Security & privacy
Your mail stays
on your device.
ClickSort works out where a message belongs on the machine you are reading it on. This page explains exactly what that means, and what does reach us — because "nothing leaves your organisation" would not be true, and you would find out.
The short version
We cannot read
your email.
Not as a policy. As a design. There is no path from your mailbox to our servers, so there is nothing for us to look at, hand over or lose.
Ask us anything about this ↗The model that predicts a folder is trained and stored in your browser profile, and it never leaves it.
Subjects, bodies, senders and attachment names are read in memory to work out a suggestion, then discarded. Nothing is written down.
Your Microsoft account and tenant identifiers, and possibly a one-way hash of your email address to match you to your payment. Not the address itself.
Where things go
Follow one
message through.
01 · You select a message
Outlook hands the add-in the subject, conversation and attachment flag for what you have selected. Up to 100 messages at a time, and only what you chose.
02 · Your device works out a suggestion
The add-in turns that message into counts — how often words and senders have gone to each of your folders before. The counts update the model on your device. The words themselves are dropped.
03 · You choose, and Microsoft moves it
The move is made through Microsoft Graph, between two folders in your own mailbox, using permission you granted. The message never travels through us.
04 · We confirm your licence
Separately, ClickSort asks our server whether your seat is current. That request carries who you are, not what you are filing.
Plainly stated
What we hold,
and what we don't.
We never receive
Subject lines. Message bodies. Recipients. Attachments or their names. Your folder names or structure. Your trained model.
We do hold
Your Microsoft tenant and user identifiers, a one-way hash of your email address where it is needed to match a payment, your plan and its expiry, and a record that your licence was checked. Card and billing details sit with Paddle, our payment provider, never with us.
We log carefully
Operational logs record what kind of request ran and how long it took. They are written so they cannot contain an address, a subject, a folder name or a message identifier.
You can remove it
Your trained model is yours. Removing the add-in or clearing its stored data removes the model with it. Export and reset controls are planned before release.
For the person approving it
The questions
IT asks first.
If you are reviewing ClickSort for an organisation rather than for yourself, these are the answers you need, and we would rather give them before you ask.
Request the detail ↗Delegated Mail.ReadWrite, for the signed-in user's own mailbox. Enough to list folders and move a message, and nothing beyond it.
Microsoft identity, through the Outlook host. We never see a password, and we never store an access token.
A web add-in for New Outlook and Outlook on the web. Central deployment from the Microsoft 365 admin centre is the intended path, and we are confirming it before release rather than assuming it.
Per seat, per user, billed through Paddle as merchant of record. A seat is tied to a Microsoft identity in your tenant, so what you pay for and what is deployed are the same list. Planned per-user prices are on the pricing page.
Online archive mailboxes are not supported. Microsoft Graph does not expose them, so ClickSort cannot file into one. An ordinary Archive folder in your main mailbox is fine.
Straight answers
Ask the awkward
questions.
Does any of my email reach an AI service?
No. The classifier is a small statistical model that runs in your browser profile. There is no large language model, no embedding service and no remote inference anywhere in the filing path. Nothing is sent anywhere to produce a suggestion.
So what exactly does leave my organisation?
A licence check: your Microsoft tenant identifier, your user identifier, and the plan you are on. It tells us that a valid seat is in use. It carries nothing about the message you are filing. We would rather say this plainly than claim nothing leaves at all, which would not survive you watching the network traffic.
Where is that information stored?
On infrastructure we run, separately from any mail data — because there is no mail data. We are confirming the exact hosting regions and will publish them here before release rather than describe them vaguely now.
What happens if your service is unavailable?
Filing keeps working. Suggestions are produced on your device and do not depend on us. A licence check that cannot reach us falls back to a cached result for a grace period.
Can our administrator remove it?
Yes. A centrally deployed add-in can be withdrawn centrally, and an administrator can decline the permission request outright. Nothing installs without an approval step in a managed tenant.
Has this been independently reviewed?
Not yet. ClickSort is in development and has not been through an external security assessment or penetration test. We will say so here when that changes, and we will not imply it before then.
Still in development
Nothing here
is live yet.
This page describes how ClickSort is being built, not a service you can buy today. Read the privacy policy for the website processing that occurs now and the service design planned for launch. If your evaluation needs more detail than this page gives, ask us.