Trust at Town

You can trust your Townie.

Your Townie works across your email, your calendar, and the tools you connect. That makes security part of the product, not a footnote. We handle it so you don't have to. Here's exactly what we do, what we don't, and where to find every resource.

Individuals

  • Using your data to train AI is off by default. Nothing is used unless you opt in.
  • No action without approval. Town never sends an email or calendar invite without your OK.
  • We never sell your data.
  • Delete your account anytime from Settings. We soft-delete immediately and permanently remove all data within 30 days.

Teams & compliance

  • SOC 2 Type 2 audited, with reports and our latest penetration test available under a self-serve NDA.
  • A public DPA with Standard Contractual Clauses, a published sub-processor list, and a security annex.
  • US-hosted on Convex and AWS, with strict tenant isolation.
Request security documentation

Do we train AIon your data?

By default, Town never trains on your data. That only changes if you explicitly opt in to training.

On a personal subscription, models like Claude and ChatGPT may train on your conversations by default. Through Town, they can’t. We negotiated agreements with our model providers, so every Town customer is protected. Same model, very different default.

Google data is always off-limits.

Nothing from Gmail, Google Calendar, or Google Drive is ever used to train AI models, no matter what your settings are. Google’s API Services User Data Policy requires it, and we stand behind it.

For everything else, training is off by default.

Using your data to train AI is controlled by a single toggle in your account settings (Settings → Privacy → “Improve Town for everyone”), and by default, it’s off for everyone. Nothing is used unless you opt in.

Our AI model providers can’t train on your data either.

Town holds agreements with the AI model providers we use so that your inputs and outputs are not used to train their models. This applies to the providers listed on our AI model providers page.

Organizations can enforce no-training for everyone.

Teams that need training disabled for every user, overriding individual settings, can get that as a contractual term in a negotiated Enterprise agreement.

Need the full security package?

Audit reports are shared under a mutual NDA. Gain access in less than 1 minute by signing yourself in our Trust Center.

Request security documentation
  • SOC 2 Type 1 & Type 2 reports
  • Latest penetration test
  • CASA Tier 2 assessment (OWASP ASVS)

Common questions

Training is off by default, and there are four layers of protection:

  • Google data (Gmail, Calendar, Drive) is never used to train AI models. No exceptions.
  • For everything else, training is controlled by a toggle in Settings → Privacy that ships off. Nothing is used unless you opt in.
  • Our agreements with our AI model providers bar them from using your inputs and outputs to train their models.
  • Organizations can enforce no-training across every user as a term in an Enterprise agreement.

No. Town doesn’t copy or index your inbox or message history. It uses your authenticated connections to pull only what a task needs, at the moment it needs it, and disconnecting an integration cuts that access immediately. What you and your Townie create together, like session history and memories, is stored encrypted and permanently removed within 30 days if you delete your account.

Yes. Town is SOC 2 Type 2 audited. Reports are shared under NDA: sign the self-serve mutual NDA in our Trust Center and the full package is released together.

Yes, and it’s public: town.com/dpa. It covers sub-processor obligations, breach notification, deletion and return on termination, and includes Standard Contractual Clauses for international transfers.

Yes. Independent penetration tests are performed regularly, and the latest report is shared under NDA through our Trust Center.

They’re governed by those services’ own terms with you. Our no-training agreements cover the AI model providers Town uses, not the apps you choose to connect.

In the United States only, on Convex and AWS. International data transfers are covered by the Standard Contractual Clauses in our DPA.

Deletion is self-serve: go to Settings and delete your account. We soft-delete immediately and permanently remove all data within 30 days.

No Town team member has production database access. Sessions are accessed only at your request, for example to help with support, or with explicit CEO or CPO approval. Beyond that, Town only receives the access you grant, connection by connection, and your data is strictly isolated from every other customer’s.

Sign in with Google or Microsoft, including Microsoft Entra ID. For teams, domain capture is available on Teams plans and above.

Found a vulnerability, or have a security question this page doesn’t answer? Email our security team directly. Reports go straight to the people who can act on them. security@corp.town.com

Protectedby default.

You shouldn’t have to configure your way to safety. These protections are on for every Town customer, from day one.

AICPASOC

SOC 2 Type 2 audited

Our security controls are independently audited against enterprise-grade standards, with reports available through our Trust Center.

Encrypted in transit and at rest

TLS 1.2/1.3 in transit and AES-256-GCM at rest, with extra application-level encryption on sensitive items like connected-account tokens.

No standing access to your data

No Town team member has production database access. Sessions are accessed only at your request, or with explicit CEO or CPO approval.

No action without approval

Town never sends emails or calendar invites without your approval. You decide what it can do on its own.

Meet your

Bo the bear Townie

bo@town.com

today.