Legal
Privacy Policy
Effective: August 4, 2026
ViewParquet is operated by Kaladev Digital Private Limited, India ("Kaladev", "we", "us"). Kaladev is the controller of personal data described in this policy. ViewParquet is local-first: opening and querying a device file does not create a Cloud copy. Cloud storage, Cloud history, managed AI, and Cloud queries are separate features you choose.
Local files and device storage
Parquet, GeoParquet, CSV, TSV, and JSON files opened from your device are processed in your browser with DuckDB-WASM. Their bytes remain on that device unless you explicitly choose Add Cloud copy. The app can store a device copy in IndexedDB so you can reopen it. Projects, layout, theme, local chat history, and optional remembered BYOK keys use functional browser storage; they are not advertising trackers.
When you open a remote HTTPS or S3-compatible source, your browser reads that source directly. Credentials entered for a private source are used in the browser and are not sent to ViewParquet. URLs containing query parameters, including presigned URLs, are kept only for the current tab.
Accounts, projects, and Cloud files
If you create an account, we process your email address, connected sign-in providers, display name, account identifiers, project names, preferences, subscription state, and service timestamps. When you add a Cloud copy, your browser uploads it directly to a private Amazon S3 bucket through a short-lived signed URL. We store its name, size, content type, checksum, project membership, availability state, and storage key in Supabase.
Device and Cloud copies have separate identities. Deleting one does not silently delete the other. Cloud data is processed to perform our contract with you, secure and operate the service, enforce plan limits, prevent abuse, and provide support.
Cloud conversations and query execution
Conversations stored On this device remain in browser storage. When history is set to Cloud sync, we store the conversation title, messages, tool activity, model, attached-file context, execution setting, branches, and timestamps in Supabase so the chat works across devices.
A Cloud query stores the validated read-only SQL, exact source references, job state, diagnostic details, runtime, result size, and cost. A short-lived Fargate worker receives only a job-scoped token and temporary AWS credentials limited to the selected source objects and result paths; it does not receive a Supabase service key or account-wide S3 access. Query previews and result files are stored in private S3 paths.
AI features
AI is optional. In BYOK mode, your browser sends requests and your API key directly to the provider you configure. ViewParquet does not receive the key or proxy that request. In managed Cloud AI mode, ViewParquet authenticates the request and sends it to OpenRouter with Zero Data Retention routing required. OpenRouter can route to an eligible downstream model provider, whose identity and availability can change.
Depending on the sharing controls you select, an AI request can include:
- Your prompt and recent conversation messages
- Names and types for relevant columns and attached tables
- File metadata, profiles, accepted SQL examples, and semantic descriptions
- Bounded query-result values only when the applicable sharing control permits them
We record model, token counts, estimated cost, account identifier, and time for allowance and abuse controls. The usage ledger does not contain prompt or response bodies; a Cloud-synced conversation separately contains the transcript as described above. AI output can be incorrect, so review SQL and results before relying on them.
ViewParquet does not use Cloud files, prompts, conversation content, SQL, or result values to train AI models. BYOK providers process requests under your provider agreement.
Analytics, reliability, and support
- Vercel Analytics: cookieless page and allowlisted product events. Viewer URLs are reduced to their path. Events exclude filenames, project/file/conversation/order IDs, email addresses, SQL, schema, values, prompts, responses, search text, exact model IDs, and payment details. Billing events use only coarse plan, action, and success/failure categories.
- Sentry: essential error and performance reports with default personal-data collection disabled and application-level scrubbing. We do not intentionally send file contents, SQL, prompts, or query values.
- Featurebase and email: messages and contact information you submit so we can respond. Do not send datasets, credentials, or secrets.
We do not use advertising cookies or cross-site behavioral profiling. Authentication providers, Polar checkout, and support tools may use strictly functional cookies or storage on their own domains. See our Subprocessors page.
Retention
- Active Cloud conversations are deleted after 24 months without use; archived conversations are deleted after 30 days; you can delete a conversation sooner.
- Cloud query result and preview objects expire after seven days.
- Cloud query SQL, source references, and diagnostic messages are removed after 30 days.
- Bounded Cloud-query usage and cost records are retained for up to 24 months.
- Managed-AI token and cost usage records are retained for up to 24 months.
- Product analytics follow Vercel's configured retention; support records remain while needed to resolve the request.
- Billing and transaction records may be retained as required for tax, accounting, fraud prevention, and legal obligations.
- Backups, if applicable, age out on their configured schedule and are not restored for ordinary product use after deletion.
Legal bases and international processing
We process account, Cloud, query, and billing information to provide the service and perform our contract; security, diagnostics, aggregate analytics, and abuse prevention for our legitimate interests; optional features according to your choices; and records where required by law. You can withdraw an optional choice by disabling it, removing its data, or deleting your account.
Our providers can process information outside your country, including India, the United States, the European Economic Area, and the region selected for Cloud infrastructure. Where required, we rely on contractual safeguards and provider data-protection terms for international transfers.
Your choices and rights
Account settings let you export a compressed copy of account, project, conversation, usage, and query data; remove individual Cloud files or chats; and delete the Cloud account. Device-only data remains under your browser's controls. Depending on your location, you may also request access, correction, portability, restriction, objection, withdrawal, or erasure, and may complain to your local data-protection authority.
Confirmed account deletion ends account access and revokes a linked subscription first. Private Cloud objects are then removed immediately when the storage provider is available; a private deletion job retries removal after a temporary provider failure. Mandatory billing records and expiring backups remain subject to the retention exceptions above.
Our business contact for questions about personal-data processing is the Founder — privacy and grievance contact. Send a privacy or grievance request to antony@kaladev.co. We may need to verify your identity. We aim to acknowledge requests promptly and respond within the period required by applicable law.
Security and children
We use access controls, private object storage, encryption in transit and at rest, short-lived signed access, row-level database policies, scoped workers, rate limits, and monitoring. No service can guarantee absolute security; report a suspected vulnerability through our Security page.
ViewParquet is intended for adults and business users and is not directed to children under 18. We do not knowingly create Cloud accounts for children.
Changes and contact
We will update the effective date when this policy changes. Material changes affecting existing Cloud customers will be communicated through the service or account email when appropriate. Questions can be sent to antony@kaladev.co or through our Support page.
Kaladev Digital Private LimitedCIN: U62010TN2024PTC168140
Registered office: D-4, Sitara Apartments, 22 Jawahar Road, Sellur, Madurai 625002, Tamil Nadu, India