Privacy policy – ChatVault Export
Effective date: 9 October 2026
ChatVault Export ("the app") is a Microsoft Teams app made by Elektraset, s.r.o. ("we", "us"). It lets a signed-in user export their own Microsoft Teams chats to a ZIP file. This policy tells what data the app uses, why, and for how long.
Summary
- The app reads your chats only when you ask for an export, and only with your own delegated Microsoft permission (
Chat.Read). - We do not store message content. The export is built in server memory, kept for at most 15 minutes so that you can download it, and then deleted. It is never written to disk.
- We keep a small audit log (metadata only) so that the admins of your organization can see who exported what scope and when.
- We do not sell data, show ads, or use your data to train AI models.
Data that the app processes
| Data | Source | Why | Kept |
|---|---|---|---|
| Your name, sign-in name (UPN), user id and tenant id | Microsoft Entra ID sign-in | Show who you are, write the export header and the audit log | In memory during your session; user id, UPN and name also in the audit log |
| Your chats, members and messages (text, replies, reactions, attachment names and links) | Microsoft Graph, on your request | Build the export ZIP | In memory only, at most 15 minutes after the export ends, or until you select "Delete now" |
| Access and refresh tokens | Microsoft Entra ID | Call Microsoft Graph for you | In memory only, at most 8 hours; never written to disk |
| Audit entry: export id, time, status, number and ids of chats, date range, whether a keyword was used (not the keyword), formats, message count, ZIP size and SHA-256, download time | The app | Accountability for your organization's admins | Default 365 days; your admin can set 30–3650 days |
| Admin policy settings | Your admin | Apply your organization's export rules | Until your admin changes them or asks us to delete them |
| Technical logs (time, URL path, status code, error code) | The app host | Run and secure the service | Up to 30 days; no message content and no tokens |
The audit log never contains message text, attachments, chat names or keywords.
Where the data is processed
The app runs on servers that Elektraset, s.r.o. operates for its apps. The ZIP goes directly from the app to your browser over HTTPS. Attachments stay in Microsoft OneDrive or SharePoint; the export holds only their names and links, which keep their Microsoft 365 permissions.
Sharing
We do not share your data with third parties. We use Microsoft services (Microsoft Entra ID and Microsoft Graph) to sign you in and read your chats. We may disclose data if the law requires it.
Security
All traffic uses HTTPS. Tokens and exports are held in memory only. Download links contain a random 256-bit token and expire. Admin views need an admin role (Global, Teams or Compliance Administrator, or an admin that your deployment names).
Your rights
You can ask for a copy or the deletion of the audit entries about you, and you can object to processing. Your organization is the controller of its Microsoft 365 data; we process it on its behalf. Write to help@elektraset.com. If you are in the EU/EEA, you can also complain to your data protection authority.
Children
The app is for work and school accounts and is not for children under 16.
Changes
We will post changes on this page and update the effective date.
Contact
Elektraset, s.r.o. – https://elektraset.com/ – help@elektraset.com