Security
Parse processes the documents you send and returns structured data. Security and privacy are defaults here, not add-ons. This page explains how we handle your files and the data we extract from them.
Encryption
All data is encrypted in transit (TLS) and at rest. Your uploaded files are never stored in plaintext.
File deletion and data retention
- Uploaded files - the documents you send for extraction - are automatically deleted within 24 hours of processing.
- Extracted results are stored in your account so you can view your history and re-export them as CSV or Excel. You can delete any extraction at any time, from your dashboard or through the API.
We never keep your documents longer than needed to run the service.
No AI training on your data
Your documents and the data we extract are never used to train AI models - not by Parse, and not by the AI providers that power extraction. We use commercial API plans on which the providers do not train on the content we send.
Infrastructure
Parse runs on hardened, access-controlled infrastructure. Uploaded files are stored on our own servers, not third-party object storage, and access is limited to the systems required to provide the service.
Data residency
Need your data processed in a specific region (for example, EU-only)? Contact us and we will discuss residency requirements for your account.
Sub-processors
We rely on a small set of vetted sub-processors for AI processing, cloud infrastructure, and payments (Paddle, our Merchant of Record). The complete, named list is available to customers under our Data Processing Agreement. We give advance notice before adding a new sub-processor, and you have the opportunity to object.
GDPR and your data rights
Parse is built for GDPR compliance. If you process personal data through Parse, we offer a Data Processing Agreement (DPA) - contact us to put one in place. You can access, export, and delete your data at any time.
Data Processing Agreement
If you process personal data through Parse, we sign a GDPR Article 28 Data Processing Agreement with you. It names our sub-processors, turns the technical and organisational measures described on this page into contractual commitments, and covers international data transfers. A signed DPA is included on every paid plan.
Request a DPABreach notification
If a personal data breach affects data we process for you, we notify you without undue delay and within 72 hours of becoming aware of it, with the detail required under Article 33(3) of the GDPR: what happened, which data is involved, the likely consequences, and what we are doing about it.
Certifications, and what we do not have
Parse does not hold SOC 2 or ISO 27001 certification. We would rather say that plainly than imply otherwise: the controls described on this page are the ones we actually run, and we will explain any of them in as much detail as your review needs. If your procurement process uses a security questionnaire, send it over and we will complete it.
Responsible disclosure
If you believe you have found a security vulnerability, please email info@conversiontools.io. We appreciate responsible disclosure and will respond promptly.