V$
va$ooli
Privacy Policy
Last updated: August 13, 2026
We collect only what's necessary to make the app work.
va$ooli is a personal project, not a commercial product. We collect minimal personal data —
only your email address, display name, and profile photo (when you sign in) — and use it
solely to identify you within your groups. We do not sell or share your data.
Please avoid entering sensitive information such as government IDs, financial account numbers,
or health information into the app.
What data is stored
va$ooli stores the following information:
- Account information — your email address, display name, and profile photo (from Google Sign-In, Sign in with Apple, or entered directly). If you use Sign in with Apple's "Hide My Email," we receive an Apple-provided private relay address instead of your real email.
- Group names
- Names of people in a group (first names or nicknames)
- Expense descriptions, amounts, dates, and categories
- Trip details — destination, dates, notes
- Booking information — flights, hotels, activities you add
- Tasks and task assignments
- Files you upload as attachments (receipts, documents)
- Group cover photos you upload to customize your My Groups screen
- Email addresses of people invited to a group (entered by the person sending the invite)
- Invite records — who was invited, when, and whether the invite was claimed
- Your saved-people list — a private list of people you've added to or invited to groups (their name and email), kept so you can add them again quickly. It is visible only to you and persists across your groups, including after you leave a group. When this feature first launched, your list was seeded from people already in your groups.
- Booking confirmation emails you choose to forward to trips@getvasooli.com, and any secondary email addresses you register to forward from — see "Email itinerary import" below
- Reports you submit about objectionable content — the category, your description, and the group it relates to — kept so we can review and act on them
All data is stored in a private PostgreSQL database hosted on Supabase (US West region).
What we do NOT store
- Passwords — authentication is handled entirely by Google, Apple, or Supabase (magic-link email)
- Device identifiers, IP addresses, or precise location data
- Browsing history or behavioral data
- Payment information of any kind
- Any information beyond what is necessary to operate the app
On-device storage
va$ooli stores your sign-in session on your device — in your browser's
localStorage
on the web, or in the app's local storage in the iOS/Android app — so you stay signed in between
visits. This session data is managed by Supabase Auth and stays on your device. Signing out, or
clearing the app's data / your browser data, removes it.
If you turn on Face ID, Touch ID, or fingerprint sign-in in the native app, va$ooli stores your
sign-in session in your device's secure hardware store (iOS Keychain / Android Keystore), protected
by your biometrics, so you can sign back in without re-entering an email code. Your biometric data
itself never leaves your device and is never seen by va$ooli — the operating system only tells the
app whether the check passed. This stored session stays on your device, is never sent to our
servers, and is removed when you turn the setting off or choose "Log out of this device".
To make the native app usable without a connection, va$ooli also caches a copy of your groups
on your device — expense, booking, and task data, group cover photos, and profile photos. This
lets you view (but not edit) your groups while offline. It's stored in the app's own sandboxed
storage, not accessible to other apps, and is cleared when you sign out, leave a group, or delete
your account.
We do not use tracking cookies or any third-party analytics.
Camera and photo access
When you choose to add a profile picture, a group cover photo, or an attachment, va$ooli may
open your device camera or photo library so you can take a new photo or pick an existing one.
This access happens only at that moment and only for the item you select — the app does not
browse, scan, or store your camera roll or photo library in the background. Only the specific
image you choose is uploaded, and it is then handled as described above (profile photos and
attachments on Supabase; group cover photos on Cloudinary).
Third-party services
va$ooli uses the following external services to provide specific features:
- Supabase — hosts our database (PostgreSQL), handles authentication, and stores uploaded files. This includes your profile photo, expense attachments (receipts, documents), and all group data. Files and data are stored on Supabase's servers in the US West region.
Supabase Privacy Policy ↗
- Google Sign-In — used for authentication. When you sign in with Google,
we receive your email address, name, and profile photo from Google.
Google Privacy Policy ↗
- Sign in with Apple — used for authentication in the iOS/Android app and on the web. When you sign in with Apple, we receive your name and email address. If you choose "Hide My Email," Apple provides a private relay address instead of your real email, and relays our emails to you.
Apple Privacy Policy ↗
- Cloudflare Pages — serves the app's frontend files (HTML, CSS, JavaScript).
Standard access logs may be retained by Cloudflare.
Cloudflare Privacy Policy ↗
- Cloudinary — stores group cover photos you upload to customize your My Groups screen. Files are stored on Cloudinary's servers.
Cloudinary Privacy Policy ↗
- Mailgun — sends and receives email on behalf of the app: invite emails, magic-link sign-in emails, trip reports, notification and weekly-digest emails, and inbound email (booking confirmations you forward to trips@getvasooli.com, and messages to support@getvasooli.com). Your email address and any email you forward pass through Mailgun to deliver these.
Mailgun Privacy Policy ↗
- Google Places API — provides address autocomplete on hotel and restaurant booking forms.
Search queries are sent to Google.
Google Privacy Policy ↗
- AeroDataBox — provides flight information for flight bookings.
Flight number queries are sent to AeroDataBox via RapidAPI.
RapidAPI Privacy Policy ↗
- Anthropic (Claude) — when you forward a booking confirmation email to trips@getvasooli.com, the email's text is sent to Anthropic's Claude API to extract structured booking details (flight, hotel, or car). If the text alone doesn't contain a recognizable booking, up to 5 PDF attachments (4 MB each, 8 MB total) are sent as well, excluding attachments that look like boilerplate by filename (terms, insurance, baggage policy, etc.). Extraction never records passport numbers, dates of birth, gender, or frequent-flyer numbers, even if a document contains them. The extracted result is shown to you for review before anything is saved. Anthropic does not train its models on data sent through the API.
Anthropic Privacy Policy ↗
- LinkPreview.net — when you add a link to a group, the URL is sent to LinkPreview.net to fetch a title, description, and thumbnail for the preview card.
LinkPreview Privacy Policy ↗
- Frankfurter — provides currency exchange rates for multi-currency expenses. Only currency codes are sent; no personal data is involved.
Frankfurter ↗
Email itinerary import
If you forward a flight, hotel, or rental-car confirmation email to trips@getvasooli.com, we process it to help you add the booking to a trip:
- The email's text is sent to Anthropic's Claude API to extract structured booking details. If the text doesn't contain enough detail — for example, the itinerary is only in an attached PDF ticket — up to 5 non-boilerplate PDF attachments are sent as well.
- The extracted details are saved to your pending-itineraries list and shown to you for review — nothing is added to a group until you confirm it.
- This only works if you forward from an email address linked to your account. You can register additional forwarding addresses in your profile; each must be verified with an emailed code before it will be trusted.
You can discard any pending itinerary at any time. If you never use this feature, no email content is ever processed.
Data sharing
We do not sell, trade, or share your data with any third parties beyond the service providers
listed above, which are necessary to operate the app.
If you sign in with your phone number, that number is used solely to deliver one-time
verification codes that sign you in. Vasooli does not send marketing or promotional text
messages. Mobile phone numbers are never shared with third parties or affiliates for
marketing or promotional purposes. Message and data rates may apply; reply STOP to opt out
or HELP for help.
Group data is accessible only to people who have been added to the group and signed in. Email invites are personal — they are tied to the specific email address the invite was sent to. The native app also offers a shareable link invite: it is single-use and expires after 7 days, but anyone holding the link can join until it's used or expires, so treat it the way you'd treat sharing an email address.
Data retention
Group data is retained indefinitely unless you request deletion. There is no automatic
expiry — your trip data stays available as long as you need it.
Uploaded files (profile photos and expense attachments) are stored on Supabase Storage and are retained until deleted from within the app or upon a deletion request. Group cover photos are stored on Cloudinary and are similarly retained until removed.
Deleting your account & data
You can delete your account yourself, anytime, from within the app: go to
My Profile → Delete Account. This immediately removes your profile
(email, display name, profile photo), your registered forwarding addresses, your
notification settings, any pending itineraries, and your own saved-people list, and
unlinks you from your groups.
Where your name and email appear in other members' saved-people lists,
your email address is removed when you delete your account; only the name they gave you
may remain, the same as in shared expense history.
Alternatively, you can email support@getvasooli.com
with your email address and/or group name, and we will delete your data within 30 days.
Your first name may remain in historical expense records within groups you participated in,
as these records are shared with other group members. Uploaded files are removed when you delete
them in the app or when your account is deleted.
Changes to this policy
This policy may be updated from time to time. The date at the top of this page reflects
the most recent revision. Continued use of va$ooli after changes constitutes acceptance
of the updated policy.
Contact
Questions about this privacy policy? Email us at
support@getvasooli.com.
Vasooli is operated by Sriram Chatrathi, a sole proprietor based in San Jose, California. It is an independent service and is not affiliated with any other company.