This Privacy Policy explains how ViaraNexus Technologies Private Limited ("we", "us", "our") collects, uses, and protects information across our website and apps, including Rook (Family Financial OS) and Gains In Motion (GIM), our AI-assisted fitness tracker and its built-in chatbot, Gimo. As we build AI-powered software for personal finance, fitness, and education, this policy will be updated to cover additional apps as they launch.

Information we collect

Rook (Family Financial OS). Account credentials — email address and hashed password, managed by Supabase Auth. Family member profiles — names and any details you choose to add. Financial records — bank accounts, investments, loans, insurance, goals, expenses, and other data you enter. Brokerage connections — if you connect Zerodha Kite, a daily access token and your holdings data (the token expires at midnight IST and is never shared). Push notification subscriptions, if you opt in. Rook does not collect usage analytics, advertising identifiers, or any data beyond what you explicitly enter. See Rook's own Privacy Policy for full detail.

Gains In Motion (GIM). Account info — email, name, and role (athlete or coach). Activities synced from Strava — distance, pace, heart rate, elevation, and similar summary and stream data, via the read-only activity:read (or activity:read_all, if you choose to share private activities) OAuth scope. GIM never requests your segments, kudos, comments, gear, or Strava social connections. Training data you or your coach create — workouts, goals, plans, and notes. Push notification subscription details, only if you opt in. Conversations with Gimo, GIM's in-app AI assistant — stored so your conversation history persists across visits, visible to you (or your coach, for a conversation about you) any time inside the chat panel.

This website. If you use the contact form, we collect the name, email, and message you submit.

How we use information

We use collected information to provide core app functionality, generate the AI-assisted features described below, improve our apps, and respond to support requests. We don't use your data to serve ads, and we don't sell it.

How it's protected

All traffic between your device and our apps is encrypted in transit (HTTPS/TLS), and we don't sell your data or share it beyond what's needed to run the features described here.

In Rook, personally identifiable fields (PAN, Aadhaar references, account numbers) are encrypted at rest (AES-GCM-256) before being stored. Every record is isolated to your account via Supabase Row Level Security, so no other user can access your data. Data is stored in Supabase (PostgreSQL) on AWS infrastructure; Vercel hosts Rook's front-end and serverless API functions.

In GIM, data lives in a Postgres database (Supabase) behind Row Level Security — enforced at the database level on every query, so an athlete can only read their own data and a coach can only read the athletes they're actually connected to. Strava access and refresh tokens are encrypted at rest (AES-256-GCM) and only decrypted server-side, momentarily, when an API call needs to be made on your behalf.

AI features and your data

Gimo, GIM's in-app chat assistant, and the AI coaching commentary in GIM (summaries, recaps, training plans) are powered by Anthropic (Claude). Anthropic receives the structured training data needed to do its job (paces, distances, recent activity, targets) — never your credentials or Strava tokens — plus whatever you type into the Gimo chat itself. Consistent with Anthropic's standard API terms, this data is not used to train their models and is retained only as long as needed to provide the service and meet legal or safety requirements. As we add AI-assisted features to Rook and future apps, this section will be updated to describe them.

Third parties and subprocessors

Zerodha Kite Connect — if you connect a Zerodha account in Rook, we request a read-only access token through Kite Connect's official OAuth flow, used only to read your equity holdings and never to place or modify orders; the token is stored encrypted and expires daily. Strava is the source of GIM's activity data — GIM only reads what you've authorized via Strava's own OAuth flow, and never posts on your behalf. Anthropic (Claude) powers GIM's AI features, as described above. Vercel hosts our apps and this website. Supabase (PostgreSQL) stores data for both Rook (on AWS infrastructure) and GIM.

Your choices and rights

In Rook, everything you enter is visible to you within the app at any time. You may request full deletion of your account and all associated data by emailing rook.support@viara.tech — we action deletion requests within 7 days. Contact us at the same address to request a copy of your data in a portable format. Rook uses browser local storage only to maintain your login session and app preferences (theme, member filter) — no tracking cookies are used.

In GIM, you can disconnect Strava any time from Settings — this stops future syncing and permanently deletes your synced Strava activity history within 24 hours; revoking access from Strava's own settings has the same effect. You can delete your GIM account any time from Settings, which removes your account and its associated training data. Push notifications are opt-in per device and can be revoked any time.

Beyond in-app controls, you can ask us to access, correct, export, or delete the personal data we hold about you at any time by emailing privacy@viara.tech. If you believe we haven't handled your data properly, you also have the right to lodge a complaint with your local data protection authority.

Children's privacy

Our apps are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we've collected information from a child under 13, we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will notify users of material changes by updating the date at the top of this page.

Contact us

Questions about this policy? For Rook-specific privacy questions or data requests, email rook.support@viara.tech. For GIM or general questions, email privacy@viara.tech, or reach out via our Contact page.