In scope
- Messages sent directly to DTD
- Emails forwarded to DTD
- Threads where DTD is CC'd
- Subsequent replies in tracked DTD conversations
The core DTD experience is designed around direct email, forwarding and CC - not full access to your entire inbox.
DTD should not require blanket access to your whole mailbox merely to handle tasks you explicitly send or CC to it.
For paid plans, customer AI provider keys should be handled server-side and kept out of ordinary task content.
Stored using appropriate encryption rather than plaintext.
Interfaces should mask credentials after they are saved.
The key is for authenticating to the provider, not for inclusion in task text.
Provider requests should be made from controlled server infrastructure rather than exposing the key to the browser.
DTD is meant to remain subordinate to the user's latest instruction.
Reply with instructions such as:
“Stop.”
“Pause this until Monday.”
“Cancel this task.”
“Don't send anything else without checking with me.”
This site intentionally makes no claim of SOC 2, ISO 27001, HIPAA or other certification. Add compliance claims only after they have genuinely been achieved and verified.
Free to try. No signup. No AI API key.
agent@dotilldone.com