1. The short version

Tenant Launcher is built to hold as little of your data as possible. We collect just enough account information to run billing and support a paid subscription. We never collect, see, or store your Microsoft passwords, access tokens, or anything from inside your customers' tenants, and we never collect IP addresses. When you sign in, your tenant list (company display names, SharePoint slugs, and optional password-vault links) is synced to our servers so it follows you between machines — nothing more. Microsoft session data, container mappings, and isolated browser profiles never leave your device. On Enterprise team accounts, opening a portal also logs a device label (your computer's name and which browser you used) so the team owner can tell which workstation an action came from — see the table below for exactly what that includes.

2. What we collect

DataCollected?Where it lives
Microsoft passwordsNever—
Microsoft access/refresh tokensNever—
Tenant names, SharePoint slugs & vault linksYesYour browser or device (browser.storage.local in the extension, a local settings file in the desktop app); synced to our servers when you're signed in, so your list follows you between machines
Firefox container mappings / desktop app browser-profile pathsYesYour device only — never transmitted
Account email addressYesOur servers
Password (for your account)Yes, hashedOur auth provider, Supabase
Subscription / plan statusYesOur servers
Portal activity (Enterprise teams only): account email, tenant name, portal type, timestamp, and device label/platformYes, when you open a portal while signed in to a team accountOur servers — visible only to your team's owner/admin in the Team Dashboard activity log
Device label & platform (Enterprise teams only): your computer's name (e.g. its Windows/Mac hostname) plus a general platform string (e.g. "Windows · Edge")Yes, on team accounts, attached to portal activityOur servers — shown to your team's owner/admin so they can tell which device an action came from
IP addressesNever—
Payment card detailsNever directlyOur payment processor, Stripe

Rows marked "your device only" are never transmitted to us. Your Microsoft sessions, cookies, container mappings, and isolated browser profiles stay on your machine; we cannot see inside any customer tenant or observe your browsing. We do not collect IP addresses anywhere in the product, including in the Enterprise activity log.

3. How we use what we do collect

We do not sell your data, and we do not use it for advertising.

4. Third parties we share data with

We use a small number of service providers to operate the Service. Each only receives the minimum data needed to do its job:

We do not share your data with anyone else, except where required by law.

5. Cookies and tracking

This website does not use advertising or cross-site tracking cookies, and we do not currently use any analytics service. If that changes, we will disclose it here first. Neither the browser extension nor the desktop app uses cookies for tracking. The extension uses Firefox's container/cookie-store APIs to keep your customers' admin sessions isolated from each other. The desktop app does the same with per-tenant isolated browser profiles for Chrome and Brave, and with per-tenant isolated in-app sessions for Edge (Edge portals render inside the app itself, in their own sandboxed session, rather than launching your system copy of Edge — this avoids Windows' own account sign-in system from linking a tenant portal to your personal Microsoft account). None of this session or cookie data is ever transmitted to us.

6. Data retention

We retain your account data for as long as your account is active. If you delete your account, we delete your email, synced tenant list, activity records, and billing association within 30 days, except where we're required to retain records for tax or legal purposes. Data stored locally on your device is entirely under your control — uninstalling the extension or the desktop app, unlinking or deleting a tenant, or clearing local storage removes it immediately.

7. Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, contact us at contact@tenantlauncher.com. EU/UK residents also have the right to lodge a complaint with their local data protection authority.

8. Children's privacy

The Service is intended for use by IT professionals and is not directed at children. We do not knowingly collect data from anyone under 16.

9. Security

We rely on our infrastructure providers' security practices (encryption in transit, hashed passwords, access controls) and design the Service to minimize what we hold in the first place — the less we collect, the less there is to protect. No system is perfectly secure, and we can't guarantee absolute security of any data transmitted to us.

10. Changes to this policy

We may update this Privacy Policy from time to time. We'll update the "Last updated" date above and, for material changes, make a reasonable effort to notify active subscribers by email.

11. Contact

Questions about this policy or your data? Contact us at contact@tenantlauncher.com.


This document is a template provided for convenience and does not constitute legal advice. You are responsible for ensuring it accurately describes your actual data practices and complies with the laws that apply to your business and your customers before relying on it.