Security & Privacy

Safe with your inbox. By design.

Useful AI for your messages without compromising on privacy or control.

Three commitments

Never used for training

Your messages are not used to train AI models. Not by us. Not by our model providers, who process messages under enterprise contracts that prohibit training on our data.

Encrypted, with no employee access

Everything we store about you (messages, tasks, brain pages, and contacts) is encrypted in transit and at rest. Message content, tasks, and brain pages are additionally encrypted under dedicated keys in AWS KMS that only the application's service roles can use to decrypt; no this+that employee or contractor has decrypt access to that content. Your calendar is not stored at all: we query your provider live over OAuth each time we need it.

Yours to delete, anytime

Disconnect an integration and we stop analyzing new messages from that source. Delete your account and everything associated with it goes too. No retention games, no friction.

How your messages flow through this+that

When you connect Gmail, Outlook, Slack, Teams, Google Chat, Telegram, or another supported source, you authorize us through that service's standard OAuth flow. We never see or store your password. Instagram and Facebook Messenger are awaiting platform approval and will be added once approved.

As messages arrive, we read them to extract tasks, follow-ups, and other action items. The reading happens through Amazon Bedrock, AWS's managed AI service, which fronts foundation models from Anthropic and other providers. Bedrock's terms prohibit using customer data to train the underlying models, regardless of which model handles a given request. All of this happens inside AWS infrastructure; no this+that employee sees plaintext at any point.

Everything we store about you (messages, tasks, brain pages, and contacts) is encrypted at rest. Message content, tasks, and brain pages are additionally encrypted under dedicated keys in AWS KMS that only the application's service roles can use to decrypt; no this+that employee or contractor has decrypt access to that content. Calendar events are never stored: we query your calendar provider live over OAuth each time we need your schedule. If you disconnect an integration, we stop syncing new messages from that source, and you can request removal of previously synced data. If you delete your account, every message, task, and record we hold for you is removed.

What we don’t do with your data

  • We don’t sell your data. To anyone. Ever.
  • We don’t share it with advertisers, data brokers, or analytics resellers.
  • We don’t use it to train AI models, and our model providers don’t either, per the enterprise terms we’ve signed.
  • We don’t retain it after you delete your account.

Compliance & certifications

SOC 2 Type I

Submitted for examination. We submitted our SOC 2 Type I report to an independent auditor in 2026 and are awaiting issuance. We will publish the report on this page once it is delivered.

SOC 2 Type II

Underway. We have engaged an independent auditor to lead our SOC 2 Type II audit, and onboarding is beginning now. We will share progress as we move through onboarding and into the observation period.

CASA Tier 2

Certified. this+that has passed the App Defense Alliance's Cloud Application Security Assessment (CASA) at Tier 2, the security assessment Google requires for applications with restricted-scope access to Gmail data. Our certification was most recently revalidated in February 2026.

GDPR, UK GDPR & CCPA

We follow the requirements that apply to us under each framework. Our Data Processing Addendum incorporates GDPR Article 28 terms, the EU Standard Contractual Clauses, and the UK International Data Transfer Addendum. You can request access to or deletion of your data at any time, in the app or by emailing privacy@thisandthat.chat.

Sub-processor list

We publish the full list of third parties that process customer data on our behalf, with at least 30 days’ notice and an objection right before any new sub-processor is added.

Breach notification

In the unlikely event of a security incident affecting your data, we will notify affected customers without undue delay and within 72 hours of confirming the incident, in line with GDPR Article 33 and the terms of our DPA.

Two-factor authentication

You can secure your account with two-factor authentication from an authenticator app, with backup codes for recovery. If you sign in with Google or Microsoft, your account inherits the multi-factor settings you have configured with that identity provider.

Service status & uptime

We publish live system status and a history of past incidents at status.thisandthat.chat, so you can check uptime and any active issues at any time, and subscribe to be notified about incidents and scheduled maintenance.

Frequently asked questions

Can I use two-factor authentication to secure my login?

Yes. this+that supports two-factor authentication directly: turn it on in Account Settings and you'll be asked for a code from your authenticator app each time you sign in. We provide backup codes so you can recover access if you lose your authenticator. If you sign in with Google or Microsoft, your this+that account also inherits whatever 2FA you've configured on that identity provider.

Is my data encrypted in transit and at rest?

Yes, both. Data is encrypted while moving between connected services (Gmail, Slack, Teams, and others) and our servers, and it's encrypted while stored. Message content, tasks, and brain pages are additionally encrypted under dedicated keys in AWS KMS, and the key material never leaves AWS's hardware security modules. Decryption happens automatically inside AWS to serve your requests, and only the application's service roles can perform it.

Can your team at this+that read my emails and messages?

No. Your message content is encrypted under a dedicated key in AWS KMS that only the application's service roles can use to decrypt, and no this+that employee or contractor has decrypt access. Our app and AI services decrypt content automatically to serve you (for example, to display an email or extract a task). If we need to investigate a specific issue you're having, we'll ask you for context rather than reading your data.

Where is my data stored?

On AWS, with DynamoDB as our primary database. AWS is the industry-standard cloud platform with extensive security and reliability certifications of its own.

How can I check whether this+that is up?

We publish live system status and a full history of past incidents at status.thisandthat.chat. You can subscribe there to be notified about incidents and scheduled maintenance.

Will this+that share my messages or data with third parties or AI developers?

No. Your data is never sold or shared for advertising. We process messages through Amazon Bedrock, AWS's managed AI service that fronts foundation models from Anthropic and other providers. Bedrock's terms prohibit training on customer data, regardless of which underlying model handles a request. AWS is our subprocessor for AI processing, not a data buyer.

What happens if I disconnect an integration?

We stop analyzing new messages from that source immediately. You can also request the removal of any previously synced data from that integration. If you delete your account entirely, everything is removed.

Do you comply with GDPR, CCPA, or other data privacy regulations?

Yes, we follow the major data privacy frameworks that apply to our service, and you can delete your account (and therefore your data) at any time. For specific requests under GDPR or CCPA, email privacy@thisandthat.chat.

What if there's a data breach? Will I be notified?

Yes. In the unlikely event of a breach affecting your data, we follow industry-standard protocols to notify affected users promptly and to take immediate steps to secure all systems.

Who can see my messages and tasks inside this+that?

Your DoBox is private. Only you see what's in it. Shared task lists are visible to everyone in that list, by design. If you move a task with an attached message into a shared list, others on that list will see the message; that visibility persists even if you later leave the list.

Questions about how we handle your data?

We answer security and privacy questions directly. Email us. A real person reads every message.

Email security@thisandthat.chat