Security
A coworker who reads your mail and touches your accounts has to be built to a higher bar. Here is how John approaches that bar.
One private workspace per customer
Section titled “One private workspace per customer”Your conversations, files, and connected accounts live in a private workspace set up just for you. They are never mixed with other customers.
Sensitive logins stay on our side
Section titled “Sensitive logins stay on our side”Platform logins that power the service stay protected on our side. John gets limited access to your connected accounts for the work you ask him to do. You can revoke connections from the dashboard at any time.
Connection secrets are encrypted at rest.
LLM spend visibility
Section titled “LLM spend visibility”The dashboard shows LLM spend so you can see how much model usage your workspace is using. Caps and billing features may still be in preview depending on your plan and environment.
Public apps on johnceo.app
Section titled “Public apps on johnceo.app”When John builds and hosts a simple public site for you, it is served on a *.johnceo.app address. Those apps are public by design - treat them like anything else you would put on the open web. Your private workspace and private chats are separate from that public surface.
Workspace email (@johnceo.email)
Section titled “Workspace email (@johnceo.email)”When email is enabled for your account, each private workspace can use a unique address like {handle}@johnceo.email.
Who controls it
Section titled “Who controls it”- The account owner enables or disables email in the dashboard.
- You choose the username (handle). You can rename it only once, so pick carefully.
- After enabling, apply changes to your private workspace so John learns the address.
Who can send to John
Section titled “Who can send to John”Inbound mail is allowlist-only. Only domains and addresses you list can reach John. Mail from everyone else is rejected.
You manage the allowlist in the dashboard (allowed domains and specific addresses).
Who can receive mail from John
Section titled “Who can receive mail from John”When email is enabled, John can send from your {handle}@johnceo.email address on your behalf as part of delegated work. Treat that address as part of your company’s public face for agent-sent mail.
Availability
Section titled “Availability”Email may not be available in every environment yet. If the dashboard says email is not available, the channel is still rolling out for your account.
Privacy and subprocessors
Section titled “Privacy and subprocessors”Questions or concerns
Section titled “Questions or concerns”Email info@john.ceo. For abuse related to public apps, use the same address and tag the subject with [Apps abuse].