Security & AI Trust
Last updated: 28 August 2026
Handing real work to AI employees takes trust. This page answers, in plain English, the questions business owners ask us most — where your data lives, what the AI can and cannot do without you, and what happens if something goes wrong. The legally binding detail lives in our Privacy Policy and Terms of Service.
1. Where is my data?
Your account data and content are stored with Supabase on Amazon Web Services, currently in the Tokyo (Japan) region, with our website delivered by Vercel. Everything is encrypted in transit. We are an ANZ company serving ANZ businesses, and we are evaluating Australian-region hosting as we grow — if data residency is critical for your business, tell us at support@imo.nz; it directly shapes that roadmap.
2. Will my data be used to train AI models?
No.We permit our AI providers to process your content only to do your work. We do not use your content to train our own or any third party’s general-purpose AI models, and we do not allow our providers to, without your express prior consent. Data we obtain through Google Workspace APIs is never used to develop, improve or train generalised AI or machine-learning models.
Where a provider’s standard terms would allow it, we opt out before we send them anything. Voyage AI, who make your documents searchable, is the case in point: their standard terms let them train on what customers send, so we opted out first, and their terms say content from an opted-out customer is deleted immediately after it has been processed.
3. What stops the AI from sending something wrong?
You decide how much rope each employee gets, and the default is careful:
- Autonomy levels.Every employee runs at a level you set — from “suggest only” and “draft for approval” (the default) up to fully autonomous. Nothing goes out at approval levels until you approve it.
- Review queue. Drafts, replies and actions wait in a queue where you approve, edit or send them back.
- Activity trail. Each employee keeps a visible feed of what it did and when, so work is auditable after the fact.
- Pause anytime. One click pauses an employee; firing one removes its access entirely.
AI can still make mistakes — outputs can be inaccurate or out of date, which is why review settings exist and why outputs are never professional advice. See our Terms for how responsibility is shared.
4. How do sign-in and connected accounts work?
- You can sign in with Google, or with an email address and password. Signing in with Google means you prove who you are to Google and we never see that password; passwords for the other kind are stored only as salted hashes by our authentication provider.
- Connecting a tool (email, calendar, social, CRM) happens on that provider’s own consent screen, and you can withdraw it at any time — from inside IMO, or from the provider’s security settings.
- We ask for the narrowest permission that does the job. Gmail is send-only: IMO can send an email you approved, and cannot read, search or delete anything in your mailbox. Google Calendar is limited to calendars you own, and IMO uses it to add the dates you approved. Both are named exactly, with the permission strings, in section 8 of our Privacy Policy.
- Google treats these two permissions as sensitive, so they go through Google’s verification before we can offer them without a warning screen; that review is under way. Neither is in the “restricted” class that requires an independent security assessment.
- We follow the Google API Services User Data Policy, including its Limited Use requirements: no ads use, no selling, no training generalised models, and people reading that information only where you agree, where a security investigation needs it, or where the law requires it.
5. How is the platform secured?
- Encryption in transit (TLS) everywhere; encryption at rest on our hosting providers.
- Row-level security on our databases: server-side policies mean one customer’s data is not readable by another’s session.
- Least-privilege access: our own staff reach production data only when operating the Service requires it — and for information from a connected Google account, only in the narrower cases the Limited Use requirements allow (see above).
- Secrets and keys are stored in managed environments, never in code.
6. What happens if there is a data breach?
We operate under the New Zealand Privacy Act 2020 and, where it applies, Australia’s Notifiable Data Breaches scheme. If a breach occurs that has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner (NZ) and, where applicable, the OAIC (AU) and the affected people, as soon as practicable — with straight answers about what happened and what we are doing about it.
7. Can I take my data and leave?
Yes. Your content is yours. For 30 days after a paid account closes you can request an export in a reasonable format; after that we delete it, apart from copies the law requires us to keep or that persist briefly in encrypted backups.
8. Found a vulnerability, or have a question?
Security reports and questions: support@imo.nz. Privacy matters: privacy@imo.nz. We read both, and responsible disclosure is genuinely appreciated.