Privacy & Security

How we keep your data safe and respect your privacy

Zero Email Storage

Unlike other email applications, Tenzing never stores your email content on our servers. When you use Tenzing, your emails are fetched directly from your email provider (Microsoft 365 or Gmail), processed in memory to apply classifications and generate drafts, and then immediately discarded.

We only store metadata necessary for the application to function: your account settings, classification rules, sender preferences, and learned patterns. Your actual email content never leaves your email provider's servers except temporarily in memory during active use.

Bring Your Own Keys (BYOK)

Tenzing offers a unique BYOK option that lets you use your own OpenAI or Anthropic API keys. This means your email content goes directly from your inbox to your chosen provider—we're just the orchestrator, never the data holder.

With BYOK, you have complete control over your costs and can audit exactly what data is being processed. You maintain a direct relationship with your chosen provider under their terms of service.

How Tenzing Works

1. OAuth Authentication: You sign in with your Microsoft or Google account. We never see your password—we receive an OAuth token that grants limited access to your mailbox.

2. Email Fetching: When you open Tenzing, we fetch your recent emails using the OAuth token. Emails are retrieved directly from your provider's API.

3. Classification: Each email is analyzed to apply relevant tags and determine priority. This happens in real-time, in memory, with results displayed immediately.

4. Learning: When you take actions (archive, label, respond), we note those patterns to improve future classifications. We store the patterns, not the emails themselves.

5. Draft Generation: When you request a draft response, the email content is sent to your configured LLM provider (or our default, if you're not using BYOK) and the response is displayed. Neither the email nor the draft is stored.

What We Store

  • Account settings: Your connected accounts, preferences, and configuration
  • Classification rules: Custom rules and tags you've created
  • Sender preferences: Your per-sender settings and contact notes
  • Learned patterns: Aggregated behavioral data (not email content) used to improve classifications
  • OAuth tokens: Encrypted tokens that allow us to access your mailbox on your behalf

What We Never Store

  • Email content (subject, body, attachments)
  • Draft responses or generated content
  • Your email password
  • Contact lists or address books

Compliance & Standards

  • GDPR Compliant: Full data portability, right to erasure, and transparency
  • SOC 2 Type II: Annual audits for security, availability, and confidentiality (in progress)
  • Data Export: Export all your data at any time in standard formats
  • Account Deletion: Delete your account and all associated data instantly

See the Difference

Tenzing

Internet
System
Action
💨

Typical Email Apps

Internet
System
Stored
🔒

Zero email storage

Emails stored on their servers

Your API keys, your AI

Their API keys, their access

Never used for training

Data used for training

See your actions & rules

Vendor lock-in

What matters to you?

Click on any concern to see how Tenzing addresses it

Have questions about privacy?

We're happy to answer any questions about how we handle your data.

Contact Our Privacy Team