceptional privileged access (if ever needed for security, abuse, or legal process) is limited, purpose-bound, and logged.
3. What Data We Collect
| Category | Where it lives | Who can see it |
|---|---|---|
| App records (expenses, budgets, bills, subscriptions, income, savings goals, money calendar) | Device IndexedDB / localStorage / native SQLite by default | Only you, unless Viridel Plus sync is enabled |
| Google identity (email, display name, Google user id) | Supabase Auth when you sign in | Viridel (account ops) + Google as IdP |
| Synced store payloads (Plus only) | Supabase PostgreSQL with RLS | You; other users blocked by RLS; Viridel does not day-to-day browse rows |
| Purchase metadata (billing email, country, plan status, Dodo IDs) | Dodo + Viridel entitlement records | Dodo (MoR) + Viridel for license verification |
| Web delivery logs (IP, user-agent, URL) | Hosting / CDN for the marketing site and web app | Host provider (short-lived operational logs) |
Identity data
When you sign in with Google, we receive your email address, your Google display name, and a unique Google account identifier. We never receive or store your Google password. You can use local-only features without signing in; sign-in is required for purchases and Viridel Plus.
Your personal records (cloud sync only)
If you enable cloud sync, the finance records you choose to sync are stored on our infrastructure: expenses, budgets, bills, subscriptions, income, savings goals, and money calendar events. Without cloud sync, none of those finance records reaches us. Viridel is not a bank and is not financial advice.
Purchase metadata
When you purchase, our Merchant of Record (Dodo Payments) handles the transaction. We receive only your billing email, billing country, subscription status, and Dodo customer/subscription IDs. We never see, store, or process your card details.
What we do NOT collect
- No analytics — no Google Analytics, no Meta Pixel, no session recording.
- No advertising or tracking cookies.
- No content of your local-only finance records (there is no server copy without Plus).
- No data used to train AI models — Viridel has no AI features.
- No bank credentials or open-banking connections.
4. Legal Basis for Processing (EU / UK / EEA)
Where the GDPR or UK GDPR applies, the legal bases we rely on are:
- Contract (Art. 6(1)(b)): operating your account, delivering Lifetime / Plus entitlements, and providing cloud sync you requested.
- Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud/abuse, and improving reliability — balanced against your rights.
- Legal obligation (Art. 6(1)(c)): tax, accounting, and responding to lawful authority requests.
- Consent (Art. 6(1)(a)): where required for a specific optional processing — withdraw anytime by disabling sync or deleting your account.
5. How We Use Data
- Authenticate you via Google OAuth and keep your session secure.
- Deliver purchased licenses and Viridel Plus sync.
- Store and sync the finance records you choose when Plus is enabled.
- Send transactional email (receipts, security, material policy changes) — never marketing blasts.
- Comply with legal obligations and respond to lawful requests from authorities.
- Investigate abuse, fraud, or security incidents.
We do not sell personal data, do not use it for advertising, and do not use it to train AI models.
6. Processors & Sub-processors
| Provider | Role | Data |
|---|---|---|
| Google LLC | OAuth identity provider | Email, name, Google user id (under Google's terms) · United States / global |
| Supabase Inc. | Auth + optional Plus sync database (processor for Plus) | Account + synced finance records · AWS eu-central-1 (Frankfurt) |
| Dodo Payments | Merchant of Record | Billing email, country, payment status (under Dodo's terms) · global |
| Resend | Transactional email (receipts / operational mail when configured) | Email address + message metadata · Ireland |
| Vercel | Hosts the marketing site and web app origin | Standard request logs (IP, URL) — not finance-record content · Frankfurt |
| Cloudflare | CDN / edge cache for public assets | May cache public marketing/app assets; request logs may include IP/URL · US-east (and other PoPs) |
Google and Dodo may act as independent controllers for identity and payment processing under their own policies. Supabase acts as our sub-processor for authentication tokens and Viridel Plus sync storage. For synced personal data under Plus, see the Data Processing Agreement. We give at least 30 days' notice before a new sub-processor begins processing Plus sync data; you may object and disable sync. There is no fee refund for that choice — see the Refund Policy.
7. International Data Transfers
Viridel is operated from India. Optional Plus sync data is stored in the EU (Supabase, AWS eu-central-1 Frankfurt), encrypted in transit (TLS) and at rest (AES-256) — this is not end-to-end encryption. Transactional email is sent via Resend (Ireland). The marketing site origin is Vercel (Frankfurt). Cloudflare’s CDN may cache and serve public assets from the United States (US-east and other points of presence), so not all traffic stays in the EU. Google OAuth identity is processed by Google globally. Where personal data of EEA/UK individuals is transferred to a country without an adequacy decision, the transfer is protected by the relevant provider's Standard Contractual Clauses (EU Commission Decision 2021/914) and supplementary measures, in line with GDPR Chapter V.
8. Data Retention
- Active account data — kept while your account is active.
- Active Viridel Plus sync data — retained without a rolling time cap for as long as your account and Plus subscription remain active (including multi-decade use) so devices can restore and merge; Cancel Plus and sync suspends after the paid period; delete your account and cloud data is purged (see below). Subscription prices may change with at least 30 days' email notice under the Terms of Service.
- Soft-deleted account data — a 48-hour recovery window, then permanent deletion; cloud data is fully removed within 30 days of a deletion request.
- Billing records — retained by Dodo Payments under their policy and applicable tax law.
- Consent / policy-ack records — kept for at least three years after account closure where needed as evidence.
- Operational logs — typically rotated within 30 days.
- Local device data — remains on your device until you clear site/app data or uninstall; Viridel cannot remote-wipe local-only storage.
9. Export & Deletion
You can export your data yourself as JSON and CSV from Settings → Data at any time (produced on-device). Deleting your account is Settings → Data → Delete account (/settings/data while signed in). Cloud-held data enters a 48-hour soft-delete recovery window, then is fully purged within 30 days. Local data stays under your control until you clear it.
10. Data Storage & Security
- Encryption in transit — TLS 1.3 on every connection; HSTS enforced.
- Encryption at rest — AES-256 (Supabase / AWS eu-central-1 Frankfurt) for synced data. This is provider-managed at-rest encryption, not end-to-end encryption of ledger contents.
- Row-level security — every cloud table enforces per-user ownership at the database layer for application access.
- Google OAuth only — no Viridel password database to breach.
- Electron desktop — context isolation enabled, Node integration disabled, minimal preload surface.
See our Security page for full detail, and report vulnerabilities to security@viridel.app.
10A. Lawful Requests
We may disclose account or synced data if required by valid legal process (court order, warrant, or equivalent). Where legally permitted, we will notify you before disclosure. We do not sell access to data for advertising.
11. Data Breach Notification
If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and where feasible within 72 hours of becoming aware (GDPR Article 33). Notice to you will be sent to your account email and will describe the nature of the breach, the categories of data affected, the measures we have taken, and any steps you can take to protect yourself.
12. California Residents (CCPA / CPRA)
Viridel does not meet the CCPA's applicability thresholds today, but we honour these rights for any California user. We do not sell your personal information, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioural advertising, so there is no "Do Not Sell or Share" link because there is nothing to opt out of.
You have the right to know, access, delete, correct, and to non-discrimination for exercising any right. Exercise these by emailing privacy@viridel.app from the email on your account.
13. Your Rights
If you are in the EEA, UK, India, or a region with equivalent law, you have the rights below, which we honour globally where the processing makes them applicable:
- Access — request a copy of the personal data we hold about you.
- Portability — export all your data yourself as JSON and CSV from Settings.
- Rectification — most fields are editable directly in the app; email us for anything you cannot self-serve.
- Erasure — delete your account and cloud data from Settings (48-hour soft-delete, then permanent removal).
- Objection / restriction — email us to object to or restrict a specific processing activity.
- Withdraw consent — disable cloud sign-in or cloud sync at any time.
- Complain to a supervisory authority — you may always lodge a complaint with your local data-protection authority.
For any request you cannot self-serve, email privacy@viridel.app from your account email. We verify the request comes from you and respond within 30 days — usually much sooner. Viridel is not required to appoint a Data Protection Officer; the Grievance Officer (grievance@viridel.app) handles all data-protection enquiries.
14. Children & Age Thresholds
Viridel is not directed to children. You must be at least 13 years old to use the service, or at least 16 in the EEA/UK (or such higher age as your country requires). We do not knowingly collect personal data from anyone below the applicable threshold. If you believe a child has provided us personal data, email us and we will delete it without delay.
16. Changes to This Policy
We may update this policy. For material changes, we will notify you by email (if signed in) and/or post a notice in the app or on the site at least 30 days before they take effect. The most recent update date is shown at the top of this page.
17. Contact
Questions or requests about this policy or your personal data: privacy@viridel.app. Grievance Officer: Shiva Kumar Esakki Pandiyan, grievance@viridel.app. Related: Terms · Refund · Cookie Policy · Security · DPA.
Disclaimer & Updates
These pages describe how Viridel operates as a product. They are not legal advice. We may update them; for material changes we notify signed-in users by email and/or post a notice on the site or in the app. The date at the top of each page is authoritative.