Privacy
What Outlook MCP stores, what it never stores, and how long it keeps it.
Last updated 11 September 2026
Outlook MCP connects a Microsoft 365 mailbox to an AI assistant. To do that it holds credentials on your behalf and records what your assistant did. It does not keep your mail.
The short version
- Message content
- Never stored. Mail, calendar entries, contacts and attachments pass through memory to answer one request and are gone when it ends.
- Access tokens
- Encrypted at rest with a key the database cannot read. Deleted when you disconnect the mailbox.
- Activity log
- Which tool ran, against which mailbox, whether it worked, how long it took. No subjects, recipients or bodies.
- Training
- Your data is never used to train any model, ours or anyone else's.
- Where it lives
- Servers in Germany, operated by Hetzner Online GmbH.
What we collect
From Microsoft, when you connect a mailbox
- Your email address, display name, and Microsoft user and tenant identifiers. The tenant identifier is how we keep one company's data separate from another's.
- An access token and a refresh token, and the list of permissions you granted.
While your assistant works
- The name of each tool that ran, the mailbox it ran against, whether it succeeded, how long it took, and how many calls it made to Microsoft.
- A monthly count of requests, used to apply your plan's limits.
This record exists so you can answer "what did my assistant do?". It carries no message content — not subjects, not recipients, not bodies. An error message returned by Microsoft is kept when a request fails, with credentials removed before it is written.
For billing
Payments are handled by Stripe. We store a Stripe customer identifier, your plan, and its status. We never see or store card numbers.
What we never collect
- Your mail. Messages are fetched from Microsoft, used to answer the request in front of us, and discarded. Nothing is written to disk and nothing is cached between requests.
- Your Microsoft password. Sign-in happens on Microsoft's own pages. We receive a token, never a credential.
- Anything for training. No model is trained, fine-tuned or evaluated on your data, by us or by anyone we use.
How long we keep it
- Access and refresh tokens
- Until you disconnect the mailbox or delete the organisation, then immediately.
- Activity log
- 180 days, then deleted automatically.
- Sent notifications
- 30 days, then deleted automatically.
- Sign-in sessions
- 14 days, or until you sign out.
- Account and billing records
- Until you delete the organisation. Invoices are kept by Stripe for as long as tax law requires.
Who else touches it
We use a small number of processors, each for one job:
- Microsoft
- Your mailbox. The service exists to talk to it.
- Hetzner Online GmbH
- Servers and database, in Germany.
- Stripe
- Payments and invoices.
- Email delivery
- Service notices such as "your mailbox is disconnected". Only the recipient address and the notice itself are shared.
We do not sell data, and we do not share it with advertisers or data brokers. There is nobody else in the chain.
Your rights
If you are covered by the UK GDPR, the EU GDPR or a similar law, you have the right to see what we hold about you, correct it, take a copy, and have it deleted. Most of it you can act on yourself:
- See it. The portal shows your mailboxes, keys, team and activity.
- Delete a mailbox. Disconnecting removes its tokens immediately.
- Delete everything. An owner can delete the organisation from the portal. This removes mailboxes, tokens, keys, activity and members, and cancels any subscription.
For anything else, write to privacy@xogent.ai and we will answer within 30 days.
Where data is processed
Our servers and database are in Germany. Microsoft processes your mailbox wherever your Microsoft 365 tenant is hosted, which is your organisation's choice, not ours. Stripe processes payments in the United States under its own transfer safeguards.
Children
Outlook MCP is a business product and is not directed at anyone under 16.
Changes
If we change how any of this works we will update this page and change the date at the top. For a change that materially reduces your protections, we will email the owners of every affected organisation before it takes effect.