Veya Privacy Policy
Last updated 6 September 2026
Veya is a desktop application made by Sozenta, Inc. It runs on your computer and keeps your work on your disk. This policy explains what data Veya touches, what leaves your machine and when, and what we do — and do not — do with information you connect from Google.
1. Who we are
Sozenta, Inc. ("Sozenta", "we") publishes Veya. You can reach us at brijesh@sozenta.ai for any question about this policy or to request deletion of data.
2. The short version
- Veya is a desktop app. Your documents, notes, mail and calendar data are stored on your own device, not on our servers.
- We do not operate a service that collects, aggregates or resells your content.
- When you connect Google, Veya talks to Google directly from your computer. Your mail and calendar data do not pass through Sozenta servers.
- We never use Google user data to train or improve any generalized AI model.
- Content leaves your machine only when you invoke a feature that requires it — and you can turn that off entirely.
3. What Veya accesses from Google, and why
Veya asks for access only when you choose to connect a Google account, and only for the features you connect it for. You can decline, and you can disconnect at any time.
| Scope | What it allows | Why Veya needs it |
|---|---|---|
https://mail.google.com/ |
Full access to the connected Gmail mailbox | The Email canvas reads, composes, sends, files and searches your mail over IMAP and SMTP. Google's narrower Gmail scopes are REST-only and do not grant IMAP or SMTP access, so this scope is the minimum that makes a real mail client work. |
https://www.googleapis.com/auth/calendar.events |
Read and write calendar events | The Calendar canvas shows your schedule and lets you create, edit and delete events. This scope does not grant access to calendar settings, sharing rules or other calendars' metadata. |
https://www.googleapis.com/auth/userinfo.email |
Your email address | So Veya can show you which account is connected, and so it can attach the right identity when sending. |
Veya requests no other Google scopes. It does not access Drive, Contacts, Photos, Chat, or your Google account profile beyond the email address above.
4. Where your data is stored
On your device. Mail, calendar events, documents and everything else Veya works with are stored in Veya's local application data directory on your computer. Deleting the app's data directory, or using Veya's own disconnect and delete controls, removes it.
Access tokens. The OAuth access and refresh tokens Google issues are stored locally on your device in Veya's application storage so you do not have to sign in repeatedly. They are not transmitted to Sozenta. Disconnecting an account in Veya deletes the stored tokens; you can additionally revoke Veya's access at any time from your Google account permissions page.
Not on our servers. Sozenta does not receive, store or back up your mailbox, your calendar or your documents.
5. When information leaves your machine
Veya makes network requests in four situations, all of which you control:
Google APIs
Directly from your device to Google, to fetch and send the mail and calendar data described above.
AI features you invoke
Veya can summarise, draft, extract from and answer questions about your content using an AI model. This happens only when you invoke such a feature. The relevant content — which may include the text of an email or a calendar entry you have asked about — is sent to the model provider you have configured, which may be Anthropic, OpenAI, Google, Amazon Bedrock, Meta, or a model running locally on your own machine or your own server.
Where a request goes is determined by the provider you configure. Veya ships a network mode control that lets you restrict this: Local models only keeps AI requests on your own hardware, and Offline stops outbound requests altogether. Under either setting, no content is sent to a remote model.
Vera, if you use it
Vera is Sozenta's optional AI gateway. If you point Veya at a Vera hub, AI requests are routed through it. You may run your own Vera instance, in which case those requests never reach Sozenta infrastructure at all. If you use a Sozenta-hosted Vera, we process the request in order to serve it and retain operational logs (timestamps, model, principal, byte counts, error status) for reliability, abuse prevention and cost control. We do not retain prompt or response content for training.
Application updates
Veya checks for a new version at launch and periodically thereafter. This request reveals your IP address, current version and operating system to our release host, and nothing else. It is disabled in Offline mode.
6. Google user data and AI — our explicit commitments
Limited Use disclosure. Veya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and without qualification:
- We do not use Google user data to develop, train, fine-tune or improve generalized AI or machine-learning models.
- We do not sell, rent or license Google user data, and we do not transfer it to data brokers, advertisers or information resellers.
- We do not use Google user data for advertising, and Veya contains no advertising.
- We do not allow humans to read your Google user data, except with your explicit consent for a specific support request, where required by law, or where necessary for security investigation or abuse prevention — and then only the minimum needed.
- Where you invoke an AI feature on Google data, that content is sent to your configured model provider for the sole purpose of returning the result you asked for. Sozenta does not retain it.
We cannot control the independent terms of a third-party model provider you choose to configure. We select defaults whose API terms preclude training on submitted data, and Veya always tells you which provider a request is going to. If that matters to you, use a local model — the same features work.
7. What we collect about you
Very little, and none of it is your content.
- No analytics or telemetry in the app. Veya does not embed usage analytics, session recording, advertising identifiers or third-party trackers.
- Update checks produce ordinary web-server records (IP address, version, OS), retained briefly for operational purposes.
- Sozenta-hosted Vera, if you use it, produces the operational logs described in section 5.
- Support correspondence you send us — we keep what you write to us so we can answer it.
8. Deleting your data
- Disconnect a Google account in Veya: this deletes the stored tokens and stops all further access.
- Revoke at Google: myaccount.google.com/permissions removes Veya's access from Google's side, independently of us.
- Delete local data: removing Veya's application data directory removes everything the app has stored.
- Ask us: email brijesh@sozenta.ai and we will delete any Sozenta-held record associated with you and confirm when it is done.
9. Security
Veya is a local-first application, which removes whole categories of risk: there is no central store of customer mailboxes to breach. Network traffic uses TLS. Sozenta-hosted Vera authenticates every request, enforces per-principal access rules and records an audit trail.
No system is perfectly secure. Because your data lives on your device, its security also depends on your device: full-disk encryption and a locked screen do more for it than anything we can do remotely.
10. Children
Veya is not directed at children under 13, and we do not knowingly collect their information.
11. International users
Sozenta, Inc. is based in the United States. If you use a Sozenta-hosted service, the limited operational data described above is processed in the United States. Your content stays on your device unless you send it somewhere, so its location is yours to determine.
12. Changes to this policy
If we change this policy in a way that materially affects how Google user data is handled, we will update the date at the top and describe the change in the Veya release notes. Continuing to use Veya after a change means you accept the revised policy.
13. Contact
Sozenta, Inc. — brijesh@sozenta.ai