Short version: standard Microsoft sign-in, local ranking, and a record that never leaves your mailbox.
Microsoft sign-in
Users sign in through Microsoft with the scopes needed for filing and mailbox actions. Nothing more.
Ranking happens locally
Suggestions are ranked from sender, recipients, subject, folder history, and Outlook's short preview text, inside the add-in.
The record stays in Outlook
MailLedger upgrades the folders you already use. Your record never moves to someone else's database.
Stripe billing
Checkout and billing run through Stripe, never through us.
Centralized deployment
IT can deploy across Microsoft 365 from the admin center. Solo users can install it themselves.
Leave with everything
Cancel and your folders, filing, and history remain exactly where they are: in your mailbox.
What MailLedger uses
Authentication runs through Microsoft.
MailLedger uses message signals plus Outlook's short preview to rank suggestions locally.
Full email bodies do not need to be stored on our servers.
Background filing temporarily stores mailbox identifiers and an encrypted Graph access token on Cloudflare.
Billing and trial start run through Stripe-backed subscription flows.
For IT administrators
The one-page version of what you approve when you deploy MailLedger across a Microsoft 365 tenant.
Permissions requested
The Outlook add-in manifest requests ReadWriteMailbox. Microsoft Graph sign-in also requests delegated Mail.ReadWrite and Mail.Send permissions for mailbox access, folder/message changes, and sending as the signed-in user. These permissions are broader than metadata-only access. They are delegated user permissions, not application permissions granting unattended access to every tenant mailbox. Consent remains subject to your organization's policies.
Where the record lives
Filed mail stays in the user's Outlook folders in your tenant. Suggestion ranking runs inside the add-in from message signals and Outlook's short preview text; full email bodies do not need to be stored on our servers.
Background filing
Send & File hands an accepted filing job to MailLedger's Cloudflare service so it can finish after the pane closes. The record contains message, folder, conversation, and tracking identifiers plus an encrypted Graph access token, not full message bodies or attachments. Jobs stop after 15 minutes; stored tokens are removed on completion, rejection, expiry, or a sign-in requirement. Job records are scheduled for deletion after 24 hours. This service does not retain a Microsoft refresh token or password.
Centralized deployment
Deploy to selected users or the whole organization from the Microsoft 365 admin center under Integrated apps. Users get the add-in on desktop and web Outlook with no individual installs. Removal from the same screen uninstalls it everywhere.
Offboarding
Cancel or uninstall and every filed message, folder, and timeline remains exactly where it is: in your users' mailboxes, under your tenant's existing retention and compliance policies. Leaving MailLedger costs you nothing. Removing the add-in does not itself delete MailLedger account, billing, or operational records; contact support for those requests. Review or revoke the application's Microsoft consent separately when offboarding.
Pricing
Start free, keep the record in Outlook
Every plan starts with a 14-day free trial. A card is required, and you pay nothing if you cancel before the trial ends.
Starter
File email and keep replies in the Outlook folders you already use.
$5.99per user / month
Best for solo users, owner-led businesses, and lean teams that need a clean record without changing workflow.
Billing runs through Stripe after your trial. Annual plans carry a 30-day money-back guarantee. Either way, cancel anytime and keep everything: the record lives in your Outlook folders.
Need centralized deployment or billing-owner approval?
Self-serve works for individual buyers. MailLedger can also be rolled out through the Microsoft 365 admin center for larger teams and controlled deployments.