Skip to main content

Privacy policy

Your information should help you move forward—not follow you everywhere.

What viamu collects, why it uses that information, how long it keeps it, who receives it, and the choices available to you.

Effective and last updated: August 11, 2026 · Version 2026-08-11

On this page
  1. Who is responsible for this information
  2. Information we collect—and what is optional
  3. How we receive information
  4. How we use information
  5. Lawful bases and purpose mapping
  6. Marketing messages
  7. Cookies, app storage, and device permissions
  8. Mobile app data and permissions
  9. When information is disclosed
  10. Provider websites and other third parties
  11. How long we keep information
  12. How we protect information
  13. Eligibility comparisons and automated processing
  14. Planned recommendations from public profiles
  15. Your choices and privacy rights
  16. Children and younger students
  17. International processing
  18. Service providers and data locations
  19. Changes to this policy

This document is currently available only in English. We are not presenting an unreviewed machine translation as legal text. Contact us if you need help understanding it before creating an account or sharing information.

This Privacy Policy covers viamu’s web service and any official viamu iOS or Android client that connects to the same account and shared backend: public opportunity discovery, accounts, eligibility profiles and comparisons, saved opportunities and alerts, and private application workspaces. It separates those practices from planned payment, AI, and public-profile recommendation features. A future feature or mobile SDK will not receive personal information until its purpose, notice, lawful basis, providers, safeguards, store disclosure, and user controls have been reviewed and disclosed.

This notice uses a layered approach: a short explanation appears where information is collected, while this page gives the full detail. It does not replace rights that apply under the law where you live.

Account data

Used to identify you, secure sessions, and provide features you request.

Private workspace

Notes, answers, checklists, and files are not sent to listed providers.

No sale or targeted ads

We do not sell or rent personal information or use it for cross-context behavioral advertising.

Who is responsible for this information

Kevin Bravo operates viamu and is the controller or responsible organization for the processing described here. Its registered or business address is Caracas, Venezuela (operador individual; sin domicilio comercial registrado). Contact onviamu@gmail.com for privacy requests. The current data-protection or representative contact, if one is appointed, is no separate data protection officer or local representative is currently listed; contact the operator at the privacy address below.

Information we collect—and what is optional

We collect only information connected to a stated feature. An authentication identity and email address are needed to use account features. Depending on your chosen method, Supabase Auth receives information from Google, email one-time codes or links, or a passkey. You can still browse public listings without signing in. Eligibility profile details, saved opportunities and alerts, notes, answers, uploads, and mobile notifications are optional; omitting them may make matching or preparation less personalized but does not prevent public browsing.

  • Account and authentication: an immutable identity subject, email, available name or avatar, preferred language, authentication and session identifiers, policy records when collected, marketing preference, and account timestamps. viamu does not operate a password database.
  • Billing when enabled: FastSpring customer, subscription, order, product, lifecycle, refund or chargeback outcome, and webhook event identifiers; viamu does not receive the full card number.
  • Eligibility profile: residence, citizenship, birth date, education, field of study, graduation year, languages, and professional experience when you choose to provide them. Residence and citizenship are user-provided profile facts, not device GPS collection.
  • Saved opportunities: the opportunity reference and the time you saved it.
  • Application workspace: opportunity, status, notes, checklist items, answers, document names, types, sizes, timestamps, and uploaded file bytes. Files or free-text answers may reveal sensitive information you choose to include.
  • Saved alerts and communications: search criteria, regional matching choices, notification settings, push-notification token if mobile notifications are enabled, and delivery or opt-out records when those features operate.
  • Technical and security data: authentication and locale cookies or equivalent app storage, request identifiers, IP or network information present in infrastructure logs, device or browser type, operating-system and app version, timestamps, crash or diagnostic information supplied by active infrastructure, and security events.

How we receive information

Private account, profile, workspace, alert, and document information generally comes from you. Opportunity records come from public provider or publisher pages, public feeds or APIs, and reviewed records. Public opportunity material may identify a provider contact, organizer, author, or publicly named participant. If we later collect identifiable public-profile information for recommendations, the separate safeguards below apply. If another person sends information about you, we assess whether it may lawfully be retained and will provide required notice where applicable.

How we use information

We limit use to disclosed purposes:

  • Create, identify, authenticate, and secure an account and maintain sessions across authorized web and mobile clients.
  • Provide filters and explainable eligibility comparisons using profile details you choose to save.
  • Maintain your private saved-opportunity shortlist.
  • Create and maintain private workspaces, checklists, answers, and uploaded documents.
  • Operate saved alerts and send service, security, or feature messages and mobile notifications you request.
  • Record and honor legal acknowledgements, privacy choices, notification settings, and communication choices.
  • Send promotional communications only where permitted and, where required, after a separate opt-in.
  • Troubleshoot, secure, and improve reliability and accessibility; aggregated or de-identified information may be used when reasonably designed not to identify you.
  • Meet legal obligations, valid legal process, safety needs, and fraud or abuse prevention.

Lawful bases and purpose mapping

The exact legal basis depends on the jurisdiction. Where GDPR-style bases apply, the current mapping is:

  • Account, authentication, profile, workspace, document, and requested-alert functions: necessary to provide the service or take steps you request before an agreement.
  • Security logs, abuse prevention, reliability, accessibility improvement, and limited service measurement: our legitimate interests in operating a safe and useful service, after balancing those interests against user rights. You may object where the law provides.
  • Records and disclosures required by tax, consumer, safety, privacy, or other law: compliance with a legal obligation.
  • Optional promotional marketing and any future non-essential analytics or advertising storage: consent where required. Consent is separate from account access and can be withdrawn as easily as it is given.
  • Protection of users or others in an emergency and establishment or defense of legal claims: the applicable vital-interest or legal-claims basis where available.
  • We do not describe privacy-policy acknowledgement as consent to every processing activity; each activity needs its own valid basis.

Marketing messages

The baseline web application does not send promotional campaigns or use third-party advertising trackers. It stores a separate, unticked marketing choice. If promotional messages are enabled, viamu will identify the sender, use the choice and any legally required consent, include a working unsubscribe method, maintain a suppression record so opted-out addresses are not re-added, and avoid profiling minors for advertising.

Service, security, account, and requested alert messages are not marketing, but they will still be limited to what is necessary for the feature or account.

Cookies, app storage, and device permissions

The web client uses service cookies for the Supabase PKCE authentication session and preference cookies. An official mobile client may use equivalent protected app storage for an authentication token, language, and settings. viamu does not intentionally use third-party advertising trackers:

  • Supabase Auth session state: the web client stores the PKCE session in cookies and sends a short-lived access JWT to the viamu API. Refresh tokens are handled by Supabase Auth. Native clients may use operating-system protected storage for equivalent session material.
  • viamu_locale and viamu_locale_choice: remember the interface language and an explicit language choice, normally for up to 365 days on the web. The mobile app may store the same preferences locally.
  • Push notifications, if offered, require the operating system’s permission and a delivery token. Refusing them does not prevent account access, and they can be disabled in device or account settings.
  • A provider site opened from viamu may set its own cookies under its own notice. Any future non-essential storage, tracking permission, advertising identifier, or analytics SDK will be disclosed and, where required, blocked until you choose it.

Mobile app data and permissions

Official viamu mobile clients use the same account and API as the web client. The baseline app must not request contacts, precise or background device location, microphone, camera, photo library, or advertising-tracking permission unless a user chooses a feature that genuinely needs it and receives a just-in-time explanation. User-provided residence and citizenship are used for opportunity matching; they are not inferred from GPS.

Before a mobile release, viamu must audit every included SDK and permission, update this policy if practices changed, and make the Apple App Privacy and Google Play Data safety declarations match the released binary. A permission prompt or store label does not replace an in-app disclosure or consent where one is required.

When information is disclosed

We do not sell or rent personal information, share it for cross-context behavioral advertising, or provide private profiles, answers, or documents to listed opportunity providers. Information may be disclosed only in these limited cases:

  • To contracted infrastructure, database, private-storage, email, security, translation, payment, and support providers that need it to operate a disclosed feature under instructions, their merchant-of-record obligations, and applicable confidentiality duties. When you start checkout, FastSpring receives the account/contact and transaction information needed to host checkout, collect tax, prevent fraud, issue invoices, process refunds and chargebacks, and pay the seller. viamu also forwards your public network address transiently so FastSpring can infer checkout country and supported currency; viamu does not store that address in its billing records and does not receive card numbers.
  • To a person or integration you deliberately ask viamu to connect, after a clear authorization step.
  • To courts, regulators, law enforcement, or other parties where legally required or reasonably necessary to protect rights, investigate abuse, or address safety.
  • During a merger, financing, acquisition, or asset transfer, subject to lawful notice, confidentiality, and continued protection.
  • In aggregated or de-identified form reasonably designed not to identify a person.

Provider websites and other third parties

viamu links to external sites so you can verify or apply. When you leave viamu, that site’s terms, privacy notice, cookies, application system, fees, and security apply. viamu does not control the site or receive what you submit there unless a future feature clearly says so and you authorize it. Review the official provider information before submitting documents or paying a fee.

How long we keep information

We retain information for the shortest period reasonably connected to its purpose, then delete or de-identify it unless law or a documented claim or security need requires longer. Current criteria and deployment periods are:

  • Supabase Auth sessions remain until expiry or revocation under the configured authentication policy. Signing out revokes or clears available session state.
  • Local viamu profile records remain while the profile is active. Automated deletion removes the local profile, billing identifiers and audit events associated with it, alerts, workspaces, answers, checklists, document metadata, and known uploaded file bytes after every subscription is fully deactivated. The separate Supabase Auth identity must currently be requested through the privacy contact. viamu retains only a one-way SHA-256 digest of its deleted identity subject to prevent that unchanged upstream identity from silently recreating the local account; the original subject cannot be recovered from this marker. It also retains keyed one-way HMAC digests of deleted provider order IDs so a late refund or chargeback can be acknowledged without restoring the account mapping or retaining the raw order ID.
  • FastSpring independently retains invoices and transaction records for the periods required by tax, accounting, fraud, refund, chargeback, and other merchant-of-record obligations. Deleting viamu does not erase those provider records.
  • A workspace and its files remain until you delete the workspace or local profile, or until the feature is retired after notice.
  • Saved alerts remain until you delete or disable them, delete the local profile, or the feature is retired.
  • Security and diagnostic logs are retained for Máximo de 30 días, con un límite adicional de 256 MB en el host.
  • Backups rotate and age out under this schedule: 7 días para respaldos automáticos; el snapshot manual de release se conserva hasta ser reemplazado. Deleted data may remain inaccessible in a backup until that backup expires and is not restored into active use except for disaster recovery with deletion reconciliation.
  • Marketing suppression evidence may be retained after opt-out so the preference can continue to be honored.

How we protect information

Supabase Auth handles Google, verified email OTP or magic-link, and feature-flagged passkey authentication. The viamu API validates signed access JWTs against the configured issuer, audience, key ID, time claims, and JWKS before resolving an immutable identity subject to a local user. Private queries are scoped to that owner, and upload bytes are stored outside public assets. Production is configured for HTTPS, restricted infrastructure access, backups, and private storage. Known upload bytes are removed before local profile deletion reports success. Uploads are type-checked but are not yet malware-scanned. No system is perfectly secure; report suspected unauthorized access promptly and avoid unnecessary highly sensitive files.

Eligibility comparisons and automated processing

If you save profile information, viamu compares residence, citizenship, age, education, field, and experience with structured criteria from an opportunity. It explains criteria that appear to match, not match, or remain uncheckable. This assists your search; it is not a provider decision and is not intended to produce a legal or similarly significant effect.

The current service does not make a solely automated decision that determines access to education, employment, funding, travel, or another similarly significant outcome. You can correct inputs, inspect reasons, and verify every result with the official provider.

Planned recommendations from public profiles

viamu’s mission includes learning from publicly available profiles or trajectories of past successful candidates. Public availability does not make identifiable information free of privacy obligations. This feature is not part of the current baseline and must not launch until viamu completes a documented lawful-basis, necessity, fairness, children’s-data, bias, and data-protection-impact review.

  • Use only information intentionally made public or lawfully licensed and relevant to application guidance.
  • Minimize identifiers and prefer aggregated patterns over exposing or ranking named individuals.
  • Provide any notice required when information is obtained indirectly, including categories, sources, purposes, retention, recipients, and rights.
  • Offer a practical correction, objection, and removal route and do not infer sensitive traits that are unnecessary for the guidance.
  • Test for discriminatory proxies, explain the limits of recommendations, and never present a profile pattern as a provider rule or guarantee.
  • Do not use private viamu workspaces, documents, answers, or profiles to train this feature without a new, specific and lawful disclosure and control.

Saying “public information only” is a safeguard, not a complete legal basis. The feature remains gated until the documented controls exist.

Your choices and privacy rights

Rights vary by location. Contact onviamu@gmail.com; we may request proportionate information to verify the account and will respond within the legally required period. You may also complain to the privacy or consumer regulator where you live. Where applicable, you can request:

  • Access to information and an explanation of its use. The account export includes local profile data, current legal acknowledgements, communication preference, billing customer/subscription/order and associated webhook identifiers, saved opportunities and alerts, and workspace metadata; file bytes and FastSpring's independent transaction records are obtained separately.
  • Correction of inaccurate or incomplete information.
  • Automated deletion of local viamu application data through Account settings, the in-app Privacy and data controls, or the public Account deletion page after every subscription is fully deactivated; deletion of the separate authentication identity can be requested through onviamu@gmail.com. Applicable legal or narrowly documented security exceptions may apply.
  • Restriction of processing or objection to processing based on legitimate interests.
  • Objection to direct marketing at any time; this right is unconditional and can be exercised in account settings or by email.
  • A portable, structured copy of information you provided where the right applies.
  • Withdrawal of consent at any time without affecting processing that was lawful before withdrawal. Mobile notification permission can also be withdrawn in device settings.
  • Information about active processors, recipients, international safeguards, and any applicable automated-decision logic.
  • Rights to limit use or disclosure of sensitive information, and to opt out of sale, sharing, or targeted advertising, where applicable. viamu currently does not sell, share for cross-context behavioral advertising, or operate targeted advertising.

Children and younger students

Students can browse public opportunity pages without an account. The current account service is for people aged 16 or older, a deliberately higher baseline while viamu serves an international audience and has no verified parental-consent flow. We do not knowingly accept an account from anyone under 16. If we learn that such an account exists, we will restrict it and delete or handle the information under the legally required process. Users aged 16 or 17 must still involve a parent or guardian where local contract, privacy, travel, employment, or provider rules require it.

The current self-confirmation is a minimum control, not a claim of universal age assurance. Before intentionally serving younger account holders in a market, viamu must assess local ages of digital consent and contract capacity, use proportionate age assurance, obtain and verify guardian authorization where required, provide child-readable notices, and avoid profiling minors for advertising.

International processing

Current processing and storage locations are: Estados Unidos (AWS us-east-1, Norte de Virginia). Where information crosses borders, the current safeguards are: Contratos con proveedores, cifrado en tránsito y en reposo, controles de acceso y minimización de datos. Depending on the route, safeguards may include an adequacy decision, approved contractual clauses, transfer-risk assessment, or another valid mechanism. Contact onviamu@gmail.com to request information about a safeguard that applies to you.

Service providers and data locations

The active production infrastructure and processor description is: Amazon Web Services (Lightsail compute, Amazon RDS para PostgreSQL y SES); sslip.io proporciona únicamente el DNS temporal. viamu maintains an internal provider inventory with each provider’s purpose, information categories, location, contract, security review, transfer mechanism, and deletion terms. A provider supported by the code is not active merely because an integration exists. FastSpring must be included when subscriptions are enabled. Private-data translation, AI, analytics, advertising, email marketing, and error-monitoring providers must be added before they receive applicable personal information.

  • Application and API hosting: serves the web client and shared Go API.
  • Database hosting: stores account, opportunity, consent, billing identifiers, alert, and workspace records in PostgreSQL.
  • FastSpring, when billing is enabled: merchant of record for hosted checkout, subscription management, tax, fraud prevention, invoices, refunds, chargebacks, and seller payout.
  • Private file storage: stores workspace bytes outside public web assets.
  • Opportunity translation, when enabled: processes canonical public opportunity text; private account and workspace data are excluded from that workflow.

Changes to this policy

We may update this policy when the product, law, providers, locations, or purposes change. The effective date and version appear at the top. For a material change, viamu will provide a prominent notice or direct communication where required and will request a new acknowledgement or consent when the law or the changed purpose requires it. Prior versions and change records should be retained by the operator.

For privacy questions, access, correction, objection, deletion, portability, or marketing opt-out requests, email us at

onviamu@gmail.com

दुनिया अगले कदमों से भरी है। अपना कदम खोजें।

छात्रवृत्तियाँ, फ़ेलोशिप, इंटर्नशिप और वैश्विक प्रोग्राम एक ही स्पष्ट जगह पर खोजें।

लॉग इन