Viela ← back to the site

Privacy Policy

Effective as of July 11, 2026.

Plain-language summary: Viela keeps only what the app needs to work — your account (email, @username, photo), what you save and the itineraries you build. We use your location only with your permission, while the app is in use, to show places near you — and we keep no history of it. We don't sell your data, we use no advertising or trackers, and you can delete your account (and everything that's yours) at any time, right in the app.

1. Who we are

Viela is a place-discovery app and website controlled by Racka (CNPJ 49.116.170/0001-25) ("Viela", "we"). For any privacy or data protection matter, including to reach our data protection officer (art. 41 of the LGPD), write to hey@racka.com.br.

This policy explains, under the Brazilian General Data Protection Law — LGPD (Law No. 13,709/2018) — which personal data we process, for what purposes, who we share it with and what your rights are.

2. What data we collect

Account data

  • Email and password, when you create an account by email; or the basic data passed along by the provider when you use Sign in with Apple or Google (account identifier and email).
  • @username — generated automatically from the first part of your email and editable in your profile.
  • Profile photo (optional) and Instagram (optional).

Location

  • Only with your permission, only while the app is in use and with approximate precision (~100 m). There is no continuous tracking and no background location.
  • We use the coordinate to look up places near you — it is sent with the query and is not stored as a history.
  • When you suggest a place, the coordinate you send is recorded as the location of the suggested place (not as yours).

Content you create

  • Saved places ("want to go" / "been there"), collections and favorites.
  • Travel itineraries: destination, dates and planned stops.
  • Place suggestions: name, city, coordinates, category and note.
  • Reviews and content reports, when those features are available.

Calendar

With your permission, the app adds your itinerary stops to the calendar on your device. We do not read or store your other events.

Technical data

  • On the download link (QR code), we record metrics with no personal identification: platform (iOS/Android), scan origin and a snippet of the browser's user-agent.
  • Our infrastructure providers (Cloudflare and Supabase) may keep technical access logs under their standard platform practices.
  • If you leave your email on the site to be notified of the launch, we use that email only for Viela announcements — and you can leave the list at any time.
What we don't do: the site uses no cookies; we use no advertising, pixels or third-party trackers; we do not access your camera, microphone or contacts; we keep no history of your location; and we do not sell personal data.

3. Why we use it (purposes and legal bases)

PurposeLegal basis (LGPD, art. 7)
Create and maintain your account; save places, collections, itineraries and suggestions Performance of a contract (item V)
Show places near you using the device's location Consent (item I) — revocable in your device settings
Send transactional emails (sign-up confirmation, password reset) Performance of a contract (item V)
Notify you about the launch, if you leave your email on the site Consent (item I)
Moderation, curation, security and abuse prevention Legitimate interest (item IX)
Aggregate usage metrics for the download link Legitimate interest (item IX) — no personal identifiers
Comply with legal obligations and orders from authorities Legal obligation (item II)

4. What is public

Some data is visible to anyone, as the social side of Viela: your @username, your Instagram (if you fill it in), your profile photo, your published reviews and the collections you mark as public. Itineraries, saved places and reports are private.

5. Who we share it with

We do not sell personal data. We share it only with the processors and partners needed to run the service:

  • Supabase — database, authentication, photo storage and transactional email delivery.
  • Cloudflare — site and API infrastructure and the aggregate download-link metrics.
  • Apple and Google — when you choose to sign in with Apple or Google; and the app's maps use Apple Maps. Place information comes in part from Google Places — that is data about the places, not about you. The app uses Firebase (Google) only as a base library, with analytics disabled.
  • Uber, Waze and Apple Maps — only when you tap to get directions or request a ride, we send the destination (the place's name, address and coordinates) to the app you chose. Your identity is not sent, and your use of those apps is governed by their own terms.
  • Public authorities, if we are legally required.

6. International transfers

Our providers (Supabase, Cloudflare, Apple, Google) may store or process data outside Brazil. In those cases, the transfer follows art. 33 of the LGPD, with vendors that adopt contractual safeguards and recognized data protection standards.

7. How long we keep it

  • Account and content: for as long as the account exists.
  • Account deletion: available in the app itself (Profile → delete account) or by email. It erases your profile, photo, saved places, collections, reviews, itineraries and counters. Reports and suggested places that have already been published are kept unlinked from you (anonymized).
  • Suggestions declined in curation are deleted automatically within 7 days.
  • Removed itineraries remain inactive in our database (for internal statistics) and are permanently deleted with the account.
  • Technical logs may be kept for the period required by law (for example, the Brazilian Internet Civil Framework — Marco Civil da Internet).

8. Your rights (art. 18 of the LGPD)

You may, at any time, request: confirmation that we process your data; access to your data; correction; anonymization, blocking or deletion; portability; information about sharing; and withdrawal of consent (the location permission, for example, can be revoked right in your device settings, without affecting the rest of the app).

Just write to hey@racka.com.br — we respond within the deadlines set by the LGPD. If you prefer, you may also petition the ANPD (Brazilian National Data Protection Authority).

9. Security

All traffic is encrypted (TLS). Database access uses row-level security (RLS) rules, so each person can only access what is theirs; session tokens are kept in the device's Keychain; and the internal curation panel is restricted by credentials. No system is infallible, but we follow good practices to protect your data.

10. Children and teenagers

Viela is not directed at children under 13 and does not knowingly collect their data. If we learn of an account in that situation without the consent provided for in art. 14 of the LGPD, it will be deleted.

11. Changes to this policy

If this policy changes in a relevant way, we will let you know through the app or the site, with the new effective date at the top. The current version is effective as of July 11, 2026.

12. Contact

Racka (CNPJ 49.116.170/0001-25) — data protection officer: hey@racka.com.br.

© 2026 Viela · Racka (CNPJ 49.116.170/0001-25) · hey@racka.com.br

Privacy Policy · Terms of Use