Trust & Security

Your data, under lock and key — and under your control.

Beemy asks for access to the most private parts of your life. Here's exactly how that access is protected, separated, and kept in your hands.

Last updated7 min read

The autonomy ladder

Trust isn't granted on connect. It's earned in stages.

  1. 01

    Read-only to start

    Connecting Gmail, your calendar and your docs doesn't hand over control. Beemy starts read-only: watching how you work before it ever acts on your behalf.

  2. 02

    Approve before it sends

    Drafts land in your drafts folder. Until you say otherwise, nothing leaves your account without a one-tap review from you.

  3. 03

    You turn the autonomy dial

    When you're ready, you decide (category by category) what Beemy can do unsupervised. Everything else keeps waiting for your say-so. Every escalation and every action still carries a plain "why this reached you," and anything Beemy handled on its own stays reviewable after the fact.

One item, shown

The approve rung, in one draft.

Illustrative

Illustrative example, built with mock data.

In Gmail · work

What arrived

Client contact

Any news before the board meets?

A client asks for a status update ahead of a board meeting, landing in the account Beemy already reads.

Beemy's draft

To Client contact

Re: Any news before the board meets?

A reply is ready, built from this week's own notes, and sits in the drafts folder instead of the client's inbox.

You approve it yourself, whenever you're ready. No deadline sends it for you.

The commitments

What's guaranteed, in plain language.

TLS 1.3

Encrypted in transit

Every byte moving between you and Beemy travels over TLS 1.3.

AES-256

Encrypted at rest

Stored data is encrypted at rest with AES-256, the same standard banks use.

architecture

Silos, kept apart by design

Personal, work and public knowledge live in strictly separated stores. There's no toggle to get wrong.

your data stays yours

Never sold, never trained on

Your data is never sold, and never used to train shared models.

account + data

Purged and key-shredded on request

Ask us to delete your account and your data, drafts and history all go with it. The audit trail proving it happened is the one thing that stays.

nothing without approval

Read-only until trusted

Beemy starts read-only. Nothing sends, posts or replies on your behalf until you approve it.

See the exact list of what Beemy will and won't send alone on On Your Behalf.

Who else sees your mail

Two outside companies help draft your mail. Here is what each one sees.

Some triage and drafting calls run on models that OpenAI and Anthropic operate. Each one sees only the message content of that one call, and nothing else. It keeps that content for no longer than the call takes.

OpenAI

Runs some of the model calls behind triage and drafting, under a zero-data-retention agreement.

What it sees
The message content sent for that one inference call. Never retained, never used to train models.
Region
United States.
OpenAI Data Processing Addendum →

Anthropic

Runs some of the model calls behind triage and drafting, under a separate zero-retention agreement.

What it sees
The message content sent for that one call. Never retained, never used to train models.
Region
United States.
Anthropic commercial terms →

Both operate under zero data retention and no-training terms, set out in each one's own data-processing agreement, linked above. Neither trains its models on your mail.

Beemy also keeps its own allowlist of endpoints cleared for zero retention. It checks the endpoint on every call, and it refuses any endpoint that is not on the list.

See every vendor, not just these two, on the sub-processors register.

The differentiator

Silos are architecture, not a setting.

Personal and work knowledge don't share a database with a permission flag on top. They live in physically separate stores. A work reply can never surface your personal life, and a personal message can never surface your work, because there's no path between them to leak across. It isn't a promise Beemy keeps. It's a wall it can't cross.

Curious why we built it this way? Read the beliefs behind this →

The other side of the ledger

What Beemy will never do.

  • Never mix personal and work context: the silos are built into the architecture, with no toggle to switch off.
  • Never send an email, message or report without your approval, until you say otherwise.
  • Never sell your data to anyone, for any reason.
  • Never train a shared model on your data; what it learns about you stays with you.
  • Never act on anything ambiguous or high-stakes without escalating to you first.

And when it does get something wrong within those limits: here's exactly what that costs.

What's connected, and how

Minimal access, made legible.

Beemy connects to the tools you already use, and reads them read-only at first, before it ever drafts, sends or files anything on your behalf. You can see exactly what's connected. To take one source away, you erase the silo that holds it: see Leaving.

  • Gmail
  • Outlook / Microsoft 365rolling out
  • Google Calendar
  • Outlook Calendarrolling out
  • Slackrolling out
  • Newsletters & RSS/blogsrolling out
  • Redditrolling out
  • News & market feedsrolling out
  • Google Docsrolling out

Security FAQ

Straight answers to the hard questions.

How soon is Beemy useful: do I have to wait a week while it learns?

No. You get a quiet, triaged inbox within your first few minutes connected, and a first draft in your voice to approve that same session. Auto-send comes later, and only for the categories you've promoted on your own autonomy dial. The early wins are fast because they're read-only or approve-first; the trust ladder above still applies underneath them.

Is my data used to train AI?

No. Beemy never uses your data to train shared models. What it learns is used only to serve you, and stays inside your own silo.

Can Beemy send email without me?

Not until you explicitly allow it, and even then only for the categories you choose (say, meeting confirmations). Everything else waits in your drafts folder for a one-tap review.

How are work and personal kept apart?

Personal, work and public knowledge live in strictly separated stores; there's no shared memory or privacy toggle in the mix. A work reply can't surface your personal life, or vice versa, because there's no path between them.

What happens when I delete my account?

Your data, drafts and history all go with it. One record stays on purpose: the audit trail that proves the deletion happened. See Leaving for the full exit path.

Where is my data stored and encrypted?

In transit, everything is encrypted with TLS 1.3. At rest, it's encrypted with AES-256 (the same standard used by banks).

Can I see why an email reached me, or what Beemy did on its own?

Yes. Every escalation comes with a plain-language "why this reached you," built from the real signals specific to that case. And anything Beemy handled automatically stays reviewable after the fact, so autonomy never becomes a black box.

Autonomy ladder, escalation, silo: the Lexicon defines the trust vocabulary on this page in plain English.

Trust also means the site works for you: what we test for accessibility, and what's still short, on the Accessibility page.

Get your time back.

Beemy is in private beta. Join the waitlist and go from connect to a quiet, triaged inbox before you close your laptop tonight.

Private beta. No spam, ever.

Talk to us