Privacy Policy

Effective: August 14, 2026

This Privacy Policy explains how Intune Documentation Generator ("we", "our", or "the Service") handles information when you use the app to generate documentation from Microsoft Intune. We designed the Service to minimize data collection and focus on privacy by default.

Data Controller

The controller responsible for data processing in connection with the Service is:

Ugurlabs UG (haftungsbeschränkt)
Fährstraße 217
40221 Düsseldorf, Germany
Managing Director: Ugur Koc
Email: support@ugurlabs.com

What We Access

  • Authentication via Microsoft OAuth 2.0 (Azure AD). We request read-only Microsoft Graph permissions necessary to list Intune configurations and related assignments.
  • Intune configuration metadata and settings required to render your documentation (policies, profiles, script and remediation resources, assignments, and related details), read-only.
  • For service-usage measurement, we process your tenant ID and user principal name. The monthly-active-user tracker stores SHA-256 hashes of those identifiers, not their raw values.

How We Process Data

  • Our application server uses your delegated access token to retrieve Microsoft Graph responses during the active request. It processes those responses transiently to collect, normalize, and redact them; it does not persist your token or Intune configuration data.
  • Sensitive values, including script bodies, passwords, tokens, pre-shared keys, QR-code payloads, and encoded configuration-file contents, are replaced with [Redacted] before data is displayed in the dashboard or included in an export.
  • PDF and DOCX generation happens in your browser. We do not upload or persist your generated documents.
  • Access tokens are managed in your browser session by MSAL and presented to our application server only for the active Graph collection request; we do not persist them server-side.

Analytics & Cookies

We use privacy-friendly analytics (Plausible) to understand aggregate website usage without cookies or personal identifiers. We also maintain service-level usage counters to understand active organizations and document exports.

  • Plausible Analytics is 100% cookieless and does not track personal data or use browser fingerprinting.
  • Plausible collects aggregated metrics such as page views, referrers, and device types.
  • When the dashboard is opened, our monthly-active-user tracker stores pseudonymous SHA-256 hashes of the user principal name and tenant ID. Operational logs may also contain the tenant ID, a hashed user identifier, the request context, and timestamp.
  • We increment an aggregate export counter when a document is generated. That counter does not contain Intune configuration data or a user identifier.
  • Your consent preference for analytics is stored in localStorage (not a cookie) and remains on your device only.
  • You can change your analytics preference at any time by clearing your browser's local storage or declining via the consent banner.

Data Sharing

We do not sell or share your configuration data with third parties. Data accessed from Microsoft Graph is used solely to generate your documentation.

Security

  • Authentication is handled via Microsoft OAuth 2.0 (Azure AD).
  • Only read-only Graph permissions are requested for Intune data.
  • Sensitive configuration values are redacted before dashboard display or export.
  • We do not persist tenant configuration data; documents are generated on demand in your browser.

Data Retention

We do not retain your Intune configuration data or generated documents. Pseudonymous monthly-active-user records and aggregate export counts are retained for service measurement and administration. Operational logs may exist within hosting-provider systems, but the Service does not intentionally write Microsoft Graph response bodies or access tokens to those logs.

Your Choices

  • You can disconnect at any time by signing out of the app.
  • You can revoke the app's permissions from your Microsoft account/tenant to prevent future access.

Your Rights (GDPR & CCPA)

If you are located in the European Economic Area (EEA), United Kingdom, or California, you may have additional rights under the GDPR or CCPA, including:

  • Right to access: Request a copy of any personal data we process about you.
  • Right to deletion: Request that we delete your personal data.
  • Right to opt-out: Opt out of any data processing that constitutes a sale or sharing of personal information (we do not sell or share personal data).
  • Right to rectification: Request correction of inaccurate personal data.

We do not persist your Intune configuration data, but the pseudonymous usage records described above may be stored. To ask about, access, or delete applicable personal data, contact us at the email below.

Children's Privacy

The Service is intended for professional/enterprise use and is not directed to children.

Changes

We may update this policy to reflect improvements or operational changes. If we make material changes, we will update the effective date above.

Contact

Questions about this policy? Contact us at support@ugurlabs.com or via LinkedIn: @ugurkocde.

You can also reach us by post: Ugurlabs UG (haftungsbeschränkt), Fährstraße 217, 40221 Düsseldorf, Germany.