Varuna privacy
Privacy Policy
This explains what Varuna collects, why we collect it, who helps us process it, and how document and email imports are handled.
Last updated: August 19, 2026
Who we are
Varuna is a portfolio tracking product developed by Bebegu Labs. In this policy, Varuna, we, us, and our refer to Bebegu Labs as the studio responsible for the product, website, account experience, import workflows, and related communications.
You can contact us at [email protected]. The studio website is bebegu.com.
Scope
This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you visit our websites, create or use a Varuna account, import documents or emails, subscribe to a paid plan, contact support, or otherwise interact with Varuna.
Varuna is a portfolio tracker. It is not a broker, custodian, bank, exchange, investment adviser, tax adviser, or accounting firm. We do not hold your securities, execute trades, or store brokerage login credentials.
Information you provide
We collect information you provide directly, including:
- Account information, such as your name, email address, profile image, and sign-in preferences.
- Portfolio information, such as portfolios, holdings, cash balances, transactions, categories, custom assets, watchlists, goals, notes, assumptions, reports, display preferences, and base currency settings.
- Import information, such as CSV files, uploaded PDFs, screenshots, images, forwarded emails, extracted rows, sender information, message metadata, filenames, document status, import decisions, and review actions.
- Support information, such as messages you send us, screenshots you choose to share, feedback, bug reports, and other information needed to respond.
Information from third parties
We may receive information from third parties that help us operate Varuna, including:
- Authentication providers, such as Google, which may provide your account identifier, name, email address, and profile image.
- Payment providers, such as Paystack, which may provide customer, payment, subscription, authorization, renewal, failure, cancellation, and webhook information. We do not store full card numbers.
- Market data providers, which may provide prices, corporate actions, fundamentals, dividends, exchange rates, symbols, company names, and other market metadata.
- Email routing and delivery providers, which may provide message headers, routing information, delivery events, and authentication results.
- Analytics, hosting, logging, security, and infrastructure providers, which may provide technical information about visits, requests, devices, browsers, pages, errors, and system activity.
Technical and usage data
We collect technical and usage information needed to run, secure, debug, and improve Varuna. This may include IP address, approximate location derived from IP, browser and device data, operating system, language, timezone, referrer, pages viewed, buttons clicked, feature usage, plan status, portfolio counts, holdings counts, import type, error events, request IDs, and timestamps.
We try to keep analytics useful without collecting unnecessary portfolio contents in event names or event properties. Some browser analytics may still capture interaction details and page paths depending on the product configuration.
Cookies and local storage
Varuna and its service providers may use cookies, local storage, session storage, pixels, and similar technologies to keep you signed in, remember preferences, secure the service, measure usage, understand marketing performance, and improve the product.
You can control cookies through your browser settings. Blocking cookies or storage may cause sign-in, preferences, billing return flows, imports, or other product features to stop working correctly.
How we use information
We use information for the following purposes:
- To create, authenticate, maintain, and secure your account.
- To provide portfolio tracking, holdings, cash, transactions, dividends, allocation, returns, goals, simulations, reports, and exports.
- To import, parse, stage, review, add, dismiss, or retry transactions from CSV files, uploaded documents, screenshots, PDFs, images, forwarded emails, and email bodies.
- To route portfolio-specific email aliases, validate senders, enforce quotas, and prevent abusive or unauthorized imports.
- To process subscriptions, payments, cancellations, renewals, entitlement checks, billing support, and plan limits.
- To provide support, respond to requests, troubleshoot bugs, investigate suspicious activity, and communicate product or account notices.
- To measure product usage, improve performance, prioritize features, understand conversion, and evaluate marketing.
- To detect, prevent, investigate, and respond to abuse, fraud, spam, security incidents, policy violations, or unlawful activity.
- To comply with legal, tax, accounting, regulatory, security, dispute, and operational obligations.
Legal bases
Where privacy law requires a legal basis, we rely on one or more of the following: performing a contract with you, taking steps at your request before entering a contract, our legitimate interests in operating and improving Varuna, your consent where required, compliance with legal obligations, and protection of Varuna, users, and the public from harm.
You may withdraw consent where processing is based on consent, but this does not affect processing that occurred before withdrawal or processing based on another lawful basis.
Documents, emails, and AI extraction
If you upload or forward a document, image, screenshot, PDF, statement, confirmation, or email, we store it temporarily while Varuna extracts transactions and prepares the result. The document or email may contain brokerage account details, transaction details, holdings, names, addresses, balances, tax information, and other information visible in the file or message.
The extraction path may send document text, email content, images, or attachments to an AI extraction provider so the transaction details can be read. We use the extracted data to stage, add, review, deduplicate, validate, or reject imports. You are responsible for reviewing imported data before relying on it.
Document bytes are deleted when an import is committed, dismissed, or otherwise cleaned up. Failed, abandoned, or retryable imports may be retained for a limited recovery period and then deleted. We may retain extracted transaction rows, metadata, logs, and audit records after the original file has been deleted where needed for the service, security, billing, support, or legal purposes.
Email imports
Portfolio email aliases are designed for importing trade confirmations, statements, and related investment records. If an email is sent to a portfolio alias, we may process the sender address, recipient alias, subject, message ID, headers, authentication results, attachments, body content, timestamps, and routing metadata.
We use this information to route the email to the right portfolio, decide whether the sender is trusted, decide whether the message can be added automatically or should stay in review, enforce limits, prevent spam, investigate abuse, and troubleshoot import failures. Anyone with access to an alias may attempt to send to it, so you should rotate or disable an alias if it is exposed or no longer needed.
Billing data
Payments and recurring subscriptions are handled by Paystack or another payment processor we may use. We may store plan, interval, subscription status, renewal state, customer code, subscription code, payment reference, payment amount, currency, payment event timestamps, webhook status, and related billing records.
We do not intentionally store full card numbers, bank account numbers, or payment method security codes. Your payment processor may process additional payment information under its own terms and privacy policy.
Sharing and service providers
We do not sell your personal information. We may disclose information to service providers, contractors, vendors, and infrastructure partners that help us operate Varuna, including:
- Hosting, database, object storage, compute, networking, security, and monitoring providers.
- Email routing, inbound email, transactional email, and support communication providers.
- Authentication providers.
- Payment processors and billing infrastructure providers.
- Market data, price, exchange-rate, and financial data providers.
- AI extraction providers used to process documents and emails you choose to import.
- Analytics providers used to understand product usage and marketing performance.
- Professional advisers, auditors, insurers, legal representatives, and compliance partners where needed.
We may also disclose information if we believe disclosure is required or appropriate to comply with law, respond to lawful requests, protect rights, property, or safety, enforce our terms, prevent abuse, investigate security incidents, collect amounts owed, or handle a merger, acquisition, financing, reorganization, sale of assets, or similar transaction.
International processing
Varuna is available over the internet and uses service providers that may process information in countries other than where you live. Those countries may have data protection rules that differ from your local laws.
Where required, we use appropriate safeguards for international transfers, such as contracts, data processing terms, provider commitments, or other mechanisms permitted by applicable law.
Retention
We keep account and portfolio data while your account is active or as needed to provide the service. Transactions, holdings, categories, goals, and reports remain until you change or delete them, or ask us to delete your account.
We may keep billing records, security logs, import metadata, outbox records, analytics records, support records, and operational records for longer where needed for accounting, tax, fraud prevention, dispute handling, abuse prevention, legal compliance, security, or reliability.
We may retain deidentified, aggregated, or anonymized information that no longer reasonably identifies you, and we may use it for analytics, product improvement, security, and business purposes.
Your rights and choices
You can update portfolio data in the app, rotate or disable portfolio email aliases, delete staged imports, cancel subscription renewal from billing settings, and change preferences where the product provides controls.
You may ask us to access, correct, export, restrict, or delete personal information where applicable. Depending on where you live, you may also have rights to object to processing, request portability, or complain to a data protection authority.
We may need to verify your identity before acting on a request. We may refuse, limit, or delay a request where permitted by law, including where information is needed for security, fraud prevention, legal compliance, billing, dispute resolution, or protecting the rights of others.
Account deletion
If you ask us to delete your account, we will delete or deidentify account and portfolio information within a reasonable period, except where retention is required or permitted for legal, security, fraud prevention, billing, accounting, backup, dispute, or operational reasons.
Deleting your account may not delete information already processed by third-party providers, payment processors, email systems, backups, logs, or analytics systems where those systems retain records under their own policies or for legal and operational reasons.
Children
Varuna is not intended for children. You may not use Varuna if you are under 18 or under the age required to enter into a binding agreement in your location. We do not knowingly collect personal information from children.
Security
We use administrative, technical, and organizational safeguards appropriate for a portfolio tracking product. No internet service is perfectly secure, so please use a strong Google account, enable multi-factor authentication where available, and report suspicious activity.
More detail about our security posture is available on the Security page.
Do Not Track
Some browsers offer Do Not Track or similar signals. There is no consistent industry standard for responding to these signals, and Varuna does not currently respond to them. We may respond to legally required opt-out preference signals where applicable.
Changes
We may update this policy as Varuna changes. If a change is material, we will take reasonable steps to notify users through the product or by email.
Continued use of Varuna after a policy update means the updated policy applies to information collected after the effective date, except where law requires a different approach.
Contact
Privacy questions, data requests, and complaints can be sent to [email protected].