Follow Me Up — Privacy Policy
Last updated: 2026-07-31
1. Who we are
Follow Me Up ("Follow Me Up", "we", "us", "our") is a software service that works on top of Microsoft Outlook and Microsoft 365. It helps you keep track of the email replies you are waiting for and your own follow-up tasks. It uses artificial intelligence to assess, for each request you send, whether the other party actually answered it, and — when you ask it to — to suggest draft replies and follow-ups in your own writing style.
The service is operated by:
- Legal entity: FollowMeUp
- Registered address: Ølandsgade 1, 2300 København, Denmark
- Privacy contact: support@followmeup.dk
This Privacy Policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights you have. It applies to our website, our web application, and the related background processing of your connected mailbox.
2. Our role: controller and processor
Depending on the data, we act in one of two roles under data protection law:
- Controller. For your account information, billing-related data, usage and diagnostic data, and our website, we decide why and how the data is processed. We are the controller and this Policy governs that processing.
- Processor. When you connect a mailbox, we process the email content and metadata in that mailbox on your behalf (and, where you use the service as part of an organization, on behalf of that organization). In that case the account holder or the organization is the controller, and we act as a processor under a separate Data Processing Agreement (DPA). For business customers, the DPA — not this Policy — governs how we handle mailbox content.
If you are unsure which role applies to a particular activity, contact us and we will explain.
3. Information we collect
3.1 Account information
When you sign in with your Microsoft account (via Microsoft OIDC), we receive basic identity details such as your name, email address, and a stable account identifier. We also store your in-app settings (for example: language, time zone, notification preferences).
3.2 Mailbox content and metadata
With your explicit authorization through Microsoft Graph, we receive delegated access to your mailbox with the Mail.ReadWrite and Mail.Send permissions. They are used as follows:
- Reading: we read messages across your mailbox folders — Inbox, Sent Items and your own folders, plus Deleted Items (so a reply you deleted can still close an open request) — to detect your requests and their replies. We never read Drafts, Junk Email (spam), or the Outbox.
- Writing and sending: used exclusively when you ask for it in the app — to save a suggested reply as a draft in your Outlook, or to send a reply you have approved. The service never creates or sends anything on its own initiative.
From these we derive and store:
- Email metadata — sender, recipients (to/cc), subject, timestamps, conversation/thread identifiers, and the technical mail headers used for threading.
- "Ask" text and reply excerpts — the specific requests we detect in your messages and the relevant portion of any reply.
- An encrypted, time-limited cache of message bodies (cleared automatically after about 90 days), used to display context and run the analysis.
- A writing-style profile — a short, AI-generated description of your writing style (tone, greetings, sentence length, etc.), derived from your own sent emails. The profile describes the style; it does not reproduce the content of your emails.
- Records of replies sent through the service — metadata only (time, message identifiers, status), not the content itself.
- Your own notes, labels and statuses on tracked items.
We do not access your password (authorization is via OAuth tokens), we do not retrieve attachments for analysis, and we do not read folders outside the scope described above.
3.3 Authorization tokens
We store the OAuth access and refresh tokens that let us connect to your mailbox. These are encrypted at rest (with key rotation) and are deleted immediately when you disconnect or request deletion of your account; at the same time we cancel the mailbox notifications with Microsoft.
3.4 Usage and diagnostic data
We record usage events (for example: features used, processing volumes for cost control, and audit/security events) needed to operate, secure, and improve the service. We also store feedback you choose to send in the app (free text), together with technical details such as the page you were on and your browser type.
3.5 Payment information
Payments are handled by Stripe acting as Merchant of Record (see Section 5). We do not collect or store your full card number. We receive limited billing-related information from Stripe, such as subscription status, plan, country, currency, and the last digits / card brand needed to show your subscription.
3.6 Cookies and similar technologies
We use a small number of strictly necessary cookies and storage items: a signed sign-in session cookie (expires after 8 hours) and your saved cookie choice (stored locally in your browser). These are always active.
Ad attribution: If you arrive at our website via a Google ad click, we store the ad click ID (gclid) in a first-party cookie (fmu_gclid, 90 days). If you create an account, the click ID is linked to the account, and if you become a paying customer we report the click ID and timestamp to Google Ads as conversion measurement — without your name or email address (see Section 5).
With your consent, we also use analytics and advertising cookies from Google (Google Analytics and Google Ads) and LinkedIn (Insight Tag) to understand how visitors find and use our website and to measure the effectiveness of our advertising. These are off by default: we ask for your choice through a cookie banner. Google's tags load with consent set to "denied" (Google Consent Mode v2) and do not store or read cookies until you accept; the LinkedIn tag is not loaded at all until you accept. You can change your choice at any time by clearing your browser's site data for our domain.
4. Why we process your data, and our legal bases (GDPR)
| Purpose | Examples | Legal basis (EU/EEA/UK) |
|---|---|---|
| Provide the service | Connect your mailbox, detect requests, match replies, show your list and tasks | Performance of a contract (Art. 6(1)(b)); for mailbox content processed for a business customer, the controller's instructions under the DPA |
| Suggest AI drafts | Generate draft replies and follow-ups in your writing style when you ask for them; build and maintain the writing-style profile | Performance of a contract (Art. 6(1)(b)) |
| Send notifications | Daily digest, reminders, reconnect prompts | Performance of a contract / legitimate interests (Art. 6(1)(f)) |
| Marketing and measurement | Analytics and advertising cookies (only with your consent); conversion measurement of ad clicks | Consent (Art. 6(1)(a)); legitimate interests (Art. 6(1)(f)) for conversion measurement |
| Billing and accounts | Manage your subscription, prevent fraud, keep records | Performance of a contract; legal obligation (Art. 6(1)(c)) |
| Security and reliability | Authentication, audit logging, abuse prevention | Legitimate interests (Art. 6(1)(f)); legal obligation |
| Improve the service | De-identified quality measurement (no email content) | Legitimate interests (Art. 6(1)(f)) |
| Comply with law | Respond to lawful requests, meet retention duties | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to such processing (see Section 10).
5. Service providers and sub-processors
We share data only with the providers needed to run the service. Each is bound by contract to protect the data and to process it only on our instructions.
| Provider | Purpose | Data involved | Location | Safeguards |
|---|---|---|---|---|
| Microsoft (Microsoft Graph / Entra ID) | Sign-in and mailbox access: reading messages and — at your request — creating drafts and sending replies | Identity, email content and metadata | Your Microsoft tenant (EU for EU customers) | Delegated OAuth (Mail.ReadWrite, Mail.Send), used only as described in Section 3.2; no password access |
| OpenAI | AI analysis (detecting requests, assessing replies), writing-style profile and drafts | Individual message text (truncated), subject and addresses, ask text and reply excerpts, and a short thread excerpt; for the writing-style profile, text from your own sent emails. Never attachments, never your whole mailbox at once | USA (OpenAI's API) | Zero-retention and no-training terms — data is not retained by the provider and not used to train models; EU Standard Contractual Clauses (SCCs); technical block against unapproved endpoints |
| Stripe (Stripe Managed Payments) | Payment processing as Merchant of Record | Billing identity, payment method, transaction and tax data | EU/US (Stripe infrastructure) | PCI-DSS compliant; we never receive full card numbers |
| Hosting provider (Euronodes) | Server and database hosting | All data at rest | EU | Sensitive fields (message-body cache, tokens) are application-encrypted; the database is not exposed to the internet; access via SSH keys |
| Resend (email delivery) | Sending service emails (digests, reminders, system notices) | Recipient address and notification content (for example, titles of pending follow-ups) | EU/US | Data processing agreement with EU Standard Contractual Clauses (SCCs); domain authentication (SPF/DKIM/DMARC) |
| Google (Analytics & Ads) | Website analytics and ad measurement — cookies only with your consent; plus conversion measurement of ad clicks (click ID and timestamp, no name/email) | Online identifiers and device/usage data set via cookies after you accept; ad click ID; never your mailbox content | EU/US | Google Consent Mode v2 (off until you accept); EU Standard Contractual Clauses (SCCs) / EU–US Data Privacy Framework; governed by Google's terms |
| LinkedIn (Insight Tag) | Measurement of LinkedIn advertising — only with your consent | Online identifiers and device/usage data set via cookies after you accept; never your mailbox content | EU/US | The tag is only loaded after you consent; EU Standard Contractual Clauses (SCCs) / EU–US Data Privacy Framework |
We keep this list current and will inform customers of material changes to our sub-processors as required under the applicable DPA. A current sub-processor list is available on request.
6. Artificial intelligence and automated processing
The service uses a large language model (provided by OpenAI under zero-retention, no-training terms — see Sections 5 and 7) for four things: detecting requests in your emails, assessing whether replies answer them, summarizing your writing style, and — when you ask for it — generating draft replies and follow-ups.
- Data minimization: the model sees one message at a time (truncated text) together with the specific request text, the relevant reply, and a short excerpt of the thread (the most recent messages) — never your whole mailbox, and never attachments. The writing-style profile is built and maintained automatically from your own sent emails (up to 200 at a time); the result is a short style description — the content of your emails is not stored in the profile.
- No autonomous action: the AI only surfaces suggestions — a proposed status or a draft — for your review. No email is ever sent unless you press send yourself (or choose to save the draft to your Outlook). The AI makes no decision that produces legal or similarly significant effects about you; a human (you) remains in control.
- Defenses against manipulation: the analysis is built fail-closed — uncertain or unverifiable model output is treated as "not answered", and the model's evidence must quote the reply verbatim before a pending request can be proposed as closed.
- Because there is no solely-automated decision-making with legal or similarly significant effect, Article 22 GDPR rights regarding automated decisions are not engaged; nevertheless you can always contact us with questions about how the analysis works.
7. International data transfers
We host the service and database in the EU. The AI analysis means the excerpts of email content described in Sections 5 and 6 are processed by OpenAI in the USA under zero-retention terms. A few other providers (Stripe, Resend, Google, LinkedIn) may also process data in the USA.
Where data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework where applicable, and additional technical measures. You can request more information about the safeguards in place.
8. How long we keep data
| Data | Retention |
|---|---|
| Email metadata and analysis records (asks, matches, statuses) | For the life of your account — until you delete items or delete the account |
| Encrypted message-body cache | Cleared automatically about 90 days after ingestion (metadata is retained) |
| Unmatched inbound replies | Marked expired after about 30 days |
| Authorization (OAuth) tokens | Until you disconnect or request deletion — deleted immediately |
| Writing-style profile | Until account deletion (rebuilt over time from newer sent emails) |
| Account and billing records | For the life of the account, plus legally required retention (bookkeeping rules — in Denmark typically 5 years) |
| De-identified quality records | May be retained — they contain no names, addresses, or email content |
Disconnecting is not deletion. Disconnecting a mailbox stops synchronization and deletes your tokens immediately, but retains your existing data until you explicitly request deletion (see Section 10).
Account deletion has a 14-day grace period. When you request deletion, access is closed immediately: the account is deactivated, our access tokens are deleted, and the mailbox notifications with Microsoft are cancelled. You receive a confirmation email with an undo link. After the grace period, your organization's data is permanently deleted across our systems. Three things are retained after deletion: billing/bookkeeping records (legal obligation, GDPR Art. 17(3)(b)), a minimal tamper-evident audit trail of the deletion itself, and fully de-identified quality records (model verdicts with no names, addresses, or email content).
9. How we protect your data
Security measures we maintain include:
- Encryption at rest for the message-body cache and for authorization tokens (with key rotation).
- Tenant isolation enforced at the database level (row-level security), tested adversarially to prevent one customer's data from being accessible to another.
- Defenses against malicious email content (prompt-injection), including a fail-closed design and verbatim-evidence checks.
- Encryption in transit (HTTPS/TLS), rate limiting, security headers, and tamper-evident audit logging.
- Operational controls such as least-privilege access and secret scanning in our build pipeline.
No system is perfectly secure, but we work to protect your data using measures appropriate to its sensitivity. If a breach affects your personal data, we will act on it promptly and notify the relevant controller and, where required, the affected individuals and supervisory authorities without undue delay (and within 72 hours where applicable).
10. Your rights — EU / EEA / UK (GDPR)
If you are in the EU, EEA, or UK, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with a supervisory authority — in Denmark, Datatilsynet (the Danish Data Protection Agency), or the authority in your country of residence.
To support these rights, the service lets you export your data (a structured JSON download) and delete your account and associated data from within the app. Note that account deletion has a 14-day grace period (Section 8) — if you want to keep a copy of your data, use the export before deleting. You can also contact us at support@followmeup.dk. We will respond within the timeframes required by law (generally one month under the GDPR).
If you use the service through an organization, please direct rights requests to that organization (the controller); we will assist them as their processor.
11. Your rights — California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it;
- Delete personal information we have collected from you, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of "sale" or "sharing" of personal information, and to limit the use of sensitive personal information;
- Non-discrimination for exercising your rights.
We do not "sell" your personal information. If you consent to advertising cookies through our cookie banner, we use Google's and LinkedIn's advertising products to measure our marketing; depending on your jurisdiction, this may be treated as "sharing" for cross-context behavioral advertising. You can decline at any time through the cookie banner, which serves as your opt-out. We use sensitive personal information (such as the contents of your communications) only to provide and secure the service you requested — never for advertising or to infer characteristics about you.
To exercise these rights, use the in-app export/delete tools or contact us at support@followmeup.dk. You may use an authorized agent to submit a request; we may need to verify your identity before acting. We will not discriminate against you for exercising your rights.
12. Children
The service is intended for business and professional use and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (for example, by email or in-app). Continued use of the service after the effective date means you accept the updated Policy.
14. Contact us
- Privacy contact: support@followmeup.dk
- Postal address: FollowMeUp, Ølandsgade 1, 2300 København, Denmark
- EU representative / Data Protection Officer (if appointed): Not applicable — FollowMeUp is established in the EU (Denmark)
- US / California inquiries: support@followmeup.dk
If you have a concern we have not resolved, you may contact your local data protection authority.
15. Geolocation (language selection)
On your first visit we derive your country from your IP address to choose a language (Danish for visitors from Denmark, otherwise English). The lookup happens locally on our own servers against a country database — your IP address is not sent to any third party and is not stored. The derived country (not your IP address) is stored on your account when you sign up and is used for language, currency, and correct tax handling. The country database is provided by DB-IP under the CC BY 4.0 license.