Skip to content
Vrge

Transparency

What Vrge can see

Your clients, projects and invoices are on your computer. We hold no copy we can read.

Last updated: September 5, 2026

Checked against the shipping app and the servers’ own schemas, not against a policy document. The table below is the whole list; there is no second one.

The short version

  • Three things carrying your business data can pass through our servers: Plaid bank reads (kept: none of it), Managed AI prompts if you subscribe (kept: token counts, never text), and encrypted Cloud Backups if you subscribe (kept: the sealed file, which we cannot open). Sign-in tokens for Stripe, Square and QuickBooks also transit, and are not kept.

  • Everything else we hold about you is what Lemon Squeezy holds about a purchase, plus aggregate update-check counts that identify nobody.

Every path

Everything that can reach a server we operate

Seven paths. Two are always on and carry no content. Four are opt-in. One is you writing to us. Each row says what passes through, what stays, and for how long.

Every data path from Vrge to infrastructure TRD Ventures operates, with defaults and retention
PathDefaultPasses through usWe keepFor
Update checksAlways onPlatform, chip, version, update laneA count per day, platform and version; a count per installerIndefinitely
Licence checkAlways on, once activatedNothing. The app calls Lemon Squeezy, not usYour email address and licence key, from the purchaseLicence plus three years
Cloud BackupOpt-in, $6/moYour database, encrypted on your machine firstThe sealed file (up to seven), size, time, device label, licence keyUntil you delete it
Managed AIOpt-in subscriptionRedacted prompt text, in memory, on to AnthropicTime, task, model, token counts, status, redaction modeIndefinitely
Plaid bank syncOpt-inEvery transaction read, in memoryNone of it; a per-IP request counterAbout an hour
Stripe, Square, QuickBooks sign-inOpt-inThe sign-in code exchange and token refreshesThe sign-in code (and QuickBooks company id) during hand-off; a per-IP request counterTen minutes; an hour
Support and waitlist mailWhen you write to usWhatever you sendThe correspondence; a waitlist addressThree years; until you unsubscribe

Path by path

What each row means

  • Update checks

    On launch and every four hours, the desktop app asks updates.getvrge.com whether a newer build exists. The request carries your platform, chip architecture, current version and update lane. That is the whole URL. Our worker adds one to a counter per UTC day, platform and version, and one to a counter per installer file when you download. It stores no IP address, no user agent and no per-request row; there is nothing to correlate. It reads the user agent only to decide whether a download was a crawler, and stores that verdict as a number. If you downloaded from a link we posted with a channel tag, the tag is counted per day. It describes our link, not you.

    Cloudflare terminates the connection, so Cloudflare sees your IP address the way it does for any site it fronts. Our code never reads it. There is no setting to turn the check off.

  • Licence check

    Once you have activated a licence, every launch sends your licence key, and the per-device activation id it issued, back to Lemon Squeezy, our merchant of record, to confirm the key is still valid. A trial copy makes no such call. The request goes to Lemon Squeezy, not to us; we operate nothing in its path, and if Lemon Squeezy is unreachable the app trusts the stored licence and carries on. Lemon Squeezy holds your name, email, country, payment details and licence. We receive your email address and licence key and keep them for the life of the licence plus three years, for warranty and tax.

    A Team server you run yourself does the same for its own key: it asks Lemon Squeezy at start-up and once a day, and keeps running if it gets no answer.

  • Cloud Backup: optional, $6 a month

    Before anything leaves your machine, the app encrypts your database with AES-256-GCM under a key derived by PBKDF2-SHA256 (600,000 iterations) from a recovery code generated on your device. The code is kept in your OS keychain and is never sent. There is no escrow, no master key and no support override: lose the code and the backup cannot be opened by anyone, including us. See the recovery code in the guide.

    What we store: the sealed file, up to seven of them, filed under a SHA-256 digest of your licence key rather than the key itself; each file’s size and timestamp; the device label you chose (it defaults to your platform’s name); and, in the subscription database, your licence key in plaintext with the Lemon Squeezy order and subscription ids. We can delete a backup. We cannot read one.

    Cancelling stops new uploads at the end of the period you paid for and deletes nothing. Listing, downloading and deleting keep working, so nobody is stranded, which also means your snapshots outlive the subscription until you remove them yourself.

    Cloudflare’s request logging is switched on for this worker too, so Cloudflare holds a per-request record for at most seven days. The worker itself prints only error messages, never a byte of a snapshot, which it could not read in any case.

  • Managed AI: optional subscription

    When you subscribe, the app sends its prompts to ai.getvrge.com and we forward them to Anthropic on our account. The prompt is derived from your email and documents and redacted according to your setting, and on this tier the setting has a floor: full content can never be sent through us. If you have chosen full content, the app substitutes a summary made locally, or strict redaction, before the call leaves your machine. The prompt passes through the worker in memory and is not written down; the usage table has no column that could hold it.

    What is written, per call: the timestamp, task, model, token counts, status and redaction mode, keyed on your licence key, plus an opaque member id in team mode. Those rows are kept indefinitely (there is no purge routine) and they survive cancellation. Cloudflare’s request logging is also switched on for this worker, so Cloudflare holds a per-request record (the request, the response and related metadata, in Cloudflare’s words) for at most seven days. The worker itself prints one alarm line about mis-priced subscription events; it never prints a prompt.

  • Plaid bank sync: optional

    Plaid requires our confidential secret on every request, so unlike every other source, each bank-transaction read is proxied: your app sends the request to oauth.getvrge.com, the worker adds the secret, forwards it to Plaid and returns Plaid’s answer verbatim. Merchant names, amounts and dates therefore cross our infrastructure. We write nothing about them down: that handler writes to no store, and this worker’s configuration does not switch on Cloudflare’s request logging. Cloudflare enables that logging by default on new Workers, so assume Cloudflare may hold a per-request record for up to seven days here, as it does for the two workers where we switched it on ourselves. What the worker keeps is a rate-limit counter per IP address and hour and, when a new bank connection is created, one per hashed licence key, both expiring about an hour later. Creating that new connection is the one request that carries your licence key: the worker checks it with Lemon Squeezy and refuses without an active licence. Reads, refreshes and removal of an existing connection never involve it. The Plaid access token stays on your device.

  • Stripe, Square and QuickBooks sign-in: optional

    These three providers require a client secret a desktop app cannot safely hold, so signing in (exchanging a one-time code for tokens) and later token refreshes go through oauth.getvrge.com. The tokens are returned to your device and not retained. Reading your data afterwards goes straight from your machine to the provider. During the browser hand-off, the one-time sign-in code (and, for QuickBooks, the company id) is parked for up to ten minutes and deleted after retrieval. The same per-IP rate-limit counter applies. Each of the three also has an advanced path where you supply your own credentials and nothing touches us.

    Everything else (Gmail, Outlook, IMAP, Google Calendar, Outlook Calendar, CalDAV, .ics feeds, a local folder, a bank CSV) connects from your machine to the provider directly, or reads a file you already have. None of it touches a server we operate. See the sub-processor list for every vendor by name.

  • Support and waitlist mail

    If you write to support@getvrge.com, privacy@ or security@, the conversation sits in our Google Workspace mailbox and is kept for three years after the last message. If you joined the waitlist before launch, that address is in a Google Sheet and at Resend, which sent your confirmation; it stays until you unsubscribe or ask us to delete it, and a deletion clears both.

As a customer

Everything TRD Ventures holds about you

The complete list, including the uncomfortable entries. Two of these records are permanent and one outlives the subscription that created it. They are here because a list that left them out would not be worth reading.

  • Your email address and licence key, from the purchase. Lemon Squeezy, as merchant of record, holds the rest: name, country, payment details. Kept for the life of the licence plus three years.

  • Support correspondence, for three years after the last message.

  • A waitlist address, if you gave one before launch, until you unsubscribe or ask.

  • Aggregate counters from the update server: downloads per installer file, update checks per day, platform and version, and downloads per channel tag on links we posted. Numbers, with no record of which copy asked.

  • Managed AI call records, if you subscribe: one row per call (timestamp, task, model, token counts, status, redaction mode) under your licence key. Kept indefinitely. There is no purge routine today, and cancelling does not remove them.

  • Cloud Backup snapshots, if you subscribe: up to seven sealed files we cannot open, their sizes, timestamps and device labels, and a subscription row holding your licence key. Snapshots outlive the subscription until you delete them; the row has no deletion routine either.

  • Cloudflare’s per-request logs for at most seven days, on the Managed AI and Cloud Backup workers, where we switched them on. The connection relay and the update server do not switch them on in their configuration, but Cloudflare enables them by default on new Workers, so assume the same seven days there rather than none.

Not on this list

Your clients. Your projects. Your invoices. Your email, calendar, files and bank transactions. None of them is in any store we operate. If someone compelled us to hand over your CRM, there would be nothing to hand over: the most anyone could obtain from us is the list on the left, and, for a Cloud Backup subscriber, a sealed file only you hold the key to.

This website is separate from the app. It uses cookieless Cloudflare Web Analytics and loads the Lemon Squeezy checkout script on every page. Details in the privacy policy.

Compared to a cloud CRM

A cloud CRM’s privacy policy is a promise about data it holds; here the database is on your disk, and where something does pass through us the table above says exactly what it is and what remains. Fewer promises, because there is less to promise about.

The long versions

This page is the summary. The documents it summarises are public, dated and specific, and the trial needs no account and no card.