Legal document
Privacy Policy
What data ParseForMe collects, how it is used, and your rights over it.
Last updated 1 August 2026
1. Data we collect
Account data: your name and email address from the sign-in provider you choose, and the workspace you create.
Documents and extracted data: the files you upload for parsing and the structured data we extract from them.
Usage and billing data: basic logs needed to run the Service securely, and the record of your token purchases (payment card details are handled by Paddle, not by us).
Website analytics: when you visit our website we record page views and similar interactions in our own first-party analytics, together with a randomly generated visitor identifier stored in a cookie, the page you viewed, your device type, referrer, any campaign parameters in the link you followed, and an approximate location (country, region and city) derived from your IP address. We store a one-way, salted hash of your IP address — never the address itself.
2. How we use it
We use your data only to provide the Service: to parse your documents, let you review and export the result, meter and bill token usage, provide support, and keep the Service secure. We do not sell your data, and we do not use the contents of your documents to train models.
We use website analytics to understand how the site is used and to measure our advertising. With your consent we also share a limited set of conversion events (such as a sign-up or purchase) with Meta and Google so we can measure and improve those campaigns. The contents of your documents and the data extracted from them are NEVER used for analytics or advertising and are never shared for those purposes. (Exporting to your own Google Sheet is a different thing entirely: that is you instructing us to send your extracted data to a spreadsheet you own — see Sub-processors.)
2a. Cookies and your choices
We set a first-party cookie holding a random visitor identifier, and a cookie recording your consent choice. Neither identifies you personally.
If you are in the EEA, the UK or Switzerland, nothing is shared with Meta or Google until you accept in the consent banner, and you can decline with a single click. Elsewhere, sharing is enabled by default and you may decline at any time using the same banner. Declining stops the sharing; we keep our own first-party analytics either way, on the basis of our legitimate interest in operating and securing the site.
3. Sub-processors
Mistral AI — optical character recognition and document parsing. Your uploaded documents are sent to Mistral solely to extract data; they are the only third party that receives document contents without you asking us to send them.
Paddle — payments and Merchant-of-Record billing (name, email, and payment details you give at checkout).
Hetzner — cloud hosting (EU data centres) where the Service and your data are stored.
Cloudflare — the network layer in front of the Service. Every request to our site and API passes through Cloudflare, which processes connection data including your IP address.
Namecheap — email hosting. When we send you an account email, such as a low-balance warning or a notice that a batch has finished, it is relayed through their mail servers, which see your email address in order to deliver it. They never receive your documents or the data extracted from them.
Google — in two separate roles. First, if you connect your own Google account to export to Google Sheets, we send the extracted rows to that spreadsheet on your instruction; this happens only for exports you start, only to the sheet you choose, and you can disconnect at any time. Second, with your consent only, a limited set of conversion events for advertising measurement.
Meta — advertising measurement only, and only with your consent: a limited set of conversion events plus the coarse location and identifiers described above. Meta never receives your documents or the data extracted from them.
Authentication is self-hosted and is not shared with a third-party identity vendor. We give reasonable notice before adding a new sub-processor.
4. Data retention & deletion
Raw uploads are deleted immediately after a document is ingested — we do not keep the original files (a 24-hour lifecycle rule is a backstop). Extracted data and exports are kept in your workspace and are automatically deleted after 90 days.
You can delete your workspace and all of its data at any time from your account, or by contacting us. Deletion removes your documents, extracted data, and workspace records.
5. Your rights
If you are in the EEA or UK, you have the right to access, correct, delete, and port your personal data, and to object to or restrict certain processing. You can exercise access and deletion directly in the app, or by emailing [email protected]. You may also complain to your local data protection authority.
6. Security
Each workspace’s data is isolated at the database level so one customer can never read another’s. The component that processes documents holds no database or storage credentials. Data is encrypted in transit (TLS) and at rest, and access is restricted and logged.
7. International transfers
The Service and your documents are hosted in the EU (Hetzner, Germany), and document parsing (Mistral) is performed in the EU. Your data is stored in the EU and stays there.
We are established in Pakistan and administer the Service from there, which means your data is accessible to us from outside the EEA. Because that access is by us as the controller rather than a disclosure to a separate recipient, it is not a transfer to a third party — the data remains stored in the EU, and the GDPR continues to apply to how we handle it.
Payment data handled by Paddle may be processed outside the EEA under Paddle’s own safeguards (such as Standard Contractual Clauses or an adequacy decision).
8. Contact
Privacy questions or data requests: [email protected].