Legal
What Veni collects, why we hold it, who it goes to, and how you get rid of it.
Effective 6 August 2026 · Last updated 6 August 2026
Veni runs the intercom, door access, front desk, and resident communication for apartment buildings. That means we necessarily handle information about who lives somewhere, who visits them, and when doors open. This page explains exactly what that involves.
Veni ("we", "us") provides building access and resident software to property owners and management companies. This policy covers the Veni resident app for iOS and Android, the visitor web experience, the management and front-desk portals, and helloveni.com.
For residents, your building's owner or management company decides that Veni is used at your building and controls the resident roster. We process resident data on their behalf as well as for our own purposes of operating and securing the service.
| Category | What it is | Why we have it |
|---|---|---|
| Account identity | Your name, email address, and phone number. | To sign you in, to attach you to the right unit, and so your building's staff can reach you. |
| Residency | The building and unit you're associated with, and when that association started or ended. | It is what authorizes you to open your building's doors and see your building's activity. |
| Entry activity | Door open events, who authorized them, guest pass redemptions, and a still image captured at the door during a video call. | Building security, and so you can see who came to your door. |
| Calls | Live audio and video between a visitor at the door and you. Where a building enables Veni Intelligence, a transcript and summary of the call. | To place the call. Transcripts exist only where the building has switched that feature on. |
| Guest passes | The name and visit window of a guest you invite, plus any note you add. | So the front desk and the door know to expect them. |
| Messages | Posts and direct messages you send in your building's community channels, including any photos you attach. | To deliver them to the people you sent them to. |
| Maintenance | Issues you report, your description, and photos you attach. | To route the request to your building's staff or a vendor. |
| Packages | Deliveries logged for your unit and their carrier and status. | To tell you a package arrived and record when you took it. |
| Device & diagnostics | Push notification tokens, device model and OS version, app version, and crash reports. | To ring your phone when someone is at the door, and to find and fix bugs. |
The app asks for your camera and microphone only to place a two-way video call with a visitor at your door, and for your photo library only when you choose to attach an image to a community post or a maintenance request. We do not access any of them in the background, and denying these permissions does not prevent you from using the rest of the app.
Sensitive fields (names, email addresses, phone numbers, access codes, guest names, notes, transcripts) are encrypted at rest with AES-256-GCM under versioned, rotatable keys. Where staff need to search encrypted contact information, they search a blind index rather than a plaintext copy.
All traffic between your device and our servers is encrypted with TLS. Access to the most sensitive records is audited, and reads of the most sensitive categories fail closed: if the audit record cannot be written, the read is denied.
You can read more about our security posture on the security page. No system is perfectly secure, and we do not claim otherwise.
We share personal information in four situations, and no others.
Your building's owner, management company, and authorized staff can see the information they need to run the building: your name, unit, contact details, entry activity for your unit, your maintenance requests, and packages logged for you. What any individual staff member can see is limited by their role and, where your building uses them, by access modes and time-boxed investigations.
Front-desk staff receive a deliberately narrower view than management. In particular, the front desk is never shown a resident's email address.
We use a small number of vendors to run the service. They may process your information only to provide their service to us:
| Provider | What it handles |
|---|---|
| Clerk | Authentication and your sign-in identity |
| LiveKit | Live audio and video for door calls |
| PubNub | Community messages and direct messages |
| Vercel | Hosting, and storage for images you upload |
| Sentry | Crash and error reporting |
| Apple, Google | Push notification delivery, and sign-in if you choose it |
| Twilio | SMS verification codes and notifications |
| Stripe | Billing for building and installer accounts, not residents |
We may disclose information where we are legally required to, or where we believe in good faith that disclosure is necessary to protect someone's safety or to investigate fraud or a security incident. We will tell you about a request for your data unless we are legally prohibited from doing so.
If Veni is acquired or merged, your information may transfer as part of that transaction. This policy continues to apply until you are given notice of a replacement.
You can delete your Veni account at any time from the resident app: Profile → Delete account. Deleting your account permanently destroys your sign-in identity and erases your name, email address, and phone number from our records, removes your device's push registrations, and revokes any guest passes you issued. It cannot be undone, and your building's manager would need to invite you again to restore access.
Some records survive deletion in a form no longer linked to your identity, in particular building entry and audit records, which exist so a building can answer security questions after the fact, and which are retained under the schedule above.
If you cannot access the app, email support@helloveni.com and we will process the deletion for you.
You can view and correct your name and contact details in the app under Profile. For a copy of the other information we hold about you, or to ask us to correct or delete something specific, email support@helloveni.com.
Depending on where you live you may have additional rights, including, under laws such as the GDPR and the CCPA, the right to know what we collect, to have it deleted, to correct it, to receive it in portable form, and not to be discriminated against for exercising any of them. We honor these requests regardless of where you live. We do not sell or share personal information as those terms are defined by the CCPA.
You control push notifications from Profile in the app, and at the operating-system level in your device settings. Turning off the lock-screen ring means door calls arrive as an ordinary notification instead.
Veni is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.
Veni is operated from the United States and your information is processed there. If you use Veni from outside the United States, you are transferring your information to a country whose data protection laws may differ from your own.
We will update this page when our practices change, and revise the "last updated" date above. If a change materially affects how we handle your information, we will give you notice in the app or by email before it takes effect.
Privacy questions, requests, and complaints: support@helloveni.com.
For anything else, the help center is the fastest route.