Preludeum
ProductPricingFAQContactLogin
Start 3-day trial

Privacy policy

How Preludeum handles account, workspace, billing, public-source, AI, draft, cookie, and browser-storage data.

Last updated: August 8, 2026

Controller

The controller is the service provider identified in the Legal Notice. The full legal name, legal form, and postal address stated there form part of this policy by reference.

Privacy requests go to support@preludeum.com. A data protection officer or EU representative is appointed and its contact details are published if legally required; otherwise no separate DPO or representative is designated.

Roles and customer data

For account administration, billing, service security, and direct support, the Preludeum operator acts as controller. When a customer uses the workspace to store campaign instructions, lead-review data, notes, or reply drafts and Preludeum processes that data only on the customer's documented instructions, the customer is generally the controller and Preludeum acts as processor. A data-processing agreement must be in place where required. For public-source retrieval and ranking, service-wide abuse prevention, security, and aggregated product reliability for which Preludeum determines the purposes and means, the operator acts as controller.

Account and security data

Depending on the feature used, Preludeum processes:

  • email address, authentication-provider identifier, account timestamps, password-reset and confirmation state, and session information;
  • identity information returned by any enabled sign-in provider, such as Google, GitHub, or Apple;
  • access-gate, OAuth state, PKCE, session, and security data such as timestamps, IP-derived security information, user agent, device, and browser information where available;
  • support messages and contact details supplied with them.

Raw passwords are handled by the authentication provider and are not stored by Preludeum in its application database.

Workspace data

Workspace data can include campaign names, offer descriptions, buyer profiles, answers, corrections, search settings, source filters, saved or hidden lead states, feedback notes, search-run metadata, CSV exports, reply drafts, and usage records. Do not enter secrets, special-category data, or confidential third-party information unless the selected service and agreement expressly permit it.

Public-source data

When a customer starts a supported search, Preludeum may receive and store public results from Reddit, X, and the configured source-search provider. Fields can include source name, public post or status ID, URL, author handle, display name, author URL, community or handle, title, text, creation time, public engagement metrics, raw provider metadata, search query, matched terms, score, explanation, rule-risk context, rejection reasons, and derived location fields where that feature is enabled.

Public availability does not remove personal-data protection. These records can identify natural persons and are processed for the search and review workflow described here. The data is not collected directly from the author. This policy is also the public notice for that activity; reliance on an exception to individual notice under Article 14(5) GDPR requires a documented assessment and appropriate safeguards.

Drafts and external actions

Preludeum currently stores reply and direct-message drafts for customer review but does not send them. When a customer chooses to act, the browser may copy the reviewed text and open the original Reddit or X surface. Connected-account posting is not currently available. Limited legacy connection metadata, if present from an earlier controlled deployment, remains server-side until it is disconnected or deleted.

AI-assisted features

When an AI-assisted feature is requested, Preludeum may send the offer, buyer-profile fields, customer instructions, selected public-source text and context, author handle, community or handle, and reply constraints to OpenAI through the server-side API integration. AI features may be unavailable when the integration is disabled. AI outputs are decision-support drafts and are returned for human review; they are not used by Preludeum to make decisions that produce legal effects or similarly significant effects about a person. Processing is governed by the active OpenAI API terms and account configuration, including applicable abuse-monitoring and retention controls. Preludeum does not opt customer content into training of a general-purpose model.

Billing and payment

Stripe is used for hosted Checkout, payment collection, subscriptions, invoices, and the customer portal. Stripe collects payment-card details under its own privacy documentation. Preludeum does not store full card numbers or card security codes. It may receive and store Stripe customer, subscription, price, checkout, invoice, payment-method display, plan, trial, billing-period, currency, amount, status, usage, and webhook-event identifiers needed to provide the paid plan, prevent duplicate trials, enforce limits, reconcile payments, and handle billing disputes.

Purposes and legal bases

Preludeum uses personal data only for the following purposes and legal bases where the GDPR applies:

  • create and secure accounts, provide the workspace, run requested searches, save results, generate requested drafts, and open requested source-platform actions: performance of a contract or pre-contractual measures under Article 6(1)(b) GDPR;
  • provide billing, invoices, payment recovery, fraud prevention, accounting, and tax records: contract performance and legal obligation under Article 6(1)(b) and (c) GDPR;
  • search, rank, deduplicate, cache, debug, protect source platforms, prevent abuse, and maintain service reliability: legitimate interests under Article 6(1)(f) GDPR after balancing those interests against the rights and expectations of affected people;
  • respond to support, security, privacy, and abuse reports: contract performance, legitimate interests, or legal obligation as applicable;
  • optional analytics, advertising, or marketing communications: consent where required. The service does not use advertising or non-essential analytics cookies.

Recipients and processors

Depending on the feature, recipients and processors include the operator's authorized personnel, Vercel for hosting/deployment, Supabase for authentication and database infrastructure, Stripe for payment and billing, OpenAI for requested AI features, ScrapeBadger for source search, enabled identity providers and source platforms such as Reddit and X, and the configured email/SMTP provider. Professional advisers, authorities, or other recipients may receive data where legally required or necessary to establish, exercise, or defend legal claims. These providers process data under their applicable DPAs and privacy terms; the provider set may change when features change and this policy will be updated where required.

Reddit and X are source platforms. They process data under their own privacy notices and terms and are not automatically processors of the operator. Customers and their own outreach tools may also be independent controllers.

International transfers

Some enabled providers may process data outside the EEA. Where that happens, the operator relies on an adequacy decision, standard contractual clauses, or another transfer mechanism permitted by the GDPR and applies supplementary measures where required. The applicable provider DPA and privacy terms describe the transfer safeguards for the relevant service.

Cookies and browser storage

Preludeum uses server cookies needed for authentication, OAuth state and PKCE, an optional private-preview access gate, and active-campaign selection. The authenticated app also uses browser storage for theme and sidebar preferences, user-bound campaign/dashboard/search caches, sync cooldowns, and campaign-analytics caches. Reply drafts are stored server-side. Cached data can still contain limited personal or customer data. These items are not used for advertising.

Where the TDDDG applies, storage that is strictly necessary to provide a service explicitly requested by the user may be used without separate consent under Section 25(2) no. 2 TDDDG. Preference storage is used to remember choices requested by the user. If analytics, advertising, retargeting, or other non-essential storage is introduced, Preludeum will provide the required information and obtain consent before setting or reading it where required.

Retention and deletion

Data is kept only for as long as needed for the stated purpose, then deleted or anonymized unless a legal retention duty, dispute, security investigation, backup cycle, or other lawful exception applies. Preludeum applies the shortest period reasonably necessary for each category.

  • account, workspace, campaign, profile, search, draft, feedback, outreach, and usage data: while the account or workspace is active and afterwards only as needed for deletion handling, support, security, disputes, or legal obligations;
  • public-source posts, author fields, derived scores, caches, and raw provider data: only for the search, review, platform-compliance, security, and legal purposes for which they are needed, then deleted or anonymized;
  • hidden lead candidates: until campaign or account deletion, unless an earlier operational cleanup removes them;
  • legacy connected-account tokens and connection records, if any: when disconnected or no longer needed, subject to documented security or dispute exceptions;
  • support, security, AI, search, application, and hosting logs: the shortest period needed for security, troubleshooting, abuse prevention, legal claims, and service operation, with access restricted by role;
  • billing, invoice, tax, and transaction records: the applicable statutory accounting, tax, fraud-prevention, and dispute periods.

The current application does not expose a self-service account-deletion route. A verified deletion request can be sent to support@preludeum.com. Preludeum will delete or anonymize the account data within the applicable period unless a legal retention duty, dispute, fraud-prevention need, or security investigation requires limited continued retention. Campaign deletion and account deletion are separate operations.

Automated processing

Preludeum uses rules, ranking models, and AI assistance to prioritize public-source results and prepare drafts. These tools can affect which candidates a customer sees, but they are not used for credit, employment, housing, insurance, education, health, legal eligibility, law-enforcement, or other similarly significant decisions about individuals. Customers must not use the outputs for those purposes. Human review is required before outreach.

Security

The service uses server-side authentication, explicit project-ownership checks, restricted server-side secrets, provider security controls, security response headers, signed billing webhooks, content-security policy, request rate limits, and restricted service credentials. No security measure guarantees that unauthorized access is impossible.

Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, data portability, and information about recipients. You may object to processing based on legitimate interests, including direct-marketing-related processing, and withdraw consent at any time where processing is based on consent. Requests go to support@preludeum.com. The operator may request information needed to verify identity and will respond within the statutory period. You may also complain to the competent data-protection supervisory authority, normally the authority at the operator's registered office or at your habitual residence, place of work, or the place of the alleged infringement.

Sensitive data and children

Do not enter special-category data, health information, financial distress, legal problems, political or religious views, sexuality, addiction, precise location, children's data, passwords, tokens, or confidential third-party information into campaigns, corrections, notes, or drafts. Preludeum is not directed to children and must not be used to target vulnerable people or to make high-impact decisions.

Changes

This policy may change when the service, vendors, purposes, legal bases, or retention practices change. Material changes will be published with a new update date and communicated to active customers where required. The version published here describes the deployed processing.

Preludeum

Find leads from public posts on Reddit and X.

Product

How it worksDashboardLeadsCampaigns

Company

PricingFAQContactLogin

Resources

AlternativesSyften alternativeLeadverse alternativeF5Bot alternativeAwario alternativeBrand24 alternativeMention alternativeBrandwatch alternativeGoogle Alerts alternativeGummySearch alternative

Legal

PrivacyTermsLegal NoticeSecurityResponsible use

© 2026 Preludeum. All rights reserved.