V$
va$ooli
Privacy Policy
Last updated: September 26, 2026
We collect only what's necessary to make the app work.
va$ooli is a personal project, not a commercial product. We collect minimal personal data —
only your email address, display name, and profile photo (when you sign in) — and use it
solely to identify you within your groups. We do not sell or share your data.
Please avoid entering sensitive information such as government IDs, financial account numbers,
or health information into the app.
What data is stored
va$ooli stores the following information:
- Account information — your email address and/or mobile phone number, display name, and profile photo (from Google Sign-In, Sign in with Apple, an email code, a phone sign-in, or entered directly). If you use Sign in with Apple's "Hide My Email," we receive an Apple-provided private relay address instead of your real email.
- Group names
- Names of people in a group (first names or nicknames)
- Expense descriptions, amounts, dates, and categories
- Trip details — destination, dates, notes
- Booking information — flights, hotels, activities you add
- Tasks and task assignments
- Files you upload as attachments (receipts, documents)
- Group cover photos you upload to customize your My Groups screen
- Email addresses of people invited to a group (entered by the person sending the invite)
- Invite records — who was invited, when, and whether the invite was claimed
- Your saved-people list — a private list of people you've added to or invited to groups (their name and email), kept so you can add them again quickly. It is visible only to you and persists across your groups, including after you leave a group. When this feature first launched, your list was seeded from people already in your groups.
- Booking confirmation emails you choose to forward to trips@getvasooli.com, and any secondary email addresses you register to forward from — see "Email itinerary import" below
- Reports you submit about objectionable content — the category, your description, and the group it relates to — kept so we can review and act on them
- Planner chat history — messages and prompts you exchange with AIda, va$ooli's trip-planning assistant, stored in our private database so your brainstormed suggestions remain accessible across sessions and devices
All data is stored in a private PostgreSQL database hosted on Supabase (US West region).
What we do NOT store
- Passwords — authentication is handled entirely by Google, Apple, or Supabase (email magic-link/code or a one-time SMS or WhatsApp code); va$ooli never sees or stores a password
- Device identifiers, IP addresses, or precise location data
- Browsing history or behavioral data
- Payment information of any kind
- Any information beyond what is necessary to operate the app
On-device storage
va$ooli stores your sign-in session on your device — in your browser's
localStorage
on the web, or in the app's local storage in the iOS/Android app — so you stay signed in between
visits. This session data is managed by Supabase Auth and stays on your device. Signing out, or
clearing the app's data / your browser data, removes it.
If you turn on Face ID, Touch ID, or fingerprint sign-in in the native app, va$ooli stores your
sign-in session in your device's secure hardware store (iOS Keychain / Android Keystore), protected
by your biometrics, so you can sign back in without re-entering an email code. Your biometric data
itself never leaves your device and is never seen by va$ooli — the operating system only tells the
app whether the check passed. This stored session stays on your device, is never sent to our
servers, and is removed when you turn the setting off or choose "Log out of this device".
To make the native app usable without a connection, va$ooli also caches a copy of your groups
on your device — expense, booking, and task data, group cover photos, and profile photos. This
lets you view (but not edit) your groups while offline. It's stored in the app's own sandboxed
storage, not accessible to other apps, and is cleared when you sign out, leave a group, or delete
your account.
We do not use tracking cookies or any third-party analytics.
Camera and photo access
When you choose to add a profile picture, a group cover photo, or an attachment, va$ooli may
open your device camera or photo library so you can take a new photo or pick an existing one.
This access happens only at that moment and only for the item you select — the app does not
browse, scan, or store your camera roll or photo library in the background. Only the specific
image you choose is uploaded, and it is then handled as described above (profile photos and
attachments on Supabase; group cover photos on Cloudinary).
Third-party services
va$ooli uses the following external services to provide specific features:
- Supabase — hosts our database (PostgreSQL), handles authentication, and stores uploaded files. This includes your profile photo, expense attachments (receipts, documents), and all group data. Files and data are stored on Supabase's servers in the US West region.
Supabase Privacy Policy ↗
- Twilio — delivers the one-time sign-in codes we send when you sign in with, or add, a phone number. In the U.S. and Canada the code is sent by SMS text; for numbers in other countries it is sent over WhatsApp. Your phone number is passed to Twilio (via Supabase Auth) solely to send that message; it is never used for marketing.
Twilio Privacy Policy ↗
- WhatsApp (Meta) — for sign-in codes delivered over WhatsApp (numbers outside the U.S. and Canada), your phone number and the one-time code pass through WhatsApp's messaging network, operated by Meta, to deliver the message.
WhatsApp Privacy Policy ↗
- Google Sign-In — used for authentication. When you sign in with Google,
we receive your email address, name, and profile photo from Google.
Google Privacy Policy ↗
- Sign in with Apple — used for authentication in the iOS/Android app and on the web. When you sign in with Apple, we receive your name and email address. If you choose "Hide My Email," Apple provides a private relay address instead of your real email, and relays our emails to you.
Apple Privacy Policy ↗
- Cloudflare Pages — serves the app's frontend files (HTML, CSS, JavaScript).
Standard access logs may be retained by Cloudflare.
Cloudflare Privacy Policy ↗
- Cloudinary — stores group cover photos you upload to customize your My Groups screen. Files are stored on Cloudinary's servers.
Cloudinary Privacy Policy ↗
- Mailgun — sends and receives email on behalf of the app: invite emails, magic-link sign-in emails, trip reports, notification and weekly-digest emails, and inbound email (booking confirmations you forward to trips@getvasooli.com, and messages to support@getvasooli.com). Your email address and any email you forward pass through Mailgun to deliver these.
Mailgun Privacy Policy ↗
- Google Places API — provides address autocomplete on hotel and restaurant booking forms.
Search queries are sent to Google.
Google Privacy Policy ↗
- AeroDataBox — provides flight information for flight bookings.
Flight number queries are sent to AeroDataBox via RapidAPI.
RapidAPI Privacy Policy ↗
- Anthropic (Claude) — when you forward a booking confirmation email to trips@getvasooli.com, the email's text is sent to Anthropic's Claude API to extract structured booking details (flight, hotel, rental car, or train/bus). If the text alone doesn't contain a recognizable booking, up to 5 PDF attachments (4 MB each, 8 MB total) are sent as well, excluding attachments that look like boilerplate by filename (terms, insurance, baggage policy, etc.). Extraction never records passport numbers, dates of birth, gender, or frequent-flyer numbers, even if a document contains them. The extracted result is shown to you for review before anything is saved. Anthropic does not train its models on data sent through the API.
Anthropic Privacy Policy ↗
- LinkPreview.net — when you add a link to a group, the URL is sent to LinkPreview.net to fetch a title, description, and thumbnail for the preview card.
LinkPreview Privacy Policy ↗
- Frankfurter — provides currency exchange rates for multi-currency expenses. Only currency codes are sent; no personal data is involved.
Frankfurter ↗
- Google (Gemini API) — powers AIda, va$ooli's conversational trip planner. The prompts and travel preferences you share with AIda are sent to Google's Gemini API to generate destination ideas, itineraries, and suggestions. AIda uses Google's free Gemini API tier first (with a paid tier as a backup), and on the free tier Google may use what you send to AIda to improve its products and AI models, and human reviewers may read it. Please don't share sensitive personal information (such as passport numbers, health details, or payment information) with AIda. Your chats with AIda are saved in va$ooli so you can pick them up later; they are private to you, and only the places you add reach your group's Trip Board.
Google Privacy Policy ↗
- Pexels — provides travel photos for trip cover pictures: the automatic picture a new trip gets, and the Search photos option on a trip card. Only the search words (a destination or the phrase you type) are sent to Pexels; no personal data or account information is shared. The photo you choose is shown directly from Pexels and is not uploaded or stored by va$ooli.
Pexels Privacy Policy ↗
- Wikimedia Foundation (Wikipedia) — provides a fallback cover picture for a new trip when Pexels has no match, using Wikipedia's public summary and search APIs. Only the destination name is sent to look up a matching article image; no personal data or account information is shared.
Wikimedia Privacy Policy ↗
Email itinerary import
If you forward a flight, hotel, rental-car, or train/bus confirmation email to trips@getvasooli.com, we process it to help you add the booking to a trip:
- The email's text is sent to Anthropic's Claude API to extract structured booking details. If the text doesn't contain enough detail — for example, the itinerary is only in an attached PDF ticket — up to 5 non-boilerplate PDF attachments are sent as well.
- The extracted details are saved to your pending-itineraries list and shown to you for review — nothing is added to a group until you confirm it.
- This only works if you forward from an email address linked to your account. You can register additional forwarding addresses in your profile; each must be verified with an emailed code before it will be trusted.
You can discard any pending itinerary at any time. If you never use this feature, no email content is ever processed.
Data sharing
We do not sell, trade, or share your data with any third parties beyond the service providers
listed above, which are necessary to operate the app.
If you sign in with your phone number, that number is used solely to deliver one-time
verification codes that sign you in — by SMS text, or (for numbers outside the U.S. and
Canada) over WhatsApp. Vasooli does not send marketing or promotional messages. Mobile phone
numbers are never shared with third parties or affiliates for marketing or promotional
purposes. Message and data rates may apply; reply STOP to opt out or HELP for help.
Group data is accessible only to people who have been added to the group and signed in. Email invites are personal — they are tied to the specific email address the invite was sent to. The native app also offers a shareable link invite: it is single-use and expires after 7 days, but anyone holding the link can join until it's used or expires, so treat it the way you'd treat sharing an email address.
Data retention
Group data is retained indefinitely unless you request deletion. There is no automatic
expiry — your trip data stays available as long as you need it.
Uploaded files (profile photos and expense attachments) are stored on Supabase Storage and are retained until deleted from within the app or upon a deletion request. Group cover photos you upload are stored on Cloudinary and are similarly retained until removed; a cover chosen through Search photos is a link to the photo on Pexels, not a stored copy.
Deleting your account & data
You can delete your account yourself, anytime, from within the app: go to
My Profile → Delete Account. This immediately removes your profile
(email, display name, profile photo), your registered forwarding addresses, your
notification settings, any pending itineraries, and your own saved-people list, and
unlinks you from your groups.
Where your name and email appear in other members' saved-people lists,
your email address is removed when you delete your account; only the name they gave you
may remain, the same as in shared expense history.
Alternatively, you can email support@getvasooli.com
with your email address and/or group name, and we will delete your data within 30 days.
Your first name may remain in historical expense records within groups you participated in,
as these records are shared with other group members. Uploaded files are removed when you delete
them in the app or when your account is deleted.
Changes to this policy
This policy may be updated from time to time. The date at the top of this page reflects
the most recent revision. Continued use of va$ooli after changes constitutes acceptance
of the updated policy.
Contact
Questions about this privacy policy? Email us at
support@getvasooli.com.
Vasooli is operated by Sriram Chatrathi, a sole proprietor based in San Jose, California. It is an independent service and is not affiliated with any other company.