Privacy Policy
Effective 20 July 2026 · Applies to the Preface 2559 platform at preface.sg
1. Who we are and what this covers
Preface 2559 (the “Platform”) is the internal operations platform of Preface (“Preface”, “we”, “us”), operated at preface.sg for Preface’s Singapore team. It is a staff tool for managing client relationships, meetings, events, and delivery. It is not a consumer product: there is no public sign-up, and accounts exist only for authorized Preface personnel.
This policy explains what personal data the Platform processes, why, how long it is kept, who it is shared with, and the choices available — including, in detail, how we handle Google user data when a staff member connects their Google account.
2. The data we process
- Staff account data — name, work email, role, and authentication records for each provisioned account, plus audit logs of significant actions taken in the Platform.
- Business relationship data — information about client organisations and their representatives: company names, contact names, business email addresses, meeting and correspondence history, and commercial records (for example invoices and delivery records) created in the course of Preface’s business.
- Google user data — described in full in section 3, processed only for staff members who explicitly connect their own Google account.
- Operational data — bounded technical logs (job runs, sync state, error codes) needed to keep the Platform reliable and auditable.
3. Google user data
Staff members may voluntarily connect their own Google Workspace account from their Profile page. Connection uses Google’s OAuth consent flow, and the Platform requests only these permissions (scopes):
- Identity (openid, email) — to verify which Google account was connected and display its address.
- Read Gmail (gmail.readonly) — to recognise correspondence with client contacts and build an accurate client timeline.
- Compose Gmail (gmail.compose) — to create a draft written in the Platform and send that exact draft, only after the staff member explicitly confirms it.
- Own-calendar events (calendar.events.owned) — to read and manage events on calendars the connected user owns, for meeting scheduling linked to client records.
What we store. The Platform is deliberately metadata-first. From Gmail it stores bounded metadata only: stable message identifiers, thread identifiers, subject lines, participant names and addresses, timestamps, labels/status flags, and attachment names/types/sizes. From Calendar it stores event identifiers, titles, locations, times, organizers, and attendee responses.
What we never store: email message bodies, snippets, or raw content; attachment contents; calendar event descriptions; raw provider responses; or plaintext credentials. OAuth refresh tokens are stored only in encrypted form (AES-256-GCM) and are never visible to any user, including administrators.
How we use it. Google user data is used solely to operate Platform features for the connected staff member: matching correspondence and meetings to client records, reconstructing client history, scheduling, and preparing drafts. No email is ever sent and no calendar event is ever written without the staff member’s explicit, per-action confirmation. Google user data is not used for advertising, is not sold, and is not shared with third parties except the service providers listed in section 6 acting on our instructions.
AI features. Where a feature uses AI assistance (Google’s Gemini model), the Platform sends only small, bounded excerpts of authorized data needed for that specific request. These excerpts are used transiently for the request and are not retained by the Platform; only the validated, structured outcome (for example a classification with its citations) is stored. AI suggestions cannot execute actions on their own.
Limited Use disclosure. Preface 2559’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How long we keep data
- Activity that is matched or explicitly linked to a client record (for example, the fact that a meeting or an email exchange took place) is kept for as long as that client record exists, because it forms the client’s business history.
- Temporary review material — items that could not be confidently matched — is kept for 90 days by default and then deleted.
- Bounded operational logs are kept for 90 days by default.
- Encrypted database backups are retained under our backup policy and deleted on their own schedule.
5. Disconnection and deletion
A connected staff member can end the Platform’s Google access at any time, in any of three ways:
- Disconnect in the Platform — Profile → Disconnect. This deletes the locally stored (encrypted) token and stops all Google access immediately.
- Revoke with Google from the Platform — Profile → Revoke with Google. This additionally asks Google to revoke the Platform’s grant.
- Revoke at Google directly — via Google Account → Security → Third-party connections. The Platform detects the revoked grant and blocks further access.
Disconnection stops synchronization and deletes the stored token; it does not by itself erase business history already matched to client records, which Preface retains as commercial records. To request deletion of specific personal data — including Google-derived metadata — contact singapore@preface.ai. We will verify the request and respond within 30 days.
7. Security
Data is encrypted in transit (TLS) and at rest. OAuth tokens are additionally encrypted at the application layer with versioned AES-256-GCM keys. Database access is restricted at the network level, protected by row-level security, and limited to the application’s server side — there is no direct browser access to the database. Access within the Platform is role-based, significant actions are audit-logged, and consequential operations require explicit human confirmation.
8. Your rights
We handle personal data in accordance with the Singapore Personal Data Protection Act (PDPA). Staff members and client contacts may request access to, or correction of, their personal data, and may withdraw consent where processing is based on consent, by contacting singapore@preface.ai.
9. Changes and contact
We will post any changes to this policy on this page and update the effective date above. Material changes affecting Google user data will be communicated to connected staff members before they take effect.
Questions about this policy: singapore@preface.ai. See also our Terms of Use.

