1. Who we are and scope
Topsail is operated by Easy Company Consulting, LLC d/b/a Topsail (“Topsail,” “we,” “our,” or “us”). This statement applies to features that connect Outlook or Microsoft 365 email to Topsail through the Microsoft Graph API. It supplements the Topsail Privacy Policy, which covers our broader products, website, account and billing information, communications, support, and privacy rights.
The Outlook and Microsoft 365 Terms of Service apply to your use of this connection. The current email connection does not request calendar permissions or provide calendar access through this OAuth flow.
2. Microsoft data we process
- Connected account identity and email address, account type, and tenant/user identifiers needed to associate the connection with your Topsail account.
- OAuth access and refresh tokens, granted scopes, expiration information, and connection metadata.
- Email content you compose or direct Topsail to send, recipients, subjects, message and conversation identifiers, and sending status.
- Inbox and junk-folder message metadata and previews used to detect replies and delivery failures, relevant message content, reply snippets, and reply or delivery status.
- Mailbox settings accessed for connected features, and signature HTML supplied or stored for use in outgoing mail.
- Microsoft Graph subscription identifiers, expiration information, and synchronization state used to maintain reply detection.
Topsail stores connection credentials, identifiers, workflow metadata, and limited message snippets. We do not ask for or store your Microsoft account password. Mailbox access is not limited by Microsoft to messages authored inside Topsail.
3. How we use Microsoft data
- Authenticate and maintain the connection you authorize, including refreshing tokens.
- Send email and replies you direct Topsail to send and append your configured signature.
- Detect replies and delivery failures and show communication activity and outcomes in your workspace.
- Maintain synchronization, integration health, security, and support for those workflows.
We process this information to provide the Service under customer instructions and agreements and to meet applicable operational and legal requirements. Where applicable, legal bases include contract performance, legitimate interests in operating and securing the Service, consent where required, and legal obligations, as described in the general Privacy Policy.
We do not sell Microsoft mail data or use it for third-party advertising. Optional AI-assisted features and the prohibition on using Customer Data to train general-purpose AI models are described in the general Privacy Policy.
4. Current OAuth permissions
The current Outlook connection requests the following delegated permissions through Microsoft consent:
openid and profile — sign-in and basic identity information.offline_access — refresh the connection while you are offline.Mail.Read — read mail in your mailbox.Mail.ReadWrite — create, read, update, and delete mail in your mailbox; it does not itself allow sending.Mail.Send — send mail as you.MailboxSettings.Read — read mailbox settings.
These permissions grant broader mailbox access than individual Topsail messages. Topsail uses the connection for the features described above, including scanning inbox and junk-folder metadata and previews before identifying relevant replies. Additional permissions will be disclosed and presented through Microsoft consent before you grant access.
5. Sharing and service providers
Microsoft processes mail and account information when Topsail makes authorized Microsoft Graph requests. Google Cloud and Firebase provide hosting, compute, authentication, and storage for Topsail. Authorized users in your customer workspace may see communication activity and outcomes according to their access permissions.
Service providers and authorized personnel may access data as necessary to operate, secure, or support the Service, subject to applicable contractual and access restrictions. Other disclosures, including legally required disclosures and customer-enabled integrations, are described in the general Privacy Policy. See the current Subprocessors page.
6. Storage, security, and international processing
Integration credentials and workflow data are stored in tenant-scoped systems. Data is encrypted in transit and at rest by the underlying cloud infrastructure. Access is controlled through authentication, application permissions, tenant scoping, and operational access restrictions.
Topsail and its service providers may process information in the United States or other countries where they operate. Applicable safeguards for international transfers and broader security practices are described in the general Privacy Policy.
7. Retention and deletion
We retain personal data only as long as reasonably necessary for the purposes described in the general Privacy Policy, customer instructions, contractual requirements, and applicable law.
Following expiration or termination of a subscription, customers have a 30-day period to retrieve or request export of Customer Data. After that period, Topsail may delete Customer Data from active systems under its retention practices. Backups, security and system logs, billing records, and other records may remain longer where reasonably necessary for security, recovery, legal compliance, or other legitimate business purposes. Backup data is deleted as backups rotate or expire.
Disconnecting Outlook does not automatically delete all previously processed workflow data. Deletion requests and retained records follow the general Privacy Policy and applicable customer agreement.
8. Your controls and privacy rights
Connecting Outlook is optional. You can disconnect Outlook in Topsail or revoke Topsail’s permissions through your Microsoft account or your organization’s Microsoft administrator. Revoking permissions stops new authorized Microsoft API access.
You may request access, correction, export, or deletion of personal data and exercise other rights available under applicable law by contacting austin@topsail.app. Rights, request handling, and customer administrator responsibilities are described in the general Privacy Policy.
9. Cookies and usage information
Website cookies, authentication storage, usage information, and analytics choices are described in the Cookie Notice and general Privacy Policy.
10. Mobile and SMS information
Topsail does not sell mobile information or share mobile opt-in information, phone numbers, or text-message consent information with third parties or affiliates for their own marketing or promotional purposes. Processing necessary to provide customer-requested communications, maintain consent and suppression records, prevent abuse, or comply with law is described in the general Privacy Policy.
11. Business use and changes
Topsail is intended for business use. Children’s information and changes to privacy disclosures are addressed in the general Privacy Policy. We may update this statement and will show its latest revision above.
12. Contact
Easy Company Consulting, LLC d/b/a Topsail
1671 NW Albany Avenue, Bend, OR 97703, USA
Email: austin@topsail.app