Privacy & Security
How we keep your data safe and respect your privacy
Zero Email Storage
Unlike other email applications, Tenzing never stores your email content on our servers. When you use Tenzing, your emails are fetched directly from your email provider (Microsoft 365 or Gmail), processed in memory to apply classifications and generate drafts, and then immediately discarded.
We only store metadata necessary for the application to function: your account settings, classification rules, sender preferences, and learned patterns. Your actual email content never leaves your email provider's servers except temporarily in memory during active use.
Bring Your Own Keys (BYOK)
Tenzing offers a unique BYOK option that lets you use your own OpenAI or Anthropic API keys. This means your email content goes directly from your inbox to your chosen provider—we're just the orchestrator, never the data holder.
With BYOK, you have complete control over your costs and can audit exactly what data is being processed. You maintain a direct relationship with your chosen provider under their terms of service.
How Tenzing Works
1. OAuth Authentication: You sign in with your Microsoft or Google account. We never see your password—we receive an OAuth token that grants limited access to your mailbox.
2. Email Fetching: When you open Tenzing, we fetch your recent emails using the OAuth token. Emails are retrieved directly from your provider's API.
3. Classification: Each email is analyzed to apply relevant tags and determine priority. This happens in real-time, in memory, with results displayed immediately.
4. Learning: When you take actions (archive, label, respond), we note those patterns to improve future classifications. We store the patterns, not the emails themselves.
5. Draft Generation: When you request a draft response, the email content is sent to your configured LLM provider (or our default, if you're not using BYOK) and the response is displayed. Neither the email nor the draft is stored.
What We Store
- Account settings: Your connected accounts, preferences, and configuration
- Classification rules: Custom rules and tags you've created
- Sender preferences: Your per-sender settings and contact notes
- Learned patterns: Aggregated behavioral data (not email content) used to improve classifications
- OAuth tokens: Encrypted tokens that allow us to access your mailbox on your behalf
What We Never Store
- Email content (subject, body, attachments)
- Draft responses or generated content
- Your email password
- Contact lists or address books
Compliance & Standards
- GDPR Compliant: Full data portability, right to erasure, and transparency
- SOC 2 Type II: Annual audits for security, availability, and confidentiality (in progress)
- Data Export: Export all your data at any time in standard formats
- Account Deletion: Delete your account and all associated data instantly
See the Difference
Tenzing
Typical Email Apps
Zero email storage
Emails stored on their servers
Your API keys, your AI
Their API keys, their access
Never used for training
Data used for training
See your actions & rules
Vendor lock-in
What matters to you?
Click on any concern to see how Tenzing addresses it
Have questions about privacy?
We're happy to answer any questions about how we handle your data.
Contact Our Privacy Team