The data Liscaragh Save never touches
An Outlook add-in that saves email and attachments into SharePoint needs permission to read your mail and write to your files. The important question isn't whether it needs permission. It's what happens to your data once you've granted it.
For Liscaragh Save, the answer is simple. Your email and attachments move directly between Microsoft services and your own Microsoft 365 tenant. They are not routed through infrastructure operated by Liscaragh Software.
Designed around delegated access
Liscaragh Save isn't a hosted email processing service. It runs inside Outlook using Microsoft's Office add-in platform.
When you choose to save an email or attachment, the add-in uses Microsoft Graph with an access token issued by Microsoft after you've signed in. The selected content is written directly into the SharePoint or OneDrive location you choose.
The email, attachment and file content travel between Outlook, Microsoft Graph and your Microsoft 365 tenant. They do not pass through servers operated by Liscaragh Software because no Liscaragh service sits in that data path.
The only backend we operate
Liscaragh Save does use a small backend hosted in Microsoft Azure.
Its purpose is limited to licensing and subscription management. It checks whether your Microsoft 365 tenant has a valid trial or subscription and manages billing through Stripe.
That backend is not involved in saving emails or attachments. It doesn't receive the content being saved, and it doesn't act as a relay between Outlook and SharePoint.
What our backend stores
Our backend stores only the information required to manage licensing. This includes:
- Your Microsoft 365 tenant ID
- Licence or trial status
- References to the associated Stripe customer and subscription
It does not store:
- Email content
- Attachments
- SharePoint documents
- Filenames
- Folder paths
- Mailbox data
- Microsoft Graph access tokens
- Microsoft 365 passwords
Microsoft authentication is handled through Microsoft Entra ID. The add-in receives Microsoft-issued access tokens for the signed-in user. Your password is never provided to Liscaragh Save.
Delegated permissions only
A Microsoft 365 administrator grants Microsoft Graph permissions during deployment.
These are delegated permissions, meaning the add-in always acts as the signed-in user. It cannot access information that the user could not already access themselves.
Liscaragh Save has no independent standing access to your tenant. Every operation is performed within the permissions of an authenticated Microsoft 365 user.
Activity logs stay under your control
Every save and undo operation is recorded so users can review what happened.
By default, that activity log is stored only in the browser's local storage on the device where the save occurred. It is not transmitted to Liscaragh Software.
Organisations that want a shared audit trail can configure the log to be written into a SharePoint document library within their own Microsoft 365 tenant.
The log moves from local storage to SharePoint under your control. It still isn't sent to Liscaragh infrastructure.
Why the architecture matters
Many SaaS applications process customer content through vendor-operated infrastructure. That model can be entirely appropriate depending on the service being delivered.
Liscaragh Save takes a different approach.
Because email content isn't routed through our infrastructure, there is no central repository of customer mail or attachments for us to protect, administer or recover.
Our backend exists to manage licensing, not customer content.
Read the full breakdown
Every permission requested, why each one is needed, and exactly what our backend can and cannot see, is set out in full on security and data handling, written to be handed to a security reviewer.
The same principle across our products
The same design philosophy appears throughout Liscaragh Software.
Liscaragh Migrate keeps migration credentials on the Windows device performing the migration rather than in vendor-operated infrastructure.
Liscaragh Save keeps email content and attachments on the direct path between Microsoft services and your own Microsoft 365 tenant.
In both cases, the goal is the same: minimise the amount of customer data and privileged information held outside your own environment.
The question worth asking
Before installing any Microsoft 365 add-in, it's worth asking one straightforward question.
Where does my data go after I click Save?
For Liscaragh Save, the answer is straightforward. It goes directly into your Microsoft 365 tenant, not through ours.