Privacy Policy
Last updated: July 4, 2026
This policy describes how Vish("we") collects, uses and protects your personal data, in accordance with Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and, for users residing in the European Union, the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
Data we collect
- Account: name, email and password (encrypted) — or your Sign in with Apple data, if you use it.
- Profile (optional): date of birth and occupation, if you choose to provide them.
- Financial data you record:transactions, accounts, subscriptions and installment purchases that you tell the assistant about or add in the app. We don't access your bank accounts — only what you tell us exists.
- Conversations and media: messages exchanged with the assistant, and photos/audio you send to record expenses. Audio is transcribed on your device; only the resulting text reaches our servers.
- Usage data:message counts and processing cost, used to enforce your plan's limits.
- Push notifications: if you enable notifications, we store a device token (via Apple) solely for that purpose.
How we use it (and who we share it with)
Your data is used exclusively to operate the product. To do so, we use the following processors, which handle data on our behalf:
- OpenAI and Anthropic(processing conversations and photos to record your expenses) — your data is not used to train these providers' models;
- Railway (API hosting);
- Neon (database hosting, in Brazil);
- Resend (transactional email: account verification and password reset);
- Apple (Sign in with Apple and subscription processing — we have no access to your payment data).
OpenAI, Anthropic and Railway operate in the United States — using Vish therefore involves an international transfer of your data outside Brazil/the EU for that part of the processing (the database itself, on Neon, is hosted in Brazil). These transfers rely on those providers' standard contractual safeguards (contractual clauses equivalent to those required by the LGPD and the GDPR).
We don't sell your data or share it for advertising. Period.
Artificial intelligence
Expense recording is done by AI and can make mistakes (amounts, categories, receipt interpretation). The app asks for confirmation before destructive actions and lets you edit or delete any entry. Review anything important.
Your conversations and financial data are sent to our AI providers (OpenAI/Anthropic) without any masking step — this is necessary for the product's core functionality (the assistant needs to see your data to help you) and is done on the basis of performing the contract between you and Vish, not for advertising or profiling.
Legal basis for processing (GDPR)
- Performance of a contract: account, authentication, recording and organizing financial data, chatting with the assistant — this is what you signed up for when creating a Vish account.
- Consent: marketing communications (you can revoke this at any time, without affecting your use of the app).
- Legal obligation / legitimate interest: security, fraud prevention and compliance with legal requirements.
Retention and deletion
You can delete your account at any time inside the app (Profile → Delete account). Upon deletion, your personal data is completely and immediately erasedfrom our production systems — accounts, transactions, conversations, the assistant's memory and credentials. There is no intermediate anonymization step or retention window: deletion is final and cannot be undone.
One honest caveat: like any cloud service, our database provider keeps a very short-lived technical history (up to 6 hours) solely for recovery in case of a severe failure — this is not an actively used backup, and that history rolls off and is discarded automatically too. This is standard industry practice (protection against failures, not active use of your data) and is not under our direct control.
Your rights
You can request access, correction, portability or deletion of your data, and revoke consents, by writing to privacy@vishapp.com.br. We respond within 1 month (the GDPR deadline, which we also follow for users in Brazil), extendable in complex cases. For access and portability, the fastest path is exporting your data directly in the app (Profile → My data) — the email above is the alternative path and covers all other requests.
Data controller / privacy contact
Vish is operated by its founder, Sérgio, who also acts as the data protection contact (LGPD "encarregado"). Contact: privacy@vishapp.com.br (temporary address, until we have a dedicated email on Vish's own domain).
European Union representative
Vish is run by a single founder and has not appointed a formal representative in the European Union (Article 27 of the GDPR) — we assess that our processing falls under the Article 27(2) exception for occasional, low-risk processing. If you are a data protection authority or an EU data subject and need direct contact, write to privacy@vishapp.com.br — we respond directly.
Security
Data travels encrypted (TLS) and is stored with access controls. Passwords are never stored in plain text. Your session token stays in the iOS Keychain on your device.
Contact
Questions about this policy: privacy@vishapp.com.br.