Ir al contenido

Security

Esta página aún no está disponible en tu idioma.

A coworker who reads your mail and touches your accounts has to be built to a higher bar. Here is how John approaches that bar.

Your conversations, files, and connected accounts live in a private workspace set up just for you. They are never mixed with other customers.

Each active coworker runs on its own isolated cloud computer with its own persistent storage, rather than in a shared runtime where customer data mixes. That physical separation is the product difference: the same kind of execution power, without parking your business next to anyone else’s.

Platform logins that power the service stay protected on our side. They are not stored on your private workspace. John gets limited, scoped access to your connected accounts only for the work you ask him to do, and that access can expire.

You can revoke connections from the dashboard at any time. When you disconnect an app, John loses that access cleanly.

Connection secrets are encrypted at rest on our side (see Encryption and access controls).

When you install John in Slack, we process Slack data only as needed to operate the coworker and carry out requests made in Slack.

What we receive. Workspace and team identifiers, the tokens needed to run the integration, channel and user identifiers, and the text of messages, direct messages, and thread replies in conversations where you add or mention John, plus files you ask him to process.

Where processing happens. Message processing occurs on your private workspace. Our side does not retain your Slack chat transcripts. Short-lived routing metadata (for example, a delivery queue and brief thread context so replies in a thread make sense) may exist on our side for delivery. That is not a long-term chat archive.

Permission-aware search. When John needs broader workspace context, search results respect your existing Slack permissions and never surface content you could not otherwise see. Those results are injected as temporary context for the current task and are not stored long-term on our routing layer.

No training on Slack data. We do not use Slack data to develop, improve, or train generalized AI models, and we do not use Slack data for advertising. Optional product-improvement or human-review programs (where offered elsewhere) do not apply to data received through Slack.

Revoking access. Uninstall John or revoke access from Slack (App Management or your workspace admin) at any time. After revocation, we stop collecting new Slack data and invalidate the associated tokens.

For the full legal description, see the Privacy policy (Slack section).

When you connect Telegram, message processing happens on your private workspace. Bot tokens and related secrets stay encrypted on our side and are made available to your coworker only as needed. You can disconnect Telegram from the dashboard at any time.

  • Encryption in transit. Dashboard and API traffic use HTTPS/TLS.
  • Encryption at rest. Connection secrets (including Slack and Telegram tokens and other connection credentials) are encrypted at rest with AES-256-GCM.
  • Access controls. Internal access to production systems uses role-based controls. Sensitive platform credentials are not stored on your private workspace; your coworker receives only scoped credentials for your account.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your own account and credentials secure.

When John builds and hosts a simple public site for you, it is served on a *.johnceo.app address. Those apps are public by design - treat them like anything else you would put on the open web. Your private workspace and private chats are separate from that public surface.

When email is enabled for your account, each private workspace can use a unique address like {handle}@johnceo.email.

  • The account owner enables or disables email in the dashboard.
  • You choose the username (handle). You can rename it only once, so pick carefully.
  • After enabling, apply changes to your private workspace so John learns the address.

Inbound mail is allowlist-only. Only domains and addresses you list can reach John. Mail from everyone else is rejected.

You manage the allowlist in the dashboard (allowed domains and specific addresses).

When email is enabled, John can send from your {handle}@johnceo.email address on your behalf as part of delegated work. Treat that address as part of your company’s public face for agent-sent mail.

Email may not be available in every environment yet. If the dashboard says email is not available, the channel is still rolling out for your account.

The dashboard shows AI spend so you can see how much model usage your workspace is using. Caps and billing features may still be in preview depending on your plan and environment.

Email [email protected]. For abuse related to public apps, use the same address and tag the subject with [Apps abuse].