Privacy Policy
How AgentDesk MCP handles your Microsoft 365 data.
Overview
AgentDesk MCP ("the App") is an AI-powered Model Context Protocol (MCP) server developed by Avid Solutions International that manages Microsoft 365 email, calendar, and tasks. This privacy policy explains how the App handles your data.
Data Collection and Use
What We Access
AgentDesk MCP accesses the following Microsoft 365 data through Microsoft Graph API using delegated permissions:
- Email: Message metadata (sender, subject, date), message body, and attachments.
- Calendar: Events, meeting details, attendee information, and availability.
- Tasks: To Do task lists, task details, due dates, and linked resources.
- User Profile: Display name and email address for authentication.
How Data Is Used
All data accessed through Microsoft Graph API is used exclusively to execute the tool operations you request (read, send, schedule, etc.) and to generate AI-powered summaries and drafts via Azure OpenAI when you invoke AI tools.
Data Sent to Azure OpenAI
When you use AI-powered tools, email previews, subjects, and sender information are sent to your configured Azure OpenAI resource for processing. This data is processed under Azure OpenAI's data privacy terms and is not used to train models.
Data Storage
No Server-Side Storage
AgentDesk MCP does not store any of your Microsoft 365 data on external servers. All API calls are made in your user context via delegated permissions.
Token Cache
OAuth access and refresh tokens are cached locally on your machine (at ~/.agentdesk-mcp/token_cache.json) or within your Azure Container App instance. Tokens are encrypted and used solely for authenticating with Microsoft Graph API.
Data Retention and Deletion
- Microsoft 365 data: Not retained. Each API call fetches data in real-time and discards it after processing.
- AI processing: Data sent to Azure OpenAI is processed in real-time and not retained by the AI service beyond the API call.
- Token cache: Deleted when you sign out or remove the
~/.agentdesk-mcp/directory.
Security Controls
- All communication with Microsoft Graph API and Azure OpenAI uses HTTPS/TLS 1.2+.
- OAuth 2.0 device-code flow, so no passwords are handled by the App.
- Delegated permissions only. The App can only access data the signed-in user has access to.
- No admin consent required for standard usage.
- Multi-tenant support. Each user authenticates with their own Microsoft 365 account.
Third-Party Services
- Microsoft Graph API, governed by Microsoft's Privacy Statement.
- Azure OpenAI Service, governed by Azure OpenAI Data Privacy.
Your Rights
- Revoke the App's access at any time via Microsoft Account App Permissions.
- Delete the local token cache to remove all stored credentials.
- Request information about your data by contacting us.
Children's Privacy
AgentDesk MCP is not intended for use by children under 13. We do not knowingly collect data from children.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted to this page with an updated "Last Updated" date.
Contact
For privacy inquiries regarding AgentDesk MCP: info@avidsolutionsintl.com. See our contact page for all support channels.