Security and Privacy
How Vireo handles your data — hashing at the edge, region pinning, retention controls, and our compliance posture.
Last updated February 2026
Our privacy posture
Three defaults, all on from day one:
- Hash at the edge. PII is hashed before it leaves the client. You opt into raw values, never out of protection.
- Pin the region. Choose where events live — EU or US — and they stay there.
- Set retention. Per-event-type windows you control, from days to years.
Compliance
Vireo is designed to help you meet GDPR and CCPA obligations: data subject export and deletion requests are supported through the dashboard, and our data processing agreement is available to all paying customers.
Reporting
Found a vulnerability? Email security@vireo.dev — we take reports seriously and respond within one business day. We also run regular third-party penetration tests and keep our dependency supply chain verified.
Frequently asked questions
Is PII hashing on by default?
Yes. Raw personal data is never collected by default — emails and identifiers are hashed at the edge before events leave the client.
Can I pin my data to a specific region?
Yes. Choose an EU or US region per workspace; events, dashboards, and exports stay in that region.
How long do you keep my data?
Retention windows are set per event type and default to sensible values. You can shorten them at any time.
Is my data used to train models or shared with anyone?
No. Your data is used only to provide the service to you. It is never sold, never shared, and never used for any other product.