What Pursor reads
Pursor reads a work mailbox only after its owner personally signs in with Microsoft and consents. The permissions are delegated: they work for that person alone, and disconnecting revokes them. We never hold organisation-wide access to anyone’s mail, and we cannot read a mailbox that has not been individually connected.
What we keep, and what we refuse to keep
Pursor is not an archive of your company’s email. When a message describes a financial commitment, we store the extracted item (who, what, roughly how much, when) with a short excerpt as evidence. When a message does not, we keep only an identifier so we never read it twice: no subject, no text, no sender.
We also hold the account details you give us (names, work email addresses, company name) and billing records. Card numbers go directly to Stripe; we never see them.
How mail is processed
Messages are read by Anthropic’s Claude models under commercial terms that do not permit training on your data. Each call is stateless: one document in, one judgement out. What Pursor learns about your company lives in our own database, where it is yours and deletable, not inside any model.
Who processes data for us
Microsoft (mailbox access and sending, under your own tenant), Anthropic (reading, no training), Neon (database hosting, US), Vercel (application hosting), Stripe (billing). Each receives only what its job requires. We do not sell data, share it for advertising, or move it to anyone else.
Deletion and retention
Disconnecting a mailbox stops all reading immediately. Any person can ask for an item about them to be removed, permanently. One reply does it. When a company leaves Pursor, its data is deleted on request; otherwise we retain it only while the account is active, plus what billing law requires us to keep.
Security
Access tokens are stored encrypted; connections use TLS; each person’s access is scoped to their own sign-in. Details worth a sceptic’s time are on the security page.
Your rights
You can ask what we hold about you, have it corrected, or have it deleted. Email contact@pursor.com and a person answers. If you are in a jurisdiction with statutory data rights (GDPR, CCPA and kin), those rights apply and we honour them.
Changes
If this policy changes materially, connected users are emailed before the change takes effect. The date at the top is the version.