Security

Last reviewed: July 2026 · Placeholder pending legal review.

Access we request

Subzero requests read-only Gmail scope. We do not send email on your behalf, modify messages or move mail.

Token handling

OAuth refresh tokens are held server-side, encrypted at rest, and rotated on every scan. Tokens are never sent to the browser.

Data we retain

We retain the minimum needed to power your dashboard: structured extracted fields, message IDs, and short subject/sender snippets used as evidence. Full email bodies are not stored.

Row-level security

Every user-owned table is protected by row-level security in PostgreSQL. Nobody but you (and Subzero admins under audit) can access your data.

Disconnect & delete

Disconnect Gmail stops all future scanning. "Disconnect & delete imported data" additionally removes every subscription, event and evidence record derived from your inbox.