The protection of your personal information is our priority. We want you to feel safe while using our Shared Email Templates for Microsoft Outlook ("Shared Email Templates" or "SET"). However, Shared Email Templates would not work if we didn't collect certain data. On this page, you can find detailed information on what data we collect, how we protect it, and where we store it.
When you create an account, you provide your first and last name, username, email address, and password. We collect this information so that you can sign in to your account.
While creating a template for email messages, appointments, signatures, and mail merge, you enter its name, description, and the template itself. All this information is saved so that you can use your templates.
We save the names of your teams, descriptions, members, their email addresses, and teammates permissions.
We use cookies and/or similar technologies to operate the core functions of Shared Email Templates. You can find more information in Privacy Policy (https://www.ablebits.com/docs/outlook-shared-templates-privacy-policy/#annex-one).
We save the date and time when you last started the add-in to identify accounts that are inactive, inform users who have inactive accounts, and delete such accounts.
When you contact our customer support service, we keep all your email and chat messages.
Your use of our products does not give us access to any sensitive personal data stored in your Microsoft account such as physical address or credit card details.
Depending on the Shared Email Templates feature you're going to use for the first time, you'll get the corresponding permissions request like the one in the screenshot below:
We use each of the permissions granted by you for a specific purpose. Please see detailed descriptions of required permissions in Privacy Policy (https://www.ablebits.com/docs/outlook-shared-templates-privacy-policy/#annex-two).
Follow instructions available on the Microsoft Support website on the Edit or revoke application permissions in the My Apps portal help page.
All your templates are stored in an encrypted cloud-based database hosted by Amazon Web Services. This is a protected storage inside an isolated private network. All data can only be accessed through the template sharing service, the core back-end service of Shared Email Templates.
When you create an encrypted team, you add one more layer of encryption. In this case, all templates are encrypted with the AES symmetric-key algorithm before being saved to the cloud database. Please note, you are the only person who knows the Team Password and passes the password to your teammates in a safe way.
Also, SET stores local copies of your templates (the local templates cache) in the following locations on your devices:
The local templates cache is isolated and not accessible by other browser extensions or Outlook add-ins. We store the local templates cache unencrypted because of the performance reasons. Otherwise we would have to decrypt templates each time you start Shared Email Templates, which would dramatically increase its startup time.
The local templates cache is refreshed with each change in templates, e.g. if your teammate creates a new template, the new template goes to the cache.
Shared Email Templates is designed and built taking care of your privacy and security; it is architected and developed following the zero-trust and privacy-by-design principles. The diagram below explains how Shared Email Templates works for the main use case—inserting a template into the email message you are writing. Your mail, attachments, images, and other Outlook or cloud-based data stay on your device and on your cloud storage. No data is sent to Shared Email Templates services or any 3rd-party service, and all actions and transformations are done locally, in your Outlook.
We do not collect any payment information, such as bank account details, credit card information, and check information.
You might find that Microsoft Office telemetry is run together with the Shared Email Templates app and add-in. This is because we use Microsoft's office.js framework.
We develop and test our products on specially created testing configurations, so access to your personal data is very limited and only a few people at our office have permissions.
However, no one has permissions to access your templates and passwords, including your personal password and Team Passwords.
Read-only access (provided on request only) is given to a few of our core engineers and only in case they need to figure out some complex technical thing.
Read-only access is provided to our senior system administrator to perform online monitoring and periodic maintenance of our servers and services.
Read-only access to your data is also given to our customer support service and sales specialists. They need your personal data to assist you when you contact us with related questions.
We make a lot of effort to keep your data safe. Firstly, we restrict physical access to our office and to our computers with door locking, access control systems, alarm system, and surveillance facilities. Secondly, we restrict access to our systems by using central management of system access, no guest accounts policy, password and authentication policies.
Also, we control access to data with the help of differentiated access rights, access rights defined according to duties, measures to prevent the use of automated data-processing systems by unauthorized persons.
To prevent unauthorized access, data alteration and disclosure, all our communication channels are encrypted using virtual private networks for remote access, transport and communication of data. All our sub-networks are joined into a wholly-owned private network. Finally, all our computers are protected with antivirus software and firewall systems.
You can find detailed information on our technical and organizational security measures in our Data Processing Agreement at https://www.ablebits.com/docs/outlook-shared-templates-dpa/#annex-two.
To remove your data, simply delete all the teams where you are the administrator, and then delete your account in the Profile section. To have all your communications with us removed from our systems, please contact our customer support service.
You can see all the information that is sent to our services and storages with your own eyes with the help of the Fiddler tool or your browser console. Also, you can inspect our client-side source code directly in your web browser.
Graph Permission | Permission Type | Justification | Azure AD App ID |
---|---|---|---|
openid | delegated | Required by Azure AD authorization flow. To sign users in and ensure their consent to using the Shared Email Templates app. | c1e89043-a87e-4168-9620-996b6174f9ce |
profile | delegated | To read basic user information. | c1e89043-a87e-4168-9620-996b6174f9ce |
offline_access | delegated | To refresh access token, when the active one is expired. | c1e89043-a87e-4168-9620-996b6174f9ce |
User.Read | delegated | To read the profile of signed-in users. Also allows the Shared Email Templates app to read basic company information of signed-in users. | c1e89043-a87e-4168-9620-996b6174f9ce |
User.ReadBasic.All | delegated | To read a basic set of profile properties of other users in the organization on behalf of the signed-in user. | c1e89043-a87e-4168-9620-996b6174f9ce |
Graph Permission | Permission Type | Justification | Azure AD App ID |
---|---|---|---|
openid | delegated | Required by Azure AD authorization flow. To sign users in and ensure their consent to using the Shared Email Templates app. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
profile | delegated | To read basic user information. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
User.Read | delegated | To read the profile of signed-in users. Also allows the Shared Email Templates app to read basic company information of signed-in users. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
Files.ReadWrite.All | delegated | To read and upload files to the signed-in user's OneDrive or SharePoint folders. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
Sites.Read.All | delegated | To read site and folder items in all site collections on behalf of the signed-in user. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
Mail.Read | delegated | To read email in user mailboxes. Required for Outlook Draft functionality. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
Mail.Read.Shared | delegated | To read mail that the user can access, including shared mail. Required for Outlook Draft functionality. | c1e89043-a87e-4168-9620-996b6174f9ce or 680093f8-3534-48f1-8dae-3a13343cc03c |
directory.read.all | delegated | Required by Azure AD authorization flow. To read data in groups of the user's organization. | c1e89043-a87e-4168-9620-996b6174f9ce |
Graph Permission | Permission Type | Justification | Azure AD App ID |
---|---|---|---|
openid | delegated | Required by Azure AD authorization flow. To sign users in and ensure their consent to using the Shared Email Templates app. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
profile | delegated | To read basic user information. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
offline_access | delegated | To refresh access token, when the active one is expired. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
User.Read | delegated | To read the profile of signed-in users. Also allows the Shared Email Templates app to read basic company information of signed-in users. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
Files.ReadWrite.All | delegated | To read and upload files to the signed-in user's OneDrive or SharePoint folders. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
Mail.Send | delegated | Allows the Shared Email Templates app to send mail as signed-in users. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
Mail.Send.Shared | delegated | Allows the Shared Email Templates app to send mail as the signed-in user, including sending on behalf of others. | 6e8e4d5c-1979-4b55-a2e8-a7531167af15 |
Responses
Why would this app collect and send information about my emails and calendar items and send them to a third party? Who is the third party? And why are you collecting and sending them my personal information? This seems to fly in the face of everthing you say about protecting privacy.
Hello Janet,
Thank you for your comment. The only third party that can get access to your data is Microsoft itself because our add-in is built on Microsoft Office extensibility technology and your Outlook account should be connected to Microsoft 365, Exchange Online, or Outlook.com. I think we need to clarify this point and update our privacy policy. Thank you once again for sharing your feedback with us.
Hi,
I was wondering the routine for restoreing missing templates? and how is the backup routine on your end? can i be sure my data won't be lost?
Hi Maren,
Thank you for your questions. The Trash folder as well as the Export / Import feature are on our roadmap for upcoming beta releases. As for the backup routine, we use a cloud-based database with its own backup scheme in Amazon Web Services.
Post a comment
Seen by everyone, do not publish license keys and sensitive personal info!