How Parsedit collects, uses, and protects your information.
Last updated: August 19, 2026
This Privacy Policy describes how Cauldrn LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects information when you use Parsedit (“Service”), available at parsedit.com. By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Parsedit is operated by Cauldrn LLC, a limited liability company organized under the laws of the State of California, United States. We are not established in the EU or the UK. For privacy-related inquiries, contact us at [email protected]. For general support, contact [email protected].
Controller vs processor. For account, billing, security logs, support tickets, and marketing (if any), Cauldrn LLC is the controller. For uploaded documents and extracted fields about third parties, you (the customer) are the controller and Cauldrn LLC is your processor. Processor terms, including the EU Standard Contractual Clauses (Module 2) and the UK Addendum, are in our Data Processing Addendum.
EU GDPR Article 27 representative. We have appointed DataRep as our representative in the European Union. DataRep is not our Data Protection Officer and is not an establishment of Cauldrn LLC in the EU.
UK GDPR Article 27 representative. We have appointed DataRep as our representative in the United Kingdom. DataRep is not our Data Protection Officer and is not an establishment of Cauldrn LLC in the UK.
The TODO_DATAREP_* lines are placeholders until the DataRep mandate pack is issued. We will not invent an EU or UK street address. The same identities will appear in the DPA Annex I once filled.
Covered Entities that intend to upload protected health information must execute our Business Associate Agreement in-app before processing healthcare documents. This Privacy Policy does not claim that Parsedit is “HIPAA compliant.”
We collect information you provide and information we obtain automatically:
drive.file scope to access only files you explicitly select or create through the Service.We use the information we collect to:
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We do not use your documents, extracted data, or Google user data to train artificial intelligence or machine learning models.
To provide document extraction, uploaded files are transmitted to our document-processing provider for OCR and structured field extraction. This is a core function of the Service. We select providers that commit to appropriate data handling practices and use them only to provide the Service on our behalf.
We use the following categories of service providers (“sub-processors”) that process personal information on our behalf:
We may update our sub-processors from time to time. We require sub-processors to protect your data and process it only as instructed by us, consistent with this Privacy Policy and applicable law.
When you configure a destination or source integration, we send or receive data only as you direct. These third parties are not our sub-processors for your account data in the same sense; you choose to connect them and their use of your data is governed by their own terms and privacy policies. Integrations available in Parsedit include:
drive.file scope only; we do not request broad Drive access).You may disconnect integrations at any time through the app or, for Google, through your Google Account permissions.
You may authorize third-party applications (such as Zapier) to access your Parsedit workspace through our OAuth authorization flow. When you approve a connection, the application receives access only within the scopes you grant, which may include:
account:read)parsers:read)documents:read)documents:write)webhooks:write)We access and transmit data through these connections only as you configure in Parsedit (for example, parser-scoped webhooks or document uploads). We do not sell this data, use it for advertising, or use it to train artificial intelligence or machine learning models.
You can revoke Parsedit OAuth access at any time from Integrations → Connected applications in the app. You should also disconnect or disable the application in the third party’s settings (for example, turn off related Zaps in Zapier).
Parsedit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you sign in with Google, we receive your name, email address, and Google account identifier to create and manage your Parsedit account. We use this information only for authentication, account management, and communicating with you about the Service.
When you connect Google integrations, we request the following OAuth scope:
https://www.googleapis.com/auth/drive.file — access only to files you explicitly open, select, or create through Parsedit (including spreadsheets you choose for export).We use Google user data solely to provide user-facing features you request:
We do not use Google user data for advertising, retargeting, or serving ads. We do not sell Google user data. We do not use Google user data to train artificial intelligence or machine learning models. We do not allow humans to read your Google user data except: (a) with your affirmative consent for a specific message or file; (b) for security purposes (e.g. investigating abuse); (c) to comply with applicable law; or (d) when the data is aggregated, anonymized, and used for internal operations in accordance with Google’s Limited Use requirements.
You may revoke Parsedit’s access to your Google account at any time through your Google Account permissions or by disconnecting the integration in Parsedit.
We may share information with:
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We retain information only as long as needed for the purposes in this policy, your plan, and the law. The clock for documents is the document’s creation time (created_at), not last viewed. Your billing account’s plan applies to every workspace billed to that owner.
Documents and extracted data (processor content) are deleted automatically after the plan window, unless you delete sooner, a legal hold applies, or you export first:
This window covers original files, extracted fields, destination delivery payloads for those documents, leftover processing jobs, and inbound email bodies/attachments if stored. It does not delete parsers, templates, destination configuration, connected integrations (encrypted tokens while connected), members, profile, or the credits ledger needed for billing disputes.
CSV/JSON download history (files you generate in-app) is kept 7 days, then deleted. This is not plan-based.
Account data (controller) is retained while your account is active. After you delete your account, we aim to erase remaining personal information within about 30 days, except records we must keep (for example tax/billing archives, security incident records, and fraud-prevention tombstones that do not store your email in plaintext).
Billing and tax records are retained about 7 years as required for accounting and tax. We do not auto-delete Stripe objects from the document-retention job.
Logs and security data are retained about 90 days, then deleted or anonymized, except longer where required for an active investigation or HIPAA documentation (audit metadata without document contents).
You may export your data (access/portability) and delete your account in Settings. A 30-day grace and notice apply if you downgrade from a 365-day plan to a 60-day plan, so you can export documents older than 60 days before they become eligible for deletion.
Enforcement of plan-based document deletion is rolled out after advance notice when we first enable it in production. Until that date, treat the windows above as the contractual/policy period we apply going forward.
We use industry-standard measures to protect your data, including:
You are responsible for keeping your password and account credentials secure. Use a strong, unique password and enable multi-factor authentication where available.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Cauldrn LLC and its hosting providers store and process Service data in the United States (including Supabase and Vercel). If you access the Service from the EEA, UK, or another region, your information is transferred to the United States.
For customer document processing (you as controller, Cauldrn as processor), transfers are governed by the EU Standard Contractual Clauses (2021) Module 2 and the UK IDTA / UK Addendum, as set out in our Data Processing Addendum. A Business Associate Agreement, if executed, does not replace those clauses.
Depending on your location, you may have the following rights regarding your personal information:
You may export a copy of your workspace data (account, members, parsers without secrets, documents and extracted fields, billing identifiers, integration provider/scopes without tokens) and delete your account in Settings → Data, using email one-time-code verification. You do not need to email us first for those self-serve rights. For other requests, or if you cannot access the app, contact [email protected] or our DataRep representatives listed in Section 1. We will verify your identity before fulfilling requests and respond within the timeframes required by applicable law.
If you are in the EEA or UK, our legal bases for processing include: performance of a contract (providing the Service), legitimate interests (security, improvement, fraud prevention), compliance with legal obligations, and consent where required (including optional analytics cookies). You have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides you with additional rights.
Categories of personal information we collect:
Your California rights:
Submit requests to [email protected]. We will verify your identity before fulfilling requests. You may designate an authorized agent to submit requests on your behalf with appropriate authorization.
Notice at collection: We collect the categories described above for the purposes in this policy (providing the Service, security, support, billing, compliance). Retention periods are described in Section 8. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at [email protected] and we will delete it promptly.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. For material changes, we may notify you by email or through the app. Continued use of the Service after the effective date of changes constitutes acceptance. We encourage you to review this policy periodically.
For privacy-related questions or to exercise your rights, contact:
Cauldrn LLC (controller/processor, United States) Email: [email protected] | [email protected]
EU GDPR Article 27 representative (DataRep) — not a DPO; not an EU establishment: TODO_DATAREP_EU_NAME; TODO_DATAREP_EU_ADDRESS; TODO_DATAREP_EU_EMAIL
UK GDPR Article 27 representative (DataRep) — not a DPO; not a UK establishment: TODO_DATAREP_UK_NAME; TODO_DATAREP_UK_ADDRESS; TODO_DATAREP_UK_EMAIL