Encrypted credentials
Access tokens for connected accounts are encrypted before storage. A database copy is not, by itself, a set of usable credentials.
Security at RenoReno can only be useful if it can reach the context you choose. Security starts by making that reach specific: selected connections, encrypted credentials, bounded Mac work, explicit approvals, and results that show their evidence.
Last updated 23 August 2026
Product controls
Access tokens for connected accounts are encrypted before storage. A database copy is not, by itself, a set of usable credentials.
Reno for Mac works from folders, projects, and browser sessions you deliberately connect. The run brief makes the active boundary visible.
Externally visible or difficult-to-reverse actions pause on the exact action, target, and account that need your approval.
Reno drives its own browser profile for agent work. You can take over for authentication or judgment and later revoke accumulated sessions.
Reno separates confirmed outcomes from unverified work and open decisions, so a successful process is not silently treated as a successful real-world result.
You can disconnect services and remove stored credentials. Account deletion requests remove the account and its contents.
Data handling
Reno does not sell your data, use it for advertising, or train generalized AI models on your content. Relevant request context is sent to model providers only to produce the response or work you asked for. Google data is handled under Google API Services User Data Policy Limited Use requirements.
Data is transmitted over TLS and stored in managed infrastructure. Connected-account tokens are encrypted before database storage.
We publish controls we can substantiate. Reno does not claim a security certification or audit scope that it has not completed and approved for public use.
Reporting and questions
For a suspected security issue or a question about these controls, contact security@withreno.com. For access, export, or deletion requests, use privacy@withreno.com.
Scopes, subprocessors, retention, rights, and deletion are documented in one place.