Legal
Privacy Policy
Effective Date: September 2, 2026
At Parlot, we take privacy seriously. This Privacy Policy explains how Nineth LLC (“Parlot,” “we,” “us,” or “our”) collects, uses, stores, and protects information when you use the Parlot website, dashboard, APIs, and related services (the “Service”), including early access via our waitlist.
1. Information We Collect
1.1 Account and organization information
When you join the waitlist, sign in, or create an organization, we collect information such as your email address and name (via our auth provider, Clerk), organization/workspace identifiers, and role memberships.
1.2 Customer observability data
When you instrument agents with Parlot SDKs or send data to our ingest endpoints, we process observability data you choose to send, which may include:
- Session, turn, span, and graph metadata (latency, handoffs, errors)
- Optional transcripts or textual content from agent runs
- Optional session audio/recordings when you enable recording
- Goal-eval and related scoring outputs
- API keys and integration configuration you create in the Service
You control instrumentation and content capture settings. Product features such as PII redaction and content opt-out are available so you can limit what is retained. On Parlot Cloud, we scrub structured identifiers at ingest and run transcript scrubbing at session close before storing previews and before sending text to LLM-based evaluators. Enabling fail-closed PII redaction for an agent additionally withholds turns and recording segments that cannot be redacted (they are not shown unredacted).
1.3 Technical and usage information
We automatically collect technical information needed to operate and secure the Service, such as IP address, browser or client user-agent, device/OS hints, request metadata, and diagnostic logs. On our marketing website (parlot.ai), we use Cloudflare Web Analytics to collect aggregate, cookieless site metrics such as page views and performance. That tool does not use cookies or localStorage, does not fingerprint visitors, and does not require an analytics consent banner.
1.4 Cookies
We use cookies and similar technologies that are necessary to operate and secure the marketing site (for example load balancing and abuse prevention). Marketing-site analytics via Cloudflare Web Analytics does not set analytics cookies.
1.5 Communications
If you email us or submit feedback, we collect the information you provide (such as email address and message content) and limited technical metadata used for abuse prevention and support.
2. How We Use Your Information
- Provide, operate, and improve the Service (dashboards, ingest, evals)
- Detect and redact personally identifiable information in Customer Content at ingest and session close (before durable analytics storage and before LLM-based evaluation), and withhold turns that cannot be fully redacted when you enable fail-closed PII redaction
- Run goal evaluation (including LLM-as-judge providers you enable or we configure)
- Authenticate users, manage organizations, and enforce plan limits
- Provide customer support and respond to legal@parlot.ai requests
- Secure the Service, prevent abuse, and diagnose outages
- Send service-related notices (for example early-access invites)
- Comply with law and enforce our Terms of Service
3. How We Store and Protect Data
We use reputable infrastructure providers and industry-standard controls, including TLS in transit and access controls for production systems. By default, customer data is scoped to your organization (org isolation). When a workspace member creates a session share link, the scoped session content for that link can be viewed by anyone with the URL until the link expires or is revoked.
Primary processors involved in operating Parlot Cloud include:
- Clerk — authentication and waitlist
- Cloudflare — edge, DNS, Workers, Web Analytics, and object storage (R2)
- Google Cloud — compute hosting for Parlot Cloud, and Google Sensitive Data Protection (Cloud DLP) to inspect Customer Content for PII during session-close scrubbing (always), with fail-closed withhold when you enable that policy for an agent
- Supabase — application database
- Tinybird — analytics/event store for observability pipelines
- LLM providers — goal evaluation when enabled (sampled by plan defaults)
Self-hosted deployments may keep redaction on your infrastructure (depending on configuration). Parlot Cloud uses Google Sensitive Data Protection by default for PII detection during session close.
No method of transmission or storage is 100% secure. We work to protect your data but cannot guarantee absolute security.
4. How We Share Information
Service providers are engaged to host and operate the Service and are expected to use information only to provide their services to us. When you create a session share link, recipients who have the link can view the session content you chose to share (subject to in-product scope, expiry, and revocation). We do not sell that data or use it for advertising. We may disclose information if required by valid legal process, to protect rights and safety, or in connection with a corporate transaction (with appropriate safeguards).
5. Retention
Retention of session analytics, graphs, and recordings depends on your plan and product settings (including free-tier and paid retention windows). We retain account and billing-related records as needed to operate the Service and meet legal obligations. You may request deletion as described below.
6. Your Privacy Rights
Depending on your location, you may have rights to:
- Access personal information we hold about you
- Correct inaccurate information
- Request deletion of personal information
- Export certain data (where the product supports export on your plan)
- Object to or restrict certain processing
To exercise these rights, contact legal@parlot.ai. We will respond within a reasonable period (typically within 30 days).
6.1 California (CCPA/CPRA)
If you are a California resident, you may have additional rights to know, delete, and correct personal information, and to non-discrimination for exercising those rights. We do not sell personal information. Contact legal@parlot.ai to submit a request.
7. Children’s Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact legal@parlot.ai.
8. International Data Transfers
Parlot is operated from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States and other countries where our providers operate.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date above and, where appropriate, provide additional notice. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
10. Contact Us
Questions about this Privacy Policy or our data practices:
Email:
legal@parlot.ai