Google data is always off-limits.
Nothing from Gmail, Google Calendar, or Google Drive is ever used to train AI models, no matter what your settings are. Google’s API Services User Data Policy requires it, and we stand behind it.
Trust at Town
Your Townie works across your email, your calendar, and the tools you connect. That makes security part of the product, not a footnote. We handle it so you don't have to. Here's exactly what we do, what we don't, and where to find every resource.

By default, Town never trains on your data. That only changes if you explicitly opt in to training.
On a personal subscription, models like Claude and ChatGPT may train on your conversations by default. Through Town, they can’t. We negotiated agreements with our model providers, so every Town customer is protected. Same model, very different default.
Nothing from Gmail, Google Calendar, or Google Drive is ever used to train AI models, no matter what your settings are. Google’s API Services User Data Policy requires it, and we stand behind it.
Using your data to train AI is controlled by a single toggle in your account settings (Settings → Privacy → “Improve Town for everyone”), and by default, it’s off for everyone. Nothing is used unless you opt in.
Town holds agreements with the AI model providers we use so that your inputs and outputs are not used to train their models. This applies to the providers listed on our AI model providers page.
Teams that need training disabled for every user, overriding individual settings, can get that as a contractual term in a negotiated Enterprise agreement.
Explore our public information and request additional security documentation below.
Our organizational, technical, and physical security measures.
What we collect, how we use it, and your rights.
The terms that govern your use of Town.
Our data-processing terms, including Standard Contractual Clauses.
Every vendor that processes customer data on our behalf.
The model providers we use and their no-training commitments.
Need the full

security package?
Audit reports are shared under a mutual NDA. Gain access in less than 1 minute by signing yourself in our Trust Center.
Training is off by default, and there are four layers of protection:
No. Town doesn’t copy or index your inbox or message history. It uses your authenticated connections to pull only what a task needs, at the moment it needs it, and disconnecting an integration cuts that access immediately. What you and your Townie create together, like session history and memories, is stored encrypted and permanently removed within 30 days if you delete your account.
Yes. Town is SOC 2 Type 2 audited. Reports are shared under NDA: sign the self-serve mutual NDA in our Trust Center and the full package is released together.
Yes, and it’s public: town.com/dpa. It covers sub-processor obligations, breach notification, deletion and return on termination, and includes Standard Contractual Clauses for international transfers.
Yes. Independent penetration tests are performed regularly, and the latest report is shared under NDA through our Trust Center.
They’re governed by those services’ own terms with you. Our no-training agreements cover the AI model providers Town uses, not the apps you choose to connect.
In the United States only, on Convex and AWS. International data transfers are covered by the Standard Contractual Clauses in our DPA.
Deletion is self-serve: go to Settings and delete your account. We soft-delete immediately and permanently remove all data within 30 days.
No Town team member has production database access. Sessions are accessed only at your request, for example to help with support, or with explicit CEO or CPO approval. Beyond that, Town only receives the access you grant, connection by connection, and your data is strictly isolated from every other customer’s.
Sign in with Google or Microsoft, including Microsoft Entra ID. For teams, domain capture is available on Teams plans and above.
Found a vulnerability, or have a security question this page doesn’t answer? Email our security team directly. Reports go straight to the people who can act on them. security@corp.town.com
You shouldn’t have to configure your way to safety. These protections are on for every Town customer, from day one.
Our security controls are independently audited against enterprise-grade standards, with reports available through our Trust Center.
TLS 1.2/1.3 in transit and AES-256-GCM at rest, with extra application-level encryption on sensitive items like connected-account tokens.
No Town team member has production database access. Sessions are accessed only at your request, or with explicit CEO or CPO approval.
Town never sends emails or calendar invites without your approval. You decide what it can do on its own.


bobobo@town.com


clausclausclaus@town.com


cliffcliffcliff@town.com


flipflipflip@town.com


snapsnapsnap@town.com


plumplumplum@town.com


budbudbud@town.com


dougdougdoug@town.com


minminmin@town.com


normnormnorm@town.com