Security & Privacy

Safe with your inbox. By design.

Useful AI for your messages without compromising on privacy or control.

Three commitments

Never used for training

Your messages are not used to train AI models. Not by us. Not by our model providers, who process messages under enterprise contracts that prohibit training on our data.

Encrypted, with no employee access

We encrypt everything we store about you (messages, tasks, brain pages, and contacts) in transit and at rest. We additionally encrypt message content, tasks, and brain pages under dedicated keys in AWS KMS that only the application's service roles can use to decrypt; no this+that employee can read that content except with your permission or for emergency support. That access is temporary and logged, and if you didn't ask us to look, we tell you. Your calendar is not stored at all: we query your provider live over OAuth each time we need it.

Yours to close, anytime

Disconnect an integration and we stop analyzing new messages from that source. Close your account and your content goes with it. We keep your contact details so we can tell you about changes; email support@thisandthat.chat to have them removed.

How your messages flow through this+that

When you connect Gmail, Outlook, Slack, Microsoft Teams, Google Chat, and WhatsApp Business, or another supported source, you authorize us through that service's standard OAuth flow. We never see or store your password. Instagram and Facebook Messenger await platform approval, and we add them once it lands.

As messages arrive, we read them to extract tasks, follow-ups, and other action items. The reading happens through Amazon Bedrock, AWS's managed AI service, which fronts foundation models from Anthropic and other providers. Bedrock's terms prohibit using customer data to train the underlying models, regardless of which model handles a given request. All of this happens inside AWS infrastructure; no this+that employee sees plaintext at any point.

Everything we store about you (messages, tasks, brain pages, and contacts) is encrypted at rest. We additionally encrypt message content, tasks, and brain pages under dedicated keys in AWS KMS that only the application's service roles can use to decrypt; no this+that employee can read that content except with your permission or for emergency support. That access is temporary and logged, and if you didn't ask us to look, we tell you. Calendar events are never stored: we query your calendar provider live over OAuth each time we need your schedule. If you disconnect an integration, we stop syncing new messages from that source, and you can request removal of previously synced data. If you close your account, we remove every message, task, and record we hold for you.

What we don’t do with your data

  • We don’t sell your data. To anyone. Ever.
  • We don’t share it with advertisers, data brokers, or analytics resellers.
  • We don’t use it to train AI models, and our model providers don’t either, per the enterprise terms we’ve signed.
  • We don’t retain it after you close your account.

Compliance & certifications

SOC 2 Type I

Complete. Atom Assurances LLC, an independent CPA firm, performed our SOC 2 Type I examination. It reports on the suitability of the design of our security controls as of July 31, 2026. The report is confidential and we share it under NDA. Email security@thisandthat.chat to request a copy.

SOC 2 Type II

Underway. A Type II report tests whether those controls operated effectively over a period of months rather than on a single date, so it takes an observation window to earn. We are working toward one and will say so here when it is complete.

CASA Tier 2

Certified. this+that has passed the App Defense Alliance's Cloud Application Security Assessment (CASA) at Tier 2, the security assessment Google requires for applications with restricted-scope access to Gmail data. Our certification was most recently revalidated in February 2026.

GDPR, UK GDPR, LGPD & CCPA

We follow the requirements that apply to us under each framework. Our Data Processing Addendum incorporates GDPR Article 28 terms, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the ANPD clauses under Resolution 19/2024 where a Brazilian customer is the exporter. We have named an Encarregado under the LGPD. You can request access to or deletion of your data at any time, in the app or by emailing privacy@thisandthat.chat.

Sub-processor list

We publish the full list of third parties that process customer data on our behalf, with at least 10 days’ notice and an objection right before any new sub-processor is added.

Breach notification

In the unlikely event of a security incident affecting your data, we will notify affected customers without undue delay, in line with GDPR Article 33 and the terms of our DPA.

Two-factor authentication

You can secure your account with two-factor authentication from an authenticator app, with backup codes for recovery. If you sign in with Google or Microsoft, your account inherits the multi-factor settings you have configured with that identity provider.

Service status & uptime

We publish live system status and a history of past incidents at status.thisandthat.chat, so you can check uptime and any active issues at any time, and subscribe to be notified about incidents and scheduled maintenance.

Frequently asked questions

Can I use two-factor authentication to secure my login?

Yes. this+that supports two-factor authentication directly: turn it on in Account Settings and you'll be asked for a code from your authenticator app each time you sign in. We provide backup codes so you can recover access if you lose your authenticator. If you sign in with Google or Microsoft, your this+that account also inherits whatever 2FA you've configured on that identity provider.

Is my data encrypted in transit and at rest?

Yes, both. Data is encrypted while moving between connected services (Gmail, Slack, Teams, and others) and our servers, and it's encrypted while stored. We additionally encrypt message content, tasks, and brain pages under dedicated keys in AWS KMS, and the key material never leaves AWS's hardware security modules. Decryption happens automatically inside AWS to serve your requests, and only the application's service roles can perform it.

Can your team at this+that read my emails and messages?

No. Your message content is encrypted under a dedicated key in AWS KMS that only the application's service roles can use to decrypt, and no this+that employee can read it except with your permission or for emergency support, and that access is temporary and logged. Our app and AI services decrypt content automatically to serve you (for example, to display an email or extract a task). If we need to investigate a specific issue you're having, we'll ask you for context rather than reading your data.

Where is my data stored?

On AWS, with DynamoDB as our primary database. AWS is the industry-standard cloud platform with extensive security and reliability certifications of its own.

How can I check whether this+that is up?

We publish live system status and a full history of past incidents at status.thisandthat.chat. You can subscribe there to be notified about incidents and scheduled maintenance.

Will this+that share my messages or data with third parties or AI developers?

No. Your data is never sold or shared for advertising. We process messages through Amazon Bedrock, AWS's managed AI service that fronts foundation models from Anthropic and other providers. Bedrock's terms prohibit training on customer data, regardless of which underlying model handles a request. AWS is our subprocessor for AI processing, not a data buyer.

What happens if I disconnect an integration?

We stop analyzing new messages from that source immediately. You can also request the removal of any previously synced data from that integration. If you close your account, all of your content is removed.

Do you comply with GDPR, LGPD, CCPA, or other data privacy regulations?

Yes, we follow the major data privacy frameworks that apply to our service, and you can close your account at any time, and email support@thisandthat.chat to remove the contact details we keep afterwards. For specific requests under GDPR or CCPA, email privacy@thisandthat.chat.

What if there's a data breach? Will I be notified?

Yes. In the unlikely event of a breach affecting your data, we follow industry-standard protocols to notify affected users promptly and to take immediate steps to secure all systems.

Who can see my messages and tasks inside this+that?

Your DoBox is private. Only you see what's in it. Shared task lists are visible to everyone in that list, by design. If you move a task with an attached message into a shared list, others on that list will see the message; that visibility persists even if you later leave the list.

Questions about how we handle your data?

We answer security and privacy questions directly. Email us. A real person reads every message.

Email security@thisandthat.chat