11.1 Trust boundary
- Message files and metadata are written with Microsoft Graph to libraries the signed-in user can access.
- There is no vendor mail store. Chronodat does not persist message bodies or files on Mailroom infrastructure.
- Delegated Graph only — Office SSO, with MSAL fallback.
- Licensing PII only — tenant ID, user email, and billing identifiers go to Chronodat and Stripe, not mail content.
- Telemetry is event names only, such as email_saved. No message content.
11.2 Suggestions are not generative AI
Destination scoring runs in the browser from keywords in the current message. There is no Azure OpenAI or Copilot dependency.
11.3 Compliance notes
- Retention labels are written to the saved drive item when you supply a published Purview label name.
- Sensitivity labels inherit from the destination library.
- Privacy: mailroom.chronodat.com/privacy.html. Terms: mailroom.chronodat.com/terms.html.