Team0
  • Product
  • How it works
  • Works with
  • Use cases
  • Pricing

What Team0 keeps, and what it doesn’t.

Letting Team0 build an understanding from your mail, calendar and meetings is a real decision. So here is the specific version: what it keeps, what it never does, who can see it, and what it is allowed to do.

Certification
CASA Tier 2, independently assessed
Sign-in
Google — we hold no passwords
The main model
Runs inside our own cloud account
A small open workshop around a section of the path; everything inside is visible and a person inspects one card with a magnifying glass.

Facts, not copies.

Your understanding is made of individual conclusions, each with a source, not a warehouse of everything Team0 has read.

What Team0 keeps from each source, and what it does not store
FromKeptNot stored
EmailWho people are, what was agreed, what you owe someone, dates that matter.The messages themselves. There is no mailbox copy on our side.
CalendarWho you are meeting, when, and your history with them.A standing copy of your calendar.
MeetingsThe transcript and summary of meetings you record.Anything from a meeting you did not ask Team0 to join.
DocumentsText from files you upload, so it can search them.Files you never gave it.
Your agentsWhat matters from your conversations with the agents you connect: who is who, what was decided, what is next, each with the line it came from.The conversation itself after 7 days, or your files, unless you put them in a message.
Connected toolsThe key you supplied, encrypted and scoped to your account alone.A copy of that tool’s data.

Recorded meetings are the exception worth knowing about: those are stored word for word, because a summary you cannot check back against is worth very little. Nothing is recorded unless you ask Team0 to join the meeting.

It works in the background, and in the moment.

Two things are happening. In the background Team0 keeps your understanding current: noticing what arrived, what changed, what conflicts and what is now overdue, so neither you nor your agents start from zero. In the moment, when one of your agents asks something, Team0 reads what that request needs, within the access you gave that agent.

Either way, what Team0 writes down is the conclusion rather than the source. This person works there, you promised them a reply, that was agreed on the 14th. Each one is separate, each shows where it came from, and each can be corrected or removed on its own. The messages themselves stay in your Google account, under the access you granted, which you can withdraw at any time.

You can see all of it, and undo all of it.

  • Every fact Team0 holds is visible to you, one at a time, with the source it came from.
  • Each agent you connect has its own access. Stop it saving and it can still read; stop all access and its next request is refused. You can see each request it made in the last 30 days, and exactly what Team0 returned for the first 24 hours.
  • Anything wrong can be corrected. Anything you would rather Team0 forgot can be removed, and it stops being used immediately.
  • A connected tool can be read-only, so Team0 can see a system without being able to change anything in it.
  • Disconnecting a tool cuts the access straight away — there is no lingering copy to go and find.
  • If you close your account, personal information is deleted within 30 days — other than billing records, which we are required by law to keep.

How the data is held.

Your data is kept apart from everyone else’s
Your people, facts, transcripts, actions and documents live in a database schema belonging to your account — the separation is in where the data is kept, not a filter the application has to remember to apply. Which account a request may touch is settled before anything runs, from your verified membership, and never from a value the caller supplies: if the same request carries two different answers to that question, it is refused rather than resolved.
Two separate checks, always
Proving who you are is not the same as proving whose data you may read, and we treat them as two questions rather than one. Anything unrecognised is refused rather than given the benefit of the doubt.
Nothing to steal at sign-in
You sign in with Google. Team0 holds no passwords — not hashed, not anywhere — so there is no password store to breach.
Encrypted throughout
Encrypted in transit on modern TLS only, and encrypted at rest with managed keys. The database is not reachable from the internet. Your connected-tool credentials are encrypted with a key specific to your account.
Independently assessed
We hold CASA Tier 2, assessed by an authorised external lab against the OWASP application security standard, and it is renewed annually rather than earned once.

What is recorded, and what you can check yourself.

Everything above is about preventing a problem. This is about noticing one.

  • Every read an agent makes is listed in the Agents view for 30 days, with the request it sent and, for 24 hours, what Team0 returned. If you also use the Chief, everything it says or sends on your behalf lands in one place, and one switch stops it on any thread, mid-conversation.
  • Infrastructure and administrative activity is logged separately from the application and retained independently of it.
  • Your own Google audit log shows what our application accessed — independent of us, and not something you have to take on trust. You can withdraw our access from your side at any moment, without asking us first.
  • If we confirm a breach affecting your data, you hear from us within 72 hours, by email to the account owner — including what we do not yet know at that point, rather than a polished account weeks later.

The main model runs in our own cloud account.

This is usually the real question, so plainly: the model that reads your mail and builds your understanding runs inside our own AWS account, on the same infrastructure as everything else, and so does search. A few smaller jobs use outside providers, listed below with exactly what they receive. Nothing we send is used to train a model.

Who else receives data, and what they receive
AWSHosting, storage and the AI model itself, under our agreement with them.
GoogleOnly what your grant permits — and you can revoke it from your Google account at any time.
OpenAIShort passages of text for a nightly second check that relationships read from your messages are supported by their own words, and to read the date in a reminder you set. Also a standby copy of the search index while we finish moving off it.
Google GeminiBefore a meeting, the name of the person or company you are meeting, to look up public information. Never your messages.
ClerkSign-in and session handling.
TranscriptionAudio from the meetings you chose to record. Named for security reviewers on request.
PaymentsBilling details. Card numbers never reach Team0 at all.

The limits are in what an agent can reach.

An agent that reads the open web and your inbox will eventually read something written to manipulate it. We do not assume we can spot every attempt. We assume some get through, and make sure it does not matter much when they do.

An agent reads only what you allowed
Each agent you connect has its own access, applied inside the query that reads your understanding, so what it may not see is never retrieved. What an agent saves back is kept as evidence under its name and is never trusted automatically. Persuading an agent to ask for more does not grant it more.
Authority is explicit, not implied
Team0 gives your agents context; the work itself is done by the agent you chose, with the permissions you gave it there. If you also use the Chief, you decide what it may do, what always needs approval and what stays read-only.
Another company’s agent sees a filtered version
When an outside agent talks to your Chief, what it can see is limited by the database query itself rather than by an instruction we hope it follows. Anything marked private or sensitive is excluded, anything not yet classified is treated as private, and an unrecognised caller falls to the narrowest setting rather than the widest.

Things we are asked, where the answer is no.

We do not have SOC 2
We hold CASA Tier 2, which Google requires of any app handling restricted Google user data — assessed by an authorised external lab and renewed every year. We do not hold SOC 2 at this point. What CASA is.
We do not offer regional data residency
Everything runs in one region in the United States. If your data has to stay in a particular country, that is worth raising with us early — it is a real constraint and we would rather work through it with you at the start than discover it late.
We do not read your data ourselves
Access to production is limited and audited, and we do not browse customer content. If we ever need to look at something to fix a problem you have reported, we ask first.

For security reviewers.

Our full posture record, control evidence and security policy go to reviewers on request. Penetration testing is welcome rather than merely tolerated — tell us the window and the scope and we will not treat it as an incident.

Email hey@team0.aiTrust and control→Privacy policy→

Revised 2026-10-02

Team0

An understanding of your work that stays with you, whichever agents you use.

CASA Tier 2 certified.

Product

  • Living Understanding
  • How it works
  • Sources
  • Walk through an example
  • Use cases
  • Pricing

Technology

  • The World Model
  • Architecture
  • Data model
  • Entity resolution
  • Truth maintenance
  • Trust and scope
  • Understanding Engine
  • Memory vs understanding
  • The 31 problems

Agents

  • Works with
  • Developers
  • Connect over MCP

Trust

  • Trust and control
  • Security
  • Privacy
  • Terms

Company

  • About
  • Blog
  • FAQ
  • Support
© 2026 Team0Invite-only private beta