Legal
Privacy Policy
Last updated: October 4, 2026
This page describes the service as of its Last updated date. Preamble changes over time, and we update this page when what it describes changes.
The short version
Preamble is a workspace where a company's people use AI with the company's own models and connected tools. A company creates a workspace, and each person in it signs in as themselves.
- Your conversations are private to the person who started them. Other members, including workspace owners and admins, cannot open them.
- Connected tools use each person's own account and permissions. There is no shared account behind them.
- Preamble's executive reports do not show activity figures for fewer than five active people in a role or team, for any reader. A team summary shown to a manager withholds them too; workspace owners and admins can see their team summaries in full.
- The services that help us run Preamble are listed under Subprocessors.
Preamble, Inc. runs the service and decides how the data described here is handled. Where a company runs a workspace, that company decides who joins it and which models and tools its people can use.
What we collect
Account details
When you sign in we receive your name, work email address and a user identifier from our identity service. We also keep your workspace, your role in it (owner, admin or member), your job title if you choose one, and your team memberships. Sign-in works with an emailed code or link, with Google, or with your company's single sign-on.
Workspace content
This is what you and your colleagues put into Preamble: the messages in your conversations, the answers the model writes, files you attach, files the assistant generates for you, feedback you leave on answers, and the skills, kits and agents your workspace builds. Conversations, workspace data and audit records are stored in a PlanetScale-hosted Postgres database. Attached and generated files are stored in cloud object storage.
Connector data
When you connect a tool such as Google Workspace, Asana, Microsoft Teams or Zapier, Preamble asks that tool for what a request needs and sends it to the model to answer you. We store the connection itself, not a copy of your mail, documents or tasks, apart from what appears in your conversations.
Usage and administration records
We record how much each conversation used (for example tokens and cost) so a workspace can see its usage. Changes to a workspace's governed settings, such as publishing a skill, registering a tool or changing a role, are written to the workspace's audit log with who made the change and when.
Technical records
Our servers write a log line for each request: the time, the page or API route, the result, how long it took, and identifiers for the request, workspace and user, including the user's email address. Our web pages also record clicks, page changes and errors from your browser so we can find and fix problems. These records do not include the query string of the page you are on, where sign-in codes and invitation tokens travel.
Cookies and browser storage
We use a session cookie that keeps you signed in. It is HTTP-only and set only for Preamble's own host. A few short-lived cookies carry a sign-in in progress. Your browser also stores your light or dark theme choice and a random identifier, kept in your browser's local storage and reused on later visits until you clear it, that ties together the technical records from that browser. We do not use advertising cookies. This page loads no monitoring script.
How we use it
- To run the workspace: sign you in, answer your requests, run connectors on your behalf and keep your conversations and files for you.
- To let a workspace govern its AI use: roles, approved models and tools, guardrails, validation checks and the audit log.
- To send the emails the service needs, such as sign-in codes and invitations.
- To keep the service secure, find faults and measure how it is used.
Who can see what
- Conversations are private to the person who started them. Another member who asks for one gets the same answer as for a conversation that does not exist, whatever their role.
- Workspace owners and admins manage people, connectors, models and kits, and can read the workspace's audit log. That does not include reading other people's conversations.
- Group figures in executive reports (activity by role or team) are withheld, for every reader, when fewer than five people in the group were active. A withheld row says so and keeps only its name and head count. A team summary shown to a manager is withheld on the same rule, but workspace owners and admins can see their team summaries in full, including for groups smaller than five.
- Improvement suggestions drafted from feedback and failed checks are shown to admins as counts. The text of colleagues' conversations is not shown to them.
- Preamble staff who operate the service can reach the production service and its logs.
Connected tools and AI models
Connectors are read-first. A tool can read what your own account can read. A small set of write actions, such as creating a Google Doc or uploading a generated file to Drive, runs in a conversation only when you ask for it in your own words. A workspace admin can also run one of these actions directly from the connector tool browser, with their own connected account. Other changes, such as sending mail, are refused. Each person connects their own account, and a connector an admin turns off stops working for everyone in the workspace.
To answer you, Preamble sends the conversation, the files you attach and any connector results the request needs to the model your workspace has chosen. Workspace admins add the provider keys, so the model providers a workspace uses, and any model endpoint it adds itself, are that workspace's choice. A provider handles what it receives under its own terms.
Assistants may run code in an isolated sandbox to produce files. The sandbox has no outbound network access.
Subprocessors
These services process data for us in order to run Preamble. This is the one place we name them, because they are parts of how the service is built, not the product you use.
- WorkOS, identity. Handles sign-in, single sign-on, directory sync and the organization and membership records behind a workspace. Receives your name, email address and sign-in details.
- Composio, connector runtime. Holds the connection between your account and Google Workspace, Asana or Microsoft Teams and carries out tool calls. Receives the requests a connector makes for you and their results.
- Postmark, transactional email. Delivers sign-in codes, sign-in links and invitations. Receives the recipient's email address and the message.
- Better Stack, logging and browser monitoring. Receives the technical records described above, including user and workspace identifiers and email addresses.
- Google Cloud, cloud hosting. Runs the Preamble application and stores its container images and the files you attach and the assistant generates.
- PlanetScale, database hosting. Hosts the Postgres database that stores your conversations, workspace data and audit records.
- Model providers chosen by the workspace. Today Preamble can call Anthropic, OpenAI and Google models, and OpenAI-compatible endpoints that a workspace's admins add. Each receives the conversation content sent for a request to a model of its own.
- Slack, only for a workspace that connects it. Receives the messages and replies exchanged in Slack with Preamble.
We will update this list when it changes.
Security
Each workspace's data is separated by workspace, and every request is checked against the signed-in person's workspace and role. Model provider keys, sign-in codes and the identity tokens behind a session are encrypted at rest. Pages and the API are served over HTTPS. Sign-in is rate limited. No system is perfectly secure, and we cannot promise that nothing will go wrong.
Keeping and deleting data
Preamble does not delete conversations or files on a schedule. When the person who started a conversation deletes it, it is hidden from them at once, but Preamble keeps it, with its files, and still counts it in the workspace's usage figures. Preamble does not yet remove deleted conversations for good. Sign-in codes, invitations and sessions expire. Preamble cannot yet remove or suspend an active member from inside the product: a workspace owner or admin can change a person's role and revoke an invitation that has not been accepted, and a person's access ends when your company's identity provider or directory removes or holds them. To ask us about a copy of your data or about removing it, write to dionny@trypreamble.com and say which workspace you mean. Data held by a model provider or connected tool is kept under that provider's own terms.
Changes and contact
When this policy changes we change the Last updated date above. Questions about it, or about your data, go to dionny@trypreamble.com. The Terms of Service cover the rest of how the service may be used.