Veya Privacy Policy

Last updated 6 September 2026

Veya is a desktop application made by Sozenta, Inc. It runs on your computer and keeps your work on your disk. This policy explains what data Veya touches, what leaves your machine and when, and what we do — and do not — do with information you connect from Google.

1. Who we are

Sozenta, Inc. ("Sozenta", "we") publishes Veya. You can reach us at brijesh@sozenta.ai for any question about this policy or to request deletion of data.

2. The short version

3. What Veya accesses from Google, and why

Veya asks for access only when you choose to connect a Google account, and only for the features you connect it for. You can decline, and you can disconnect at any time.

ScopeWhat it allowsWhy Veya needs it
https://mail.google.com/ Full access to the connected Gmail mailbox The Email canvas reads, composes, sends, files and searches your mail over IMAP and SMTP. Google's narrower Gmail scopes are REST-only and do not grant IMAP or SMTP access, so this scope is the minimum that makes a real mail client work.
https://www.googleapis.com/auth/calendar.events Read and write calendar events The Calendar canvas shows your schedule and lets you create, edit and delete events. This scope does not grant access to calendar settings, sharing rules or other calendars' metadata.
https://www.googleapis.com/auth/userinfo.email Your email address So Veya can show you which account is connected, and so it can attach the right identity when sending.

Veya requests no other Google scopes. It does not access Drive, Contacts, Photos, Chat, or your Google account profile beyond the email address above.

4. Where your data is stored

On your device. Mail, calendar events, documents and everything else Veya works with are stored in Veya's local application data directory on your computer. Deleting the app's data directory, or using Veya's own disconnect and delete controls, removes it.

Access tokens. The OAuth access and refresh tokens Google issues are stored locally on your device in Veya's application storage so you do not have to sign in repeatedly. They are not transmitted to Sozenta. Disconnecting an account in Veya deletes the stored tokens; you can additionally revoke Veya's access at any time from your Google account permissions page.

Not on our servers. Sozenta does not receive, store or back up your mailbox, your calendar or your documents.

5. When information leaves your machine

Veya makes network requests in four situations, all of which you control:

Google APIs

Directly from your device to Google, to fetch and send the mail and calendar data described above.

AI features you invoke

Veya can summarise, draft, extract from and answer questions about your content using an AI model. This happens only when you invoke such a feature. The relevant content — which may include the text of an email or a calendar entry you have asked about — is sent to the model provider you have configured, which may be Anthropic, OpenAI, Google, Amazon Bedrock, Meta, or a model running locally on your own machine or your own server.

Where a request goes is determined by the provider you configure. Veya ships a network mode control that lets you restrict this: Local models only keeps AI requests on your own hardware, and Offline stops outbound requests altogether. Under either setting, no content is sent to a remote model.

Vera, if you use it

Vera is Sozenta's optional AI gateway. If you point Veya at a Vera hub, AI requests are routed through it. You may run your own Vera instance, in which case those requests never reach Sozenta infrastructure at all. If you use a Sozenta-hosted Vera, we process the request in order to serve it and retain operational logs (timestamps, model, principal, byte counts, error status) for reliability, abuse prevention and cost control. We do not retain prompt or response content for training.

Application updates

Veya checks for a new version at launch and periodically thereafter. This request reveals your IP address, current version and operating system to our release host, and nothing else. It is disabled in Offline mode.

6. Google user data and AI — our explicit commitments

Limited Use disclosure. Veya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, and without qualification:

We cannot control the independent terms of a third-party model provider you choose to configure. We select defaults whose API terms preclude training on submitted data, and Veya always tells you which provider a request is going to. If that matters to you, use a local model — the same features work.

7. What we collect about you

Very little, and none of it is your content.

8. Deleting your data

9. Security

Veya is a local-first application, which removes whole categories of risk: there is no central store of customer mailboxes to breach. Network traffic uses TLS. Sozenta-hosted Vera authenticates every request, enforces per-principal access rules and records an audit trail.

No system is perfectly secure. Because your data lives on your device, its security also depends on your device: full-disk encryption and a locked screen do more for it than anything we can do remotely.

10. Children

Veya is not directed at children under 13, and we do not knowingly collect their information.

11. International users

Sozenta, Inc. is based in the United States. If you use a Sozenta-hosted service, the limited operational data described above is processed in the United States. Your content stays on your device unless you send it somewhere, so its location is yours to determine.

12. Changes to this policy

If we change this policy in a way that materially affects how Google user data is handled, we will update the date at the top and describe the change in the Veya release notes. Continuing to use Veya after a change means you accept the revised policy.

13. Contact

Sozenta, Inc. — brijesh@sozenta.ai