Information used by the app
The service processes work-account identity, organization and mailbox membership, imported message text, sender and recipient details, subjects, dates, conversation and attachment metadata, user corrections, prompts and requested AI results. Microsoft connection credentials are stored encrypted. Access, usage and security records support operation, troubleshooting and abuse prevention.
Attachments are stored in Microsoft 365. When an authorized person opens an eligible attachment, the app retrieves it through Microsoft Graph and passes it to the browser without retaining a copy in the app. Current classification requests do not include attachment files.
Purpose and access
Authorized information supports email organization, search, conversation review, AI-assisted answers and requested draft suggestions. A person's own work mailbox is limited by app membership; company ownership alone does not grant another person's mailbox access. This does not restrict the customer's Microsoft administrator's independent powers or authorized service operations.
Customer organizations decide which users and mailboxes may participate and must provide any required notices or authority for employee and correspondent information.
Service providers and locations
Microsoft Entra supplies work-account sign-in; Microsoft Graph supplies mailbox access; Ashby uses Azure hosting, PostgreSQL and Key Vault. Azure OpenAI processes selected message content, metadata, business context and user instructions for AI features. The configured model uses an Azure US Data Zone deployment. East US 2 is the application hosting region, not a promise that all processing stays in that region.
Ashby's operator works from China, so authorized support or administrative access may occur there. This must be considered before connecting restricted data. See the provider list. Paddle is the selected merchant of record; live billing has not yet passed acceptance.
Retention, disconnection and requests
Disconnecting a mailbox is separate from deleting information already mirrored into the application. Subscription expiry is not a deletion request. Our approved closure policy stops sync and AI and removes saved mailbox credentials after verified company closure. Customers have 14 days to request an app-data export; live mirrored mailbox content is scheduled for deletion within 30 days, with an earlier verified request supported. Outlook mail stays untouched.
Necessary billing, acceptance and security records are handled separately. Database backups currently have a retention setting of 7 days; this is not immediate backup erasure. Recovery and repeated deletion after recovery still require operational verification. These details remain subject to the completed customer agreement and applicable legal holds.
Email seth@ashbysystems.com for access, correction, disconnection or deletion requests. We need to verify identity and authority; an employee's request may need to be directed to their employer. Applicable rights depend on location and law.
Security and limitations
The application uses tenant and mailbox access controls and encrypted saved Microsoft tokens. No independent security certification or absolute security guarantee is claimed. AI results require human review. Customer mailbox access remains gated while the release checks and service documents are completed.
Optional replies
Replies are not currently released to customers. If enabled later, separate permissions and disclosures will cover Outlook draft creation, user-confirmed sending, reply credentials, review records and send-attempt audit information. Read-only use will remain available without granting reply permission.