Verzeta

Privacy

Privacy policy

Verzeta runs on your own machines. There is no Verzeta server, no account and no telemetry. Each app has its own policy below.

Verzeta Studio

This document describes what Verzeta™ Studio does with your data. It is written in plain language and applies to the open-source software distributed by the project; it does not describe what any third-party LLM provider you use does with the data you send them.

For the formal regulatory analysis (GDPR / HIPAA / PCI DSS posture), see COMPLIANCE.md.


The short version

Verzeta Studio is local-first software.

  • Your conversations, settings, attachments, and skills live on your own machine.
  • The developer (the publisher of this software) has zero access to your data.
  • The app has no telemetry, no analytics, no cloud sync, and no "phone home" of any kind.
  • Verzeta only connects to services you set up: model providers, paired devices, your web search backend, image and embeddings providers, MCP servers, ClawHub when you search for skills, and Hugging Face when you download a model.
  • Your data exists only on your device. Removing the app does not delete it; see "Delete everything" below.

If you read nothing else, that is the policy.


Who runs Verzeta Studio

Verzeta Studio is open-source software distributed under a triple-license arrangement: GPL-3.0-or-later, LGPL-3.0-or-later, or commercial terms, depending on the component and the user's choice. The per-component breakdown is in LICENSING.md. The publisher distributes the source code and binaries. Each user installs and runs the software on their own hardware.

There is no Verzeta-operated server, no Verzeta cloud account, and no Verzeta-side database holding user data. The publisher has no operational role in any individual user's installation.

This makes Verzeta Studio different from a typical Software-as-a-Service product: there is no central operator who could even theoretically access your data.


What data Verzeta stores on your device

Verzeta stores the following on the device where you install it:

Data Stored where Purpose
Conversations and messages SQLite DB in ~/.local/share/Verzeta/verzeta-studio/ (Linux) or %APPDATA%\Verzeta\verzeta-studio\ (Windows) Persisting your chats
Attachments (files, images) Same data folder Persisting message attachments
Skills skills/ inside the data folder Skill packs you have installed
Project documents Per-project folders inside the data folder Documents you attach to a project
Canvas artifacts Same data folder Files agents have opened in canvas
API keys Obfuscated in the local settings file (~/.config/Verzeta/verzeta-studio.conf on Linux, the registry on Windows). Not encrypted. Authenticating you to the LLM providers you configure
Logs logs/ inside the data folder Local diagnostic logs; rotated
Paired-client tokens Local credentials database (only if you enable Remote Access) Authenticating paired Android and VS Code clients
Activity log Local database The audit trail of agent actions

Every entry on this list is on your machine and is fully under your control. None of it is replicated anywhere else by Verzeta.


What data Verzeta sends, and to whom

Verzeta initiates network traffic in only the following situations:

1. LLM provider API calls

When you send a message in a conversation, the message body, conversation history relevant to the request, system prompt, and any tool schemas are sent to the LLM provider you have configured for that conversation or member. This is the only way LLM chat works.

Supported providers:

Note: When you use a cloud provider, you are agreeing to that provider's terms. Verzeta sends the provider what the model needs (the system prompt, recent messages, any summary or retrieved context, and tool definitions) and does not log or copy the request anywhere else. Each provider's privacy policy applies directly to your traffic with them. The publisher of Verzeta is not in the middle.

Each provider's privacy policy:

2. Remote pairing (optional)

If you enable Remote Access in Settings, Verzeta runs a separate daemon (verzeta-remote) on your machine that accepts WebSocket connections from paired devices (the Android and VS Code clients). Traffic between your desktop and paired devices is:

The data flowing over a remote-pairing connection is exactly the same data your local desktop holds. The phone is a remote front end to the desktop, not a duplicate runtime. No third party operates this connection.

3. Optional skill marketplace download

If you use the ClawHub integration to install a skill from a public catalog, Verzeta downloads the skill ZIP from the ClawHub URL you searched. The download is a normal HTTPS request. No identifying information beyond a standard User-Agent is sent. You can also install skills entirely from local folders without contacting ClawHub.

4. Web search (optional, agent-initiated)

If an agent calls the search_web tool, an HTTPS request is made to the configured web search backend. The agent's query is sent to the backend; the backend's results are returned to the agent. This traffic is the same shape as any other web search you do.

5. Model and voice downloads (optional)

When you click Download recommended or download a voice or speech model, Verzeta downloads the file from Hugging Face over HTTPS. Nothing about you or your conversations is sent.

6. Image, embeddings and MCP providers (optional)

If you set up an image provider, a remote embeddings endpoint, or an MCP server, Verzeta sends it the prompt, text or tool arguments it needs, and nothing else.

What Verzeta does not transmit, ever


What Verzeta logs

Verzeta writes local diagnostic logs to its data folder so you can troubleshoot issues. Logs are written only to your machine.

Logs include things like:

Logs are rotated by size; they do not grow indefinitely. Logs may include excerpts of error messages from providers, which may include sanitised request/response shapes. Logs do not record full API keys.

You can:

The publisher of Verzeta does not receive your logs unless you choose to attach them to a bug report you file yourself.


Activity log (in-app audit trail)

Verzeta records every agent turn, tool invocation, poll vote, member change, canvas edit, and file write into a local activity_log table. It stays on your device:

See Documentation/User/09-activity-timeline.md for the full details.


Your rights and how to exercise them

Because there is no central operator who holds your data, the rights data-protection regimes (GDPR / CCPA / etc.) grant data subjects are exercised by you directly on your device.

What you may want to do How to do it
Read all of my data Open the app; browse conversations. The SQLite database is also readable with any SQLite browser.
Export my data Right-click the conversation in the sidebar → Export… (Markdown or JSON). The SQLite database can be copied directly.
Remove a conversation's messages Type /flashmemory in the chat, then /flashmemory confirm.
Delete a conversation Right-click in the sidebar → Delete.
Delete everything Close the app and delete the data folder and settings (~/.local/share/Verzeta/verzeta-studio/ and ~/.config/Verzeta/verzeta-studio.conf on Linux; %APPDATA%\Verzeta\verzeta-studio\, %LOCALAPPDATA%\Verzeta\verzeta-studio\ and the registry key HKEY_CURRENT_USER\Software\Verzeta\verzeta-studio on Windows).
Stop transmitting to a particular provider Open Settings → Text Providers, click the provider, Remove. The API key is deleted; no further requests go there.
Stop a paired device from accessing my desktop Settings → Remote Access → Manage Remote Access → Paired devices → Revoke. The device can no longer connect.
Disable the remote-access feature entirely In Settings → Remote Access → Manage Remote Access, turn off the server and Auto-start at app launch.

You do not need to contact the publisher for any of these. There is no publisher account to manage and no developer-side data to delete.


Children's privacy

Verzeta Studio is not directed at children under 13 (or under any other applicable age threshold for child data protection laws in your jurisdiction). The application does not collect age information because it does not collect personal information at all.

If you are responsible for a minor's use of Verzeta Studio:


Cookies, tracking, and identifiers

Verzeta Studio is a native desktop and mobile application, not a website. It does not set cookies, run third-party JavaScript, or fingerprint the device.

The optional ClawHub skill search is the only feature that contacts a third-party service for content discovery, and the request is a plain HTTPS GET with a generic User-Agent.


Changes to this policy

This policy is part of the source tree. Material changes are made via Git commits with explanatory messages. The Git history is the canonical record of every change.

If the application ever begins to collect or transmit any new category of data on the publisher's behalf, this policy must be updated before that change ships.


Questions


Last reviewed: 2026-09.

Verzeta for Android

Last updated: 2026-09-25

Verzeta for Android is the companion app for the Verzeta Studio desktop application. The Android app does not run AI or language-model code on the device. It pairs with your own copy of Verzeta Studio on your desktop, and all processing happens on that desktop, which you control.

This is the privacy policy for Verzeta for Android. In the app, the Settings → About Verzeta → Privacy policy row opens this policy on verzeta.com.

Who publishes this app

Verzeta for Android is published by Aditya Mehra (sole developer). There is no Verzeta cloud service, no intermediary server and no developer-accessible data store between the Android app and your desktop. The app makes network connections only to the desktops you pair it with.

What the app stores on the device

The app stores two small files in its private storage:

The app writes no database, analytics buffer, cookie or log file. When you play a generated audio clip, the app keeps a temporary copy in its private cache and deletes it when playback ends.

What the app sends off the device

When you send a message, attach a file, upload a project document, edit a canvas or change a setting, the app sends that data over a connection your phone opens to the desktop you paired with. The desktop processes it, may pass it to the language-model providers you set up there (for example Ollama on your own computer, OpenAI, Anthropic or Gemini, as you choose on the desktop), and sends the responses back.

No data passes through Verzeta servers. The app connects directly to the desktop address you entered when pairing.

What the app does not collect or send

The app does not read, store or send:

The app contains no third-party analytics, crash reporting, advertising, push-notification or social-login code. The only library that uses the network is OkHttp, used only for the connection you open to your desktop.

Notifications

If you allow notifications, the app shows a system notification when an agent mentions you in a conversation you do not have open. The notification shows the agent's alias and the start of the message, so it can appear on your lock screen, depending on your Android notification settings. Notifications are created on the device from the live connection to your desktop. No push service is used.

What the developer sees

Nothing. The developer runs no server that receives your data. The developer cannot read your chat messages, see your desktop's settings or observe your activity, because there is no service that could.

Security

Revoking access

Two ways revoke the pairing, and a third removes it from this device only:

  1. From the desktop. In Verzeta Studio, open Settings → Remote Access → Manage Remote Access, find the Android device under Paired devices, and click Revoke. The desktop cancels the token at once, and the next request from that device is refused.
  2. From the Android app. Open Settings and tap Revoke this device. The desktop cancels the token, and the app clears its data for that desktop.
  3. Uninstall the app, or use Android's Settings → Apps → Verzeta → Storage → Clear storage. This removes both files from the device. The desktop keeps the token until you revoke it with option 1, because uninstalling does not revoke it.

Children's privacy

This app sends what you type to language models on your desktop, which may pass it to third-party AI providers you have set up. The output of those models varies and depends on your setup. The app is intended for people aged 13 and over and is not marketed to children under 13. The app collects no information that would allow age verification and does not knowingly contain content directed at children.

Your data rights

The developer runs no servers and stores no user data, so there is no data controller to make GDPR or CCPA requests to. All data the app produces lives either:

For data stored on the desktop, see Verzeta Studio's own privacy policy.

Changes to this policy

When this policy changes, we update the date at the top of this page and publish the new version at the link in the app's About Verzeta → Privacy policy row. Material changes (new kinds of data, new destinations or new third parties) may also be noted in the app's release notes.

Contact

Verzeta for VS Code

Last updated: 2026-09.

Verzeta for VS Code is a paired companion to the Verzeta Studio desktop application. The extension does not run AI or language-model code in the editor. It pairs with the user's own desktop instance of Verzeta Studio over a WebSocket connection, and all processing happens on that desktop machine, which the user controls.

Who runs this service

The Verzeta extension is published by Aditya Mehra (sole developer). There is no Verzeta-controlled cloud service, no intermediary server, no developer-accessible data store that sits between the extension and your desktop. The extension makes outbound network calls only to the desktop hosts you pair it with.

What the extension stores

The extension persists a small amount of state through VS Code's own storage APIs. Nothing else is written by this extension.

The extension does not write any database, cache, analytics buffer, cookie, or log file beyond VS Code's own Output channel (which stays on your machine).

What the extension sends off-device

When you send a message, attach a file, add context, or change a configuration, the extension transmits that data over the WebSocket you initiated, to the user-controlled desktop you specified during pairing. If you share a workspace with a conversation, the files an agent asks for are served to that same paired desktop. The desktop processes everything, may forward it to the language-model providers you have configured there (Ollama running locally, OpenAI, Anthropic, Gemini or others, as you choose on the desktop), and streams responses back.

No data is routed through Verzeta-controlled servers. The extension opens a direct connection to the host you specify during pairing. Nothing transits a Verzeta-owned middleman.

What the extension does NOT collect or transmit

The extension does not read, store, or send:

The extension contains no third-party analytics, crash-reporting, advertising, or telemetry SDK. There are none in its dependency tree. The only dependency that touches the network is undici, used solely as the WebSocket transport for the connection you initiate.

What the developer sees

Nothing. We do not operate any servers that receive your data. The developer cannot read your chat messages, see your desktop's configuration, or observe your activity. There is no service infrastructure to do so.

Security

For the full security posture and how to report a vulnerability, see SECURITY.md.

Revoking access

Ways to remove a pairing:

  1. From the desktop: open Verzeta Studio, go to Settings > Remote Access > Manage Remote Access, find the editor under Paired devices, and click Revoke. The host invalidates the token immediately.

  2. From the extension: while connected, click Revoke this device on the extension's Settings tab. The host invalidates the token. Removing the host afterwards (Verzeta: Remove Host…) deletes the local copy.

Removing a host without revoking it deletes only the local copy of the token; the token stays valid on the host. Uninstalling the extension does not revoke the token on the host either. Revoke the device first with option 1 or 2.

Your data subject rights

Because we (the developer) do not operate any servers and do not store any user data on our own infrastructure, there is no data-controller relationship to invoke GDPR / CCPA-style rights against. All data the extension produces lives either on your own machine (VS Code's SecretStorage + settings + workspace state) or on your own paired desktop, which you operate and control completely.

For data stored on the desktop side, refer to Verzeta Studio's own privacy policy and compliance posture in the host repository.

Changes to this policy

When this policy changes we update the date at the top of this file. Material changes (new data categories, new transit destinations, new third parties) may also be noted in the extension's release notes.

Contact