Privacy Policy

Last updated: September 21, 2026

MailLedger (“we,” “our,” or “us”) is committed to protecting your privacy. This policy describes how we collect, use, and safeguard information when you use our Outlook add-in and related services.

Information we process

MailLedger uses Microsoft Graph APIs with the delegated permissions Mail.ReadWrite and Mail.Send. We process email metadata (e.g. sender, subject, date) plus Outlook's short message preview to rank folder suggestions locally in the add-in. We do not store full email bodies on our servers. Processing happens in accordance with your Microsoft 365 tenant and applicable data processing terms.

When you use Send & File, our background filing service receives message, folder, conversation, and tracking identifiers, together with a Microsoft Graph access token. This lets an accepted filing operation continue after the Outlook pane closes. The token is encrypted in storage; this service does not receive a Microsoft refresh token or password. Full message bodies and attachments are not part of the background filing record.

We also store account and organization identifiers, contact/profile details, subscription status, and operational audit records to authenticate users, manage access, and operate billing. MailLedger infrastructure runs on Cloudflare, and Stripe processes payments and subscriptions.

On the website, we may also process business contact information, first-party attribution details, and product-interaction events when you start a trial, request a rollout, use the ROI calculator, or interact with pricing and onboarding flows.

How we use your data

We use sender, recipients, subject, folder history, thread patterns, and Outlook's short preview text to file emails into the right project folders and maintain audit-ready timelines. Our systems do not train on or retain full message bodies on our servers, and local ranking stays inside the add-in under your Microsoft 365 session.

We also use first-party website and product interaction data to measure trial activation, improve onboarding, and send operational follow-ups related to a trial, billing, or a requested rollout.

Data retention and security

We retain only what is necessary to operate the service and comply with law. We use industry-standard measures to protect data in transit and at rest. MailLedger is designed to align with the product architecture described on the security page: Microsoft authentication, local Outlook ranking, and Outlook-native records.

Folder caches, learned rules, recent folders, filing history, and preferences are stored in the add-in's browser storage. Microsoft session and access-token caches also use browser storage. Filed messages remain in your Microsoft mailbox.

Background filing jobs stop attempting work after 15 minutes. Their stored access token is removed when the job completes, is rejected, expires, or requires sign-in again. Job identifiers and status records are scheduled for deletion 24 hours after the job was created. These limits describe the background filing records, not account, billing, or platform backup retention.

Your rights

You may request access to, correction of, or deletion of personal data we hold about you. To do so, or to withdraw consent where applicable, contact us at the email below. We will respond in accordance with applicable law.

Removing the add-in does not itself delete account, billing, or operational records held by MailLedger. Contact us for requests concerning those records. Removing the add-in also leaves your filed email and folders in your Microsoft mailbox.

Contact

For privacy-related questions, contact us at support@mailledger.ai.