Data Security and Privacy at Toggles

How we protect user data, ensure secure access, and maintain compliance.

Data Security

  • • All data is stored in a secure, enterprise-grade backend-as-a-service platform.
  • • Data is encrypted both at rest and in transit.
  • • Row-level security policies are enabled on all database tables used by production applications to enforce the applicable user and organization access boundaries.

Access Control & Authentication

  • • Toggles does not store or manage user passwords.
  • • Supabase handles authentication through either a passwordless email one-time password (OTP) flow or Microsoft OAuth / OpenID Connect.
  • • Microsoft sign-in is routed through Supabase's Microsoft OAuth connector. Any MFA or administrator-approval requirements configured for the Microsoft account or tenant apply to that sign-in method; Toggles does not separately require MFA for email OTP sign-in.

File Handling & Storage

  • • Private workflow attachments are stored in a shared Supabase bucket with organization-specific object paths and access policies that enforce organization boundaries.
  • • Private attachments use randomized UUID object names and are downloaded through signed URLs that currently expire after 30 seconds.
  • • Images embedded in workflow email content are intentionally stored in a public Supabase bucket so recipients' email clients can retrieve and display them. Anyone with an embedded image's public URL can retrieve it, so sensitive or confidential information should not be placed in these images.

Infrastructure Location & Backups

  • • Toggles uses Amazon Web Services (AWS) for cloud hosting and Supabase for backend database, authentication, and storage services. Both are configured in United States regions for primary customer application, workflow, and file data.
  • • Microsoft Azure is used for the Toggles Microsoft app registration and identity integration, not as the primary application hosting platform.
  • • Analytics, billing, identity, and transactional-email providers may process service data under their own infrastructure, terms, and privacy notices. The US-region statement does not represent that every third-party processing activity occurs exclusively in the United States.
  • • Automated daily backups are maintained by our hosting provider.

Data Retention & Deletion

  • • Canceling a subscription or allowing it to expire does not automatically delete account data or uploaded files.
  • • Uploaded files and other account data are retained until the user submits a verified account-deletion request through support.
  • • After a verified account-deletion request, associated application, workflow, and file data is deleted from production systems. Deleted database data may remain in backups for up to seven days before expiring through the backup cycle.

Permissions & Scope

  • • Toggles runs inside Outlook compose and reply flows. Users remain in control of applying, reviewing, and sending every email.
  • • Through Office.js, the add-in can read and modify the email currently being composed or replied to, including its body, subject, recipients, and attachments. This current-item access is why Microsoft displays a broad mailbox-item capability notice for the add-in.
  • • Toggles uses Microsoft identity permissions for sign-in and basic profile access. It does not request Microsoft Graph Mail.Read or Mail.Read.Shared permissions.
  • • The add-in cannot browse or read arbitrary inbox messages or calendar items.

Data We Don't Collect

  • • We do not passively collect, monitor, or store inbox messages, contacts, calendar items, or private file storage outside content a user intentionally saves into Toggles.
  • • Website analytics do not authorize Toggles to collect Outlook inbox contents, email drafts, recipients, attachments, or workflow content.

Website Analytics & Browser Storage

  • • The Toggles website uses Google Analytics 4 and PostHog to measure page visits, referral and campaign attribution, feature usage, and interactions such as workflow, AppSource, signup, and walkthrough actions.
  • • These services may receive page URLs, referral and campaign parameters, interaction events, browser and device information, IP-derived location information, and identifiers stored in cookies or browser storage.
  • • Toggles also uses session storage to retain initial referral and UTM attribution during a browser session.
  • • PostHog automatic element capture and session recording are disabled. Toggles sends reviewed product and marketing events instead of recording page contents or free-form customer input.

Email Data Handling

  • • During ordinary compose or reply use, Toggles processes the current draft locally within Outlook and does not transmit its body, subject, recipients, attachments, or embedded images to Toggles servers.
  • • When a user explicitly saves a workflow from a draft, the draft's body, subject, recipients, attachments, and embedded images, when present, are transmitted and stored to build the workflow template.
  • • Toggles does not browse arbitrary mailbox items or passively scrape, monitor, or collect email contents.

Admin Controls & Consent

  • • Admins can deploy, restrict, or remove Toggles via AppSource and the Microsoft admin portals.
  • • Users and tenant admins can revoke permissions at any time in the My Apps portal.

Platform Certifications

  • • Toggles does not currently maintain its own SOC 2 or ISO 27001 certification.
  • • Toggles is hosted on third-party cloud infrastructure that maintains industry security and compliance programs.

Administrative Access

  • • Production administrative access is currently limited to Toggles' founder and sole employee.
  • • No other employee or contractor currently has Toggles administrative access to production customer data.

Third-Party Services

  • • Amazon Web Services (AWS) provides cloud hosting infrastructure.
  • • Supabase provides backend authentication, database, and storage services.
  • • Microsoft Azure is used for the Microsoft app registration and identity integration.
  • • Stripe is used for payment processing; no credit card data is stored by Toggles.
  • • Resend is used to send transactional and onboarding emails.
  • • Google Analytics 4 and PostHog are used for website and product-usage analytics as described in the Privacy Policy.
  • • Microsoft may collect usage analytics via the Office.js Outlook integration.

For Administrators

  • • No domain-wide Graph mailbox access required – Toggles operates on a per-user basis and does not request Mail.Read or Mail.Read.Shared.
  • • Limited mailbox use – The add-in is designed for compose and reply workflows. Toggles does not request Microsoft Graph mailbox-read scopes and does not perform ongoing inbox monitoring, scraping, or passive email collection.
  • • Microsoft capability disclosure – Office.js allows Toggles to work with the body, subject, recipients, and attachments of the current compose or reply item. This does not allow Toggles to browse arbitrary inbox messages or calendar items.
  • • Passwordless authentication – Supabase handles both email OTP authentication and Microsoft OAuth/OpenID Connect through its Microsoft connector. Toggles does not store or manage user passwords.
  • • Admin controls – Email OTP provides a non-Microsoft authentication path without a separate Toggles MFA requirement. Microsoft account or tenant MFA and administrator-approval policies apply when a user chooses Microsoft sign-in.
  • • Data residency – AWS and Supabase are configured in United States regions for primary customer application, workflow, and file data. Other service providers may process limited service data under their own infrastructure and terms.
  • • Microsoft AppSource listing – Toggles is available through Microsoft AppSource and can be deployed or restricted through Microsoft admin controls.

For more details, refer to our Privacy Policy and Terms of Service.

If you have any questions or concerns about our security practices, please contact us.

Last Updated: August 15, 2026