Microsoft API Services Privacy Policy

Last updated: July 24, 2026

Overview

This policy describes how Mesh ("we," "us," or "our") accesses, uses, stores, and shares Microsoft user data when you connect your Microsoft Outlook calendar or mailbox to our platform through Microsoft Graph. This policy supplements our general Privacy Policy.

Mesh accesses Microsoft data only with your consent (or, for a work or school account, your organization administrator's consent), and uses it solely to provide the user-facing features described below. We do not sell your Microsoft data, and we do not use it to train, retrain, or improve generalized artificial intelligence or machine learning models.

1. What Microsoft Data We Access

Depending on which features you enable, we request the following Microsoft Graph delegated permissions (OAuth scopes):

  • Calendar, read-only (Calendars.Read): We read your calendar event details (titles, dates, times, attendees, meeting links, and descriptions) to display upcoming meetings and prepare for them. We cannot create, modify, or delete your calendar events with this scope.
  • Mail, send (Mail.Send): We send a message on your behalf, but only a message you have individually reviewed and approved. The message is sent from your own mailbox and appears in your Sent folder. This is a send-only permission: it does not grant Mesh any ability to read your inbox or your sent mail.

Our Outlook email integration is send-only. We do not request a mail-read or mail-read/write permission, so Mesh cannot read, triage, classify, or scan any message in your mailbox. There is no automated or bulk sending.

2. How We Use Microsoft Data

We use your Microsoft data exclusively for the following purposes:

  • Meeting Scheduling & Preparation: Displaying your upcoming meetings and generating AI-powered meeting prep briefs with relevant client context.
  • Sending Email You Approve: Transmitting a specific message you have reviewed and approved, through your own mailbox. The message is composed from your own Mesh workspace data, not from anything in your mailbox.

We do not use Microsoft data for advertising, market research, training or improving generalized AI or machine learning models, or any purpose unrelated to providing the Mesh service to you.

3. The Draft, Approve, Send Model

Mesh never sends email without your approval. Every message Mesh prepares is first shown to you as a draft that you can read, edit, and either approve or discard. A message is transmitted only when you explicitly approve that specific message, one at a time. No automated process, background job, or workflow can send on your behalf.

4. How We Store Microsoft Data

  • Calendar event data is stored in our secure, encrypted PostgreSQL database with row-level security isolating each organization's data.
  • OAuth tokens (access and refresh tokens) are stored encrypted and are used only to maintain the connection you enabled.
  • Because our email integration is send-only, we do not read or store the contents of your inbox or sent mail.
  • When you send an approved message, we store that message's content (encrypted) and its delivery metadata as part of your business records.
  • We retain Microsoft data only for as long as your connection is active, subject to the regulatory record-retention obligations described in our general Privacy Policy. When you disconnect, we clear the stored OAuth tokens.

5. How We Share Microsoft Data

We do not sell, rent, or share your Microsoft data with third parties, except:

  • AI Processing: When Mesh drafts an email for your approval, the workspace content used to compose it (such as your meeting notes and client records) may be sent to our AI/LLM providers, after automated redaction of sensitive identifiers such as Social Security numbers and account numbers. We do not send the contents of your Microsoft mailbox, because our email integration is send-only. AI/LLM providers do not use this data to train their models.
  • Infrastructure Providers: Our hosting and database providers process data on our behalf under strict contractual obligations and do not have independent access to your data.

Mesh does not use any data received from Microsoft APIs to train, retrain, or improve generalized artificial intelligence or machine learning models. Email content Mesh drafts is generated from your own Mesh workspace data, such as meeting notes and client records.

6. Revoking Access

You can disconnect your Microsoft connection at any time by:

  • Going to Settings in your Mesh dashboard and disconnecting the Microsoft integration. This clears the stored OAuth tokens immediately.
  • Revoking Mesh's access from your Microsoft account. For a personal account, use your app access settings. For a work or school account, your administrator can remove Mesh from the Microsoft Entra admin center.

When you revoke access, we delete your stored Microsoft data and OAuth tokens within 30 days.

7. Contact Us

If you have questions about how we handle your Microsoft data, please contact us:

See also our general Privacy Policy for full details on how Mesh handles all user data.