Privacy Policy
Last updated: October 9, 2026
1. Information We Collect
When you use TenantIQ, we collect:
- Your Microsoft 365 account email and profile information via OAuth
- Microsoft 365 tenant data accessed through the Microsoft Graph API (users, license assignments, user activity, subscription details, security posture, alerts and Intune device compliance)
- Azure cost data from Azure Resource Manager, where you grant TenantIQ the Cost Management Reader role
- Questions you ask the AI Assistant
- Usage data about how you interact with the Service
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Display license analytics and cost insights within your dashboard
- Answer your questions in the AI Assistant using your organization's data
- Send billing alerts and operational notifications
- Respond to support requests
3. Data Storage
Your tenant data is stored securely in our database (Supabase/PostgreSQL) with row-level security. Each tenant's data is strictly isolated and inaccessible to other tenants.
4. Data Sharing and Subprocessors
We do not sell, trade, or rent your personal or organizational data to third parties. We use the following service providers (subprocessors) solely to operate the Service:
- Microsoft (Entra ID, Microsoft Graph, Azure) — sign-in, reading your Microsoft 365 and Azure data, and hosting the AI Assistant model (Azure OpenAI)
- Vercel — application hosting
- Supabase — database hosting for your synced tenant data
- Resend — sending notification and digest emails
- Lemon Squeezy — payment processing and subscription billing (merchant of record)
5. AI Assistant
The AI Assistant (Enterprise plan) answers questions about your organization's data. When you ask a question, your question and the parts of your tenant data needed to answer it (for example license counts, user names and email addresses, or security findings) are sent to a large language model hosted in Microsoft Azure OpenAI within our Microsoft Azure subscription, using a global deployment that may process data in any Azure region.
- Under Microsoft's Azure OpenAI terms, your prompts and the model's answers are not used to train Microsoft or OpenAI models. Microsoft may retain them for a limited period for abuse monitoring, as described in Microsoft's Azure OpenAI data, privacy and security documentation.
- TenantIQ does not store your AI conversations on its servers. A conversation is kept only in your browser for the current tab and is deleted when you sign out, start a new chat or close the tab. Our server logs record usage metrics (such as token counts), not the content of your questions or answers.
- The AI Assistant only reads your own organization's data and cannot make changes to your Microsoft 365 or Azure environment.
6. Microsoft Graph API Access
TenantIQ accesses your Microsoft 365 tenant data using app-only permissions granted during admin consent. We only request the minimum permissions necessary to provide the Service. You can revoke access at any time through the Azure Portal.
7. Data Retention
We retain your data for as long as your account is active. Upon account deletion or cancellation, your data is deleted within 30 days. AI Assistant conversations are not retained by TenantIQ (see section 5).
8. Security
We implement industry-standard security measures including encrypted connections (HTTPS), row-level security in our database, and scoped API tokens. However, no method of transmission over the internet is 100% secure.
9. Your Rights
You have the right to access, correct, or delete your personal data. To exercise these rights, contact us at support@tenantiq.tech or info@tenantiq.tech.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or a notice within the Service.
11. Contact
For privacy-related questions, contact us at info@tenantiq.tech.