The plain-words promises are on Is it safe?. This page is for the person who has to sign off: what runs where, what protects it, and how to tell us about a problem.
One database and file store, run by Supabase on Amazon Web Services in Sydney, Australia. AI processing happens where the AI provider operates; every provider, and exactly what each one sees, is listed on the privacy page.
Four things, and only these. As items arrive: their opening text, to find private items and keep them private, and their full text in pieces, to make them searchable. When you ask: the question and the records it needs. When you upload an image or scanned PDF: that file, to read its text. When you ask for web research: the company names and descriptions involved (for an account brief, also who you know there and what you offer). All of this goes to Google’s Gemini today; if you choose a Claude or GPT model once they are available, that provider writes your answers instead. Paid terms; no training on your data.
Mail and calendar items that match your Never-read list are dropped before they’re stored. Anything else that matches is hidden, and hidden items are never sent to an AI provider. Two exceptions: your own notes and memories stay visible to you even when they match, and an image or scanned PDF you upload is read before the list is checked.
For each email: the subject, who it’s between and a one-line summary of the sender’s own words. Newsletters, no-reply senders, notification mail and mail from people you’ve never dealt with are not kept. The full message stays in your mailbox and is fetched live only when you, or a double you switched on, needs it; it is not stored.
In transit: HTTPS everywhere. At rest: the database and file storage are encrypted. Mailbox sign-in tokens are kept in an encrypted vault inside the database and can be revoked in Settings.
Every table has row-level security switched on, so the database itself refuses to return someone else’s rows, whichever door the request comes through: the app, a connected assistant such as Claude, or a double running overnight.
Service keys are held as server secrets, never in code or in the app. Connected-assistant keys can be revoked in Settings and stop working when they expire.
Items that look like health or personal money are marked private as they arrive in your personal space (in a shared space they are held for you to review) and stay out of answers, doubles and connected assistants unless you ask. Private items can live only in your personal space; the database refuses to move or share them into a shared one.
Nothing leaves your mailbox unless you tap Send or schedule it, after a screen naming the recipients. Doubles and connected assistants can draft; none can send.
No person at Twoself reads your data unless you ask for support, or for a security or legal reason.
One switch pauses every user-facing service within seconds if something goes wrong; scheduled work has its own switch.
Delete your account in Settings: every connection is cut at once, and everything is erased after 30 days (sign in within that time to keep it). Export everything first as Markdown, CSV and JSON Lines files.
If your information is accessed or disclosed without authority, or lost, you hear from us within 72 hours of our confirming it, with what happened and what to do. The detail is in the privacy policy.
An independent security review is planned before public launch. The summary will be published here. Google requires an annual security assessment for apps that read Gmail; ours will happen as part of Google’s review.
Email team@twoself.ai. A person replies within two working days.
twoself.ai, app.twoself.ai, the Twoself connector for AI assistants and Twoself’s email.
Test against accounts that aren’t yours; read, change or delete other people’s data (stop and tell us if you reach any); run denial-of-service or high-volume automated tests; use social engineering or phishing; or test the services we build on (Supabase, Microsoft, Google, Lovable, Resend). Report those to them.
An acknowledgement within two working days, updates as we fix it, and credit if you want it. If you act in good faith and follow this page, we will not take legal action against you. Please give us 90 days from our acknowledgement before you publish.
We don’t run a paid bug bounty.
Questions from your IT or security team: team@twoself.ai. Machine-readable contact: /.well-known/security.txt
Become two of you.
Free during the invited beta. I’ll write when it’s your turn.