Founding member offer: 50% off every plan — locked in for life while you stay subscribed. Claim a founding seat →

Security & privacy

How we protect your data, who can see it, and your export and deletion controls.

Yes — the short version: OAuth-scoped access only (we never see or store your mailbox password), TLS in transit and encrypted storage on our managed database, with mailbox credentials and OAuth tokens encrypted again under a separate key we keep in a secrets vault. Every workspace is isolated by a tenant key enforced on every API request, backed by row-level security policies in the database, and sensitive actions are audit-logged. Monty uses vetted AI providers as processors to generate drafts; under our API terms your data is not used to train their models, and what Monty learns from your inbox improves your workspace only. A current security overview document is available on request from hello@montyai.co.

Everyone in your workspace — and no one outside it. Roles control who can approve and send drafts and who can change settings; anyone with access to your workspace can read its inbox, so grant access accordingly. Monty's staff console has no mailbox browser — it shows account, billing, and system-health data, not your message content — and staff actions there are recorded in an audit log with the operator's identity and the workspace they touched. If a support case ever requires looking at a specific message, that happens with your knowledge. We never sell data, never share it with advertisers, and never use one customer's mail to benefit another.

In encrypted cloud infrastructure, isolated per workspace. If you have data-residency or compliance requirements, mention them when you talk to the team — we'll tell you honestly what we can support today and what's on the roadmap.

Not yet. Today you sign in with Google, or with email and password. SAML/OIDC single sign-on and SCIM provisioning are on our enterprise roadmap — if they're a requirement for your team, tell us through the contact form and we'll keep you posted on timing.

Both. Export your profile and account data any time from Settings → Account, and email hello@montyai.co for a full conversation and lead export in portable formats — or to delete your workspace's data (mail, drafts, and learned voice profile) on request. You can delete your own account from Settings → Account. Revoking OAuth at your mail provider immediately stops Monty renewing access, and any session already in flight ends within the hour — that stops future syncing, so ask us if you also want what Monty already stored removed.

Email hello@montyai.co with details and reproduction steps if you have them. We take responsible disclosure seriously: you'll get an acknowledgment quickly, a human follow-up with our assessment, and credit if you want it. Please don't test against other customers' workspaces — spin up a trial workspace and go at that instead.

Didn’t find what you needed?

Contact support
Security & privacy — Support · Monty AI