Trust

Security & Trust

Last updated: July 7, 2026

Your relationships are your business. Here's how Reframe Lab protects them — in plain English.

The headline: headers only

When you connect your email, Reframe Lab reads message headers only — who, when, and the subject line. We never fetch, store, or read the body of your email. That's a design decision, not a setting: the product is built so bodies are never requested from Google at all.

Encryption

All traffic to and from Reframe Lab is encrypted in transit with TLS. Data at rest is encrypted by our database provider (MongoDB Atlas).

Your data is yours, and it's isolated

Every account's data is partitioned per user. Your contacts, history, and drafts are scoped to your account — other users can never see them. We don't sell your data and we don't use it for advertising.

Access is granted by you, revocable by you

Google access happens through your own OAuth grant — you see exactly what's requested before you approve. You can disconnect inside Reframe Lab at any time, or revoke access from your Google Account permissions — either one stops all syncing immediately.

You approve everything that goes out

Reframe Lab drafts; you decide. No message is ever sent on your behalf without your explicit approval.

Google API compliance

Reframe Lab's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Report a vulnerability

Found a security issue? Please tell us before anyone else: support@reframelab.ai with "SECURITY" in the subject. We take every report seriously and will respond quickly.