Privacy Policy

Last updated: 2026-09-11. (Sep 11, 2026: added "Our website" — outlookdog.com now counts visits with a cookieless measurement tag that sets no cookies and builds no advertising profile; the add-in is unaffected. Sep 7, 2026: named the new on-device "? Questionable" grade in the link double-check section — no new data leaves your device. Sep 3, 2026: the trial-abuse marker now also covers a hash of the account identifier. Sep 2, 2026: clarified how long error diagnostics are kept. Aug 31, 2026: site navigation updated — no change to this policy.) This is a plain-English summary of how OutlookDog handles your data. August 2026: added the rules you teach, the mailbox reads that back them, and anonymous usage counts.

The short version

OutlookDog asks for permission to read your email because no email assistant can work without it. Here is the deal we make with that access: your mail is never stored on our servers, never sold, and — on our managed AI lane — never used to train AI models. The add-in runs inside your own Outlook. When you use an AI action, your message text is sent for processing in that moment — through our encrypted relay to Microsoft Azure OpenAI on our managed lane, or, if you bring your own key, directly to the AI provider you chose, under that provider's own terms — and nothing is kept afterwards except a usage count.

What OutlookDog reads

To do its job, OutlookDog reads the message you have open (subject, body, sender, attachment names, and message headers). If you tap the Categorize icon at the top of the pane to sort your whole inbox, it also reads your recent inbox messages — that data flows directly between your Outlook and Microsoft's own service (Microsoft Graph) and never touches OutlookDog's servers. The optional sender-history signal ("first message from this sender") likewise queries your own mailbox via Microsoft Graph directly. That inbox access is consented just-in-time: Microsoft asks for it the first time you categorize your whole inbox — reading the single message you have open needs no consent beyond installing the add-in.

Once you have granted that permission, three more things use it. So that the list is complete, here is every time OutlookDog reads your mailbox beyond the message you have open, and what each read is for:

All four read your mailbox through Microsoft Graph, directly from the add-in. None of them copies your messages to OutlookDog’s servers, and the only change any of them can make to a message you receive is adding or removing one of your Outlook category labels.

Two AI lanes

Bring your own key (BYO): for the AI features you drive — summaries, reply drafts, and turning a typed sentence into a rule — your message goes directly from the add-in to the AI provider you chose, and never passes through or is stored on OutlookDog's servers. Your key is stored as-is (not encrypted by OutlookDog) in your own mailbox's add-in settings — Microsoft protects it like the rest of your mailbox data, it roams with your account, and anyone with full access to your mailbox could read it, so we recommend a key you can revoke. Your key is sent only to that provider, never to us. The one exception is safety. The automatic scam checks that guard you — the link double-check and the shared-file screen described below — always run on OutlookDog's own backend, for everyone, because a warning that decides whether to trust a message must run behind our own hardened prompts and cannot be pointed at whatever model a key names. So when the shared-file screen runs, that one message and the page its link opens are sent to our backend even on the bring-your-own-key lane; we never store either.

OutlookDog-AI (managed): your message is sent over an encrypted connection to our backend, which relays it to Microsoft Azure OpenAI to generate the result, and returns it to you. OutlookDog never stores your message content, and it is never used to train any models. As part of Microsoft's Azure OpenAI service, prompts may be retained by Microsoft for up to 30 days solely for abuse monitoring, after which they are deleted. We retain only usage counts and the account details described below.

Most AI features run when you ask for them — a summary, a draft, a rule. A few run on their own once you are signed in (or whenever your own key is active for the ones that use it): the automatic summary of an opened message — on unless you turn it off in Settings — the AI's explanation of a message OutlookDog flags as a likely scam (for the milder ⚠ Suspicious and ? Questionable tiers the read runs only when you open the details yourself), and, described under “Shared-file safety screen” below, an automatic safety check when a first-time sender's message links to a file-sharing service. Each reads that one message the same in-the-moment, never-stored way described above. If you are signed out, none of them runs and nothing asks you to sign in. (The free domain-level link double-check under “Link safety checks” also runs on its own when you are signed in — domains only, never your message.)

Link safety checks

To warn you about known-dangerous links, OutlookDog may check the web addresses (URLs) found in a message against Google Web Risk (Google's commercial Safe Browsing database) via our backend. Only the URLs are sent — never the message text, subject, or sender.

When the instant check suspects a scam only because a message's links go somewhere other than the sender's own site, OutlookDog double-checks before showing its strongest warning: it sends the sender's domain (like example.com — never the address or display name), each suspicious link's claimed and actual domain along with that link's visible label (the words the link shows, like "Register here"), and OutlookDog's own reason sentences to our backend AI, which judges whether that pattern looks like a real service the sender's organization would use. Domains, those link labels, and our own sentences only — never the message body, subject, or attachments. If you are signed out, this check simply doesn't run and the message keeps the warning the instant checks earned — the ⚠ Suspicious pill, or the milder ? Questionable note when a verified sender's routine-looking message shows no other warning signs. That milder grade is computed on your own device by the same instant checks; it sends nothing anywhere.

Shared-file safety screen

A common scam hides on a real file-sharing service: an attacker puts a fake sign-in page on their own SharePoint, Google Drive, Dropbox, or DocuSign account and emails you the link. Everything checks out — the mail really is from the service — so the instant checks can't see it. When a message from a first-time sender links to one of these services, OutlookDog screens it before deciding whether to warn you: the message text and the shared link are sent to our backend AI, and our backend fetches the linked page itself — only on those recognized sharing services, only the page the link opens — to look for a password prompt or a redirect away from the service. It warns only if that screen finds a scam; an ordinary share shows no warning. Like every other AI check, this reads the message in the moment and never stores it, and it runs on OutlookDog's backend for everyone (including bring-your-own-key), because a safety verdict must run behind our own hardened checks. If you are signed out, the screen doesn't run.

Feedback

If you tap 👍/👎 on a result, we record the rating and which labels were on screen at the time (for example "Noise" or "Suspicious") so we can improve accuracy — never the message itself. If you send us a free-text note through "Talk to the Dog," we store and email ourselves exactly what you type, so we can reply and improve — please don't paste your message content into it.

Error diagnostics

If the add-in hits an unexpected error, it sends us a diagnostic report so we can fix it: the error message and technical stack trace, the add-in version, the page address, and your account email. These reports are designed to capture what went wrong — not your message content — and go only to our support inbox.

Our website

On outlookdog.com — this website, not the add-in — we count visits so we know which pages people find useful. We use Microsoft's UET tag for this, deliberately configured cookieless: it stores nothing on your device, sets no cookies, and builds no advertising profile of you. We record which page was viewed and which site linked you here — the referring site's name only, never the full address you came from — so we can tell which places are worth our time. We see aggregate counts, not individuals. The add-in itself carries no website analytics of any kind.

Your account

When you sign in with Microsoft, we store your account email address and name to operate your account, enforce free-trial limits, and send you occasional product updates (for example, new features or upgrade options). We never sell it or use it for third-party advertising. You can opt out of product emails anytime by emailing support@outlookdog.com.

Billing

If you subscribe to a paid plan, checkout and payment are handled by Stripe as our merchant of record. Stripe collects your payment and billing details directly — we never see or store your card number. We receive only your subscription status, plan, and a Stripe customer/subscription identifier, which we store to run your account and unlock Pro. See Stripe's privacy policy for how they handle payment data.

Rules you teach it

When you teach OutlookDog a rule — “mail from @invoices.acme.com goes in Read” — that rule is compiled on your device and stored in your own mailbox, in Outlook’s roaming settings. It is not sent to us and it is not stored on our servers. That is why your rules follow you between Outlook on the desktop, the new Outlook, and Outlook on the web without us holding a copy.

Deleting your rules is entirely in your hands. Open the Training page from the top of the pane and remove one, or remove them all. Because we never hold them, there is nothing for us to delete on your behalf — deleting your account does not remove rules from your mailbox, and removing them from your mailbox removes them everywhere.

If you write a rule in plain English, the sentence you typed — together with a short, bounded list of sender addresses from your recent mail, so it can work out who you meant — is sent once to the AI lane you are using, in the moment, to turn it into a rule. It is used for that single request and then discarded. We never store it, never write it to our logs, and it is never used to train a model — the same Azure OpenAI terms described above apply to it, so Microsoft may hold it for up to 30 days for abuse monitoring and no longer. On bring-your-own-key it goes directly to your provider and never touches our systems at all, under whatever terms you agreed with them.

Anonymous usage counts

To see whether features work — how often people finish signing in, how often a taught rule actually fires — the add-in sends us counts only. An event says that something happened and nothing else: no rule text, no sender addresses, no message content, no subject lines, and nothing that identifies you. We store the totals per day; we do not record who sent them.

Data retention & deletion

We keep usage counts and your account email and name while your OutlookDog account is active, to run the service and contact you about it. You can download or permanently delete your data yourself on your account page (Data & privacy) once any active subscription is cancelled — or email support@outlookdog.com and we'll do it for you, including unsubscribing you from product emails. Billing records stay with Stripe as required by tax law.

Rules are the exception, and only because we never have them. Any rules you taught live in your mailbox, not on our servers, so deleting your account leaves them untouched. Remove them yourself from the Training page at the top of the pane — “Remove all” clears every one.

What deletion does. When you delete your data, we erase everything — your name, usage, feedback, and subscription details — from our live systems immediately, with one exception: a one-way hash of your email address and of your Microsoft account identifier. We keep only these hashes — never the address or identifier themselves — so we can tell whether that account has already used a free trial and prevent repeat free trials (a fraud-prevention measure we have a legitimate interest in). It's checked only at sign-up, and never used to contact, market to, or profile you. Ask us and we'll remove it too, once any trial-abuse concern has passed. Any operational email we generated about your account — for example a sign-up or support notification held in our own support mailbox — is removed within 30 days of your deletion request.

Backups. We keep encrypted, access-controlled backups of our account data (never your email content — that is never stored) so we can recover from a failure. Deleted data is removed from live systems right away and then ages out of backups automatically: daily backups are kept for 3 months and monthly archives for up to 3 years, after which they are permanently deleted. Backups are used only for disaster recovery, never to repopulate deleted accounts.

Who's responsible, legal bases & your rights

Data controller: Speraj LLC (OutlookDog). For any privacy request, contact support@outlookdog.com.

Why we're allowed to process your data (legal bases): to provide the service and run your subscription (performance of a contract); for fraud/abuse prevention, security, and product improvement (our legitimate interests); and, where the law requires it, with your consent. The trial-abuse hashes (email + account identifier) are kept under the legitimate interest of enforcing one free trial per person.

Where your data is processed: on Microsoft Azure (hosting, storage, Azure OpenAI, and Azure Communication Services for email), Stripe (payments), and Google (Web Risk link-safety lookups — the links in an email you open are checked against Google's database) — which may process data in the United States and other regions. International transfers rely on those providers' Standard Contractual Clauses and equivalent safeguards. Your email content is never stored. For Business and Enterprise customers, our Data Processing Agreement (DPA) is incorporated into the Terms by reference and applies automatically — you do not need to request or sign it. If you need a countersigned copy for procurement, email us.

How long we keep it: account data (email, name, usage, subscription) while your account is active; on deletion it's removed from live systems immediately and ages out of backups (3-month dailies, 3-year monthly archives). Feedback notes and error diagnostics are kept only as long as we need them to investigate the issue and improve OutlookDog, and you can ask us to delete yours at any time (support@outlookdog.com).

Your rights: you can request access to, correction of, deletion of, or restriction of your data, or a portable copy, and you can object to processing based on legitimate interests — email support@outlookdog.com (you can also self-serve download or delete on your account page). If you're in the EEA or UK, you have the right to lodge a complaint with your local data-protection supervisory authority.

Age: OutlookDog is a workplace/productivity tool intended for adults. It is not directed to children, and you must be at least 16 (or the age of digital consent in your country) to use it.

What we never do

We never sell your data, never store your email content, and never send, forward, delete, or move mail on your behalf. The only change OutlookDog makes to a message you receive is adding or removing one of your Outlook category labels. The single exception is on a reply you open from a draft: unless you turn off the optional “Sent using OutlookDog” setting, a short one-line note is added at the bottom of that reply before you send it, and you can delete it from any reply.

Contact

Questions: support@outlookdog.com.