Privacy
Viola Privacy Policy
Viola is a browser. Where you go and what you do there is your business, not ours. This page explains exactly what leaves your device, what never does, and how to turn off the parts you don't want.
Effective 30 July 2026 · Applies to the Viola browser on all platforms
Viola is early access software. Features described here may change, and behaviour in a pre-release build may not always match this page. When the two disagree, the software is the accurate description and this page is the bug. Tell us and we will fix it.
1. The short version
We do not collect or retain readable browsing history. History is written to your device. If you turn on Viola Sync, a copy is end-to-end encrypted on that device before upload so your other signed-in devices can restore it. We store only ciphertext and cannot read, search, or disclose the sites in it.
What does leave your device falls into three small buckets: a periodic update check, narrow first-party operational and product statistics, and encrypted browser sync if you create a Viola account. Native crash diagnostics stay on your device unless you deliberately send them to us. Separately, a browser is a network client — it connects to the sites you ask for, to your chosen search engine, and to a handful of Chromium infrastructure endpoints described in section 6. We tell you about those too, because pretending they don't exist would be dishonest.
2. What this policy covers
This policy covers the Viola browser application. Our marketing website is covered by section 11.1.
It does not cover the websites you visit through Viola, the extensions you choose to install, or the search engine you set as your default. Those are run by other people under their own policies, and a browser cannot make promises on their behalf.
The data controller is the operator of ViolaBrowser.com.
3. What stays on your device
The following is stored locally. Items marked as syncable are uploaded only as end-to-end encrypted ciphertext when you deliberately enable Viola Sync:
- Browsing history (syncable) and download history (device only)
- Bookmarks, tab groups, splits, pinned tabs and workspaces (organization is syncable)
- Cookies, site data, cache and local storage
- Saved passwords and payment details
- Form autofill entries
- Your settings, themes and layout preferences
- Permissions you have granted to individual sites
- Extension files, permissions, settings, storage and runtime data
Passwords are stored using your operating system's credential store where one is available — Keychain on macOS, and the platform equivalents elsewhere — so they are protected by your device's own account security.
4. What Viola collects
4.1 Update checks
Viola periodically asks our update server whether a newer version exists. That request necessarily includes your IP address, plus the current version, operating system and CPU architecture, so we can serve the right build. We use these requests in aggregate to estimate how many people are running Viola and on what.
We do not store IP addresses from update checks in a form linked to an install. Update checks can be disabled in settings, in which case you are responsible for updating manually.
4.2 Crash diagnostics — kept on your device
Viola's native crash reporter writes diagnostic dumps to your operating system's crash directory with automatic uploads disabled. We do not receive those dumps unless you deliberately attach one to a support or security report.
Be aware: a crash dump is a snapshot of memory at the moment things went wrong. It can contain fragments of whatever the browser was holding, including page content, a URL, or text you had typed. Review what you send and do not send a dump unless it is needed to investigate the problem.
4.3 Operational and product statistics
Viola always sends two deliberately limited operational events: one when an installation is first reported and at most one active-app event per UTC day. Each event has its own random retry token, which is used only to prevent a retry from being counted twice and is deleted within two days. Tokens differ between events, so they cannot form a device or person history. The event includes Viola version, operating-system family and coarse version, CPU architecture, and release channel. These totals tell us whether Viola is being installed and used at all; they cannot truthfully tell us that two days came from the same person.
More detailed anonymous product statistics are on by default with a free opt-out. When enabled, Viola sends a separate random identifier that changes every UTC day, plus launch count and active minutes. The service hashes that one-day identifier with a server-only secret and never links it to your Viola account.
After each day, device-level rows are converted into aggregate totals and deleted. You can turn detailed product statistics off at any time in Settings → Privacy; Viola then deletes the current daily identifier locally and sends no further launch or active-minute events unless you turn the setting back on. The two unlinked operational counts above continue. Any prior aggregate totals cannot identify or be removed for one person.
We never include URLs, page titles, search terms, bookmark names, tab or workspace names, page content, cookies, or account identity in these reports.
5. Automatic connections
Beyond the traffic you initiate, Viola makes a small number of background connections. Each is listed below with who receives it and how to stop it.
- Update check — to us. Disable in settings.
- Operational counts — one unlinked install event and at most one unlinked active-app event per UTC day, sent to us.
- Component updates — certificate revocation lists, media components and filter lists. See section 6.
- Connectivity and time checks — used to detect captive portals and validate certificates.
- Extension update checks — see section 8.
- Search suggestions — to your chosen engine as you type, if enabled. See section 7.
6. Chromium and Google services
Viola is built on Chromium, the open-source project that also underpins Chrome, Edge, Brave and others. Chromium ships with a number of Google-operated services wired in. Some are genuinely useful, some we have removed, and we think you are entitled to know which is which.
6.1 What we removed from upstream Chromium
The following upstream behaviours are disabled or stripped in Viola builds:
- Google usage metrics and crash-report uploads — native crash diagnostics remain local, while our narrow first-party statistics are disclosed above
- The promotional /
RLZtracking tag appended to searches - The install-tracking ping sent on first run
- Field-trial identifiers attached to outgoing Google requests
- Sign-in to a Google Account and account-linked sync
6.2 Safe Browsing
Current Viola builds do not enable Google's Safe Browsing list service, do not send page addresses or hash-prefix lookups to Google for that service, and do not operate a Safe Browsing proxy. Your operating system, security software, an extension, or a download service may perform its own reputation checks under that provider's privacy policy.
6.3 Component Updater
Separately from browser updates, Chromium fetches small components on a schedule: certificate revocation lists, TLS root updates, and the DRM module described below. These requests go to Google's component servers and include your IP address. They exist to keep the browser cryptographically current, which is why they are on by default.
6.4 Variations
Chromium-based products can fetch configuration seeds that control feature rollouts. Current Viola builds do not configure, fetch from, or self-host a Chromium variations service.
6.5 Media and DRM
Playing protected video — most streaming services — requires a content decryption module. When you first play such content, a device-bound identifier may be generated and shared with the site's licence server. This identifier is specific to your device and is not visible to us. Protected content playback can be disabled in settings, which will break those services.
7. Search
When you search from the address bar, your query goes to whichever search engine you have set as your default. It does not pass through us and we never see it.
If search suggestions are enabled, characters are sent to that engine as you type — before you press enter. That is how suggestions work, and it means partial queries reach your search provider. Suggestions can be turned off in settings.
Your search provider's handling of that data is governed by their privacy policy, not ours.
8. Extensions
Viola can install extensions from the Chrome Web Store. Two things follow from that:
- Installing and updating extensions involves Google. Store requests and periodic update checks go to Google's servers and include your IP address.
- Chromium carries a blocklist of extensions known to be malicious, which is fetched periodically and can result in a harmful extension being disabled on your device.
An extension you install can, depending on the permissions you grant it, read and change the pages you visit. Extensions are written by third parties under their own privacy policies. We do not review them and cannot vouch for them. Grant permissions deliberately.
9. Sync
Sync is optional. If you create an account, we store your email address, display name, password verifier, registered-device metadata, session records, and encrypted browser snapshots. Passwords are salted and hashed; we cannot recover them.
Synced browser organization and history are end-to-end encrypted on your device before upload. A compatible Chrome Web Store extension's ID, name/version and enabled state may also be included so a supported desktop peer can reinstall it; extension files, local/unpacked extensions, permissions, settings, storage, cookies and credentials are excluded. Your password unwraps the sync key locally. We store only its password-protected envelope and ciphertext; the service cannot read your history, tab URLs, titles, groups, workspace names, or compatible extension list.
The account manager shows registered devices and their last-seen and last-sync times. You can sign out individual devices, change your password, or permanently delete the account and its cloud ciphertext at any time.
10. What we never do
- We do not sell personal data. There is no "sale" or "sharing" of personal information as those terms are defined under California law, and no arrangement under which we would.
- We do not build advertising profiles, and Viola contains no advertising.
- We do not embed third-party analytics or tracking inside the browser.
- We do not read, scan or index the pages you visit.
- We do not require an account to use the browser; an account is needed only for optional sync.
11. Who else touches data
DigitalOcean hosts our website, API, database, and update files in the United States. Resend delivers account verification email. Google processes identity information if you choose Google sign-in and receives the Google or Chrome Web Store requests described above. GitHub hosts public manual-download release files. These providers process the account, IP address, and request information needed to provide their part of the service under their own privacy terms and our applicable agreements. Viola does not use a remote crash-report processor.
We will disclose data to law enforcement only where we are legally compelled by valid process, and we will tell you unless we are prohibited from doing so. In practice, the most common answer we can give to such a request is that we do not hold what is being asked for.
11.1 This website
The Viola website and account service are hosted on infrastructure operated by DigitalOcean, which necessarily processes IP addresses to deliver requests. Cloudflare provides authoritative DNS but does not currently proxy Viola website or API traffic. The public site sets no advertising or analytics cookies. The account manager sets one short-lived, secure, HttpOnly sign-in cookie.
12. How long we keep things
- Update check logs — aggregated immediately; raw logs discarded within 30 days.
- Crash diagnostics — native dumps remain on your device and are never uploaded automatically. A dump you deliberately send is handled as support correspondence.
- Operational statistics — event retry tokens are deleted within two days. Daily report pseudonyms are aggregated and deleted after the UTC day closes. Aggregate daily totals are kept for up to 24 months.
- Sync accounts — retained until you delete the account. Expired and revoked sessions are periodically removed.
- Support correspondence — kept for up to 24 months, then deleted.
- Website and update requests — first-party access logging is not enabled. Hosting and network providers may retain operational or security records under their own policies. Any first-party incident log we deliberately preserve is deleted within 30 days unless a longer period is required for security, fraud prevention, or law.
13. Security
Everything Viola sends travels over TLS. Access to what little we hold is limited to people who need it. Viola is built on Chromium and inherits its security architecture, including site isolation and the sandbox, and we track upstream security releases so that fixes reach you quickly.
No system is perfectly secure, and this is early access software. If you find a vulnerability, please report it to security@violabrowser.com rather than posting it publicly, and we will work with you on a fix.
14. Children
Viola is not directed at children under 13, and we do not knowingly collect personal data from them. Because the browser requires no account and collects no personal data by default, there is very little for us to collect from anybody. If you believe a child has provided us with personal data through a crash report or support message, contact us and we will delete it.
15. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, to object to processing, and to withdraw consent at any time. Where we rely on consent — including crash reports and, where local law requires it, detailed product statistics — you can withdraw it by switching the setting off, with no effect on anything already processed.
If you are in California, you have the right to know, delete, correct and opt out of sale or sharing, and not to be discriminated against for exercising those rights. As noted above, we do not sell or share personal information.
To exercise any of these, write to privacy@violabrowser.com. We will respond within the period the applicable law requires. Be aware that for most requests our honest answer will be that we hold nothing about you — the browser is built so that this is true.
Our lawful bases are: legitimate interests for update checks, security, and narrow aggregate operational measurement; legitimate interests for first-party product measurement where applicable law permits it; and consent for information you deliberately send in a support or security report and for product measurement where local law requires consent.
16. International transfers
Our first-party website, API, database, and update infrastructure is operated from the United States, and our providers may process information in other countries. Those locations may have different privacy laws from yours. Where applicable law requires a transfer mechanism, we use the provider's applicable contractual safeguards, an adequacy decision, or another lawful mechanism.
17. Changes to this policy
We will update this page when what Viola does changes, and the effective date at the top will change with it. For anything that materially reduces your privacy, we will give notice in the browser or by email before it takes effect, rather than quietly editing this page.
If a change is not acceptable to you, the remedy is straightforward: stop using Viola. We would rather lose a user than have one who disagrees with how their data is handled.
18. Contact
Privacy questions and rights requests:
privacy@violabrowser.com
Security reports: security@violabrowser.com
Everything else: hello@violabrowser.com
See also the Terms of Service.