Privacy
Viola Privacy Policy
Viola is a browser. Where you go and what you do there is your business, not ours. This page explains exactly what leaves your device, what never does, and how to turn off the parts you don't want.
Effective 26 July 2026 · Applies to the Viola browser on all platforms
Viola is early access software. Features described here may change, and behaviour in a pre-release build may not always match this page. When the two disagree, the software is the accurate description and this page is the bug. Tell us and we will fix it.
1. The short version
We do not collect or retain your browsing history. It is written to your device and stays there. We have no copy, no way to request one, and nothing to hand over if somebody asks us for it.
What does leave your device falls into four small buckets: a periodic update check, narrow first-party operational and product statistics, a crash report if you opt in, and encrypted workspace/tab sync if you create a Viola account. Separately, a browser is a network client — it connects to the sites you ask for, to your chosen search engine, and to a handful of Chromium infrastructure endpoints described in section 6. We tell you about those too, because pretending they don't exist would be dishonest.
2. What this policy covers
This policy covers the Viola browser application. Our marketing website is covered by section 11.1.
It does not cover the websites you visit through Viola, the extensions you choose to install, or the search engine you set as your default. Those are run by other people under their own policies, and a browser cannot make promises on their behalf.
The data controller is the operator of ViolaBrowser.com.
3. What stays on your device
All of the following is stored locally and is never transmitted to us:
- Browsing and download history
- Bookmarks, tab groups, splits, pinned tabs and workspaces
- Cookies, site data, cache and local storage
- Saved passwords and payment details
- Form autofill entries
- Your settings, themes and layout preferences
- Permissions you have granted to individual sites
Passwords are stored using your operating system's credential store where one is available — Keychain on macOS, and the platform equivalents elsewhere — so they are protected by your device's own account security.
4. What Viola collects
4.1 Update checks
Viola periodically asks our update server whether a newer version exists. That request necessarily includes your IP address, plus the current version, operating system and CPU architecture, so we can serve the right build. We use these requests in aggregate to estimate how many people are running Viola and on what.
We do not store IP addresses from update checks in a form linked to an install. Update checks can be disabled in settings, in which case you are responsible for updating manually.
4.2 Crash reports — off unless you turn them on
If Viola crashes and you have enabled crash reporting, we receive a stack trace, the browser and OS version, and basic device information.
Be aware: a crash report is a snapshot of memory at the moment things went wrong. It can contain fragments of whatever the browser was holding — which may include page content, a URL, or in rare cases text you had typed, including a password. We discard the raw dump after processing and keep only the stack trace. We would rather tell you this plainly than let you assume a crash report is harmless.
4.3 Operational and product statistics
Viola always sends two deliberately limited operational events: one when an installation is first reported and at most one active-app event per UTC day. Each event has its own random retry token, which is used only to prevent a retry from being counted twice and is deleted within two days. Tokens differ between events, so they cannot form a device or person history. The event includes Viola version, operating-system family and coarse version, CPU architecture, and release channel. These totals tell us whether Viola is being installed and used at all; they cannot truthfully tell us that two days came from the same person.
More detailed anonymous product statistics are on by default with a free opt-out. When enabled, Viola sends a separate random identifier that changes every UTC day, plus launch count and active minutes. The service hashes that one-day identifier with a server-only secret and never links it to your Viola account.
After each day, device-level rows are converted into aggregate totals and deleted. You can turn detailed product statistics off at any time in Settings → Privacy; Viola then deletes the current daily identifier locally and sends no further launch or active-minute events unless you turn the setting back on. The two unlinked operational counts above continue. Any prior aggregate totals cannot identify or be removed for one person.
We never include URLs, page titles, search terms, bookmark names, tab or workspace names, page content, cookies, or account identity in these reports.
5. Automatic connections
Beyond the traffic you initiate, Viola makes a small number of background connections. Each is listed below with who receives it and how to stop it.
- Update check — to us. Disable in settings.
- Operational counts — one unlinked install event and at most one unlinked active-app event per UTC day, sent to us.
- Component updates — certificate revocation lists, media components and filter lists. See section 6.
- Connectivity and time checks — used to detect captive portals and validate certificates.
- Safe Browsing list updates — see section 6.
- Extension update checks — see section 8.
- Search suggestions — to your chosen engine as you type, if enabled. See section 7.
6. Chromium and Google services
Viola is built on Chromium, the open-source project that also underpins Chrome, Edge, Brave and others. Chromium ships with a number of Google-operated services wired in. Some are genuinely useful, some we have removed, and we think you are entitled to know which is which.
6.1 What we removed from upstream Chromium
The following upstream behaviours are disabled or stripped in Viola builds:
- Google usage metrics and crash reporting endpoints — replaced with our own first-party, disclosed controls
- The promotional /
RLZtracking tag appended to searches - The install-tracking ping sent on first run
- Field-trial identifiers attached to outgoing Google requests
- Sign-in to a Google Account and account-linked sync
6.2 Safe Browsing
If enabled, Viola checks the addresses you visit against a list of known phishing and malware sites. This works by downloading a list of hashed prefixes and matching locally; the full address is only involved when a prefix matches, and even then only a partial hash is sent. The address of the page you are visiting is never sent in the clear.
The list is operated by Google. [CONFIRM: state whether Viola proxies these requests so the user's IP is not exposed to Google, and on which platforms — this is the single most meaningful Chromium-fork privacy claim, and it must be accurate.]
Safe Browsing can be turned off in settings. Doing so removes a real layer of protection.
6.3 Component Updater
Separately from browser updates, Chromium fetches small components on a schedule: certificate revocation lists, TLS root updates, and the DRM module described below. These requests go to Google's component servers and include your IP address. They exist to keep the browser cryptographically current, which is why they are on by default.
6.4 Variations
Chromium periodically fetches a configuration seed that controls feature rollouts. Viola [CONFIRM: uses / does not use / self-hosts] the variations service. Where it is used, no identifier tying the request to your install is attached.
6.5 Media and DRM
Playing protected video — most streaming services — requires a content decryption module. When you first play such content, a device-bound identifier may be generated and shared with the site's licence server. This identifier is specific to your device and is not visible to us. Protected content playback can be disabled in settings, which will break those services.
7. Search
When you search from the address bar, your query goes to whichever search engine you have set as your default. It does not pass through us and we never see it.
If search suggestions are enabled, characters are sent to that engine as you type — before you press enter. That is how suggestions work, and it means partial queries reach your search provider. Suggestions can be turned off in settings.
Your search provider's handling of that data is governed by their privacy policy, not ours.
8. Extensions
Viola can install extensions from the Chrome Web Store. Two things follow from that:
- Installing and updating extensions involves Google. Store requests and periodic update checks go to Google's servers and include your IP address.
- Chromium carries a blocklist of extensions known to be malicious, which is fetched periodically and can result in a harmful extension being disabled on your device.
An extension you install can, depending on the permissions you grant it, read and change the pages you visit. Extensions are written by third parties under their own privacy policies. We do not review them and cannot vouch for them. Grant permissions deliberately.
9. Sync
Sync is optional. If you create an account, we store your email address, display name, password verifier, registered-device metadata, session records, and encrypted tab/workspace snapshots. Passwords are salted and hashed; we cannot recover them.
Synced browser organization is end-to-end encrypted on your device before upload. Your password unwraps the sync key locally. We store only its password-protected envelope and ciphertext; the service cannot read your tab URLs, titles, groups, or workspace names.
The account manager shows registered devices and their last-seen and last-sync times. You can sign out individual devices, change your password, or permanently delete the account and its cloud ciphertext at any time.
10. What we never do
- We do not sell personal data. There is no "sale" or "sharing" of personal information as those terms are defined under California law, and no arrangement under which we would.
- We do not build advertising profiles, and Viola contains no advertising.
- We do not embed third-party analytics or tracking inside the browser.
- We do not read, scan or index the pages you visit.
- We do not require an account to use the browser; an account is needed only for optional sync.
11. Who else touches data
We use a small number of service providers to run the things described above: [LIST PROCESSORS: update/CDN host, crash-report processor, website host, and the country each operates in.] They act on our instructions under contract and may not use the data for their own purposes.
We will disclose data to law enforcement only where we are legally compelled by valid process, and we will tell you unless we are prohibited from doing so. In practice, the most common answer we can give to such a request is that we do not hold what is being asked for.
11.1 This website
The Viola website and account service are hosted on infrastructure operated by DigitalOcean, which processes standard server logs including IP addresses for security and reliability. Cloudflare provides DNS and may provide network security services. The public site sets no advertising or analytics cookies. The account manager sets one short-lived, secure, HttpOnly sign-in cookie.
12. How long we keep things
- Update check logs — aggregated immediately; raw logs discarded within 30 days.
- Crash reports — raw dump discarded after processing; stack trace kept up to 12 months.
- Operational statistics — event retry tokens are deleted within two days. Daily report pseudonyms are aggregated and deleted after the UTC day closes. Aggregate daily totals are kept for up to 24 months.
- Sync accounts — retained until you delete the account. Expired and revoked sessions are periodically removed.
- Support correspondence — kept for up to 24 months, then deleted.
- Website server logs — [HOST'S RETENTION PERIOD].
13. Security
Everything Viola sends travels over TLS. Access to what little we hold is limited to people who need it. Viola is built on Chromium and inherits its security architecture, including site isolation and the sandbox, and we track upstream security releases so that fixes reach you quickly.
No system is perfectly secure, and this is early access software. If you find a vulnerability, please report it to security@viola.app rather than posting it publicly, and we will work with you on a fix.
14. Children
Viola is not directed at children under 13, and we do not knowingly collect personal data from them. Because the browser requires no account and collects no personal data by default, there is very little for us to collect from anybody. If you believe a child has provided us with personal data through a crash report or support message, contact us and we will delete it.
15. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, to object to processing, and to withdraw consent at any time. Where we rely on consent — including crash reports and, where local law requires it, detailed product statistics — you can withdraw it by switching the setting off, with no effect on anything already processed.
If you are in California, you have the right to know, delete, correct and opt out of sale or sharing, and not to be discriminated against for exercising those rights. As noted above, we do not sell or share personal information.
To exercise any of these, write to privacy@viola.app. We will respond within the period the applicable law requires. Be aware that for most requests our honest answer will be that we hold nothing about you — the browser is built so that this is true.
Our lawful bases are: legitimate interests for update checks, security, and narrow aggregate operational measurement; legitimate interests for first-party product measurement where applicable law permits it; and consent for crash reports and product measurement where local law requires consent. [If you have EU/UK users at scale, you may need an Article 27 representative and a named supervisory authority — check with counsel.]
16. International transfers
Our infrastructure is located in [COUNTRIES]. Where data moves out of the UK or European Economic Area, we rely on [Standard Contractual Clauses / UK IDTA / adequacy decision].
17. Changes to this policy
We will update this page when what Viola does changes, and the effective date at the top will change with it. For anything that materially reduces your privacy, we will give notice in the browser or by email before it takes effect, rather than quietly editing this page.
If a change is not acceptable to you, the remedy is straightforward: stop using Viola. We would rather lose a user than have one who disagrees with how their data is handled.
18. Contact
Privacy questions and rights requests:
privacy@viola.app
Security reports: security@viola.app
Everything else: hello@viola.app
See also the Terms of Service.