Mail Rail privacy policy
Last updated: 9 October 2026
Mail Rail ("the app") is a Microsoft Teams app that shows your Outlook mailbox inside Microsoft Teams. It is published by Elektraset, s.r.o. ("we", "us"). This policy explains which data the app processes, why, and what choices you have.
Contact: help@elektraset.com · Website: https://elektraset.com/ · App: https://mail-rail.apps.elektraset.com
Summary
- Mail Rail reads, changes and sends email only when you use it, with the delegated Microsoft Graph permissions that you or your administrator approved.
- We do not store the content of your email (bodies, subjects, attachments, contacts) on our servers. Email passes through our server only to be shown to you or sent for you.
- We do not sell data, show ads, or use your data to train AI models.
Data that the app processes
| Data | Why | Stored? |
|---|---|---|
| Email messages, folders, attachments (via Microsoft Graph) | To show, search, flag, move and send email at your request | No. Processed in memory for the request only |
| Your Microsoft Entra user ID, tenant ID and display name | To identify your session and your settings | Yes, encrypted |
| OAuth tokens issued by Microsoft (access and refresh tokens) | To call Microsoft Graph for you, also for notifications | Yes, encrypted at rest (AES-256-GCM) |
| Notification settings, the ID of your Microsoft Graph change subscription, and the IDs of up to 300 recent messages that were already notified | To send optional Teams activity feed notifications for new or flagged mail without duplicates | Yes, encrypted |
| Technical logs (time, error codes) | To run and secure the service | Short-term; logs never contain email content or tokens |
Microsoft permissions
Mail Rail asks for these delegated Microsoft Graph permissions: User.Read (your name and address), Mail.ReadWrite (read and organise your mail, create drafts), Mail.Send (send mail as you), and offline_access (keep you signed in, needed for notifications). The Teams app also asks for the resource-specific permission TeamsActivity.Send.User, which only allows it to post notifications to your own Teams activity feed. Mail Rail does not use application permissions to read any mailbox.
Notifications
If you turn on notifications in Mail Rail settings, the app creates a Microsoft Graph change subscription for your Inbox. When Microsoft tells the app that a message arrived or was flagged, the app reads the sender name and subject of that message and sends a Teams activity feed notification to you. The subject is shown in your activity feed; it is not stored by us. Turning notifications off deletes the subscription.
Sharing
We share data only with the services that are needed to run the app: Microsoft (Microsoft Entra ID, Microsoft Graph, Microsoft Teams) and our hosting provider, which runs the app server for us under a data processing agreement. We do not share data with anyone else unless the law requires it.
Retention and deletion
- Sign-in sessions expire after 30 days. Signing out deletes your session and your cached tokens.
- Notification settings and tokens are kept while you use the app. Email us to delete them; we delete them within 30 days. You can also remove the app's access at any time at https://myapps.microsoft.com (or your administrator can remove it in the Microsoft Entra admin center); the stored tokens then stop working.
Security
All traffic uses HTTPS. Tokens and settings are encrypted at rest. Email HTML is sanitised and displayed in a sandboxed frame, and remote images are blocked by default to stop tracking pixels.
Your rights
Depending on where you live (for example under the EU GDPR), you can ask for access to, correction of, or deletion of your personal data, object to processing, or ask for data portability. Write to help@elektraset.com. You can also complain to your data protection authority. When your organisation provides Mail Rail to you, your organisation is the controller of your mailbox data and we act as its processor.
Children
Mail Rail is a business app and is not meant for children under 16.
Changes
We will post changes on this page and update the date at the top.