Security

Your data is yours. Full stop.

Sauna connects to your tools to get real work done — not to collect you. We don't sell it, we don't train on it, and we don't act without your OK.

Never soldNever trained onNever without your OK

What Sauna touches

Here's what we access, and why.

EmailTriages your inbox and drafts replies in your voice. Sauna reads only what a task needs — it doesn't browse for anything else.
CalendarPreps briefings, finds conflicts, and manages invitations in Google Calendar.
DocumentsPulls context from Drive, Notion, Granola, and other sources you connect — for the task at hand, not a standing archive.
Slack and 3,000+ appsLinear, GitHub, HubSpot, Stripe, and thousands more. Every connection is optional, and you pick what's linked.

Any tool, your way

Connect from the library, or bring your own.

However your stack is wired, Sauna meets it — the built-in library, a raw API key, or an MCP server you already run.

1
Pick from the library
Search 3,000+ built-in connections and authorize in a click.
2
Bring an API key
Add any HTTP service yourself — Bearer token, header key, query param, or basic auth.
3
Point at an MCP server
Give Sauna a URL. It handles OAuth, dynamic registration, or a plain key — whatever the server speaks.
And you can always take it back.Remove a connection from Settings and we don't just stop referencing it — we lose access to it entirely. Tokens are revoked immediately. We don't pretend it's still there when it isn't.

Nothing happens without your OK

You hold the switch.

Approval before it acts.By default, Sauna asks first. In Slack it surfaces an inline approval button before sending a follow-up — you click it, nothing fires on its own.
Autonomous mode is opt-in.You can turn on autonomous handling for a specific routine so it stops asking every time. That's a setting you choose — never the default.
Memory you control.Sauna's Memory notes live in your workspace as plain files. View, edit, or delete any of them whenever you want.
Delete your data anytime.Close your account from Settings or email us, and we remove your account, content, and memory within 30 days.

How we lock it down

Security isn't a feature. It's how we build.

CASA-approved.We've completed a Cloud Application Security Assessment, independently validated against the OWASP ASVS standard.
SOC 2 Type II compliant.Independently audited for how we handle your data. Live status and reports on our Trust Center.
Encrypted everywhere.TLS 1.2+ in transit and AES-256 (or equivalent) at rest — including every OAuth token and API key behind a connection.
U.S.-hosted infrastructure.For U.S. customers, infrastructure and data storage are hosted in the United States.
Google API Limited Use compliant.Gmail, Calendar, and Drive data is used only to provide the features you ask for — never for ads, never to train AI/ML models.
Least-privilege access.Production access is limited on a least-privilege basis, protected with MFA, and logged.

Want the receipts? Our Trust Center has live compliance status and audit reports. Found a vulnerability? Email security@sauna.ai — we investigate every report.

Common questions

Have a question we didn't cover?

Do you sell my data?

No. We never sell your data or use it for advertising.

Do you use my data to train AI models?

No. We don't use anything you give Sauna to train models — ours or anyone else's.

Can anyone at Sauna see my data?

Not everyone. Access is guarded to a small few, and every access is logged.

Can I delete my account and data?

Yes. Delete your account from Settings or email privacy@sauna.ai, and we remove everything within 30 days.

What happens if I disconnect an integration?

We don't just stop referencing it — we lose access to it entirely. Tokens are revoked immediately, and Sauna can't reach that connection anymore.

Will Sauna send emails without my permission?

By default, no — Sauna always asks first. If you turn on autonomous mode for a specific routine, it can act without asking every time, but that's a setting you choose, not the default.

Can Sauna read all of my email?

No. Only what a task needs — drafting a reply, organizing your inbox, surfacing what matters. Nothing else.

How do I report a security issue?

Email security@sauna.ai. We investigate every report.

How can I verify your certifications?

Our Trust Center has live compliance status and audit reports for CASA and SOC 2 Type II. Visit the Trust Center

For the full detail, read our Privacy Policy or email privacy@sauna.ai.

Bringing Sauna to your team?

If your organization has security requirements, we’d love to talk.

Contact us