Security & privacy

DTD should only see what you deliberately hand it.

The core DTD experience is designed around direct email, forwarding and CC - not full access to your entire inbox.

Email DTD
Email access

DTD only reads what you send it.

In scope

  • Messages sent directly to DTD
  • Emails forwarded to DTD
  • Threads where DTD is CC'd
  • Subsequent replies in tracked DTD conversations

Not required for the core experience

DTD should not require blanket access to your whole mailbox merely to handle tasks you explicitly send or CC to it.

Customer AI keys

Treat API keys like credentials, not content.

For paid plans, customer AI provider keys should be handled server-side and kept out of ordinary task content.

Encrypted at rest

Stored using appropriate encryption rather than plaintext.

Never displayed back in full

Interfaces should mask credentials after they are saved.

Not intentionally included in model prompts

The key is for authenticating to the provider, not for inclusion in task text.

Used server-side

Provider requests should be made from controlled server infrastructure rather than exposing the key to the browser.

User control

Stop, pause or change course in the same thread.

DTD is meant to remain subordinate to the user's latest instruction.

Task controls

  • Stop a task
  • Pause a task
  • Cancel a task
  • Review ongoing tasks
  • Request deletion of task data

Plain-language controls

Reply with instructions such as:

“Stop.”
“Pause this until Monday.”
“Cancel this task.”
“Don't send anything else without checking with me.”

No invented badges

Trust should come from implemented controls, not logos.

This site intentionally makes no claim of SOC 2, ISO 27001, HIPAA or other certification. Add compliance claims only after they have genuinely been achieved and verified.

Try the real product

Try DTD without connecting your inbox.

Free to try. No signup. No AI API key.

agent@dotilldone.com
Email DTD