Privacy Policy
Last updated: 30 April 2026
Effective date: 30 April 2026
This Privacy Policy explains how Vishnu Vijayakumar, a sole proprietor based in India operating the “Deviza” service (the “Service”, “we”, “us”), collects, uses, discloses, and safeguards information about you (the “User”, “you”) when you use devizalabs.com or our Telegram bot.
We have written this policy to comply with: the EU and UK General Data Protection Regulation (“GDPR”), the Indian Digital Personal Data Protection Act, 2023 (“DPDP Act”), the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”), the Virginia, Colorado, Connecticut, Utah, and other US state privacy laws, the Australian Privacy Act 1988 and the Australian Privacy Principles (“APPs”), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”), and the Saudi Personal Data Protection Law (“KSA PDPL”).
1. Who is the data controller
For users in the European Economic Area, the United Kingdom, and Switzerland, the data controller is Vishnu Vijayakumar. For users in India, we are the Data Fiduciary under the DPDP Act. For users in California, we are the Business under the CCPA/CPRA.
You can reach us at:
- Email: devizalabs@gmail.com
- Postal address: available on written request to the email above.
We have not appointed a Data Protection Officer because we are not required to under GDPR Art. 37 or DPDP §10. If we cross the regulatory threshold (e.g. are designated a Significant Data Fiduciary under the DPDP Act), this section will be updated.
2. What we collect
2.1 Information you provide
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Email address, password hash (managed by Supabase Auth), Google OAuth ID | You, on sign-up |
| Profile data | Display name, currency, locale, household member names | You, on onboarding |
| Financial transaction data | Date, amount, category, description, payment mode, classification, free-text notes | You, via manual entry, file upload, or Telegram bot |
| Source documents | WhatsApp chat exports (.txt), bank statement PDFs, CSV files | You, via the upload feature. Files are processed in memory and not stored. |
| Telegram identifiers | Telegram chat ID, link tokens (short-lived) | You, when linking Telegram |
| Payment records | Subscription tier, plan expiry, gateway payment / order ID | Razorpay or Lemon Squeezy webhook (we do not see card numbers) |
2.2 Information we collect automatically
- Authentication cookies set by Supabase Auth so we can keep you signed in. These are first-party, HTTP-only, and essential to the Service.
- Browser session storage for your chosen month and theme preference. This stays on your device and is never transmitted to us.
- Server logs from our hosting provider (Vercel) and our database (Supabase) which include IP addresses, user-agent strings, and request timestamps. Used only for security, debugging, and abuse prevention. Vercel retains access logs for up to 30 days.
2.3 Information we do not collect
- We do not use third-party advertising trackers, marketing pixels, or behavioural-analytics SDKs.
- We do not collect biometric data.
- We do not collect precise geolocation. We may infer your locale from your browser’s timezone for currency formatting; this is processed in your browser.
- We do not knowingly collect data from anyone under 18 (see Section 9).
3. Why we use your data — legal basis & purposes
Under GDPR Art. 6 we rely on the following legal bases. Under the DPDP Act we rely on consent or “legitimate uses” under §7. Under the CCPA we process for the “Business Purposes” declared below.
| Purpose | Legal basis (GDPR) | Legal basis (DPDP) |
|---|---|---|
| Provide the Service (account, dashboard, AI extraction) | Contract (Art. 6(1)(b)) | Consent / performance of contract |
| Process payments & manage subscriptions | Contract (Art. 6(1)(b)) | Consent / performance of contract |
| Detect fraud, abuse, and enforce plan limits | Legitimate interest (Art. 6(1)(f)) | Legitimate use under §7 |
| Comply with tax, accounting, and legal obligations | Legal obligation (Art. 6(1)(c)) | Legal obligation under §7 |
| Send transactional email (password reset, payment receipts) | Contract (Art. 6(1)(b)) | Consent / performance of contract |
| Improve the Service via aggregated, non-identifying metrics | Legitimate interest (Art. 6(1)(f)) | Legitimate use under §7 |
We do not send marketing email and do not sell, rent, or share your personal information for cross-context behavioural advertising. For CCPA/CPRA purposes, we have not “sold” or “shared” (as defined in the statute) personal information in the preceding 12 months.
4. AI processing of your transactions
When you upload a chat or statement, or send text to our Telegram bot, we send the relevant text to Google’s Gemini API for structured extraction of transaction fields (amount, category, description). We use the paid tier of the Gemini API; per Google’s Gemini API Additional Terms, Google does not use API requests to train or improve its generative models for paid customers, and Google retains the prompts and responses only for the period necessary to detect and prevent abuse. Google’s data processing is governed by their Data Processing Addendum.
We do not use any of your transaction data to train our own models. The AI-generated outputs (categorisation, classification) are decisions made by an algorithm; you may at any time edit, override, or delete any AI-generated value. Under GDPR Art. 22 you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; the AI here is purely advisory and does not produce such effects.
5. Who we share data with — sub-processors
We disclose personal data only to vendors who help us run the Service. Each is bound by a written data-processing agreement. Current sub-processors:
| Vendor | Purpose | Location |
|---|---|---|
| Supabase | Authentication & database hosting (PostgreSQL) | Mumbai, India (ap-south-1) |
| Vercel | Application hosting, edge functions, access logs | Global edge network |
| Google LLC | Gemini API for AI transaction extraction; OAuth sign-in | USA & global |
| Razorpay Software Pvt. Ltd. | Payment processing for users billed in INR | India |
| Lemon Squeezy LLC | Payment processing for users billed outside India | USA & global |
| Telegram Messenger Inc. | Bot API (only if you choose to link Telegram) | Global |
We will publish material changes to this list at least 30 days in advance on this page. Other than the categories above, we share personal data only:
- with your explicit consent;
- to comply with legal obligations, court orders, or lawful government requests, after verifying the request and notifying you where legally permitted;
- to protect our rights, property, or the safety of our users or the public; or
- in connection with a merger, acquisition, or sale of assets — in which case we will give 30 days’ advance notice and you may delete your account before the transfer.
6. International data transfers
Your account, profile, and transaction data are stored in India (Supabase ap-south-1, Mumbai). However:
- To the United States:When we call the Gemini API or process payments via Lemon Squeezy, data may be transferred to the United States. For users in the EEA / UK / Switzerland, these transfers rely on the European Commission’s Standard Contractual Clauses (Module 2 / Module 3) and any supplementary measures recommended by the European Data Protection Board.
- Globally: Vercel routes traffic through its global edge network. Static content is cached at the edge; personal data writes go straight to our database in India.
Under the DPDP Act §16, the Government of India may notify countries to which cross-border transfer is restricted; as of the date of this policy, no such restriction applies to the destinations above.
7. How long we keep data
- Active account data (profile, transactions, telegram link) is kept for as long as your account is active.
- Account deletion: When you delete your account from Settings, we soft-delete your data immediately (hidden from all surfaces, inaccessible to support) and hard-delete it 30 days later. Within those 30 days you can email us to recover the account.
- Payment and tax records (invoice ID, plan, amount, date) are retained for 7 years after your last transaction, as required by §44AA of the Income-tax Act, 1961, and §35 of the CGST Act, 2017. These records are minimised — they do not contain transaction descriptions or other expense details.
- Server logs are retained by our hosting providers per their standard retention (Vercel: up to 30 days; Supabase: up to 7 days for database logs).
- Backups: Supabase performs automated point-in-time recovery backups retained for up to 7 days, after which deleted records are no longer recoverable.
8. Your rights
You have the following rights, exercisable by emailing devizalabs@gmail.com. We will respond within 30 days (extendable by 60 days for complex requests under GDPR; 45 days under CCPA, extendable by 45 more). We do not charge for requests, except that we may charge a reasonable fee for manifestly unfounded or excessive requests as permitted by Art. 12(5) GDPR.
8.1 Rights available to all users
- Access — get a copy of the personal data we hold about you.
- Portability — receive your data in a structured, machine-readable format. You can also export your transactions as CSV from inside the app.
- Rectification — correct inaccurate data. The app already lets you edit any transaction or profile field.
- Erasure — delete your account and personal data, subject to the 7-year tax-record retention noted above.
- Object & restrict — object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
- Withdraw consent — at any time, without affecting the lawfulness of processing performed before withdrawal.
8.2 EU / UK / Switzerland (GDPR)
In addition to Section 8.1, you may lodge a complaint with your supervisory authority. A list of EU authorities is at edpb.europa.eu. The UK supervisory authority is the ICO.
8.3 India (DPDP Act)
You may nominate another individual to exercise your rights in the event of your death or incapacity (DPDP §14). You may also lodge a grievance with the Data Protection Board of India once it is operational. Our grievance officer is reachable at devizalabs@gmail.com.
8.4 California (CCPA / CPRA)
California residents may, in addition to Section 8.1, request the categories and specific pieces of personal information we have collected, and a list of categories we have disclosed. You have the right not to receive discriminatory treatment for exercising any of these rights. We do not sell or share personal information; therefore there is no “Do Not Sell or Share” opt-out link to display. You may designate an authorised agent to make a request on your behalf.
8.5 Other US states
If you reside in Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive privacy law, you have the rights described in Section 8.1. Where the relevant statute provides for an appeal of a denied request, you may appeal by replying to our response email; we will respond to the appeal within the statutory period (e.g. 60 days under VCDPA).
8.6 Australia (Privacy Act 1988)
You may complain about our handling of your personal information directly to us; if unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC).
8.7 UAE / Saudi Arabia / GCC
Users in the United Arab Emirates may complain to the UAE Data Office; users in Saudi Arabia may complain to the Saudi Data & AI Authority (SDAIA).
9. Children
The Service is not directed to and not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us personal data, please email devizalabs@gmail.com and we will delete it promptly.
10. Security
We use industry-standard safeguards to protect your data:
- TLS 1.2+ in transit and AES-256 at rest (provided by Supabase).
- Row-level security (RLS) policies on every table that contains user data; users can read or modify only their own rows.
- Authentication cookies are
HttpOnlyandSameSite=Lax; passwords are hashed (bcrypt) by Supabase. - Webhook signatures are verified with constant-time HMAC comparison.
- API tokens (Telegram link tokens) are generated with a cryptographically-secure random source and expire in 15 minutes.
- Production secrets are never committed to source control.
No system is perfectly secure. If we discover a personal data breach we will notify the affected users and the relevant supervisory authority within 72 hours of becoming aware (GDPR Art. 33), as soon as reasonably possible (DPDP §8(6)), or as required by the applicable US state notification law, whichever is shortest.
11. Cookies
We use only first-party, strictly-necessary cookies set by Supabase Auth to keep you signed in and to refresh your session token. We do not use cookies for marketing, analytics, or cross-site tracking. Because we use only strictly-necessary cookies, no consent banner is required under the EU ePrivacy Directive or the UAE Cabinet Resolution No. 31 of 2023.
12. Do Not Track / Global Privacy Control
We do not engage in cross-context behavioural advertising and we do not sell or share personal information. Where the Global Privacy Control (GPC) signal applies, it is observed by default because we do not engage in the activities that GPC opts you out of.
13. Changes to this policy
We may update this policy. If we make material changes that affect your rights, we will notify you by email and/or by a prominent in-app notice at least 30 days before the change takes effect. The “Last updated” date at the top reflects the latest revision. Continuing to use the Service after the effective date constitutes acceptance.
14. Contact
For any privacy-related question, request, or complaint, contact us at devizalabs@gmail.com or by post at the address in Section 1.