Last updated: April 2026
When you sign in, we receive your Microsoft account name, email address, tenant ID, and an OAuth access token scoped to the permissions you grant. We store your name, email, and tenant ID in our database to identify your workspace. Directory data (users, devices, licenses, sign-in logs) is retrieved live from the Microsoft Graph API when you view a page and is not warehoused. We do store operational records the Service creates: proposed and executed admin actions (including the target's name and a before/after preview), an audit trail of significant events (action metadata, IP address, user agent, and a short summary of assistant queries), and any scheduled report configuration you set up.
Your data is used solely to operate the Service — authenticating you, routing you to your tenant's data, and (in future) sending scheduled reports you request. We do not sell your data or use it for advertising.
Sessions expire within 8 hours or on sign-out. Account records (name, email, tenant ID) and the operational records described in Section 1 (actions and audit trail) are retained while your account is active. You can request deletion by emailing us.
Unify365 uses Vercel (application hosting), Neon (managed Postgres database), and Microsoft Azure (AI processing). When you use the assistant, your question and the tenant data its tools retrieve to answer it are processed by AI services hosted on Microsoft Azure; this data is not used to train models. Outside of that processing, Microsoft 365 tenant data is not sent to any third party other than Microsoft Graph itself. All services are governed by their own privacy policies.
At install, Unify365 requests read-only delegated Microsoft Graph permissions (users, groups, devices, licenses, security signals, audit logs, reports, sites, teams, and applications). Write permissions are a separate, explicit admin consent granted only if you enable automation — and even then every change is drafted with a dry-run preview and applied only after an administrator types a confirmation. With admin consent, the Service also uses application permissions to read mailbox settings tenant-wide for reports such as the forwarding-rule scan. Actions targeting Global Administrator accounts are refused outright.
You can revoke Unify365's access to your tenant at any time via Microsoft My Apps.
Privacy questions? Email hello@unify365.ai.