How Parsedit collects, uses, and protects your information.
Last updated: September 28, 2026
This Privacy Policy describes how Cauldrn LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects information when you use Parsedit (“Service”), available at parsedit.com. By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Parsedit is operated by Cauldrn LLC, a limited liability company organized under the laws of the State of California, United States. We are not established in the EU or the UK. For privacy-related inquiries, contact us at privacy@parsedit.com. For general support, contact support@parsedit.com.
Controller vs processor. For account, billing, security logs, support tickets, and marketing (if any), Cauldrn LLC is the controller. For uploaded documents and extracted fields about third parties, you (the customer) are the controller and Cauldrn LLC is your processor. Processor terms, including the EU Standard Contractual Clauses (Module 2) and the UK Addendum, are in our Data Processing Addendum.
EU / UK GDPR Article 27 representatives. Because we are not established in the EU or the UK, GDPR and UK GDPR require an Article 27 representative where those laws apply. We plan to appoint DataRep for both the EU and the UK once mandates are signed. Until public contact details from the signed mandate pack are published, EU and UK data subjects and supervisory authorities should contact privacy@parsedit.com. DataRep (when appointed) is not our Data Protection Officer and is not an establishment of Cauldrn LLC in the EU or UK.
Placeholder fields below are not a street address and must not be treated as one:
The Service is focused on business document extraction for accounting and related workflows. Do not upload protected health information (PHI), medical records, or other healthcare-regulated documents. We do not offer a HIPAA Business Associate Agreement, and we do not claim HIPAA certification or “GDPR certification.”
We collect information you provide and information we obtain automatically:
drive.file scope to access only files you explicitly select or create through the Service.We use the information we collect to:
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
We do not use your documents, extracted data, or Google user data to train artificial intelligence or machine learning models.
To provide document extraction, uploaded files are transmitted to our document-processing provider for OCR and structured field extraction. This is a core function of the Service. We select providers that commit to appropriate data handling practices and use them only to provide the Service on our behalf.
We use the following categories of service providers (“sub-processors”) that process personal information on our behalf:
We may update our sub-processors from time to time. We require sub-processors to protect your data and process it only as instructed by us, consistent with this Privacy Policy and applicable law. The dated internal list is also maintained for operations; material additions are announced on about 14–30 days’ notice where practicable.
When you configure a destination or source integration, we send or receive data only as you direct. These third parties are not our sub-processors for your account data in the same sense; you choose to connect them and their use of your data is governed by their own terms and privacy policies. Integrations available in Parsedit include:
drive.file scope only; we do not request broad Drive access).Legacy workspace-gated options (Airtable export, Slack notifications) may appear when enabled; they are not part of the default integration set.
You may disconnect integrations at any time through the app or, for Google, through your Google Account permissions.
You may authorize third-party applications (such as Zapier) to access your Parsedit workspace through our OAuth authorization flow. When you approve a connection, the application receives access only within the scopes you grant, which may include:
account:read)parsers:read)documents:read)documents:write)webhooks:write)We access and transmit data through these connections only as you configure in Parsedit (for example, parser-scoped webhooks or document uploads). We do not sell this data, use it for advertising, or use it to train artificial intelligence or machine learning models.
You can revoke Parsedit OAuth access at any time from Integrations → Connected applications in the app. You should also disconnect or disable the application in the third party’s settings (for example, turn off related Zaps in Zapier).
Parsedit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you sign in with Google, we receive your name, email address, and Google account identifier to create and manage your Parsedit account. We use this information only for authentication, account management, and communicating with you about the Service.
When you connect Google integrations, we request the following OAuth scope:
https://www.googleapis.com/auth/drive.file — access only to files you explicitly open, select, or create through Parsedit (including spreadsheets you choose for export).We use Google user data solely to provide user-facing features you request:
We do not use Google user data for advertising, retargeting, or serving ads. We do not sell Google user data. We do not use Google user data to train artificial intelligence or machine learning models. We do not allow humans to read your Google user data except: (a) with your affirmative consent for a specific message or file; (b) for security purposes (e.g. investigating abuse); (c) to comply with applicable law; or (d) when the data is aggregated, anonymized, and used for internal operations in accordance with Google’s Limited Use requirements.
You may revoke Parsedit’s access to your Google account at any time through your Google Account permissions or by disconnecting the integration in Parsedit.
We may share information with:
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We retain information only as long as needed for the purposes in this policy, your plan, and the law. Different deletion paths apply to documents, parser/template configuration, plan changes, and account erasure. They are not the same.
The clock for documents is the document’s creation time (created_at), not last viewed. Your billing account’s plan applies to every workspace billed to that owner.
Documents and extracted data (processor content) become eligible for automatic deletion after the plan window, unless you delete sooner, a legal hold applies, or you export first:
In scope for the 60/365 plan purge (when enabled — see §8.6):
CSV/JSON download history (files you generate in-app) and DSAR export ZIPs are kept 7 days, then deleted. This is not plan-based.
The plan window does not delete:
Those items last for the account lifetime until you delete them in-app (see Deleting parsers and templates) or delete the account (see §8.4).
A 30-day grace and notice apply if you downgrade from a 365-day plan to a 60-day plan (including when a paid subscription ends and you return to Free), so you can export documents older than 60 days before they become eligible for deletion. Grace starts when the shorter retention window actually takes effect (for example when the subscription ends), not merely when cancellation is scheduled for period end. Downgrade does not by itself delete parsers, templates, destinations, or integrations.
You may delete your account in Settings (email one-time-code verification). Account deletion is intended to erase workspace content in production systems, including:
Immediate cascade: associated workspace rows and files tied to the account are removed as part of account deletion (not a deferred 30-day document cron). We then aim to clear residual personal information in logs and backups within about 30 days, except records we must keep:
free_credit_claims)Data already sent to destinations you configured (Google Sheets, QuickBooks, Xero, webhooks, etc.) is outside Parsedit; you must delete or manage copies there yourself.
Account owners (or members with settings permission) can place a workspace on legal hold so automatic document purge skips that billing account and its workspaces. Export / DSAR still works during a hold. Legal hold does not block voluntary user deletes of individual documents or parsers unless we are legally required to preserve specific records.
Enforcement of plan-based document deletion is rolled out after advance notice when we first enable it in production (feature flag). Until that date, treat the windows above as the contractual/policy period we apply going forward. Dry-run mode may list expired documents without deleting them.
This section describes customer-initiated deletion of parsers, field templates, and destinations inside the Service — separate from plan retention (§8.1) and account erasure (§8.4).
Deleting a parser permanently removes from the Service:
| Asset | Effect |
|---|---|
| Parser configuration | Deleted |
| Field template / field definitions | Deleted with the parser |
| Destination configuration for that parser | Deleted with the parser (cascade) |
| Destination secrets stored for those destinations | Deleted with the destination (cascade) |
| Documents under that parser (metadata + extracted fields) | Deleted from the Service database (cascade) |
| Destination delivery payloads for those documents | Deleted with the related documents |
| Processing jobs for those documents | Deleted with the related documents |
| Original files in object storage | Removed when document deletion / retention / account-deletion storage cleanup runs for those objects |
| Account-level integration connections (Google, Xero, etc.) | Not removed by parser delete — disconnect under Integrations if needed |
| Credits ledger / billing history | Not removed |
| Access-audit / retention-audit metadata | May retain ids and timestamps only (no file bytes, no extracted JSON) |
Deletion of a parser cannot be undone. Data already delivered to your destinations remains under your control at those third parties.
Downgrading or letting a subscription lapse does not delete parsers, templates, or destination configuration. Only the document retention window shortens (with the 30-day grace in §8.3).
We use industry-standard measures to protect your data, including:
You are responsible for keeping your password and account credentials secure. Use a strong, unique password and enable multi-factor authentication where available.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Cauldrn LLC and its hosting providers store and process Service data in the United States (including Supabase and Vercel). If you access the Service from the EEA, UK, or another region, your information is transferred to the United States.
For customer document processing (you as controller, Cauldrn as processor), transfers are governed by the EU Standard Contractual Clauses (2021) Module 2 and the UK IDTA / UK Addendum, as set out in our Data Processing Addendum.
Depending on your location, you may have the following rights regarding your personal information:
You may export a copy of your workspace data (account, members, parsers without secrets, documents and extracted fields, billing identifiers, integration provider/scopes without tokens) and delete your account in Settings, using email one-time-code verification. You do not need to email us first for those self-serve rights. For other requests, or if you cannot access the app, contact privacy@parsedit.com. Once Art. 27 representatives are appointed, you may also contact them using the published details in §1. We will verify your identity before fulfilling requests and respond within the timeframes required by applicable law.
If you are in the EEA or UK, our legal bases for processing include: performance of a contract (providing the Service), legitimate interests (security, improvement, fraud prevention), compliance with legal obligations, and consent where required (including optional analytics cookies). You have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides you with additional rights.
Categories of personal information we collect:
Your California rights:
Submit requests to privacy@parsedit.com. We will verify your identity before fulfilling requests. You may designate an authorized agent to submit requests on your behalf with appropriate authorization.
Notice at collection: We collect the categories described above for the purposes in this policy (providing the Service, security, support, billing, compliance). Retention periods are described in Section 8. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at privacy@parsedit.com and we will delete it promptly.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date. For material changes, we may notify you by email or through the app. Continued use of the Service after the effective date of changes constitutes acceptance. We encourage you to review this policy periodically.
For privacy-related questions or to exercise your rights, contact:
Cauldrn LLC (controller/processor, United States) Email: privacy@parsedit.com | support@parsedit.com
EU / UK GDPR Article 27 representatives — to be appointed (planned vendor: DataRep); not a DPO; not an establishment. Until details are published, use privacy@parsedit.com.