Security & Trust

Last updated August 2026 · Beta

Pip reads your email receipts to help you manage subscriptions — so trust is the whole product. Here's exactly how your data is protected and how Pip behaves.

The short version. Pip never acts without your approval, never trains AI on your data, and encrypts everything in transit and at rest. US-hosted. Read-only access. You're always in control.

No action without your approval

Pip never contacts anyone or changes anything on your behalf without you approving it first. It drafts cancellation messages for you to send, never sends or deletes email, and its calendar is read-only. Pip assists — it never impersonates you.

No model training on your data

Your data is never used to train AI models — not by Pip, and not by our AI provider (Anthropic does not train on data sent through its API). We don't sell your data or use it for advertising.

Encrypted in transit and at rest

Your data is encrypted everywhere it travels (HTTPS on every connection) and everywhere it lives; mailbox tokens are additionally encrypted at the application layer. Pip is US-hosted on Render and AWS, with Cloudflare in front.

Read-only, minimum access

Pip requests only read-only email access — the narrowest scope that lets it find receipts. It never reads Trash or Spam, never has your password, and you can delete everything Pip imported at any time.

Independent audit (SOC 2) — on our roadmap. Pip is early-stage and not yet SOC 2 certified. We build to those standards (least-privilege access, encryption, approval-gated actions) and will pursue a formal independent audit as we grow. We'll always say so honestly and never claim a certification we don't hold.

Contact

Security questions or a data request? Email hello@pip-guardian.com. See also our Privacy Policy.