LEGAL / DATA USE
Privacy Policy
This policy explains how Veetbot handles information on its public website and in its optional Gmail integration.
Effective September 2, 2026
1. Scope and who controls data
Veetbot is a self-hostable AI agent. The operator of a Veetbot deployment controls that deployment and its stored records. This policy describes the current Veetbot public website and the owner-operated Gmail integration. It does not replace the policies of Google, an AI model provider, or another service you choose to connect.
2. Public website data
The public website does not provide accounts, forms, behavioral analytics, advertising, or advertising cookies. Hosting and security infrastructure may process ordinary request data such as IP address, browser type, requested URL, and timestamps to deliver the site, prevent abuse, and diagnose failures.
3. Google data Veetbot accesses
Veetbot requests three separate Gmail permissions. Each is used only when its corresponding integration is enabled:
gmail.readonly- Search threads and read message metadata, headers, labels, snippets, and plain-text message bodies. HTML is reduced to text. Attachment names, media types, and sizes may be seen, but attachment contents are not downloaded.
gmail.modify- Create drafts; add or remove labels; archive or mark threads read; and move threads to or from Gmail trash.
gmail.send- Send a plain-text message after the complete proposed message has been presented for approval.
Veetbot does not use these permissions to permanently delete Gmail messages, download attachments, access calendars, or connect additional mailboxes without a new authorization.
4. How Google data is used
Google data is used only to provide user-facing features, including:
- searching, reading, and summarizing mail you ask Veetbot to review;
- preparing drafts and organizing messages at your direction;
- sending messages that you explicitly approve;
- running email-triage schedules you configure; and
- maintaining security, reliability, and an inspectable record of agent work.
Veetbot does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train a general-purpose AI model.
5. AI processing and sharing
To perform an email task, relevant message content and metadata may be sent to the AI model provider configured by the Veetbot operator. This processing is limited to producing the requested user-facing result, such as a summary, classification, draft, or proposed action. The selected provider processes that data under its own terms and privacy policy. Connect Gmail only if you accept that processing arrangement.
Veetbot may otherwise disclose data only to service providers needed to operate the requested feature, to investigate a security incident, when you explicitly direct or consent to the disclosure, or when required by law. Human access is limited to those purposes and to support you explicitly request.
6. Storage and retention
OAuth client secrets and refresh tokens are stored in private operator-controlled credential files. Tokens and raw Google error responses are excluded from Veetbot tool results, events, and logs.
Gmail content selected for a task, tool inputs and outputs, generated summaries and drafts, approval records, and related artifacts may be retained in Veetbot's session and run history. This supports inspection, continuation, recovery, and auditing. Retention is controlled by the deployment operator; protected backups may persist until their normal rotation. Deleting mail in Gmail does not automatically delete a copy already retained in a Veetbot record.
7. Your choices and deletion
You may:
- decline the Gmail permissions and use Veetbot without email tools;
- revoke Veetbot's Google access through your Google Account's third-party connection settings;
- disable the Gmail integration and remove its credential files; and
- delete available sessions or ask the deployment operator to delete associated Veetbot records and artifacts.
Revoking Google access stops future Gmail API access but does not automatically erase existing Veetbot records. A deletion request may be subject to short-lived backup retention and any legal obligation that requires preservation.
8. Security
Veetbot uses scoped credentials, access controls, encrypted transport, deterministic policy checks, approval requirements, bounded outputs, and secret-redaction controls. No system is perfectly secure, and operators remain responsible for securing their hosts, provider accounts, and backups.
9. Google API Limited Use
Veetbot's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Changes and contact
This policy may change when Veetbot's data practices change. The effective date above will be updated, and material changes affecting Google data will be disclosed before the new use begins. For privacy or deletion requests, use the support address displayed on Veetbot's Google OAuth consent screen. For non-sensitive public questions, use the project issue tracker.
See also the Veetbot Terms of Service.