Last updated: July 16, 2026
This Privacy Policy describes how Cauldrn LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects information when you use Parsedit (“Service”), available at parsedit.com. By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who we are
Parsedit is operated by Cauldrn LLC, a limited liability company organized under the laws of the State of California, United States. For privacy-related inquiries, contact us at [email protected]. For general support, contact [email protected].
We collect information you provide and information we obtain automatically:
- Account information: Name, email address, password (if you register with email and password), and, if you sign in with Google OAuth, identifiers and profile information from Google (such as your Google account ID, name, and email address). For team accounts, we store member emails, roles, and permissions.
- Billing information: Payment and subscription data are processed by Stripe. We do not store full card numbers. We receive billing metadata (such as plan, subscription status, invoice history, and payment method type) necessary to provide the Service.
- Documents and extracted data: Files you upload (PDF, DOCX, images, and other supported formats) and the structured data we extract from them. This includes parser configurations, field definitions, review edits, and export history. Documents are stored in your account and processed to provide the Service.
- Integration data: OAuth tokens (stored encrypted), connection settings, and metadata for third-party integrations you connect (such as Google Drive, Google Sheets, Airtable, QuickBooks, Xero, Slack, and webhooks).
- Inbound email data: If you use email-to-parser intake, we receive emails and attachments sent to your parser’s inbound address via our email provider (Postmark), including sender address, subject, body, and attachments.
- Usage and technical data: Log data, IP address, browser and device information, pages visited, features used, and timestamps. This data is used for security, support, debugging, and improving the Service.
- Optional analytics data: If you accept optional analytics cookies, Google Analytics 4 may collect aggregated usage metrics (such as page views, device/browser type, approximate location derived from IP, and Core Web Vitals). This does not load unless you consent. See our Cookie Policy.
- Error and performance data: If error monitoring is enabled (e.g. Sentry), we may collect error reports, stack traces, and performance metrics. We configure such tools to avoid collecting unnecessary personal information where possible.
- Communications: Information you provide when you contact support, submit feedback, or communicate with us by email.
- From you: Registration, profile updates, uploaded documents, parser and integration settings, billing choices, and communications you send us.
- From integrations you connect: When you authorize a third-party integration, we receive the access tokens and scopes you grant. For example, when you connect Google Drive or Google Sheets, we receive the
drive.file scope to access only files you explicitly select or create through the Service. - From Google Sign-In: If you authenticate with Google, we receive basic profile information (name, email, profile identifier) as permitted by Google’s OAuth consent screen.
- Automatic: Cookies, local storage, server logs, and similar technologies as described in our Cookie Policy.
We use the information we collect to:
- Provide, operate, maintain, and improve the Service (including document upload, OCR and field extraction, review workflows, and delivery to your chosen destinations).
- Authenticate you, manage sessions, and enforce access controls (including team roles and row-level security).
- Process payments, manage subscriptions, credits, and usage limits.
- Send transactional communications (account confirmations, password resets, billing notices, service updates).
- Respond to support requests and comply with legal obligations.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Analyze aggregated site usage when you consent to optional analytics (Google Analytics), to improve the Service.
- Send marketing communications where permitted by law (you may opt out at any time).
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We do not use your documents, extracted data, or Google user data to train artificial intelligence or machine learning models.
5. Document processing and sub-processors
To provide document extraction, uploaded files are transmitted to our document-processing provider for OCR and structured field extraction. This is a core function of the Service. We select providers that commit to appropriate data handling practices and use them only to provide the Service on our behalf.
Sub-processors
We use the following categories of service providers (“sub-processors”) that process personal information on our behalf:
- Supabase — database hosting, authentication, and private file storage. Processes account data, documents, extracted data, and integration tokens.
- Vercel — application hosting and content delivery. Processes request logs, IP addresses, and technical metadata.
- Cloudflare — bot protection (Turnstile CAPTCHA on authentication forms) and edge security. Processes interaction data necessary for CAPTCHA verification.
- Stripe — payment processing and subscription management. Processes billing information, payment method metadata, and transaction records. Stripe’s privacy policy is available at stripe.com/privacy.
- Extend — document OCR and structured field extraction. Processes uploaded documents and parser configuration data to return extracted fields. This is the primary sub-processor for document content. Extend does not use your data to train its models.
- Postmark — inbound email delivery for email-to-parser intake. Processes sender addresses, email content, and attachments you route to a parser.
- Resend or SMTP mail provider (e.g. Nodemailer) — outbound transactional email (account verification, password reset, billing notifications). Processes recipient email addresses and message content.
- Sentry (when enabled) — error monitoring and performance diagnostics. Processes error reports, stack traces, and limited technical context.
- Google Analytics (only with your consent) — optional website analytics. Processes usage and device data as described in the Cookie Policy and Google’s privacy policy. We configure Consent Mode so advertising/retargeting signals remain denied.
We may update our sub-processors from time to time. We require sub-processors to protect your data and process it only as instructed by us, consistent with this Privacy Policy and applicable law.
User-connected integrations
When you configure a destination or source integration, we send or receive data only as you direct. These third parties are not our sub-processors for your account data in the same sense; you choose to connect them and their use of your data is governed by their own terms and privacy policies. Integrations available in Parsedit include:
- Google Drive — import files you explicitly select (
drive.file scope only; we do not request broad Drive access). - Google Sheets — append approved extracted rows to spreadsheets you connect.
- Airtable — export extracted data to bases and tables you authorize.
- Intuit QuickBooks Online — export extracted data to your QuickBooks account.
- Xero — export extracted data to your Xero organization.
- Slack — send notifications to channels or webhooks you configure.
- Zapier / Make — deliver data via webhooks you configure.
- Generic webhooks — POST approved extracted data to URLs you supply.
- Email delivery — send extracted data to email addresses you specify.
You may disconnect integrations at any time through the app or, for Google, through your Google Account permissions.
Third-party applications connected via Parsedit OAuth
You may authorize third-party applications (such as Zapier) to access your Parsedit workspace through our OAuth authorization flow. When you approve a connection, the application receives access only within the scopes you grant, which may include:
- Reading workspace and account details (
account:read) - Listing and viewing parsers (
parsers:read) - Reading documents and extracted results (
documents:read) - Uploading documents to parsers you specify (
documents:write) - Subscribing to document events via webhooks you configure (
webhooks:write)
We access and transmit data through these connections only as you configure in Parsedit (for example, parser-scoped webhooks or document uploads). We do not sell this data, use it for advertising, or use it to train artificial intelligence or machine learning models.
You can revoke Parsedit OAuth access at any time from Integrations → Connected applications in the app. You should also disconnect or disable the application in the third party’s settings (for example, turn off related Zaps in Zapier).
6. Google user data and Limited Use
Parsedit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Sign-In (authentication)
If you sign in with Google, we receive your name, email address, and Google account identifier to create and manage your Parsedit account. We use this information only for authentication, account management, and communicating with you about the Service.
Google Drive and Google Sheets (integrations)
When you connect Google integrations, we request the following OAuth scope:
https://www.googleapis.com/auth/drive.file — access only to files you explicitly open, select, or create through Parsedit (including spreadsheets you choose for export).
We use Google user data solely to provide user-facing features you request:
- Import documents from Google Drive that you explicitly select.
- Append approved extracted data to Google Sheets you connect.
- Display connection status and manage your integration.
We do not use Google user data for advertising, retargeting, or serving ads. We do not sell Google user data. We do not use Google user data to train artificial intelligence or machine learning models. We do not allow humans to read your Google user data except: (a) with your affirmative consent for a specific message or file; (b) for security purposes (e.g. investigating abuse); (c) to comply with applicable law; or (d) when the data is aggregated, anonymized, and used for internal operations in accordance with Google’s Limited Use requirements.
You may revoke Parsedit’s access to your Google account at any time through your Google Account permissions or by disconnecting the integration in Parsedit.
7. Sharing and disclosure
We may share information with:
- Sub-processors listed in Section 5, who process data on our behalf under contractual obligations.
- Integrations you configure, when you approve sending extracted data to a destination you have set up.
- Legal and safety purposes, if required by law, regulation, legal process, or governmental request; to enforce our Terms or EULA; to protect the rights, property, or safety of Cauldrn LLC, our users, or the public; or to detect and prevent fraud or abuse.
- Business transfers, in connection with a merger, acquisition, reorganization, or sale of assets, subject to the acquirer honoring this Privacy Policy.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
8. Data retention
We retain your information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account data is retained while your account is active and for a limited period after termination as needed for legal, security, or support purposes.
- Documents and extracted data are retained while your account is active. You may delete documents through the app where that feature is available. When you delete your account (or a team you own), associated documents, parsers, and export records for those workspaces are deleted as part of account deletion.
- Billing records are retained as required for tax, accounting, and legal compliance.
- Logs and security data are retained for a limited period appropriate for security and troubleshooting, then deleted or anonymized.
After account termination, we will delete or anonymize your personal information within a reasonable period, except where retention is required or permitted by law.
9. Security
We use industry-standard measures to protect your data, including:
- Encryption in transit (TLS/HTTPS) and encryption at rest for stored data.
- Row-level security so you can access only your own account and authorized team data.
- Private storage buckets with access via short-lived signed URLs generated server-side.
- Encrypted storage of OAuth tokens for third-party integrations.
- Access controls, authentication requirements, and monitoring for suspicious activity.
You are responsible for keeping your password and account credentials secure. Use a strong, unique password and enable multi-factor authentication where available.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. International transfers
Our providers may store or process data in the United States or other countries. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other jurisdictions where our sub-processors operate. We take steps (such as standard contractual clauses and vendor agreements) to ensure that such transfers comply with applicable law.
11. Your rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request deletion of your personal information, subject to legal exceptions.
- Portability — request a copy of your data in a structured, machine-readable format where technically feasible.
- Restriction — request that we limit processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw consent at any time (this does not affect prior processing).
- Opt out of marketing — unsubscribe from marketing emails using the link in any marketing message.
You may access, correct, or delete much of your account data directly through the app. For other requests, contact us at [email protected]. We will verify your identity before fulfilling requests and respond within the timeframes required by applicable law.
European Economic Area and United Kingdom
If you are in the EEA or UK, our legal bases for processing include: performance of a contract (providing the Service), legitimate interests (security, improvement, fraud prevention), compliance with legal obligations, and consent where required (including optional analytics cookies). You have the right to lodge a complaint with your local supervisory authority.
California residents
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides you with additional rights.
Categories of personal information we collect:
- Identifiers (name, email, IP address, account ID, Google account identifier).
- Commercial information (subscription plan, billing history, usage credits).
- Internet or other electronic network activity (logs, feature usage, session data).
- Professional or employment-related information (if you provide it in documents or account details).
- Inferences (limited; e.g. usage patterns for account management).
- Sensitive personal information: we do not intentionally collect sensitive categories (such as government ID numbers, health data, or biometric data) except as may be contained in documents you voluntarily upload for processing.
Your California rights:
- Right to know what personal information we collect, use, disclose, and sell (we do not sell).
- Right to delete personal information (subject to exceptions).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing for cross-context behavioral advertising (we do not sell or share for such purposes).
- Right to limit use of sensitive personal information (we do not use sensitive personal information beyond what is necessary to provide the Service).
- Right to non-discrimination for exercising your privacy rights.
Submit requests to [email protected]. We will verify your identity before fulfilling requests. You may designate an authorized agent to submit requests on your behalf with appropriate authorization.
Notice at collection: We collect the categories described above for the purposes in this policy (providing the Service, security, support, billing, compliance). Retention periods are described in Section 8. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
12. Children
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at [email protected] and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. For material changes, we may notify you by email or through the app. Continued use of the Service after the effective date of changes constitutes acceptance. We encourage you to review this policy periodically.
For privacy-related questions or to exercise your rights, contact:
Cauldrn LLC Email: [email protected] | [email protected]