Third Party Index

Snapshot 74815

Document
Security page
URL
https://www.town.com/features/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
119062 bytes
SHA-256 (raw)
5441aecd1374767487bdc14f721a2a926c36d2c6dc14667c83307b0a4ea83f90
SHA-256 (normalized text)
207d6de0e34c566dc5c93cd047681acd8aad735bcb8b9cc08dcced2915f504d2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Your data is yours. Here's how we protect it.Your data is yours.Here's how we protect it.
Town connects to your tools to work on your behalf. We never sell your data, and we never act without your permission.
Your data serves you—and only you.
We connect to your tools for one reason: to do the work you ask us to do.
We don't sell your data. We don't share it for advertising.
Your content powers and improves Town for you. That's it.
You own your content.
Everything you bring into Town — emails, documents, prompts, outputs — remains yours. We claim no ownership over your content.
AI providers only process your requests.
Town uses AI models through their APIs, where terms explicitly prohibit using your inputs, outputs, or conversations for model training.
Google data is never used for model training.
Data from Gmail, Google Calendar, and Google Drive is never used to train machine learning models. Required by Google's API Services User Data Policy — and a commitment we stand behind.
Why Town needs access.
Here's what we access, and why.
Email
Surfaces what matters, drafts replies, organizes your inbox. Only accesses what's needed.
Calendar
Prepares briefings, finds conflicts, manages invitations. Never modifies events without your approval.
Documents
Reads docs from Drive, Notion, and other sources for task context. Files are not stored beyond what's necessary.
Slack and more
Brings context from Slack, GitHub, Linear, HubSpot, and more into one place. Every integration is optional.
You're always in control.
Town gives you a dial, not a switch. Start cautious, then grant autonomy when you're ready.
Approval-required by default.
Town never sends an email, modifies a document, or takes a destructive action without your explicit approval — unless you configure it otherwise. See approval modes.
You choose what to connect.
Every integration is optional. Connect email, calendar, Drive, Slack, or any combination. Disconnect anytime from your settings.
See everything it does.
Full action log for every routine. Clear reasoning for every step. Complete transparency into what happened, when, and why.
Three modes for every routine.
Read-only for monitoring. Approval-required for review before action. Autonomous when you're ready. Adjust per-routine and per-tool. See routine modes and approval details.
Delete your data anytime.
Go to Settings to delete your account. We soft-delete immediately and permanently remove all data within 30 days.
Revoke access instantly.
Disconnect any integration from your settings, or revoke Town's access directly from your Google, Slack, or Notion security settings.
How we protect your data.
Security isn't a feature we ship. It's how we build.
Encrypted everywhere.
All data is encrypted in transit and at rest.
US-hosted infrastructure.
Data hosted on Convex and AWS in the United States.
Third-party security review.
CASA (Cloud Application Security Assessment) completed, validated by an independent third party based on the OWASP ASVS standard.
Strict internal access controls.
No team member has production database access. User sessions are only accessed at your request, or with explicit CEO or CPO approval.
SOC 2 Type 2 compliant.
SOC 2 Type 2 certified for audited assurance of our security controls.
Google API Limited Use compliant.
Google user data is used only to provide services to you. Never shared, sold, or used for advertising.
Town wants to send an email to finance
You asked Town to send this draft update after approval.
maya@town.com
To
finance@acme.com
Subject
Q2 budget update
Permissions reset when you start a new thread. Learn more about different settings.
Approvals that match your risk level
Set permission mode in the composer with the shield control, then review each required action in-chat before anything executes.
Ask-before-write mode keeps outbound actions gated.
Safe-actions mode lets low-risk actions run automatically.
Allow-all mode is available when you explicitly choose speed over review.
Approval cards show exactly what Town wants to do before execution.
Learn more about modes and approvals →
Common questions.
Bringing Town to your team?
If your organization has security requirements, we'd love to talk.
Contact us