ClickSort docs

Data and privacy

What ClickSort keeps on your device, what reaches Vonian, and who else holds anything. Written for a security reviewer as much as a user.

The short version: your mail stays on your device. What reaches us is who you are and what you have paid for. The full policy is the Vonian privacy policy; this page says the same thing in product terms.

We would rather say this precisely than say it impressively. "Nothing leaves your tenant" would be a stronger-sounding claim and it would not be true — the licence check sends identity. Everything below is the honest version.

On your device

WhatWhat it containsKept until
The trained modelCounts of derived features per folder. Not text, not messagesYou reset it, clear site data, or remove it
Folder catalogue cacheFolder IDs and names from your own mailboxRefreshed when older than a day; replaced
PreferencesExcluded folders, onboarding stateYou reset it
Undo recordsMessage ID, source folder, expiry — in memory onlyMinutes; expiry is part of the record
Message content while filingSubject, sender, recipients, attachment flag — in memory onlyDiscarded as soon as features are derived
Free-tier countersToday's count and date, lifetime total. Integers and dates onlyUntil stored settings are cleared

This is your data, on your machine, inside your Microsoft 365 profile. Vonian cannot read it and has no mechanism to.

What reaches Vonian

No message content, ever. Not a subject, a body, a recipient, an attachment name, or a folder name — a folder name is message content by another route, so usage counts never name one.

Who else holds something

WhoWhat they holdWhy
PaddleYour name, billing address, card, tax status and invoicesPaddle is the merchant of record
HubSpotWebsite enquiries, and the account record: name and email in plaintextWebsite and CRM
CloudflareHosting and DNS for Vonian's own services, and the licence databaseInfrastructure
MicrosoftYour mailboxIt is your tenant, not ours

Because HubSpot holds your address in plaintext as the CRM record, "Vonian does not store your email address" is not a claim we make. The licence database is the system that holds a hash; the CRM is not.

Claims we will not make

We do not claim GDPR compliance on this page, and we will not until the region of the licence database is fixed and the data-processing agreements with our providers are confirmed in writing. When that is done it will be said plainly, with dates.

Your rights, and asking us things

To ask what is held about you, to correct it, or to have it deleted, email support@vonian.net. Deleting your device model does not need us at all — clear the add-in's stored data, or remove the add-in, and it is gone.

See also Training ClickSort on your folders for how the model is built, and Support for how to reach us.