Privacy Policy

Effective Date: July 4, 2026

This Privacy Policy explains how Margin for Outlook (the "Add-in," "Service," or "we"/"us"/"our") collects, uses, shares, and protects information when you use the Add-in. Margin for Outlook is an Outlook task-pane add-in that lets members of an organization add internal collaborative comments and private notes alongside their email conversations.

Margin for Outlook is operated by Younes Azamiyan, a software developer based in New South Wales, Australia. For the purposes of this policy and of the Privacy Act 1988 (Cth), the operator is the entity responsible for the personal information described below. Because the Add-in runs inside your organization's Microsoft 365 tenant, your organization also acts as a controller of that information.

We have designed the Add-in to access as little of your email as possible and to encrypt the content you create. This policy describes exactly what that means.


1. Introduction

We are committed to protecting your privacy. This policy applies to the Margin for Outlook add-in and its backend service. It does not apply to Microsoft Outlook, Microsoft 365, or any third-party services that you access independently of the Add-in.

By using the Add-in, you agree to the collection and use of information as described in this policy.

2. Information We Collect

We collect only the information needed to provide the Service.

2.1 Identity information (from Microsoft Entra ID)

When you sign in, we receive the following from your Microsoft 365 identity token:

2.2 Email association data (identifiers only)

To attach your comments and notes to the correct email, the Add-in reads a limited set of properties from the currently selected message via Office.js:

Important: We do not store the body of your emails, the recipients of your emails, attachments, or sender/recipient address books. We store only the conversation and item identifiers needed to link your comments and notes to a message.

2.3 Content you create

2.4 Usage and preference data

3. How We Use Your Information

Information Purpose
Entra user ID, tenant ID, display name, email Authenticate you, enforce tenant isolation, attribute comments/notes, and display authorship
Conversation ID / item ID Link your comments and notes to the correct email conversation
Comment and note content Provide the core collaboration and private-notes features
Membership data (emails, roles, hashed codes) Manage who can access shared comments in a mailbox and verify invitations
Feedback and support content Respond to your requests and improve the Service
Preference and usage data Personalize and improve the in-app experience
Operational logs Maintain security, reliability, and troubleshoot issues

We do not use your information for advertising, and we do not sell your personal data.

4. Microsoft Integration

The Add-in operates within the Microsoft 365 ecosystem and relies on Microsoft Entra ID for sign-in.

Your use of Microsoft Outlook and Microsoft 365 is governed by Microsoft's own privacy terms.

5. Data Sharing and Sub-processors

We do not sell your data and we do not share it with advertising networks. We share information only with the service providers necessary to operate the Add-in:

In addition, we may use the following infrastructure and operational sub-processors:

We do not use general-purpose analytics or marketing telemetry (for example, Google Analytics, Mixpanel, or Application Insights).

Data location and overseas disclosure. The information we store is held in Australia: our database is hosted in the Sydney region, and our application backend and encryption-key storage run in the Microsoft Azure Australia East region. The Add-in's static web files — which contain no personal information — are served from a Microsoft Azure region in the United States. Two of our sub-processors, Postmark and Sentry, are operated by providers based in the United States, so the limited information sent to them (email-related data for Postmark; error and diagnostic identifiers for Sentry) is processed overseas. Where information is processed overseas, we take reasonable steps to ensure it is handled consistently with this policy and applicable law, including the Australian Privacy Principles.

We may also disclose information if required to do so by law or valid legal process, or to protect the rights, safety, and security of our users and the Service.

6. Data Retention

To request deletion of your data, contact us at [email protected] (see Section 8).

7. Data Security

We apply technical and organizational measures to protect your information, including:

No method of transmission or storage is completely secure, but we work to protect your information using industry-standard practices.

8. Your Rights

Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you may:

If you are in the European Union or another jurisdiction with equivalent laws (for example, under the GDPR), you may additionally have rights to:

Because the Add-in operates within your organization's Microsoft 365 tenant, your organization (as a controller of that data) may also administer or fulfill some of these rights. To exercise any of these rights, contact us at [email protected], or contact your organization's administrator. We will respond within a reasonable period and in accordance with applicable law.

9. Cookies and Local Storage

The Add-in does not use cookies for authentication. Sign-in tokens are obtained through Office.js and sent in the request authorization header; they are not persisted in cookies.

The Add-in may use the browser's local storage within the task pane to remember user-interface state (such as onboarding progress or dismissed banners). This data stays on your device and is not used for tracking.

10. Children's Privacy

The Add-in is intended for use by organizations and their staff through Microsoft 365 work or school accounts that the organization provisions. It is not directed to children.

We are not involved in the creation of these accounts and do not receive any date-of-birth or age information about users, so we have no means of independently verifying a user's age. Because access to the Add-in is provisioned and approved by your organization's administrators, your organization is responsible for ensuring that the individuals it authorizes to use the Add-in meet the applicable age requirements (see the Eligibility section of our Terms of Service). Consistent with this, we do not knowingly collect personal data from anyone under the age of 16.

If you or your organization believe that a child has provided us with personal data, contact us at [email protected] and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" above and communicate material changes through the Add-in or by other reasonable means. Your continued use of the Add-in after changes take effect constitutes acceptance of the revised policy.

12. Contact Information

For privacy questions or to exercise your rights, contact us at: