Privacy Policy
On this page
This Privacy Policy explains how Liouville Labs, Inc., a Delaware corporation ("Liouville Labs", "we", "us") handles personal information in connection with Biddle, the AI chief of staff for product teams, and the askbiddle.ai website (together, the "Service").
Biddle handles two kinds of personal information, and our role is different for each:
- Workspace content. When an organization connects Biddle to its Slack workspace, GitHub organization, Linear workspace, or another tool, Biddle processes the content and people data in those tools on that organization's behalf. For this data the organization (our "Customer") decides what Biddle can see, and we act as its processor (a "service provider" under the CCPA). We use it only to provide the Service to that Customer.
- Our own data. For the early-access form, website analytics, and our own business contacts, we decide how the data is used and act as the controller (a "business" under the CCPA).
If you are a member of a Customer's workspace and want to exercise your rights over workspace content, you can contact your organization or us; see Your rights.
Information we collect
From Slack
Biddle is a Slack app installed by your organization. It reads:
- Messages in channels it is invited to, public or private, including threads and reactions, and messages in direct messages people send to Biddle. It does not read direct messages between people or channels it has not been invited to.
- Profile information of workspace members: Slack user ID, name, display name and handle, profile title, time zone, locale, account type (for example member, guest, or external), and email address (through the
users:read.emailscope). We use email addresses to match a person's Slack account to their GitHub account. - Your interactions with Biddle: questions you ask it, corrections and feedback you give, the watches you set, and settings such as pausing its DMs.
From GitHub
Biddle is a GitHub App installed by your organization with read-only permissions for contents, pull requests, issues, checks, actions, and metadata. It receives and reads:
- Pull requests (titles, descriptions, commits and commit messages, changed-file lists, reviews and review comments), pushes, issues and issue comments, check runs, and workflow runs.
- Code contents, read on demand: for example, a diff excerpt of a pull request when Biddle summarizes it. Biddle does not copy your whole codebase.
- GitHub usernames and the names attached to that activity.
- If you choose Connect GitHub to link your GitHub account to your Slack account, your GitHub username and the verified email addresses on that account, which we use only to confirm the link.
Biddle never comments on pull requests or writes code.
From Linear, when connected
If a leader or workspace admin connects Linear from Biddle's Home tab in Slack, Biddle reads issues and comments from that Linear workspace, and the names of the people attached to them, through a read-only connection. The access token is encrypted at rest.
From other tools you connect
If your organization connects another tool, such as Notion, Figma, Google Analytics, Meta Ads, Gmail, or Google Drive, Biddle reads the content that connection gives it access to. Some of these connections run through Composio, an integration provider that holds the access tokens for the connection and relays data between the tool and Biddle. Biddle only reads from these tools, and disconnecting a tool deletes what Biddle stored from it.
From the early-access form
When you request early access on askbiddle.ai we collect your email address, and, if you provide them, your company and what you are building. We also keep the time of the request.
From the website
askbiddle.ai uses Google Analytics 4, which sets cookies and collects information such as pages viewed, referring site, approximate location derived from your IP address, browser and device type, and the time of your visit. When the early-access form succeeds, we record a request_access event; that event never includes what you typed into the form. See Cookies and analytics.
From Liouville Labs staff
Our internal admin console is limited to Liouville Labs staff, who sign in with their Google Workspace account. We receive their name and work email address from Google and keep a session cookie.
What we do not collect
We do not ask for or intend to collect sensitive personal information such as government ID numbers, financial account credentials, precise geolocation, or health data. Workspace content is whatever your team writes in the channels, repositories, and Linear workspace you connect, so it can contain anything your team puts there. We do not collect payment information during early access.
How we use information
We use workspace content only to provide the Service to the Customer that connected it:
- to build and keep a record of workstreams, decisions, and open questions, each linked to its source;
- to write the leader's morning briefing, team recaps, member notes, and nudges, and to answer questions people ask Biddle in Slack;
- to decide who can see what: an answer in a channel uses only that channel and the public channels the asker can see, and private-channel content never reaches a public answer;
- to keep the Service secure, debug it, and measure the quality of its output for that Customer.
We use the information we control:
- Early-access form: to reply to you, set up the Service with you, and contact you about Biddle. Each new request is sent to our team as a Slack message.
- Website analytics: to understand how people find and use askbiddle.ai and to improve it.
- Staff sign-in: to control access to our internal tools.
We do not sell personal information, and we do not use workspace content for advertising.
AI processing
Biddle uses large language models to read workspace content and write briefings, notes, nudges, and answers.
- We do not train AI models on your data. Liouville Labs does not use Customer workspace content to train or fine-tune any AI model.
- Model calls go through Anthropic's API, under Anthropic's commercial terms.
- Search embeddings, when enabled, go through Voyage AI, with training on your data turned off.
Biddle's output is generated by AI and can be wrong. Every claim it makes links to the pull request, commit, or message behind it so you can check it, and you can correct it by replying in the briefing's thread.
Subprocessors and other recipients
We share personal information only with the service providers that help us run the Service, with the tools your organization chooses to connect, or when the law requires it.
| Provider | What it does for Biddle | Data involved | Location |
|---|---|---|---|
| Anthropic | Language model processing, under Anthropic's commercial terms | Workspace content sent in model calls | United States |
| Voyage AI | Search embeddings (when enabled), with training on customer data turned off | Excerpts of workspace content | United States |
| Fly.io | Hosting for Biddle's backend, job queue, and database | All Service data | United States |
| Vercel | Hosting for askbiddle.ai | Website request data | United States and global edge network |
| Google Analytics 4 on askbiddle.ai; Google sign-in for Liouville Labs staff | Analytics data; staff name and email | United States | |
| Slack | The workspace Biddle reads from and posts to; our own Slack receives early-access requests | Workspace content; early-access requests | United States |
| GitHub | The source of repository activity; account linking | Repository activity; GitHub username and verified emails | United States |
| Linear | The source of issues and comments, when connected | Linear issues and comments | United States |
| Composio | Integration provider for tools a Customer connects (such as Notion, Figma, Google Analytics, Meta Ads, Gmail, Google Drive): holds the access tokens and relays data | Access tokens; content from the connected tool | [CONFIRM: COMPOSIO DATA LOCATION] |
Slack, GitHub, Linear, and the other tools you connect are services your organization already uses and connects at its own choice. Their handling of your data is governed by your organization's agreements with them. We will update this list before adding a new subprocessor that processes workspace content.
We may also disclose information if required by law, to protect the rights, safety, or property of our users or others, or as part of a merger, acquisition, or sale of assets, in which case this policy will continue to apply to the information transferred.
How long we keep information
| Data | How long we keep it |
|---|---|
| Raw events (Slack messages, GitHub and Linear activity as received) and the search index built from them | 90 days, then deleted by a daily job. A small number of events our team labels to evaluate Biddle's accuracy can be kept longer, until the organization is removed. |
| Notes Biddle derives (workstreams, decisions, open questions, briefings) | Until the Customer's organization is removed from Biddle |
| Data from a disconnected tool (for example Linear or Notion) | Deleted when the tool is disconnected: its stored events, search documents, identity links, and access token. Workstreams and decisions Biddle already wrote stay, with their links. |
| Everything for an organization | Deleted when the organization is removed from Biddle, within 30 days |
| Early-access requests | Until you ask us to delete them, or until they are no longer needed to set up and contact you |
| Website analytics | As set in Google Analytics: [GA4 DATA RETENTION SETTING] |
| Staff sign-in sessions | Until the session expires or the staff member signs out |
Deleted data can remain for up to 5 days in encrypted backups before it is overwritten. We may keep information longer where the law requires it.
Cookies and analytics
askbiddle.ai uses Google Analytics 4 cookies (such as _ga) to measure visits. We do not use advertising cookies. [CONFIRM: GA4 GOOGLE SIGNALS AND ADS PERSONALIZATION ARE OFF]
You can block or delete cookies in your browser settings, or install the Google Analytics opt-out browser add-on. The site works without analytics cookies. Our internal admin console uses a strictly necessary session cookie.
Security
We protect information with measures appropriate to an early-stage service, including:
- encryption in transit (HTTPS) for the website and the Service's endpoints;
- verification of the signatures on every webhook Slack and GitHub send to Biddle;
- read-only access to GitHub, Linear, and other connected tools;
- encryption at rest of connector access tokens (AES-256-GCM);
- secrets kept in our hosting provider's secret store, never in source code;
- audience rules that keep private-channel content out of public answers;
- access to internal tools limited to Liouville Labs staff signed in with their company Google account.
No system is perfectly secure. If we learn of a security incident affecting your personal information, we will notify the affected Customer, and you where the law requires, without undue delay.
Your rights
Depending on where you live, you may have the right to:
- know and access the personal information we hold about you, and receive a copy in a portable format;
- correct inaccurate information;
- delete your information;
- object to or restrict certain processing, and withdraw consent where we rely on it;
- opt out of the sale or sharing of personal information. We do not sell personal information or share it for cross-context behavioral advertising;
- limit the use of sensitive personal information. We do not use sensitive personal information for purposes that would give rise to this right;
- not be discriminated against for exercising any of these rights.
To exercise a right, email contact@askbiddle.ai. We will confirm your request within 10 business days and respond within 45 days, or tell you if we need more time as the law allows. We will verify your request by matching the email address you write from, or other information, against what we hold. You can use an authorized agent; we may ask the agent for proof of authorization and ask you to confirm your identity.
Workspace content. If your request concerns content in your organization's Slack, GitHub, Linear, or another connected tool, we act on the instructions of the Customer that connected it. We may refer your request to that organization, and we will help it respond.
California residents
In the past 12 months we have collected these categories of personal information: identifiers (name, email address, Slack and GitHub user IDs, IP address); internet or network activity (website usage, interactions with Biddle); professional information (company, job title, work activity in connected tools); approximate geolocation derived from IP address; and inferences in the form of the notes Biddle derives about work. Sources, purposes, recipients, and retention periods for each are described above. We have not sold or shared personal information, and we have no actual knowledge of selling or sharing information of consumers under 16.
International transfers
Biddle is hosted in the United States. If you use the Service from another country, including the European Economic Area, the United Kingdom, or South Korea, your information is transferred to and processed in the United States, where data protection laws may differ from yours. Where the law requires a transfer mechanism, we rely on appropriate safeguards such as standard contractual clauses or your consent. A Korean-language version of this policy, covering the disclosures the Korean Personal Information Protection Act requires, is available at /ko/privacy.
Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We will post any change on this page and update the date at the top. If a change is material, we will tell Customers by email or in Slack before it takes effect.
Contact
- Company: Liouville Labs, Inc.
- Address: 455 Market St Ste 1940 PMB 213430, San Francisco, CA 94105, USA
- Privacy contact: [PRIVACY OFFICER NAME], contact@askbiddle.ai
- General: contact@askbiddle.ai