Vireo Spend privacy
What Spend records, where it is kept, and who cannot see it.
Read this with Vireo’s main policy
This page explains what is specific to Vireo Spend. The Vireo-wide privacy also applies and covers the shared Vireo layer.
What Spend records
Spend records what you enter yourself: an amount and currency, the wallet it came from, a category, who it was with, an optional note, and the date. Nothing else is added on your behalf.
Spend does not connect to a bank, a card, or any account you hold elsewhere. There is no feed to import and no balance to read. If it is in your Spend ledger, you put it there.
Your ledger is yours
Every read and write happens under your own sign-in. Your entries are scoped to you in the database itself, and a reference from one person’s records to another’s cannot be constructed. Other participants in the beta cannot see your ledger, and you cannot see theirs.
What Vireo staff cannot see
The tool Vireo uses to run the beta cannot return an amount, a counterparty, a note, or a voice transcript. That is a property of the tool rather than a promise about our conduct: no command in it selects those fields, and the identifiers it does print are one-way stubs rather than your account.
It can count how many of the twenty places are taken, check whether scheduled jobs have run, record an invitation, open an incident, and complete a deletion you already confirmed. Every one of those writes records who did it and why.
On your phone
Entries save on your device first, so capture works with no signal, and reach your ledger when the signal returns. That local copy is bound to the account signed in on that device.
Voice notes
When you speak an entry, the audio is used to produce text and is never kept. Spend stores no recording, and there is none to hand over or recover.
The text of what you said is stored only if you turn on the separate voice-learning choice, and only encrypted. If the encryption key is not configured, the text is stored nowhere at all rather than stored in the clear. You can turn that choice off in Settings, and Spend stops keeping transcripts from that point.
Voice is limited to ten notes per person per day, counted on Belize’s day.
Optional use signals
At activation you may choose to share basic use signals that help us find rough edges — which screens are reached and where a flow stalls. These never include an amount, a place, a counterparty, or the text of a note.
The choice is recorded with your activation and is separate from the required terms. ⚠ To change it, write to contact@vireo.bz and name Vireo Spend.
Taking a copy, and leaving
You can build an export at any time. It contains everything your own eyes may see in Spend, as a single file, and deliberately excludes sign-in material, other people’s records, and stored voice transcripts. The download link works once and expires; if you need another copy, build another export.
Deleting your Spend records tells you first how much will go, asks you to type the word DELETE, signs out every device, and returns your place to the beta. It is not reversible, which is why the export is offered beside it.
A day is a Belize day
Spend decides which day an entry belongs to using Belize’s calendar day, not the clock of whatever server answered. A late-evening entry stays on the evening it happened, wherever you are when you record it.
Questions or requests
Contact contact@vireo.bz and name Vireo Spend in your message.