BEGL asks for your inbox. Here's what that means.
Connecting an email account to any third-party tool deserves scrutiny. This page describes how that access actually works, what protects it, and who to contact if you find a problem.
We never see your password
Connecting an inbox uses OAuth. You authorize access with Google or Microsoft directly, and BEGL receives a revocable token — never your credentials. You can revoke that token at any time from your Google or Microsoft account, without going through us.
Encrypted in transit and at rest
Data in transit is encrypted using TLS. Data at rest is encrypted using AES-256 or equivalent. Backups are encrypted as well.
Access ends when your subscription does
If your subscription lapses, your email integration is automatically disconnected seven days later. That behavior is written into our Terms, not left to our discretion.
We do not sell your personal information
Not to advertisers, not to data brokers, not to anyone. Your inbox is not a product we resell, and our Privacy Policy commits us to that in writing.
Who builds this

Bryson Loughmiller
Founder, Petracore
Bryson Loughmiller founded Petracore, the company behind BEGL. He has spent more than ten years building software and keeping other people's data safe — most recently as Principal Security Engineer & Architect at Entrata, before that running the information security team at Podium, and at Adobe, where he led the security integration of Adobe's acquisition of Marketo. He holds a master's in Information Systems with a cybersecurity emphasis from BYU's Marriott School of Business.
- 10+ years protecting user data· Adobe, Podium, Entrata
- Principal Security Engineer & Architect· Entrata
- Manager, Information Security· Podium
- Information Security Engineer· Adobe
- MISM, Cybersecurity emphasis· BYU Marriott
Our email infrastructure provider
BEGL does not build its own mail connectivity. Email access is brokered by Nylas, a dedicated email API provider, which is also where authentication is handled. The certifications below are Nylas's own attestations, not BEGL's. We list them because the security of your mail connection genuinely depends on them — not to imply BEGL holds them.
| Certification | Scope |
|---|---|
| SOC 2 Type II | Covering the security, availability, and confidentiality trust service criteria |
| ISO 27001 | Information security management systems (ISMS) |
| ISO 27701 | Privacy information management systems (PIMS) |
| HIPAA | Security and privacy controls for protected health information |
| CSA STAR Level One | Cloud Security Alliance transparency and auditing program |
| PCI-DSS SAQ A | Self-Assessment Questionnaire A |
Nylas additionally states compliance with GDPR, EU-U.S. Data Privacy Framework (self-certified), UK Extension and Swiss-U.S. DPF, CCPA, GLBA Privacy Rule, and encrypts data at rest with AES-256 or equivalent and data in transit with TLS v1.2 or higher.
To be direct about our own certifications
BEGL does not hold a SOC 2 report, an ISO certification, or any other third-party security attestation of its own. We are a small, early company, and claiming otherwise — or hiding behind phrases like “compliance ready” — would be misleading. The certifications above belong to the infrastructure we build on. Ours would have to be earned separately, and we haven't earned them yet.
What we can offer in the meantime is specificity: the practices on this page, the retention limits below, and a Privacy Policy that names every subprocessor. Judge us on those.
What we actually store
We retain email content only for messages identified as brand offers. Those are the messages the product exists to work on — extracting terms, deadlines, and deliverables requires having the text. Mail that isn't an identified offer is not retained as content.
The practical consequence: connecting BEGL does not create a second copy of your whole mailbox. It creates a working record of your brand deals. Retention periods and deletion rights are covered in the Privacy Policy.
Subprocessors
We use Nylas for email processing and Supabase for data storage. The complete, current list — with links to each provider's own privacy terms — lives in our Privacy Policy, alongside the specifics of what data we retain and for how long.
Found a vulnerability?
Report it to [email protected] with enough detail to reproduce it. We will confirm receipt, keep you updated while we investigate, and we will not pursue action against good-faith research that avoids privacy violations, service degradation, and access to accounts that aren't yours.
Worried an email you received is a phishing attempt rather than a real sponsorship? That is a different problem, and we wrote it up: red flags in a brand sponsorship email.
Ready to spend less time on brand deals?
Start your 30-day free trial and see BEGL in action. No credit card required.
Cancel anytime. Early adopters lock in $5/mo off forever.