The short version: AES sends emails on your behalf using your own Microsoft account. We store only what we need to run your campaigns, we never sell your data, and you can delete everything at any time.
1. Who we are
Automatic Email Scheduler ("AES", "we", "us") is a Microsoft Outlook add-in that helps consulting professionals schedule and send personalized email campaigns directly from their own Microsoft accounts. This Privacy Policy explains how we collect, use, and protect your information when you use AES.
If you have questions, contact us at AEscheduler@outlook.com.
2. What information we collect
Information you provide
- Microsoft account information: When you sign into AES, we receive your Microsoft account ID, email address, and display name via Microsoft's OAuth 2.0 service. We use this to identify your account and authenticate your sessions.
- Client roster: Names, email addresses, phone numbers, company names, and notes you add for your clients.
- Groups: Group names, colors, and which clients belong to each group.
- Email templates: Subject lines, body text, and any attachments or images you save as templates. For templates imported from Outlook Drafts, this includes the HTML content and inline images of those drafts.
- Campaign configuration: Campaign names, schedules, status, and the history of sent emails.
Information collected automatically
- OAuth tokens: When you sign in, Microsoft provides us with an access token and refresh token. We store these securely on our servers so AES can send emails on your behalf at scheduled times — including when you are not actively using the add-in.
- Session data: We create a session ID stored in your browser's localStorage to keep you signed in across sessions.
- Usage logs: Our servers log basic request data (IP address, endpoint, timestamp) for security and debugging purposes. These logs are retained for 30 days.
Payment information
If you upgrade to AES Pro, payment is processed by Stripe. We receive a Stripe customer ID and subscription status, but we never see or store your full credit card number, CVV, or billing address — those go directly to Stripe.
3. How we use your information
- To authenticate you and maintain your session
- To send scheduled emails to your clients on your behalf via the Microsoft Graph API, using your own Outlook account as the sender
- To store and display your roster, groups, templates, and campaigns within the add-in
- To manage your subscription and billing via Stripe
- To detect and fix bugs, and to improve the reliability and performance of AES
We do not use your data for advertising, and we do not share your data with third parties except as described in Section 5.
4. Emails sent on your behalf
AES sends emails using the Microsoft Graph API with your OAuth credentials. This means:
- Emails are sent from your own Microsoft account (your actual email address)
- Sent emails appear in your Sent Items folder in Outlook
- Recipients see your real name and email address, not AES
- AES does not store copies of sent email content beyond what is in your template
5. Data sharing and third parties
We share your data only with the following service providers, and only to the extent necessary to operate AES:
- Microsoft / Azure: Authentication and email sending via the Microsoft Graph API. Microsoft Privacy Statement.
- Stripe: Payment processing for Pro subscriptions. Stripe Privacy Policy.
- Railway: Backend hosting infrastructure where your data is stored. Railway Privacy Policy.
- Netlify: Frontend hosting. Netlify Privacy Policy.
We do not sell, rent, or trade your personal information to any third party for their own marketing or commercial purposes.
6. Data retention and deletion
We retain your data for as long as your account is active. If you stop using AES, your data remains stored unless you request deletion.
To delete your account and all associated data (roster, groups, templates, campaigns, and OAuth tokens), email us at AEscheduler@outlook.com with the subject "Delete my AES account." We will permanently delete your data within 30 days.
You can also revoke AES's access to your Microsoft account at any time via myaccount.microsoft.com/permissions. Revoking access will prevent AES from sending future emails, but will not delete your stored data — send us an email if you want that removed too.
7. Security
We take reasonable technical measures to protect your data:
- All data is transmitted over HTTPS / TLS
- OAuth tokens are stored in an encrypted database and are not exposed in API responses
- Session IDs are random, long tokens with no personally identifiable information
- Daily database backups are retained for 7 days
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at AEscheduler@outlook.com.
8. Children's privacy
AES is intended for business professionals and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top. Continued use of AES after changes constitutes acceptance of the updated policy. We will notify you of material changes by email where possible.
10. Contact
Questions or concerns about this Privacy Policy? We're here to help:
Email: AEscheduler@outlook.com