Privacy Policy

Reef by Lobster Computer

Last updated: August 3, 2026

Reef is a product of Lobster Computer, Inc. ("we", "us", "Reef"). This policy explains what data Reef accesses, why, how we store and protect it, and the choices you have. Questions: privacy@lobstercomputer.com.

What Reef is

Reef lets you connect your own accounts (Google and others) so that an AI agent working on your behalf can read and act on your data — for example, drafting an email, reading a document, or bringing a meeting into your personal knowledge base. You connect an account explicitly, and you can disconnect it at any time.

Google user data

When you connect your Google account, Reef requests only the scopes needed for the features you use. Each scope maps to a specific capability:

Google scopeWhy Reef requests itAccess
gmail.readonlyRead messages so the agent can search and read your mail, and so email you choose to ingest becomes part of your personal knowledge baseRead
gmail.sendSend or reply to email that you or your agent composeWrite (send only)
calendar.eventsRead your events and create or update events on your behalfRead/Write
tasksRead and manage your Google TasksRead/Write
driveSearch, open, create, move, share, and trash your Drive files at your directionRead/Write
documentsRead and edit Google DocsRead/Write
spreadsheetsRead and edit Google SheetsRead/Write
presentationsRead and edit Google SlidesRead/Write
openid, emailIdentify which Google account is connectedRead (account address)

We request access only for accounts you explicitly connect, and only to provide the features described above. Mutating actions (sending mail, editing or sharing files, changing events) are taken on your behalf and, where applicable, staged for your approval before they run.

Limited Use disclosure

Reef's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

  • transfer or sell your Google user data to third parties, except as necessary to provide or improve the Reef features you use, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you;
  • use your Google user data for serving advertisements;
  • allow humans to read your Google user data, unless (a) you give explicit consent to read specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is needed to comply with applicable law, or (d) the data is aggregated and anonymized and used to maintain or improve the service.

Slack user data

When you connect the shared Reef Slack app, Reef receives a delegated Slack authorization for you. Slack continues to enforce your own conversation membership and permissions: connecting Reef does not let it read a private channel or direct message that you cannot access.

Reef processes Slack message content, conversation metadata, and basic member profile information to provide search, summaries, private knowledge, event validation, and limited history catch-up. The shared app does not post, edit, or delete Slack messages or manage your workspace. Reef does not sell Slack data, use it for advertising, or use it to train general-purpose models.

The workspace installation and your personal authorization are separate. You can disconnect your personal authorization in Settings → Connections without uninstalling the shared app for coworkers. A Slack workspace admin can remove the shared app through Slack's Manage apps page. See the complete Slack connection & removal guide, including every requested scope and its purpose.

How we store and protect your data

  • Credentials. OAuth access and refresh tokens are encrypted at rest with AES-256-GCM (a unique initialization vector per record) and are decrypted only in memory, when needed to act on your behalf.
  • Content. Content you choose to bring into Reef (for example, ingested email or calendar items in your personal knowledge base) is encrypted at rest and is accessible only to you and the agent acting on your behalf.
  • Transport. All data moves over encrypted (TLS) connections.
  • Access. Access to connected-provider data by the agent is scoped to you; Reef does not use Google or Slack user data to train general-purpose models.

Your choices and data deletion

  • Disconnect at any time. In Reef, go to Settings → Connections and remove a connection. This revokes Reef's stored tokens for that provider and stops further access.
  • Revoke from Google. You can also revoke Reef's access directly at myaccount.google.com/permissions.
  • Deletion. When you disconnect a provider or delete your Reef account, we delete the associated stored credentials and the content ingested from that provider, subject to short-lived backups and any retention the law requires.

Data we collect beyond connected providers

To operate the service we process basic account information (your Reef sign-in identity and email address) and standard operational logs. We use these to authenticate you, secure the service, and debug problems — not to advertise to you.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above.

Contact

Lobster Computer, Inc. — privacy@lobstercomputer.com