Security

Last updated: 2 September 2026

Zenlym reads your email, so the honest position is that you are extending us real trust. This page describes what we actually do about that. Zenlym is in beta, and everything below is a statement of current practice rather than a certification.

Credentials

Mail account credentials — IMAP and SMTP passwords, and OAuth access and refresh tokens — are encrypted at rest with authenticated symmetric encryption. They are decrypted only at the moment a connection to your mail provider is made, and the encryption key is held separately from the database.

Where a provider supports OAuth, as Google and Zoho do, we use it in preference to storing a password at all. You can revoke that access from your provider at any time, without us.

In transit

Traffic between your browser and Zenlym is encrypted with TLS. Connections to your mail provider use the provider's encrypted ports.

Authentication

Sign-in is handled by Clerk. We never receive or store a Zenlym password. Every request to our API is verified cryptographically against a pinned signing key, and an unverified request is rejected before it reaches any of your data.

Access to your mail

Your email content is not read by our staff. The exceptions are narrow and are the same ones set out in our Privacy Policy: with your explicit consent for a specific support request, where the law requires it, or during investigation of a security incident or abuse.

Your mail is never used to train machine learning models — not ours, and not our providers'. Content sent to OpenAI's API for classification and drafting is not used for training.

Google API data

Our handling of data received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. The scopes we request and the reason for each are listed in the Privacy Policy.

Infrastructure

Data is stored in a managed Postgres database with encryption at rest and automated backups. Production access is limited to the people who operate the service.

Deleting your data

Disconnecting a mailbox removes its stored credentials and stops processing for that account. Deleting your account removes stored message content, classifications, summaries and learned preferences. Email hello@zenlym.com to request deletion.

Reporting a vulnerability

If you find a security issue, please tell us at hello@zenlym.com before disclosing it publicly. We will acknowledge your report, keep you updated, and will not pursue action against good faith research that avoids privacy violations and service disruption.