VISH

Ler em português

Privacy Policy

Last updated: July 4, 2026

This policy describes how Vish("we") collects, uses and protects your personal data, in accordance with Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and, for users residing in the European Union, the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

Data we collect

How we use it (and who we share it with)

Your data is used exclusively to operate the product. To do so, we use the following processors, which handle data on our behalf:

OpenAI, Anthropic and Railway operate in the United States — using Vish therefore involves an international transfer of your data outside Brazil/the EU for that part of the processing (the database itself, on Neon, is hosted in Brazil). These transfers rely on those providers' standard contractual safeguards (contractual clauses equivalent to those required by the LGPD and the GDPR).

We don't sell your data or share it for advertising. Period.

Artificial intelligence

Expense recording is done by AI and can make mistakes (amounts, categories, receipt interpretation). The app asks for confirmation before destructive actions and lets you edit or delete any entry. Review anything important.

Your conversations and financial data are sent to our AI providers (OpenAI/Anthropic) without any masking step — this is necessary for the product's core functionality (the assistant needs to see your data to help you) and is done on the basis of performing the contract between you and Vish, not for advertising or profiling.

Legal basis for processing (GDPR)

Retention and deletion

You can delete your account at any time inside the app (Profile → Delete account). Upon deletion, your personal data is completely and immediately erasedfrom our production systems — accounts, transactions, conversations, the assistant's memory and credentials. There is no intermediate anonymization step or retention window: deletion is final and cannot be undone.

One honest caveat: like any cloud service, our database provider keeps a very short-lived technical history (up to 6 hours) solely for recovery in case of a severe failure — this is not an actively used backup, and that history rolls off and is discarded automatically too. This is standard industry practice (protection against failures, not active use of your data) and is not under our direct control.

Your rights

You can request access, correction, portability or deletion of your data, and revoke consents, by writing to privacy@vishapp.com.br. We respond within 1 month (the GDPR deadline, which we also follow for users in Brazil), extendable in complex cases. For access and portability, the fastest path is exporting your data directly in the app (Profile → My data) — the email above is the alternative path and covers all other requests.

Data controller / privacy contact

Vish is operated by its founder, Sérgio, who also acts as the data protection contact (LGPD "encarregado"). Contact: privacy@vishapp.com.br (temporary address, until we have a dedicated email on Vish's own domain).

European Union representative

Vish is run by a single founder and has not appointed a formal representative in the European Union (Article 27 of the GDPR) — we assess that our processing falls under the Article 27(2) exception for occasional, low-risk processing. If you are a data protection authority or an EU data subject and need direct contact, write to privacy@vishapp.com.br — we respond directly.

Security

Data travels encrypted (TLS) and is stored with access controls. Passwords are never stored in plain text. Your session token stays in the iOS Keychain on your device.

Contact

Questions about this policy: privacy@vishapp.com.br.