Trust & Security – Town Docs

Trust & Security

You’re always in control of what your assistant can do. Town treats trust and security as core to the product, not as an afterthought — your data stays protected, and nothing happens on your behalf until you’ve approved it.

This page answers the most common questions about how Town handles your data and your permission. For the mechanics of how you grant and limit that permission, see the sub-pages below.

In this section

Will Town email, schedule meetings, or message people without my permission?

No — never without your permission. By default, Town asks first and waits for your go-ahead before any email, message, or calendar invite goes out. Nothing is sent or scheduled behind your back.

You stay fully in control: Town can draft replies, suggest messages, and prepare invites for you, and by default nothing is sent until you review and approve it. Think of Town as preparing the work and handing it to you for the final say.

Some advanced features let you grant that permission ahead of time. For example, you can set up a trusted contacts list so your assistant can email specific people or domains directly, without approving each message. Features like this are always opt-in and off by default — you choose exactly who they cover, and you can change or remove them anytime — so it’s still your permission, just granted in advance rather than message by message.

The exact way you grant that approval — per-session permission levels, per-routine modes, and per-tool controls — is covered in Modes & Approvals.

Does Town train its AI on my data?

Who at Town can see my data, emails, or messages?

Access is tightly restricted by design.

How is my data encrypted, and where is it hosted?

Encrypted everywhere. All your data is encrypted in transit (HTTPS/TLS) and at rest (AES-256). On top of that, especially sensitive items — like the access tokens for your connected accounts — get an extra layer of application-level AES-256 encryption.

US-hosted. Your data is hosted in the United States on Convex and AWS.

One honest note: this isn’t “zero-knowledge” encryption. Town’s systems work with your data to actually do tasks for you, so the service can process your content during normal operation. What we promise is that it’s encrypted, access is tightly controlled, and it’s only ever used to help you.

How long do you keep my data if I delete it or my account?

You can delete your account anytime from Settings.

Want to step back without deleting everything? You can disconnect any integration anytime from your settings — or revoke Town’s access directly from your Google, Slack, or Notion security settings.

Do you have SOC 2, a DPA, or compliance docs?

Security is built into how Town works, not bolted on. Here’s where things stand:

Bringing Town to a team with specific security requirements? We’re happy to talk — email support@corp.town.com and we’ll walk you through the details.

Where to find our security & privacy documentation

Doing a security review? These are the canonical resources:

Encryption specifics

Data residency & transfers

Town is US-hosted (Convex and AWS). We don’t offer EU data residency today. International data transfers are covered by the Standard Contractual Clauses (SCCs) in our DPA.

Enterprise: SSO, SCIM, HIPAA, GDPR

For teams evaluating Town against enterprise requirements, here’s where things honestly stand today:

If any of these are requirements for your organization, reach out to support@corp.town.com or via the Trust Center so we can talk through your needs and timeline.

Built-in protections

Beyond the controls you set, Town includes security measures that apply automatically:

Learn more in Security.

Does Town have a privacy policy?

Yes. You can read it anytime at town.com/privacy-policy. It explains exactly what information Town collects, how it’s used, and the safeguards in place to keep your data protected.

Last updated on August 8, 2026.