Privacy Policy
Effective date: August 9, 2026
This policy explains what TKToTell's desktop application does on your own device, and what the TKToTell purchase and licensing backend processes separately when you buy or manage a license. These are two distinct parts of the product, described separately below.
1. The desktop application, on your device
Outlook data
To detect new mail, TKToTell reads the Subject, Sender Name, Received Time, and Entry ID fields from the Outlook folders you explicitly select for monitoring. It does not read message bodies, attachments, or any folder you have not selected.
Telegram
TKToTell sends a notification (the subject, sender, and a title you configure) to the Telegram Bot API, using the Bot Token and recipient chat ID(s) you provide. This is the only notification destination TKToTell contacts on your behalf.
Locally stored data
Your profiles, selected Outlook folders, notification rules, and provider settings are stored on your own device under %LOCALAPPDATA%\TKToTell\. A profile's Telegram Bot Token is encrypted using the Windows Data Protection API, tied to your Windows user account. If you use the optional Token Vault, it is separately password-protected and encrypted; TKToTell never stores the vault password itself.
Update checks
TKToTell periodically makes an anonymous, unauthenticated network request to this project's own backend to check for a newer version. This request carries no account information, machine identifier, or other identifying data.
2. The purchase and licensing backend
When you purchase or manage a license, TKToTell's backend processes only what is needed to deliver and support that license:
- the email address you provide, to deliver your license and respond to support requests;
- a purchase reference and a machine identifier derived from your device, used to issue and bind your license;
- purchase and license status (such as whether payment was completed and whether a license has been issued);
- a reference to which payment provider processed your purchase;
- operational records needed to support your purchase, such as when a status changed.
The public download page also counts anonymous, aggregate download totals - this counter does not identify individual visitors and is not linked to any purchase or account.
3. Third parties
Depending on how you use TKToTell, the following third parties may process data on your or the backend's behalf, each under its own separate privacy terms: Microsoft/Outlook and Telegram (desktop side, using credentials you provide); PayPal, and, where available, Paddle (payment processing); Cloudflare (hosting and infrastructure for the backend); and Resend (delivery of license and support emails). TKToTell is an independent application and is not affiliated with, endorsed by, or sponsored by any of them.
4. What we don't do
We do not sell personal information, and we do not use advertising trackers or behavioral analytics.
5. Retention
We retain purchase and license records for as long as reasonably needed to support your license, resolve disputes, and meet applicable legal, tax, or accounting obligations - we do not commit to a single fixed retention period beyond that.
6. Security
We take reasonable measures to protect the data described above, but no method of storage or transmission is completely secure, and we cannot guarantee absolute security.
7. Your requests
To ask about, correct, or request deletion of your data, contact abdullah.alghamdi.dev@outlook.com. Some records may need to be retained despite a deletion request where applicable law or a payment provider's own obligations require it.