Is OutlookDog safe?
Short answer: OutlookDog reads email, so it was built on one uncompromising idea — your mail is never stored, and with our managed AI it never leaves the Microsoft cloud. Here are the questions people actually ask, answered plainly. The full technical detail lives on our Security page.
Who is behind OutlookDog?
Speraj LLC, a Microsoft verified publisher, distributed through Microsoft AppSource — which means Microsoft has verified the publisher's identity, and the add-in went through AppSource validation.
Does OutlookDog store my email?
No. Message text is processed in the moment and discarded — email bodies, subjects, attachments, and recipients are never written to disk on our side. What we do store: your account identifier, email address, display name, daily usage counts, and subscription status — encrypted at rest. (One honest footnote: Azure OpenAI's built-in abuse monitoring on Microsoft's side may retain prompts up to 30 days — see our Privacy Policy.)
Is my email used to train AI?
No. The AI is Azure OpenAI — Microsoft's own AI service, running in Azure — and it does not train on your data. We never retain content to train anything.
Can OutlookDog send, delete, or move my mail?
No. OutlookDog only ever advises. The only change it makes to a message is a category label; drafted replies are inserted for you to review and send. There is no code path that sends, forwards, moves, or deletes mail — including through taught rules, which are validated against a schema that has no field where “forward” or “delete” could even be written. How rules are hardened →
What permissions does it take?
The least it can. The add-in itself installs with Outlook's least-privileged
read/write tier (ReadWriteItem) — the message you have open, nothing
more. Sign-in asks only for basic profile. Broader mail access (Microsoft Graph
Mail.ReadWrite) is requested once, only if you tap Categorize,
and its complete list of uses is published on the Security page.
Will it fight with my company's security policies?
It runs on them. Sign-in uses your existing Microsoft Entra ID — no separate password — so your conditional access and MFA policies apply automatically, and revoking a Microsoft account revokes OutlookDog at the same moment.
Is the scam detection guaranteed?
No, and we say so plainly: AI can make mistakes. A ⛔ flag is a heads-up to look closer, not proof; a “safe” result is not a guarantee. OutlookDog's job is to get your attention and save you time — you decide what to do.
What about GDPR, our DPA, compliance paperwork?
Our Data Processing Agreement applies automatically to every Business and Enterprise account — nothing to request, nothing to sign (read it). You can download or delete your data yourself from your account page. Microsoft 365 App Compliance Publisher Attestation is in progress; we are not SOC 2 certified and say so honestly — details.
I'm from IT and I have 20 more questions.
Good — we wrote them down for you: the OutlookDog Security Review Kit (PDF) — architecture, data handling, every permission and exactly what it's used for, subprocessors, outage behavior, and the 10-minute centralized-deployment runbook. Or just email support@outlookdog.com — security questions get first priority.
Try it on tomorrow's mail.
