Privacy Policy
Assurance Map for Microsoft Teams · Effective 24 August 2026
This policy describes how Macon Apps, Investor Direction LLC ("Macon Apps", "we", "us") handles information when you use the Assurance Map application for Microsoft Teams and Microsoft 365 (the "App"), including its Microsoft Marketplace purchase page at am.maconapps.com.
The short version
- The App stores only what your own people type into it, plus the minimum identity information needed to know who typed it.
- It does not read your chats, channels, files, mail, meetings, calendar or
directory. It requests one Microsoft Graph permission:
User.Read, the ordinary sign-in permission. - Evidence of assurance work is stored as a reference or a link, never as a copy of a report or document.
- We do not sell data, do not use advertising or analytics trackers, and do not use your content to train any model.
What we collect
| Data | Where it comes from | Why |
|---|---|---|
| Your Microsoft Entra tenant ID and user object ID; your display name and sign-in name as carried on the sign-in token | The Microsoft Entra single sign-on token Teams provides when you open the App | To identify your organization and you, and to attribute each map, risk, assurance source, activity and snapshot to the person who made it |
| Assurance map content: map names, principal risks and their inherent scores, the assurance sources you name, the activities they perform, their frequency and last-performed dates, line-of-defence classification, and reliance assessments (competence, objectivity, adequacy of evidence) | Typed by your own people | This is the product — the matrix your organization maintains |
| Evidence references: a citation, document reference or link that your people choose to record against an activity | Typed by your own people | To point at where the underlying work lives. The App never fetches or copies the referenced content |
| Point-in-time snapshots of a map's computed analysis | Generated by the App when a user takes a snapshot | So the position reported to an audit committee stays answerable after the underlying rows change |
| Subscription state (plan, seat count, status, billing term) and, for the purchasing account, its email address | Microsoft's SaaS Fulfillment API and Microsoft Graph license information | To know which features your organization and each user are entitled to |
What we do not collect
No content from Teams, Outlook, SharePoint, OneDrive or any other Microsoft 365 service. No copies of audit reports, review findings or other assurance evidence — only the references your people type. No directory listings. No device identifiers, location, or behavioral analytics. The App sets no cookies inside Teams; the purchase page sets one short-lived sign-in session cookie used solely to complete Microsoft sign-in.
How data is stored and protected
- Data is stored in Cloudflare's D1 database and Workers KV services, currently in Cloudflare's North American region, and is encrypted in transit (TLS) and at rest.
- Every request is authenticated with a signature-validated Microsoft Entra token; nothing asserted by the browser is trusted for identity.
- Data is isolated by organization (tenant) and, within an organization, by team.
- Credentials used to talk to Microsoft are held in an encrypted secret store and never sent to the browser.
- Entitlement decisions are cached briefly; the cache is cleared when Microsoft notifies us of a subscription change.
Who can see your data
Members of the team that owns a map can read that map; on paid plans, assurance sources maintained in other teams are aggregated into it by your own configuration. Our staff do not access customer content except where strictly necessary to resolve a support request you have raised, or as required by law. Our sub-processors are Cloudflare, Inc. (hosting, database and cache) and Microsoft Corporation (identity, licensing and commerce). No other third party receives your data.
Retention and deletion
- Maps and snapshots are kept for as long as your organization uses the App, because an answerable history is the point of a snapshot.
- When your subscription ends, your data is retained for 90 days so that a reinstated subscription finds it intact, then deleted.
- You may request deletion of your organization's data, or of an individual's data, at any time using the contact below. We act on verified requests within 30 days.
- Paid plans include a CSV export so that you always hold your own copy.
Your rights
Depending on where you are, you may have rights to access, correct, export, restrict or delete personal data, and to complain to a supervisory authority. Because the App is used within your employer's Microsoft 365 environment, your employer is normally the data controller and we act as its processor; requests are usually best routed through your organization's administrator, but you may also contact us directly.
Changes
We will post any change to this policy at this address and update the effective date above. Material changes will also be noted in the App.
Contact
Macon Apps, Investor Direction LLC · support@maconapps.com