Last updated: June 15, 2026
When you join the VRITTI waitlist or create an account, we collect your email address and, optionally, your business name and province. When you use VRITTI, we collect transaction data you input, account information you connect, and usage analytics to improve the product.
We use your information to:
AI features (Ask Vritti chat and voice replies, receipt scanning, and PDF statement import) are powered by Anthropic (Claude Haiku 4.5): your message, an aggregated summary of your numbers, or the document being scanned is processed by Anthropic's commercial API to generate the result. Per Anthropic's commercial API terms, API inputs are not used to train models by default, and the receipt or statement is used for one-time extraction and not retained by the extraction service. We do not send your name, email, or account id to Anthropic. Conversations are stored encrypted on your device only. Voice input is transcribed by Apple or Google's speech recognition service (processed per your device settings) — VRITTI receives only the text, never the audio. Subscription billing is handled by Apple. We name any new processor before its data flow begins.
Your data is stored in Supabase, our managed Postgres backend, with row-level security (RLS) so you can only read your own rows — the server enforces this even if a query forgets to. All traffic is encrypted in transit over HTTPS; we never accept unencrypted connections. Connection tokens for any bank or platform you link are encrypted at rest in Supabase Vault — the values in our database are opaque references, and only the server can decrypt them. Your auth session lives in iOS Keychain or Android Keystore, not plain device storage. We never store your bank credentials directly; bank connections, when they ship, are handled through a secure read-only integration.
We do not sell, rent, or trade your personal information, and we never train AI models on your data or serve ads. We share data only with the service providers essential to running VRITTI, each of which sees only the minimum it needs:
Each provider is bound by its own privacy commitments and data-processing terms. We will not add a new sub-processor without updating this policy first.
You have the right to:
We honour these rights under PIPEDA (Canada) and similar laws. While your account is active we keep your data only as long as the app needs it to work. After you delete, we wipe everything immediately, except where law requires retention (Canadian tax records, for example, must be kept for six years). Encrypted backups roll off within 30 days.
VRITTI uses minimal analytics to understand how the product is used. We do not use third-party advertising trackers. This website records first-party page events; the app sends pseudonymous product events to PostHog (US-hosted), tied to a random account id — never your amounts or transaction details — and you can turn them off any time in the app under Settings → Privacy.
VRITTI is for self-employed adults. We do not knowingly collect data from anyone under 16. If you believe a minor has signed up, email us and we'll delete the account.
We may update this policy as VRITTI evolves. For material changes — new sub-processors, new data categories, new retention rules — we'll notify you by email or through the app at least 14 days before the changes take effect.
For privacy questions or data requests, email us at hello@vritti.app.