Last updated: July 26, 2026
1. Who We Are & Our Role
Viridel is operated as a sole proprietorship by Shiva Kumar Esakki Pandiyan, based in Secunderabad, Telangana, India. For account, authentication, and billing metadata you provide to Viridel, we act as the data controller (Data Fiduciary under India's DPDPA 2023). For finance-record payloads you sync under Viridel Plus, you are the controller and Viridel is the processor — see the DPA.
Grievance Officer. In accordance with Rule 3(1)(a) of the IT Rules 2021 and the DPDPA 2023, our Grievance Officer is Shiva Kumar Esakki Pandiyan, contactable at grievance@viridel.com. General privacy enquiries: privacy@viridel.com. Complaints are acknowledged within 48 hours and resolved within 15 days under the IT Rules (30 days for data-principal requests under the DPDPA).
2. Local-First Architecture
Viridel is local-first. By default, every finance record you create — expenses, budgets, bills, subscriptions, income, savings goals, and money calendar events — is stored only on your device, in your browser's IndexedDB / localStorage or your app's native storage. That content is not transmitted to Viridel's servers. If you never enable cloud sync, there is no server-side copy of those finance records for us to open.
Viridel is local-first: your data is stored on your device (localStorage/IndexedDB). You are solely responsible for backing up your data. We are not liable for data loss from device failure, cleared caches, uninstallation, or OS updates. If you use the optional Plus cloud sync, we make commercially reasonable efforts to secure it but do not guarantee against loss or interruption. Claims about data loss or calculation/reminder errors are also governed by the Terms (Limitation of Liability and Mandatory Arbitration).
Cloud sync is an opt-in paid feature (Viridel Plus). Only when you enable it do those records leave your device. Synced rows are protected by database row-level security so other users cannot read them through the application APIs. We do not browse customer sync data in ordinary operations; exceptional privileged access (if ever needed for security, abuse, or legal process) is limited, purpose-bound, and logged.
3. What Data We Collect
| Category | Where it lives | Who can see it |
|---|---|---|
| App records (expenses, budgets, bills, subscriptions, income, savings goals, money calendar) | Device IndexedDB / localStorage / native SQLite by default | Only you, unless Viridel Plus sync is enabled |
| Google identity (email, display name, Google user id) | Supabase Auth when you sign in | Viridel (account ops) + Google as IdP |
| Synced store payloads (Plus only) | Supabase PostgreSQL with RLS | You; other users blocked by RLS; Viridel does not day-to-day browse rows |
| Purchase metadata (billing email, country, plan status, Dodo IDs) | Dodo + Viridel entitlement records | Dodo (MoR) + Viridel for license verification |
| Web delivery logs (IP, user-agent, URL) | Hosting / CDN for the marketing site and web app | Host provider (short-lived operational logs) |
Identity data
When you sign in with Google, we receive your email address, your Google display name, and a unique Google account identifier. We never receive or store your Google password. You can use local-only features without signing in; sign-in is required for purchases and Viridel Plus.
Your personal records (cloud sync only)
If you enable cloud sync, the finance records you choose to sync are stored on our infrastructure: expenses, budgets, bills, subscriptions, income, savings goals, and money calendar events. Without cloud sync, none of those finance records reaches us. Viridel is not a bank and is not financial advice.
Purchase metadata
When you purchase, our Merchant of Record (Dodo Payments) handles the transaction. We receive only your billing email, billing country, subscription status, and Dodo customer/subscription IDs. We never see, store, or process your card details.
What we do NOT collect
- No analytics — no Google Analytics, no Meta Pixel, no session recording.
- No advertising or tracking cookies.
- No content of your local-only finance records (there is no server copy without Plus).
- No data used to train AI models — Viridel has no AI features.
- No bank credentials or open-banking connections.
4. Legal Basis for Processing (EU / UK / EEA)
Where the GDPR or UK GDPR applies, the legal bases we rely on are:
- Contract (Art. 6(1)(b)): operating your account, delivering Lifetime / Plus entitlements, and providing cloud sync you requested.
- Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud/abuse, and improving reliability — balanced against your rights.
- Legal obligation (Art. 6(1)(c)): tax, accounting, and responding to lawful authority requests.
- Consent (Art. 6(1)(a)): where required for a specific optional processing — withdraw anytime by disabling sync or deleting your account.
5. How We Use Data
- Authenticate you via Google OAuth and keep your session secure.
- Deliver purchased licenses and Viridel Plus sync.
- Store and sync the finance records you choose when Plus is enabled.
- Send transactional email (receipts, security, material policy changes) — never marketing blasts.
- Comply with legal obligations and respond to lawful requests from authorities.
- Investigate abuse, fraud, or security incidents.
We do not sell personal data, do not use it for advertising, and do not use it to train AI models.
6. Processors & Sub-processors
| Provider | Role | Data |
|---|---|---|
| Google LLC | OAuth identity provider | Email, name, Google user id (under Google's terms) |
| Supabase Inc. | Auth + optional sync database (processor for Plus) | Account + synced finance records |
| Dodo Payments | Merchant of Record | Billing email, country, payment status (under Dodo's terms) |
| Web host / CDN (e.g. Vercel) | Serves marketing site and web app assets | Standard request logs (IP, URL) — not finance-record content |
Google and Dodo may act as independent controllers for identity and payment processing under their own policies. Supabase acts as our sub-processor for authentication tokens and Viridel Plus sync storage. For synced personal data under Plus, see the Data Processing Agreement. We give at least 30 days' notice before a new sub-processor begins processing Plus sync data; you may object and disable sync. There is no fee refund for that choice — see the Refund Policy.
7. International Data Transfers
Viridel is operated from India; some sub-processors are based in the United States. Where personal data of EEA/UK individuals is transferred to a country without an adequacy decision, the transfer is protected by the relevant provider's Standard Contractual Clauses (EU Commission Decision 2021/914) and supplementary measures, in line with GDPR Chapter V.
8. Data Retention
- Active account data — kept while your account is active.
- Active Viridel Plus sync data — retained without a rolling time cap for as long as your account and Plus subscription remain active (including multi-decade use) so devices can restore and merge; Cancel Plus and sync suspends after the paid period; delete your account and cloud data is purged (see below). Subscription prices may change with at least 30 days' email notice under the Terms of Service.
- Soft-deleted account data — a 48-hour recovery window, then permanent deletion; cloud data is fully removed within 30 days of a deletion request.
- Billing records — retained by Dodo Payments under their policy and applicable tax law.
- Consent / policy-ack records — kept for at least three years after account closure where needed as evidence.
- Operational logs — typically rotated within 30 days.
- Local device data — remains on your device until you clear site/app data or uninstall; Viridel cannot remote-wipe local-only storage.
9. Export & Deletion
You can export your data yourself as JSON and CSV from Settings at any time (produced on-device). Deleting your account removes cloud-held data after a 48-hour soft-delete window, with full purge within 30 days. Local data stays under your control until you clear it.
10. Data Storage & Security
- Encryption in transit — TLS 1.3 on every connection; HSTS enforced.
- Encryption at rest — AES-256 (Supabase / AWS) for synced data.
- Row-level security — every cloud table enforces per-user ownership at the database layer for application access.
- Google OAuth only — no Viridel password database to breach.
- Electron desktop — context isolation enabled, Node integration disabled, minimal preload surface.
See our Security page for full detail, and report vulnerabilities to security@viridel.com.
10A. Lawful Requests
We may disclose account or synced data if required by valid legal process (court order, warrant, or equivalent). Where legally permitted, we will notify you before disclosure. We do not sell access to data for advertising.
11. Data Breach Notification
If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and where feasible within 72 hours of becoming aware (GDPR Article 33). Notice to you will be sent to your account email and will describe the nature of the breach, the categories of data affected, the measures we have taken, and any steps you can take to protect yourself.
12. California Residents (CCPA / CPRA)
Viridel does not meet the CCPA's applicability thresholds today, but we honour these rights for any California user. We do not sell your personal information, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioural advertising, so there is no "Do Not Sell or Share" link because there is nothing to opt out of.
You have the right to know, access, delete, correct, and to non-discrimination for exercising any right. Exercise these by emailing privacy@viridel.com from the email on your account.
13. Your Rights
If you are in the EEA, UK, India, or a region with equivalent law, you have the rights below, which we honour globally where the processing makes them applicable:
- Access — request a copy of the personal data we hold about you.
- Portability — export all your data yourself as JSON and CSV from Settings.
- Rectification — most fields are editable directly in the app; email us for anything you cannot self-serve.
- Erasure — delete your account and cloud data from Settings (48-hour soft-delete, then permanent removal).
- Objection / restriction — email us to object to or restrict a specific processing activity.
- Withdraw consent — disable cloud sign-in or cloud sync at any time.
- Complain to a supervisory authority — you may always lodge a complaint with your local data-protection authority.
For any request you cannot self-serve, email privacy@viridel.com from your account email. We verify the request comes from you and respond within 30 days — usually much sooner. Viridel is not required to appoint a Data Protection Officer; the Grievance Officer (grievance@viridel.com) handles all data-protection enquiries.
14. Children & Age Thresholds
Viridel is not directed to children. You must be at least 13 years old to use the service, or at least 16 in the EEA/UK (or such higher age as your country requires). We do not knowingly collect personal data from anyone below the applicable threshold. If you believe a child has provided us personal data, email us and we will delete it without delay.
16. Changes to This Policy
We may update this policy. For material changes, we will notify you by email (if signed in) and/or post a notice in the app or on the site at least 30 days before they take effect. The most recent update date is shown at the top of this page.
17. Contact
Questions or requests about this policy or your personal data: privacy@viridel.com. Grievance Officer: Shiva Kumar Esakki Pandiyan, grievance@viridel.com. Related: Terms · Refund · Cookie Policy · Security · DPA.
Disclaimer & Updates
These pages describe how Viridel operates as a product. They are not legal advice. We may update them; for material changes we notify signed-in users by email and/or post a notice on the site or in the app. The date at the top of each page is authoritative.