Privacy
Privacy statement
Last updated: September 25, 2026
This statement explains how SafeShell handles personal data when you visit safeshell.ai, contact us, use SafeShell, or connect SafeShell to Microsoft services.
1. Who is responsible
The SafeShell team is responsible for personal data collected through this website and publisher-operated SafeShell services. When an organization deploys SafeShell for its users, that organization may be the data controller for workplace data processed through the product.
2. Data we process
The data processed depends on how you use SafeShell.
- Contact information you submit, including your name, email address, company, subject, and message.
- Microsoft account and tenant identifiers, granted permissions, authentication tokens, and data made available through the Microsoft services you choose to connect.
- Technical and security information such as IP address, request time, requested path, browser information, and error records.
- Product content and metadata that you or your organization choose to process with SafeShell.
3. How we use data
We process personal data only for the following purposes:
- To authenticate users and provide requested SafeShell functionality.
- To connect to Microsoft services using the permissions approved by the user or organization.
- To answer enquiries, provide support, and communicate about the service.
- To maintain security, prevent abuse, diagnose errors, and improve reliability.
- To comply with applicable legal obligations and protect legal rights.
4. Microsoft data
SafeShell accesses Microsoft data only after authorization and only within the permission scopes displayed on Microsoft's consent screen. That data is used to provide the features requested by the user or their organization.
SafeShell does not sell Microsoft user data, use it for advertising, or disclose it for unrelated purposes. Access can be revoked through Microsoft account or organization settings. Disconnecting an integration stops new access and initiates deletion of credentials retained by SafeShell, subject to limited security backups and legal requirements.
5. Legal bases
Where the GDPR or similar law applies, processing is based on performance of a contract or steps requested before a contract, consent for optional integrations, legitimate interests in operating and securing the service, and compliance with legal obligations. Consent may be withdrawn at any time without affecting earlier lawful processing.
6. Sharing and international transfers
Data may be shared with Microsoft, hosting and email providers, technical service providers acting on our instructions, and public authorities when legally required. We do not sell personal data. Where data is transferred internationally, we use safeguards required by applicable law.
7. Retention
Contact messages are normally retained for no longer than 24 months. Security and operational logs are normally retained for no longer than 90 days. Integration credentials are retained while the connection is active and removed after disconnection or withdrawal of access, subject to limited backups. Data may be retained longer when required by law or necessary to resolve a dispute.
8. Security
We use technical and organizational safeguards intended to protect personal data, including encrypted transport, access controls, restricted credentials, and security monitoring. No system can guarantee absolute security.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or obtain a copy of your personal data; object to certain processing; withdraw consent; and complain to a data protection authority. We may need to verify your identity before acting on a request.
10. Children, changes, and contact
SafeShell is intended for professional use and is not directed to children. We may update this statement when our services or legal obligations change. The date above identifies the latest revision. Contact us with privacy questions or requests at the address below.