Security
How we keep your email and data safe.
OAuth 2.0 Authentication
We never ask for or store your Gmail password. We use Google's OAuth 2.0 flow to obtain time-limited access tokens. You can revoke access at any time from your Google account.
Encrypted Transport
All data between your browser and Valora's servers is encrypted via TLS 1.3. Your tokens are stored encrypted at rest using AES-256.
Minimum Permissions
Valora requests only the permissions it needs. We never read emails from folders you haven't connected, and we never access contacts or Drive.
AI Processing
When Zara processes emails, only relevant content is sent to AI models. We do not use your email data to train AI. Email content is never stored in plaintext in our AI logs.
What permissions we use
gmail.readonlyRead your emails for display and AI analysisgmail.sendSend emails when you explicitly ask Zara togmail.modifyArchive, star, and label your emailscalendarRead and create calendar eventsResponsible Disclosure
If you discover a security vulnerability in Valora, please report it to us privately. We'll acknowledge your report within 48 hours and work to fix the issue promptly.
security@valorahq.in