Operator: Ulaş Çiçek, independent operator of Inlyra · Gaziantep, Türkiye · Contact: privacy@getinlyra.com.
1. Scope
This policy applies to the Inlyra marketing website, private-pilot communications, Microsoft 365 product, billing workflows, support, and security operations.
2. Information we process
Website and pilot information may include a work email address, company name, team and mailbox ranges, the inbox problem described by the requester, consent status, and correspondence. When submitted, the public pilot form sends these details to Inlyra's application service for validation and delivery through Postmark. A request may be held in an encrypted transactional-email queue and limited operational records needed for delivery, duplicate prevention, abuse prevention, and follow-up. If secure submission is temporarily unavailable, the form may instead open the visitor's own email application with the request prepared.
Product information may include Microsoft identity identifiers, tenant and mailbox connection metadata, delegated authorization tokens, mailbox metadata, message content required for released analysis, analysis results, user feedback, billing status, support records, operational audit events, and security logs.
3. Microsoft 365 access
Inlyra uses delegated Microsoft Graph permissions. Initial connection uses openid, profile, offline_access, and Mail.Read. Inlyra does not claim unrestricted access to every mailbox in a Microsoft tenant. Additional permissions are requested only when a released feature requires them and the user consents.
4. Why information is used
Information is used to authenticate users, connect authorized mailboxes, provide priority, reply, follow-up, message-analysis and risk-review workflows, operate subscriptions, respond to support and pilot requests, protect accounts, prevent abuse, maintain reliability, and comply with applicable law.
5. Providers and international processing
Core providers include Microsoft Entra ID and Microsoft Graph, Google Cloud in europe-west1, Postmark for transactional email, and Paddle for checkout, subscription administration, tax and payment records when paid checkout is enabled. These providers may process limited information under their own contractual and security obligations.
6. Retention and deletion
Private-pilot requests and related correspondence are retained only as needed to evaluate the request, communicate with the requester, prevent abuse or duplicates, and document the resulting business relationship. Authorization tokens are deleted when a connection is disconnected. Operational and security records are retained only for service integrity, fraud prevention, dispute handling, and legal obligations. Billing records may be retained for the period required by the payment provider or applicable law. Account deletion requests are assessed against active subscriptions, security investigations, backups, and mandatory retention duties.
7. Sharing
Inlyra does not sell personal data and does not use advertising pixels. Information is shared only with service providers needed to operate Inlyra, professional advisers under confidentiality, or authorities where disclosure is legally required.
8. Security
Inlyra uses scoped access, encrypted secrets, access controls, audit records, staged deployments, backup and recovery controls, and human review for consequential signals. No claim of SOC 2, ISO certification, external audit, or perfect detection is made.
9. Rights and choices
Subject to applicable law, people may request access, correction, deletion, restriction, objection, or portability. Microsoft access can be stopped by disconnecting the mailbox connection. Requests should be sent to privacy@getinlyra.com.
10. Children
Inlyra is a business service and is not directed to children.
11. Changes
Material changes will be posted on this page with a revised effective date. Where appropriate, account users will also receive notice by email or inside the product.