// Legal
Privacy Policy
How Prelude collects, uses, stores, and deletes personal data, and the rights you have over it. This policy reflects how the product actually behaves — see Trust & Privacy for the engineering detail behind each claim.
Last updated: 28 June 2026
Prelude is currently operated as a sole trader pending incorporation. Once the operating company is registered, its legal name, company number, and registered address will be added here.
Who we are
Prelude (“Prelude”, “we”, “us”) is an AI copilot for solutions engineers, currently operated as a sole trader pending incorporation. For any privacy question, or to exercise the rights below, contact finnlawfordmee@gmail.com. We are the “controller” of the account data we hold about you, and a “processor” of the customer content you put into the product (for which a Data Processing Agreement governs our handling).
What we collect
- Account data — your name, email, and authentication identifiers, handled by our auth provider (Clerk).
- Billing data — subscription status and the customer/identifier tokens needed to bill you. Card details are handled by Stripe; we never see or store full card numbers.
- Content you submit — transcripts, artifacts, Vault items, writing samples, and (if you connect them) context pulled from Gmail, Calendar, HubSpot, Salesforce, Granola, Zoom, or Slack. This may contain personal data about third parties (e.g. people on your calls).
- Operational metadata — identifiers, durations, token counts, and sanitized error messages. We log metadata only; transcript or artifact content is never written to logs, analytics, or URLs.
How we use it
We use your data only to provide the product: to authenticate you, generate and review your artifacts, maintain your Answer Vault, bill your subscription, and keep the service secure and reliable. We do not sell your data, and your content is never used to train AI models — ours or our providers’.
Redaction before processing
For pasted and uploaded transcripts, PII redaction runs in your browser before anything is sent. For connected sources (Gmail, Calendar), content is redacted server-side before it is stored or processed. Either way, the content sent to our AI processors is post-redaction. CRM structured fields (deal names, contact emails/domains) are treated as metadata — never logged, never sent to an AI model.
Who we share it with (subprocessors)
We share data only with the subprocessors needed to run the product, each bound by no-training and zero/short-retention terms:
- Anthropic — AI generation and review (receives post-redaction transcript content; no training on inputs).
- Scaleway — Vault embeddings on an EU-sovereign endpoint, only when the Answer Vault is enabled.
- Neon — Postgres database hosting (eu-west-2, London).
- Vercel — application hosting.
- Clerk — authentication and identity.
- Stripe — subscription billing (card details are handled by Stripe; we never see or store full card numbers).
- Resend — transactional email; receives your email address to send account, billing, and job-status notices. No marketing.
- Sentry — error monitoring; receives error and metadata only (ids, codes, route patterns) — never transcript, artifact, or other content.
Optional, and only if you choose to connect them — data then flows between Prelude and your own account at that provider:
- HubSpot, Salesforce — CRM sync and pushing artifacts back to a deal/record.
- Google (Gmail + Calendar) — reading a prospect’s email/calendar to ground prep (read-only; redacted server-side before storage).
- Granola, Zoom — importing meeting transcripts as deal calls.
- Slack — delivering artifact-ready notifications and shared artifacts to a channel you choose.
Adding any new third party that receives your content is treated as a security review, not a routine change. The current list is maintained on the Trust & Privacy page.
Where your data lives
Your data is stored in the UK/EU. Our database is pinned to the eu-west-2 (London) region, fixed at creation. Some subprocessors may process data outside the UK/EU under appropriate safeguards (e.g. Standard Contractual Clauses); these are listed in the DPA.
How long we keep it
We keep your content for as long as your account is active. When you delete your account, your data is hard-deleted — deleting your user record cascades through every deal, call, artifact, version, Vault item, embedding, and questionnaire you own. There are no soft-delete flags. It is immediate and irreversible, and you can do it yourself from your Account page.
Your rights
Subject to applicable law (including UK/EU GDPR), you have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can export and delete your own data from the product directly; for anything else, contact finnlawfordmee@gmail.com. You also have the right to lodge a complaint with your local data-protection authority (in the UK, the ICO).
Changes to this policy
We’ll update this page when our practices change and revise the “last updated” date above. Material changes will be communicated through the product or by email.