Data and privacy
What ClickSort keeps on your device, what reaches Vonian, and who else holds anything. Written for a security reviewer as much as a user.
The short version: your mail stays on your device. What reaches us is who you are and what you have paid for. The full policy is the Vonian privacy policy; this page says the same thing in product terms.
We would rather say this precisely than say it impressively. "Nothing leaves your tenant" would be a stronger-sounding claim and it would not be true — the licence check sends identity. Everything below is the honest version.
On your device
| What | What it contains | Kept until |
|---|---|---|
| The trained model | Counts of derived features per folder. Not text, not messages | You reset it, clear site data, or remove it |
| Folder catalogue cache | Folder IDs and names from your own mailbox | Refreshed when older than a day; replaced |
| Preferences | Excluded folders, onboarding state | You reset it |
| Undo records | Message ID, source folder, expiry — in memory only | Minutes; expiry is part of the record |
| Message content while filing | Subject, sender, recipients, attachment flag — in memory only | Discarded as soon as features are derived |
| Free-tier counters | Today's count and date, lifetime total. Integers and dates only | Until stored settings are cleared |
This is your data, on your machine, inside your Microsoft 365 profile. Vonian cannot read it and has no mechanism to.
What reaches Vonian
- Licence identity. Your Microsoft tenant ID and user object ID, so we can confirm an active entitlement. Where an email address is held at all in the licence database, it is a keyed hash, not plaintext.
- Subscription and entitlement records. Plan, status, seats, period end, and Paddle's customer and subscription identifiers.
- Operational logs. Operation type, duration, HTTP status class, client version, host type and a random correlation ID. Their retention is Cloudflare's, up to seven days.
No message content, ever. Not a subject, a body, a recipient, an attachment name, or a folder name — a folder name is message content by another route, so usage counts never name one.
Who else holds something
| Who | What they hold | Why |
|---|---|---|
| Paddle | Your name, billing address, card, tax status and invoices | Paddle is the merchant of record |
| HubSpot | Website enquiries, and the account record: name and email in plaintext | Website and CRM |
| Cloudflare | Hosting and DNS for Vonian's own services, and the licence database | Infrastructure |
| Microsoft | Your mailbox | It is your tenant, not ours |
Because HubSpot holds your address in plaintext as the CRM record, "Vonian does not store your email address" is not a claim we make. The licence database is the system that holds a hash; the CRM is not.
Claims we will not make
We do not claim GDPR compliance on this page, and we will not until the region of the licence database is fixed and the data-processing agreements with our providers are confirmed in writing. When that is done it will be said plainly, with dates.
Your rights, and asking us things
To ask what is held about you, to correct it, or to have it deleted, email support@vonian.net. Deleting your device model does not need us at all — clear the add-in's stored data, or remove the add-in, and it is gone.
See also Training ClickSort on your folders for how the model is built, and Support for how to reach us.