Privacy Policy
Last updated: May 1, 2026
VIMS — Virtual Intelligence Management System
VIMS ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the VIMS desktop application and any associated services (collectively, the "Service").
1. Information We Collect
We collect only what is necessary to provide the Service:
- Account data — email address and display name when you create a VIMS account.
- Financial connection data — if you connect a financial institution via QuickBooks Online or Plaid, we store encrypted OAuth tokens and access tokens locally on your device. We do not transmit your raw financial credentials to our servers.
- Usage data — anonymous crash reports and feature usage telemetry (no personal identifiers, opt-out available in Settings).
- Local AI data — prompts and responses processed by local AI models remain entirely on your device and are never sent to VIMS servers.
2. How We Use Your Information
- To authenticate you with third-party services (e.g., QuickBooks Online, Plaid) on your behalf.
- To provide bookkeeping, financial analysis, and AI assistant features within the app.
- To improve app stability via anonymized crash and error reports.
- To communicate important service updates or security notices.
3. Financial Data & Third-Party Services
When you connect a financial account:
- QuickBooks Online — OAuth tokens are stored encrypted (AES-256-GCM) on your local device. Token exchange is facilitated via our Cloudflare relay but tokens are never persisted on our servers beyond the transit handoff.
- Plaid — Access tokens are stored encrypted on your local device only. Financial data fetched via Plaid is processed locally and is not uploaded to VIMS servers.
Your financial data is governed by the respective third-party privacy policies: Intuit Privacy Policy and Plaid Privacy Policy.
4. Data Storage & Security
Sensitive tokens and credentials are encrypted at rest using AES-256-GCM with keys derived via HKDF from a device-specific seed. We use industry-standard transport security (TLS 1.2+) for all network communication.
5. Data Sharing & Disclosure
We do not sell, rent, or share your personal information with third parties except:
- As required by law or valid legal process.
- To protect the rights, property, or safety of VIMS, our users, or the public.
- With service providers acting on our behalf under confidentiality agreements (e.g., Cloudflare for relay infrastructure).
6. Data Retention
Account data is retained for the duration of your account. You may request deletion at any time by contacting us at [email protected]. Locally stored tokens are removed when you disconnect a financial integration within the app.
7. Children's Privacy
VIMS is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us immediately.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal data. To exercise these rights, contact [email protected].
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via the app or by email. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact
Questions about this Privacy Policy? Contact us at [email protected].