Parlot
  • Product
  • Pricing
  • Docs
Sign in Request early access

Legal

Privacy Policy

Effective Date: September 2, 2026

At Parlot, we take privacy seriously. This Privacy Policy explains how Nineth LLC (“Parlot,” “we,” “us,” or “our”) collects, uses, stores, and protects information when you use the Parlot website, dashboard, APIs, and related services (the “Service”), including early access via our waitlist.

No data selling. We do not sell your personal information or customer session data. We do not share it with advertisers.

1. Information We Collect

1.1 Account and organization information

When you join the waitlist, sign in, or create an organization, we collect information such as your email address and name (via our auth provider, Clerk), organization/workspace identifiers, and role memberships.

1.2 Customer observability data

When you instrument agents with Parlot SDKs or send data to our ingest endpoints, we process observability data you choose to send, which may include:

  • Session, turn, span, and graph metadata (latency, handoffs, errors)
  • Optional transcripts or textual content from agent runs
  • Optional session audio/recordings when you enable recording
  • Goal-eval and related scoring outputs
  • API keys and integration configuration you create in the Service

You control instrumentation and content capture settings. Product features such as PII redaction and content opt-out are available so you can limit what is retained. On Parlot Cloud, we scrub structured identifiers at ingest and run transcript scrubbing at session close before storing previews and before sending text to LLM-based evaluators. Enabling fail-closed PII redaction for an agent additionally withholds turns and recording segments that cannot be redacted (they are not shown unredacted).

1.3 Technical and usage information

We automatically collect technical information needed to operate and secure the Service, such as IP address, browser or client user-agent, device/OS hints, request metadata, and diagnostic logs. On our marketing website (parlot.ai), we use Cloudflare Web Analytics to collect aggregate, cookieless site metrics such as page views and performance. That tool does not use cookies or localStorage, does not fingerprint visitors, and does not require an analytics consent banner.

1.4 Cookies

We use cookies and similar technologies that are necessary to operate and secure the marketing site (for example load balancing and abuse prevention). Marketing-site analytics via Cloudflare Web Analytics does not set analytics cookies.

1.5 Communications

If you email us or submit feedback, we collect the information you provide (such as email address and message content) and limited technical metadata used for abuse prevention and support.

2. How We Use Your Information

  • Provide, operate, and improve the Service (dashboards, ingest, evals)
  • Detect and redact personally identifiable information in Customer Content at ingest and session close (before durable analytics storage and before LLM-based evaluation), and withhold turns that cannot be fully redacted when you enable fail-closed PII redaction
  • Run goal evaluation (including LLM-as-judge providers you enable or we configure)
  • Authenticate users, manage organizations, and enforce plan limits
  • Provide customer support and respond to legal@parlot.ai requests
  • Secure the Service, prevent abuse, and diagnose outages
  • Send service-related notices (for example early-access invites)
  • Comply with law and enforce our Terms of Service

3. How We Store and Protect Data

We use reputable infrastructure providers and industry-standard controls, including TLS in transit and access controls for production systems. By default, customer data is scoped to your organization (org isolation). When a workspace member creates a session share link, the scoped session content for that link can be viewed by anyone with the URL until the link expires or is revoked.

Primary processors involved in operating Parlot Cloud include:

  • Clerk — authentication and waitlist
  • Cloudflare — edge, DNS, Workers, Web Analytics, and object storage (R2)
  • Google Cloud — compute hosting for Parlot Cloud, and Google Sensitive Data Protection (Cloud DLP) to inspect Customer Content for PII during session-close scrubbing (always), with fail-closed withhold when you enable that policy for an agent
  • Supabase — application database
  • Tinybird — analytics/event store for observability pipelines
  • LLM providers — goal evaluation when enabled (sampled by plan defaults)

Self-hosted deployments may keep redaction on your infrastructure (depending on configuration). Parlot Cloud uses Google Sensitive Data Protection by default for PII detection during session close.

No method of transmission or storage is 100% secure. We work to protect your data but cannot guarantee absolute security.

4. How We Share Information

✓ We do not sell personal information. We share data only with service providers who process it on our behalf, when you direct us to (for example exports or session share links), or when required by law.

Service providers are engaged to host and operate the Service and are expected to use information only to provide their services to us. When you create a session share link, recipients who have the link can view the session content you chose to share (subject to in-product scope, expiry, and revocation). We do not sell that data or use it for advertising. We may disclose information if required by valid legal process, to protect rights and safety, or in connection with a corporate transaction (with appropriate safeguards).

5. Retention

Retention of session analytics, graphs, and recordings depends on your plan and product settings (including free-tier and paid retention windows). We retain account and billing-related records as needed to operate the Service and meet legal obligations. You may request deletion as described below.

6. Your Privacy Rights

Depending on your location, you may have rights to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Request deletion of personal information
  • Export certain data (where the product supports export on your plan)
  • Object to or restrict certain processing

To exercise these rights, contact legal@parlot.ai. We will respond within a reasonable period (typically within 30 days).

6.1 California (CCPA/CPRA)

If you are a California resident, you may have additional rights to know, delete, and correct personal information, and to non-discrimination for exercising those rights. We do not sell personal information. Contact legal@parlot.ai to submit a request.

7. Children’s Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact legal@parlot.ai.

8. International Data Transfers

Parlot is operated from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States and other countries where our providers operate.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the Effective Date above and, where appropriate, provide additional notice. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

10. Contact Us

Questions about this Privacy Policy or our data practices:
Email: legal@parlot.ai

Parlot
  • Docs
  • Privacy
  • Terms
  • GitHub
  • Early access

© Parlot.ai