1. Controller
Nexscientia operates the Nexscientia platform and the EVA cognitive assistant ("EVA", "we", "us"). This policy describes how we handle personal data when you use www.nexscientia.com and eva.nexscientia.com (both hosts serve this application) and related services.
2. What EVA is (and is not)
EVA is an account-based cognitive platform. Depending on your package and the connections you choose to enable, it may help you search and reason; use Google Calendar and Gmail when you connect those Google services; send transactional or service SMS when you have consented and the required authorization steps are completed (for example phone verification, identity verification, security notifications, and service updates); use voice calling features when enabled; and use specialized aviation and maintenance assistance tools when available to your account. EVA does not claim to send marketing blast SMS.
3. Data we collect
- Account identifiers (email, user id) and authentication session data.
- Content you submit to EVA (chat, uploads you choose to provide, and related working context for a request).
- Google OAuth tokens when you connect Calendar and/or Gmail (stored only for your account so EVA can call Google on your behalf).
- SMS-related records that are content-free where possible: peer number digests, consent and allowlist flags, delivery status metadata — not full message bodies in consent records.
- Technical logs needed to operate and secure the service (IP, user agent, error diagnostics), minimized where feasible.
4. Google OAuth scopes and what each one does
Calendar and Gmail access happen only after you connect the relevant Google permissions. EVA requests these scopes:
https://www.googleapis.com/auth/gmail.readonly— read and search your Gmail inbox when you ask EVA to look up or open mail.https://www.googleapis.com/auth/gmail.compose— create Gmail drafts and send a draft only after your explicit confirmation.https://www.googleapis.com/auth/gmail.modify— archive, label, mark, move to recoverable trash, and manage filters only after your explicit confirmation. EVA never requestshttps://mail.google.com/and never permanently deletes mail.https://www.googleapis.com/auth/calendar— view, create, and delete events on your Google Calendar.
Gmail read, draft, and manage permissions are requested in separate connection steps where applicable. Calendar uses its own Google connection. We do not request Google scopes we do not use for the functions above.
5. Google data, email content, and language models
Language generation for ordinary chat may use contracted model providers. Those providers process the prompts and responses needed to answer your requests. Do not submit secrets you are not authorized to share with processors.
For Gmail content obtained through Google's APIs, the following applies (as implemented in EVA today):
- Email message content is not sent to language-model providers. When you ask EVA to read or search mail, EVA does not forward the message body to an LLM to summarize or rewrite it.
- Reading is deterministic: EVA quotes the plain-text body it retrieved (within safety limits). It does not ask a model to summarize that mail.
- Incoming email bodies are not stored in our database.
- Incoming email bodies are not written into long-term conversation memory or your personal knowledge documents.
- Correspondence turns are isolated from conversational continuity: those replies are not kept in the chat history that later turns send back into the model context.
- Gmail content obtained through Google APIs is not used to train any machine learning or AI models.
Your own chat messages (for example text you type asking EVA to draft a reply) may still be processed by language-model providers like other EVA chat. That is separate from forwarding Gmail API message bodies to those providers.
6. What we do store from Google connections
When you connect Google:
- OAuth tokens (access/refresh) so EVA can call Gmail or Calendar for your account until you disconnect.
- Action metadata needed to prove that a governed action occurred (for example that a draft was created or a message was sent), without storing incoming mail bodies.
- Sealed draft plans for outbound email you asked EVA to prepare: recipients, subject, and body you supplied (or confirmed), held only as needed to complete confirmation and create the draft.
We do not retain incoming Gmail message bodies in our database.
7. Google API Services User Data Policy — Limited Use
Nexscientia's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
In particular, for Gmail and Calendar user data obtained via Google APIs:
- We use that data only to provide or improve user-facing features that are prominent in the requesting application's interface (reading/searching mail you ask for, drafting/sending with your confirmation, and calendar view/create/delete).
- We do not transfer Google user data to others except as necessary to provide those features (for example to Google as the API provider), for security/legal compliance, or with your direction.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless you give us permission to do so for support, it is necessary for security or legal reasons, or the data is aggregated and anonymized for internal operations where allowed.
- We do not use Gmail message content obtained via Google APIs to train generalized AI / ML models.
8. SMS and telephony
Outbound SMS, when enabled for your account, requires consent and additional authorization steps. Submitting a web consent form does not by itself send an SMS; messages are sent only after the required authorization and verification steps are completed. Voice calling, when enabled, is a separate feature with its own authorization steps. We do not sell personal data.
SMS / mobile messaging
Mobile information and SMS messaging opt-in/consent data are used to provide the Nexscientia / EVA transactional messaging program. That program may include phone verification, identity verification, security and account notifications, and service-related messages about EVA / Nexscientia. This program is not a marketing or promotional SMS list. EVA does not send marketing or promotional blast SMS.
Nexscientia does not share, sell, rent, or provide users' mobile phone numbers or other mobile information to third parties or affiliates for their marketing or promotional purposes. Nexscientia does not share, sell, rent, or provide SMS messaging opt-in/consent data to third parties or affiliates for their marketing or promotional purposes.
Message frequency varies.
Message and data rates may apply.
Reply STOP to opt out of further SMS from this program. Reply HELP for help. Web consent is recorded at SMS Consent. See also the SMS Messaging Terms and Terms of Service.
9. Retention
We retain account, token, custody, and operational records for as long as needed to provide the service, meet security and audit needs, and comply with law. You may request deletion of account-associated data subject to legal retention requirements and technical feasibility.
10. Your choices and revocation
For SMS: reply STOP to opt out of further SMS; reply HELP for help.
Disconnect in EVA: in Organizer, use Disconnect Gmail (labelled "Desconectar Gmail" in the interface) and Disconnect Calendar (labelled "Desconectar Calendar" in the interface). Each control deletes our stored OAuth tokens for that Google integration and asks Google to revoke the grant when possible.
Disconnect in Google: you may also revoke EVA's access at any time at https://myaccount.google.com/permissions. After revocation, EVA can no longer call Gmail or Calendar for your account until you reconnect.
If you revoke access in your Google Account without using Disconnect in EVA, our stored tokens become unusable. For both Gmail and Google Calendar, we delete those tokens from our systems when the next token refresh fails because Google reports the grant as revoked (invalid_grant). Until that next failed use, a revoked token row may still exist but cannot be used to access your data.
What is deleted on in-app disconnect: our stored OAuth tokens for that Google integration. Incoming mail bodies were not stored. Sealed outbound draft plans and action metadata may be removed or expire according to normal retention; you may also request broader account deletion.
You may close your account and contact us for privacy requests using the address below.
11. Contact
Privacy contact: privacy@nexscientia.com. Platform: https://www.nexscientia.com and https://eva.nexscientia.com.