Privacy Policy
Last updated: September 16, 2026
Teable AI, Inc. ("Teable," "we," "us") provides an AI spreadsheet for business. This policy explains how we handle information across our websites, applications, and related services (the "Service").
1. Information we collect
Account and contact information. We collect information you provide when you register, manage your profile, contact us, or purchase a subscription. This may include your name, email address, profile picture, password, organization, job title, phone number, country or region, billing details, and support messages. If you use a sign-in provider, we receive the account information it shares with your permission. For example, Apple may provide a relay email address instead of your personal address.
Content you provide. We process the records, files, images, messages, and other content you add to your spaces and projects, including content submitted to AI features or connected integrations. Features such as photo uploads or voice input may request camera, photo library, or microphone access when needed. You can manage these permissions in your device settings; declining access limits the features that need it.
Usage and technical information. We collect information such as IP addresses, browser and device details, operating system and app versions, referring pages, screens viewed, actions taken, and error, crash, and performance reports. Cookies and similar technologies may assign browser or device identifiers. Usage and diagnostic information may be associated with your account ID; it is not necessarily anonymous.
2. How we use and share information
We use information to provide and maintain the Service, authenticate users, enable collaboration and AI features, process payments, respond to support requests, improve performance and usability, protect against abuse, and meet legal obligations. We also send service notices and marketing communications, which you can unsubscribe from.
Service providers. We share information with providers that help us operate the Service, including hosting, payment, email, analytics, and diagnostic services. They process information to perform their services for us, subject to applicable agreements. Content is also shared with collaborators and integrations according to the permissions and workflows you configure.
AI features. When you use AI, your message and the project content needed to fulfill your request are sent to the model provider, directly or through a service such as Vercel's AI Gateway. These providers include OpenAI. They act as our processors and are contractually barred from training their models on your content. They may retain content briefly for abuse monitoring under their policies.
Legal and business purposes. We may disclose information when reasonably necessary to comply with law, enforce our terms, investigate fraud or security issues, or protect users and others. Information may also be transferred as part of a merger, acquisition, or sale of assets, subject to this policy.
We may use aggregated or de-identified information to understand usage trends and improve the Service. Information linked to an account, browser, or device is not treated as anonymous merely because it does not include a name.
3. Cookies, analytics, and advertising
We use cookies and similar technologies to keep you signed in, remember preferences, understand usage, and measure advertising effectiveness. Blocking necessary cookies may prevent parts of the Service from working. You can manage cookies through your browser and use the consent controls shown on our websites.
Analytics and diagnostics. We use PostHog and Google Analytics to understand usage, Sentry for error and crash reports, and Microsoft Clarity to understand interactions with web pages, including pages displayed inside our applications. Clarity uses strict masking to obscure page text and images before recordings leave your browser. PostHog may also record sessions on our marketing website to help us understand visits from advertising campaigns. Native application screens are not session-recorded.
Website advertising. We use tools from Google, Meta, and OpenAI (ChatGPT Ads) to measure website visits and advertising conversions. These tools may receive browser or device identifiers, referring information, and events such as page views, sign-ups, or purchases. Advertising partners may associate this information with information they hold to measure campaigns or personalize advertising, subject to your choices and their policies. You can also manage advertising preferences with those providers.
We do not sell personal information for money. Website advertising disclosures may qualify as "sharing" or a "sale" under some privacy laws. You may contact us to exercise applicable opt-out rights. Product analytics and crash reporting are used to operate and improve the Service; they are distinct from the website advertising activities described above.
4. Self-hosted deployments
For self-hosted deployments, your administrator controls the server and its content retention settings. Internet-connected deployments may send a limited license compliance attestation to Teable to validate licenses, detect copying or overuse, and verify authorized software distributions. This is separate from optional product analytics.
Attestations may include instance and license identifiers; license plan, seat limit, and expiration dates; edition, application and build versions, image digest, and build channel; aggregated user, project, and space counts or count buckets; last activity time; operating platform, CPU architecture, and Node.js version; hashed machine and public origin hostnames, public origin top-level domain, and compliance risk signals.
Attestations do not include workspace content, table records, schema names, field values, SQL queries, secrets, credentials, authentication tokens, license keys, user email lists, user names, or full public origin URLs. Payloads are encrypted in transit, and hostnames are hashed before transmission. Instance and license identifiers may be sent in their original form for validation.
We retain raw attestation events only as reasonably necessary for compliance, security, fraud prevention, disputes, and audits. Aggregated or derived compliance status may be retained for the customer relationship and any legally required period. Administrators can disable reporting, including attestation, with TELEMETRY_REPORT_DISABLED=true. This does not itself prevent offline license activation, but may limit compliance verification and investigation.
5. Security and retention
We use technical and organizational safeguards, including encryption and access controls, to protect information. No system is completely secure. Keep your account credentials private and contact us if you suspect unauthorized access.
You can permanently delete your account from Account in your settings. We immediately delete or anonymize the personal information attached to it, including your name, email address, and profile picture, and remove access tokens, connected sign-in providers, collaborator memberships, invitations, and notifications.
Spaces, projects, tables, and records are deleted separately, before or during account deletion. On our hosted service, deleted content is retained in the trash for thirty days unless you empty it sooner. Server logs and database backups are retained for up to thirty days. Payment records are kept as required by tax and accounting law. AI providers may briefly retain content as described above.
6. Your choices and rights
You can update your profile and delete your account in settings. You may also request access to, correction of, or deletion of your personal information by emailing [email protected]. Depending on your location, you may have rights to data portability, to object to or restrict processing, to withdraw consent, to opt out of certain advertising disclosures, or to complain to a data protection authority. We respond as required by applicable law and do not discriminate against you for exercising your rights.
Use the unsubscribe link in promotional emails to stop receiving marketing messages. We may still send essential account, security, and service notices.
7. Google API services user data
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, we access only the data authorized by the scopes you grant:
- Gmail read-only access (
gmail.readonly): lists labels and retrieves messages and attachments for the Email Received automation trigger. - Gmail send access (
gmail.send): sends emails through workflows you configure. - Profile information (
userinfo.email,userinfo.profile): displays the connected account in integration settings.
Google user data is used only to provide and improve the user-facing features you configure, not for advertising, marketing, or unrelated purposes. OAuth tokens and associated metadata are encrypted, and tokens are retained only while the integration is active. Email content is processed to run your workflows and is not permanently stored beyond what execution requires.
We do not sell or transfer Google user data except as needed to provide the Service, protect security, or comply with law. Human access requires your affirmative consent, a security need, or a legal requirement. You can revoke access in Teable's integration settings or on your Google Account permissions page.
8. Children and third-party services
The Service is not directed to children under 13, and we do not knowingly collect their personal information or allow them to register. If you believe a child has provided personal information, contact us so we can delete it.
Third-party websites and services you choose to visit or connect have their own privacy policies. Review those policies to understand how they handle your information.
9. Changes and contact
We will notify you of significant changes by email or a prominent website notice at least thirty days before they take effect. Minor changes and clarifications take effect when posted.
For questions about this policy or your information, contact Teable AI, Inc. at [email protected].