Legal
Privacy Policy
Last updated 15 August 2026 (draft)
Vivio is operated by Sam M, trading as Vivio Solutions (ABN 66 834 759 267) ("Vivio", "I", "we"). This policy explains how I handle personal information when you visit the Vivio website, create or use an account, pay for a subscription, use the desktop app, submit a plan for AI-assisted reading, save a report, or contact me. Vivio is intended for business and trade users and isn't directed to children under 18.
Plan documents can contain personal information about people other than the account holder — names, addresses, or property details. Only upload plans you're authorised to use, and remove anything that isn't needed for the takeoff. I don't sell personal information or use it for third-party targeted advertising.
1. Information I collect
- Account and team: email address, display name, account role, team membership, and invited teammate email addresses. Supabase Auth handles passwords — Vivio never sees or stores them.
- Subscription and billing: selected plan, subscription status, Stripe customer and subscription references, payment status, and transaction metadata. Stripe receives your card details directly; Vivio never sees or stores a full card number or security code.
- Plans and reports: plan pages submitted for scanning, optional project name, extracted items and quantities, review flags, the generated report PDF, preparer/team member, and scan or report timestamps.
- Usage and support: which scans were run, when, and by whom; quota use; fault or security information needed to run the service; and anything included in support messages.
- Website and device: IP address, browser or device type, operating system, referring page, and similar request data collected by the website, its hosting/CDN, and its authentication and payment providers.
- Stored on your device: remembered email, Supabase refresh token, licence reference, app settings, local report files, and — if you choose to use one — your own Anthropic API key.
2. How I use it
- To create and secure accounts, maintain sessions, manage teams, and show account roles.
- To process plan pages, produce draft item lists, and generate downloadable reports.
- To save and retrieve cloud reports and track shared scan allowances.
- To start and administer subscriptions, verify payment status, and keep financial records.
- To send essential account, security, billing, and service messages.
- To send product news or offers, where you've consented or the law otherwise permits.
- To provide support, diagnose faults, prevent misuse, and protect the service.
- To comply with the law and establish, exercise, or defend legal claims.
If you don't provide required account, payment, or plan information, some features won't work.
3. Plan documents, AI processing, and reports
On a subscription, relevant plan pages are sent through Vivio's server-side proxy to Anthropic's Claude API. The proxy keeps Vivio's own Anthropic credential off your device and meters usage against your account. If you use your own Anthropic API key instead, scans are billed to your own Anthropic account.
Vivio does not add your original source PDF or image file to its saved-report store after a scan — only the page images needed for processing are used, and the original stays on your device unless you delete it. Anthropic's published commercial API terms generally describe automatic deletion of submitted content within 30 days for standard use, subject to Anthropic's own exceptions and any separately configured retention.
Reports are saved to your computer when you generate them. If you're signed in, a copy of the report and its details may also be uploaded to your account in Vivio's private report storage, where account-scoped access rules control which team members can see it.
4. Who receives information
I disclose information only as needed to operate Vivio, process payments, support users, protect the service, or comply with the law. The main recipients are:
- Anthropic — AI reading of relevant plan pages and generation of the extracted item list. Processing occurs in the United States and locations used by its subprocessors.
- Supabase — account authentication, database hosting, team data, usage records, session handling, and cloud report storage. Primary project region is ap-southeast-2 (Sydney, Australia).
- Stripe — embedded checkout, payment processing, subscription administration, and fraud prevention.
- Netlify and jsDelivr — website hosting/delivery and delivery of the Supabase browser library, including standard security and request logging.
I may also disclose information to professional advisers bound by confidentiality, a regulator or authority where required or authorised by law, or a successor in a genuine business sale or restructure, subject to appropriate safeguards. Where the information goes to an overseas recipient, I take reasonable steps appropriate to the circumstances before disclosing it.
5. Marketing communications
I may use your name, email address, and customer relationship information to send product news, feature announcements, and offers where you've given consent or the law otherwise permits. Every commercial message identifies Vivio, gives current contact details, and includes a clear way to unsubscribe. A minimal suppression record may be kept after you opt out, so I don't contact that address again.
6. Website technology and local app data
The website is hosted on Netlify and loads Supabase and Stripe functionality. Supabase may use browser storage to maintain your signed-in session; Stripe's embedded checkout may use cookies or similar storage to process payments and reduce fraud. The website does not intentionally add advertising trackers or behavioural analytics, though the providers above may collect technical information for their own service, security, and compliance purposes. Blocking browser storage or provider scripts may prevent sign-in or checkout from working.
The desktop app stores settings and credentials locally on your Windows device. The current build can store a login token and any API key you supply as plain, unencrypted text — this is a known limitation. Protect your Windows account and device, and clear the app's local data before handing the computer to anyone else. A signed-in subscription's managed licence key is session-only and is not written to disk.
7. How long I keep information
- Source plan pages aren't added to Vivio's saved-report store after a scan.
- Cloud reports and line items are kept while your account is active.
- Account, team, and usage data is kept while needed to run your account, administer billing and quotas, secure the service, and resolve disputes.
- Payment information is kept by Stripe under its own policy; Vivio keeps limited subscription and transaction references for as long as needed for service and financial records.
- Local device data stays on your device until you delete local reports or app data — removing your online account doesn't automatically remove files or credentials stored on a device.
- Website and provider logs are kept by the relevant hosting, CDN, authentication, and payment provider under its own retention schedule.
8. Security and data breaches
Vivio uses third-party authentication and password hashing through Supabase Auth, account-scoped access controls, and encrypted network connections. No internet or storage system can be guaranteed completely secure. You're responsible for protecting your device, account password, email account, and any API key you supply — tell me promptly if you suspect unauthorised access. If a data breach occurs, I'll assess it and notify affected people and regulators where required by law.
9. Your rights
You can ask me to access or correct personal information held about you, request deletion of your account and cloud reports, unsubscribe from marketing, or ask how your information was handled. Contact Vivioreplies@outlook.com. I may need to verify your identity and may refuse or limit a request where the law permits, and I'll explain why if so.
Deleting Vivio-held data doesn't automatically delete information already processed or retained by Anthropic, Stripe, Supabase, Netlify, or other providers under their own retention rules. It also doesn't remove local files, remembered sessions, or API keys already stored on a device.
10. Privacy complaints
Send a privacy complaint to Vivioreplies@outlook.com with enough detail for me to understand the issue, and I'll acknowledge and look into it within a reasonable timeframe. If you're not satisfied with my response and Australian privacy law applies, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
11. Changes to this policy
I may update this policy as the product, providers, or legal requirements change. The current version is always published here with a revised last-updated date, and I'll give reasonable notice of material changes where appropriate.
12. Contact
- Operator: Sam M, trading as Vivio Solutions (ABN 66 834 759 267)
- Privacy email: Vivioreplies@outlook.com
- Business region: South East Queensland, Australia