Privacy policy
365Boost browser extension. Last updated 3 October 2026. Version française.
365Boost is a browser extension for Microsoft 365 administrators, published by Clidsys. The short version: it reads what your own admin session can already read, keeps its settings in your browser, and sends nothing to us except a license check once a day.
What the extension reads
- The pages of the Microsoft Entra admin center, the Intune admin center and the Microsoft 365 admin center, when you have them open. This is how it adds buttons, colours and popups to those pages.
- The Microsoft Graph requests those pages already make, to reuse the access token issued to you when you signed in. This is what removes the need for an app registration or a consent screen. Requests are observed, never altered or blocked.
- Directory data returned by Microsoft Graph for the reports you run: users, groups, devices, applications, policies, sign-in logs. Every request is a read (HTTP GET) made with your own session, from your own browser, and the result stays in the tab.
What the extension stores
- Your settings (which features are on, privacy mode, tenant colours, saved filter views) in the browser's extension storage, on your machine.
- Your license key in the same local storage, with the last signed answer of our license service, a random identifier created by the extension for this browser and the date of the last check.
- Nothing is synchronised through a browser account, and nothing is written outside the browser except the files you export yourself.
What the extension sends
To Microsoft: the extension's directory reads go to Microsoft (the admin centers, graph.microsoft.com and the Exchange admin center), the same destinations your browser was already talking to. It has no analytics, no crash reporting and no telemetry. When the extension is uninstalled, the browser opens 365boost.io/goodbye once, with the edition, the version and whether the other edition was installed beside it; that page is counted by Plausible like any other and offers an optional one-click reason. Nothing identifies you in it. The extension adds a 365Boost/<version> product token to the User-Agent of the requests it sends itself to Microsoft Graph, so your organisation can identify that traffic in its own logs; that is a label, not data.
The license check
365Boost checks its license with our license service, license.365boost.io, when the Toolbox or the side panel opens and then at most once a day. A check sends:
- your license key;
- a random identifier created by the extension for this browser (not derived from your device, your account or your browser) and the browser's name (Chrome, Edge or Firefox);
- for a Single Tenant license, and for the default trial (which is one): the Object ID of the admin account you are signed in with, to check that the license covers that account. The ID of its Microsoft Entra tenant goes with it, and the service does not keep it.
For Multi-Tenant and Team licenses, and for a Multi-Tenant trial (asked for several tenants), nothing about your tenant or your account is sent. In every case, no access token, no data read from your tenant and no browsing history ever leaves your browser.
Activating a browser. A Single Tenant license and the default trial are activated with the admin session, with no code: the first admin account that activates a trial takes its seat. Multi-Tenant and Team licenses (and a Multi-Tenant trial (asked for several tenants)) are activated with a 6-digit code sent by email: to the address of the license (Multi-Tenant, trial) or to your work address on your company's domain (Team). Each admin can use the license on 2 browsers; activating a third replaces the oldest one. The license owner receives an email when a browser is activated (Multi-Tenant).
What the service keeps. Your key only as a fingerprint (SHA-256). The offer, status and end date of the subscription, the name and company given at purchase, the email of a Multi-Tenant or trial license (codes are sent there) and the domain of a Team license. For each browser: its random identifier, its name and when it was activated and last checked. Every other identifier (Team admin addresses, the Object IDs of a Single Tenant license or trial, the codes) only as a keyed hash (HMAC-SHA256 with a secret held by the service), which cannot be matched against a list of tenants or addresses without that secret. Next to each Object ID the service keeps its first four and last four characters, so that a seat can be recognised in a support exchange; the rest of the identifier is never written down. Your IP address is never stored: the counters that protect the service use a keyed hash of it and are deleted after an hour. A journal of license events (activations, refusals and their reason, payments, our own changes) is kept for 5 years, with the same keyed hashes, to answer support requests and disputes.
The service runs on Cloudflare. Without an answer from it for 48 hours, the features stop until it answers again; if your network blocks license.365boost.io, ask for it to be allowed.
The purchase of 365Boost
Buying a license happens on 365boost.io, outside the extension. Payment is handled by Stripe (name, email, billing address, VAT number, card details processed by Stripe). To issue and manage your license we keep your email, your company name and the key itself in our records (Stripe and Airtable), for the duration of your subscription and the legal retention period for invoices. The Object IDs of a Single Tenant license are kept only as keyed hashes. The key is sent to you by email through Postmark. None of this is read back by the extension.
This website
365boost.io uses Plausible, a privacy-friendly analytics service with no cookies and no personal identifiers, to count visits. The launch notification form stores the email address you enter, for the single purpose of that notification.
Your rights and contact
Clidsys, France, is the data controller for the purchase and website data above. You can ask what we hold about you, have it corrected or deleted, by writing to hello@365boost.io. For the data the extension handles in your browser, you are in control: uninstalling the extension removes its storage.
Changes
If this policy changes in a way that matters, the date at the top changes with it and the extension's store listing points here.