Via Solutions LLC

Privacy Policy

Last updated 7 October 2026

Who we are

Via Solutions LLC ("we", "us") operates two products under the VioVia name: Via Chat, a team chat and task application, and VioVia, an inventory, production and purchasing system.

Our products are used by organisations. If you are using one because your employer or a team invited you, that organisation decides who is in its workspace and what is done there, and we handle the information on their behalf.

What this policy covers

This policy covers Via Chat: the application atchat.viovia.io, and the Via Chat apps for iPhone and Android.

VioVia is not covered by this policy. It is not generally available, and it is deployed for each organisation under its own written agreement, which is what governs the information in it. If your company uses VioVia and you want to know what is held about you, ask your own administrators first, or write to us and we will point you to the right answer.

How to reach us

For anything at all, including reporting something you have seen in the app, a privacy request, or a security problem: santi@viovia.io. A person reads it.

What we collect

When you sign up and sign in

Signing in to Via Chat uses an email address and a password.

  • Your email address, which identifies you and is how invitations reach you
  • Your display name, so your teammates can tell who wrote what
  • Your password, which we never store. We keep only a scrypt hash of it, with a random salt, which cannot be turned back into your password
  • A profile photo, if you add one. It is cropped in your browser before it is uploaded, and only the square you chose is sent

What you create in the app

  • Messages, replies, thread replies, reactions and edits
  • Files and images you attach
  • Projects, sections, tasks, subtasks, comments, due dates, custom fields and their values
  • Channels, groups and direct messages, and who is in them
  • Invitations you send, including the email address you send them to
  • Reports you raise about a message, described in its own section below

Technical information

  • Session records. When you sign in we create a session that lasts 30 days. We store only a one-way hash of the session token, never the token itself, so a copy of our database cannot be used to sign in as you.
  • Your time zone, sent by your browser each time the app starts, so that reminders and the morning summary arrive in your morning rather than ours.
  • When you were last active, used to show your teammates who is around, and to decide whether a notification is worth sending to a device you are already looking at.
  • Notification details, only if you turn notifications on. On the web that is the address your browser gives us to reach your device and the keys needed to encrypt a notification to it. In the iPhone and Android apps it is the token Apple or Google issues for that installation. You can turn this off at any time, and removing the app removes it.
  • Server logs kept by our hosting provider in the ordinary course of running the service.

We do not use any analytics, advertising or tracking services. There is no Google Analytics, no advertising pixel, no session recorder and no third-party tracker of any kind in Via Chat. We do not build profiles of you, we do not sell or rent your information to anyone, and we do not use what you write to train AI models.

Why we collect it

WhatWhy
Email addressTo identify you, to decide whether you were invited, and to send you invitations and password resets
Password hashTo check your password without ever holding it
Name and photoSo your teammates can tell who wrote what
Your messages, tasks and filesTo provide the service, which is to show them to the people you sent them to
Session recordsTo keep you signed in, and to let you sign out
Time zoneTo send scheduled summaries at a sensible local hour
Notification detailsTo notify you when someone mentions you or sends you a direct message
ReportsTo let the people who run your workspace deal with something that should not have been posted

We rely on our agreement with the organisation that runs your workspace, and on our legitimate interest in operating and securing the service.

Who can see your information

Inside a workspace, visibility follows the role you were given:

  • Members can see the workspace directory, the channels they are in, and the projects and tasks they have access to.
  • Guests see only the conversations somebody has added them to, and only the people in those conversations. They cannot browse the directory.
  • Admins can additionally manage people and roles, see pending invitations, see an activity feed of what has happened in the workspace, and see reported messages.

Anything you write in a conversation is visible to the other people in that conversation. Direct messages are visible to the people in them. We do not read your messages except where it is strictly necessary to operate or fix the service, or where the law requires it.

Reporting a message

If somebody posts something that should not be there, you can report it from the message itself.

  • A report goes to the admins of your own workspace. It does not come to us, and there is no queue outside your organisation.
  • The report records which message it was, who raised it, the reason you picked, anything you chose to add in your own words, and when.
  • Admins can see the reported message, deal with it, and mark the report handled. Who closed it is kept.
  • Admins can also remove or deactivate somebody from the workspace, which is how an abusive account is stopped.

If something needs to reach us rather than your workspace's admins, including anything your admins are themselves involved in, write to santi@viovia.io.

Who we share it with

We use a small number of service providers, listed here in full. We do not share your information with anybody else, and we do not sell it.

ProviderWhat it doesWhat it receives
RailwayRuns the application and the databaseEverything stored in Via Chat, as our hosting provider
Cloudflare R2Stores files, images and profile photosYour attachments and your photo
ResendSends invitation and password reset emailsThe recipient's email address and the text of that email
Apple and GoogleDeliver notifications to the iPhone and Android appsThe notification itself and the device token, only if you turned notifications on
AnthropicPowers Vio, the assistant, when a workspace turns it onSee the section below

We may also disclose information if we are legally required to, or where it is necessary to protect the rights or safety of people using the service.

Vio and AI

Via Chat includes an assistant called Vio. It matters that you understand exactly when it is involved, because it is the one feature that sends what you write to another company.

  • Vio is off by default, and is turned on per workspace by an admin. There are two separate switches: a daily summary that runs entirely on our own servers and uses no AI at all, and answering, which does.
  • When answering is on, Vio only acts when it is spoken to, by name, or when it runs a standing job an admin has written. It does not read along in the background.
  • When Vio does answer, we send the recent conversation to Anthropic to produce the reply. That means the last messages in that conversation, including who wrote them, plus whatever Vio looks up to answer, such as project names, task titles and the names of people in the workspace.
  • Vio never has access to direct messages, only to group conversations in its own workspace.
  • We do not use anything you write to train any model.
  • Anything Vio does in the app carries its own name, so you can always tell its work from a person's.

If your workspace has Vio's answering turned off, nothing you write is ever sent to Anthropic.

Stored on your device

Via Chat sets no cookies. That is why you were never asked to dismiss a cookie banner. We keep a small amount of information in your browser's local storage instead, all of it functional:

  • Your session token, which is what keeps you signed in
  • Which workspace you were last looking at
  • Your light or dark appearance choice
  • Which channel categories you have collapsed
  • Whether you have dismissed the prompt to install the app

None of it is sent anywhere except the session token, which is sent to us to identify you. Signing out removes the token. Clearing your browser data, or removing the app, removes all of it.

How long we keep it

  • Messages, tasks and files are kept until they are deleted, or until the workspace is deleted. A chat history that disappears on its own is not much use, so we do not delete it on a timer.
  • Sessions expire 30 days after you sign in, and immediately when you sign out.
  • Invitations expire after 7 days, and password reset links after one hour.
  • Deleted channels and groups are marked deleted and stop being shown. Their messages may remain in our database for a period before they are removed.
  • Reports are kept after they are handled, so a workspace has a record of what was raised and who dealt with it.
  • Your account lasts until you delete it, or an admin removes you. When you delete it, everything that identifies you is removed at once; what you wrote stays, with no name on it. Seeyour choices and rights for exactly what that means.

Security

  • All traffic is encrypted in transit.
  • Passwords are stored only as scrypt hashes, each with its own random salt. We cannot read your password, and neither can anybody who obtains a copy of our database.
  • Session tokens are stored only as hashes.
  • Access to a workspace is decided per request, and guests are separated from the rest of the workspace at the database level rather than only in the interface.
  • Keys that let another application post into Via Chat are shown once, stored hashed, scoped to what they may do, and can be revoked at any time.

No service can promise perfect security, and we will not pretend otherwise. If we become aware of a breach affecting your information, we will tell the affected workspace's administrators without undue delay.

Your choices and rights

Depending on where you live, you may have the right to see the information we hold about you, to correct it, to have it deleted, to object to how we use it, or to receive a copy of it.

You can delete your account yourself, from inside the app. Open the account menu and choose "Delete my account". It asks for your password, because it cannot be undone.

Here is exactly what that does, because the word "delete" is used loosely by a lot of software and we would rather be specific.

Removed immediately and permanently: your name, your email address, your profile photo (including the stored file itself, not merely the link to it), your password, your time zone, every session you are signed in on, and every push subscription and mobile device token, so your phone stops receiving notifications. You come out of every workspace, channel, project and watch list, which means you stop appearing in the places that list people.

Kept, with your name taken off it: messages you sent, files you shared, comments you wrote, and tasks and projects you created. These appear as coming from "Deleted user" and carry nothing that identifies you.

We keep them because they are not only yours. They are part of conversations other people are still having and work other people are still doing, and removing them would tear holes in a shared history that other people rely on and did not agree to lose. This is the same approach Slack, Microsoft Teams and GitHub take. If you need a particular message removed as well, you or an admin can delete that message, before or after deleting your account.

One restriction: if you are the only administrator of a workspace, you have to make somebody else an administrator first. Otherwise that workspace would be left with nobody who can invite people, change roles, or act on a reported message. The app tells you this before asking for your password.

Deleting your account releases your email address, so you can sign up again later with the same one. It will be a new account, and it will not be connected to the old one.

For the other rights above, seeing what we hold, correcting it, or getting a copy, there is not yet a self-service button. We would rather say so than imply otherwise. Write tosanti@viovia.io and we will do it by hand, within 30 days. There is no charge, and we will not treat you differently for asking.

Other things you can do today without asking us: change your display name and photo in the app, remove your photo, change your password, turn notifications off, sign out to end a session, report a message to your workspace's admins, and ask an admin to remove you from a workspace.

If your workspace belongs to an employer, some requests are theirs to decide rather than ours, and we will point you to them.

Children

Via Chat is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has an account, write to us and we will remove it.

Changes

If we change this policy we will update the date at the top. If a change materially affects what we collect or who we share it with, we will tell workspace administrators rather than relying on you to notice.

Contact

Via Solutions LLC. Questions, requests, reports, or anything that looks wrong:santi@viovia.io.