← Parley
Privacy Policy
See how Parley Notes keeps your conversations private.
Also: Terms of service · Legal notice · If you were recorded · Complaints · Delete your account
Last updated: 15 September 2026 · Applies to the Parley Android app, the Parley web app at app.parleynotes.com, the Parley browser extension for Chrome and Edge, and this website. Operated by Carbon Bridge Services B.V. ("we", "us"). This is the English text and it is the controlling version.
The short version
- Where your recording is transcribed depends on your device and your setting. On Android, if you have downloaded the on-device speech model and cloud transcription is switched off, the audio never leaves your phone. Otherwise, and that is the state of a new install until you download the model, the audio is sent over an encrypted connection to our backend in Belgium and on to our AI provider to be transcribed. In the web app and the browser extension, recordings are always transcribed in the cloud. You can see and change the phone setting in Settings.
- Your notes sync to your own space in our database when you sign in, so you can read them on another device. No other Parley user can read them unless you deliberately share a folder.
- We do not sell your data and it is never used to train an AI model, ours or anybody else's.
- You can delete everything with one button in the app, Settings then Delete all my data. That deletes your account too.
- Some of what Parley holds is sensitive. Your voice profile is biometric data. Your Journal mood, supplements and medication are health data. Both are optional, both are off until you switch them on, and this policy says exactly what happens to them.
- If you are in the United Kingdom, the UK GDPR protects you as well as the EU GDPR, you can complain to us directly and we must acknowledge it within 30 days, and you can complain to the Information Commissioner's Office. Section 1 has the details.
1. Who is responsible
Carbon Bridge Services B.V., registered in the Netherlands (KvK 42156684, VAT NL869964070B01), registered address George Gershwinlaan 517, 1082 MT Amsterdam, the Netherlands. Applicair is the name we publish Parley Notes under, on Google Play and elsewhere; it is not a separate company. Contact: admin@parleynotes.com, telephone +31 6 1151 4036, or write to us at the address above.
We have not appointed a Data Protection Officer. Privacy questions go to admin@parleynotes.com.
Who controls what. When you decide to record a conversation, you decide what is recorded and who is in the room, and for that decision you are the controller. You are responsible for telling the other people in the room that you are recording, where the law requires it, and the app reminds you of this before your first recording. We decide which AI models run, what the summary extracts, what is stored, where it is stored and for how long, and for those decisions we are the controller. If you use Parley for your business and you need a data processing agreement, write to us and we will send you one.
Which data protection law applies to you
We are established in the Netherlands and we have no office or branch anywhere else. Because of that, the EU General Data Protection Regulation applies to everything we do with personal data, wherever you are (Art. 3(1) GDPR). Depending on where you are, a second law applies on top of it.
- If you are in the European Economic Area, including the Netherlands, Ireland and Spain, the GDPR is the whole answer. Because we are established in the Netherlands, our lead supervisory authority is the Autoriteit Persoonsgegevens, under Art. 56 GDPR. You can complain to it, or to the authority in your own country instead. In Ireland that is the Data Protection Commission and in Spain it is the Agencia Española de Protección de Datos.
- If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to you as well, because we offer Parley to people in the UK (Art. 3(2) UK GDPR), and your supervisory authority is the Information Commissioner's Office. See the block below.
- If you are in Brazil, the Lei Geral de Proteção de Dados applies to you as well, and the Portuguese page at parleynotes.com/pt/privacidade is written for you under that law. Where the two pages differ, the Portuguese page governs for Brazil.
The rights this policy describes are the same either way. Where we cite an article of the GDPR, the same article number applies under the UK GDPR unless we say otherwise. The two laws differ in two places that matter here, automated decisions (section 11) and transfers out of the country (section 13), and the UK adds a complaints route of its own (section 1 and section 18). Everything else reads the same.
If you are in the United Kingdom
Complaining to us. Since 19 June 2026, s. 164A of the Data Protection Act 2018, inserted by s. 103 of the Data (Use and Access) Act 2025, gives you the right to complain to us directly if you think we have processed your personal data in a way that breaches data protection law. To do that, write to admin@parleynotes.com and put the word "complaint" in the subject line, so it is not read as an ordinary support question. Tell us what happened, when, and what you want us to do. We will acknowledge your complaint within 30 days of receiving it, which is what that section requires. We will then look into it without undue delay, in a way that is proportionate to what you have raised, keep you informed while we do, and tell you the outcome. You do not have to complain to us before going to the regulator, and complaining to us does not stop you going to the regulator afterwards.
Complaining to the ICO. Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Online at ico.org.uk/make-a-complaint, or by telephone on 0303 123 1113.
2. Your recordings: where the audio actually goes
This is the part people most want a straight answer on, so here it is in full.
On the Android app
There are two paths and the app tells you which one you are on.
- On device. If you have downloaded the on-device speech model and cloud transcription is switched off in Settings, the recording is transcribed and split into speakers on your phone. The audio stays in the app's private storage and no server of ours receives it. Only the resulting text transcript is sent to our backend to be written up.
- In the cloud. If the on-device model is not downloaded, which is the state of a new install, or if you switch cloud transcription on, the audio file itself is sent over an encrypted connection to our backend on Google Cloud Run in Belgium, and from there to our AI provider to be transcribed and written up. We do not keep the audio after the transcript comes back. The finished write-up, including the transcript, is held for 24 hours as described in section 11.
The recording stays in your phone's private app storage until you delete the meeting, or automatically after the write-up if you have turned off "keep audio" in Settings. Recordings and voice profiles are excluded from Android's automatic backup to Google Drive, so they do not leave the phone that way.
In the web app and the browser extension
There is no on-device option in a browser. A recording you start in the web app, and a call the extension captures from the browser tab you choose, are always uploaded to our backend and transcribed in the cloud on the path described above. In the extension this captures everyone on the call, not just you; the extension says so, and reminds you that telling them is your responsibility, before its first recording, and the web app does the same before yours.
Large recordings
A recording too large to send in a single request is staged in our AI provider's file store first, we ask for it to be deleted as soon as the transcript comes back, and the provider expires it automatically within 48 hours in any case. Our delete request is best effort: if it fails, the file still expires within 48 hours.
Google Drive backup
If you turn on recording backup, in the web app or on the phone, a copy of each recording is uploaded to a "Parley Recordings" folder in your own Google Drive. That is a second way audio leaves the handset, into storage you own. It is off until you turn it on.
3. Voice profiles
A voice profile, or voiceprint, is a mathematical fingerprint of a voice. It is biometric data, and both European and UK law treat it as a special category, so it is off until you switch it on.
- We create a voice profile of you and of nobody else. If you enable speaker recognition, you record a short sample of your own voice in Settings and a voiceprint is created from it on your phone. Parley can then label your turns in later recordings.
- Other speakers are never enrolled. Naming a speaker in a transcript labels that transcript. It does not create a voiceprint of that person and it does not teach Parley to recognise them later. Other people are named from what is said in the conversation and from the names on your calendar invite, not from their voice.
- Your voice profile stays on the phone. It is not uploaded, it is not synced, and it is excluded from Android's automatic backup. It does not follow your account to a new phone: on a new phone you record the sample again. You can delete it in Settings at any time, and Delete all my data removes it.
- The legal basis is your explicit consent under Art. 9(2)(a) GDPR, or Art. 9(2)(a) UK GDPR if you are in the United Kingdom, given on the screen where you enrol. You can withdraw it at any time by deleting the profile in Settings.
4. Your notes, and what we store in your account
If you sign in, the following is stored in your own space in our database and is readable only by your signed-in account:
- Notes: transcripts, summaries, action items, decisions, open questions, participant names, folders, tags and your app settings.
- Account: if you sign in with Google we receive your name, email address and Google account identifier through Firebase Authentication. If you sign in with an email address and a password, we hold the email address and Firebase holds the password in hashed form. We never see your password.
- People: the names of people who appear in your meetings, so Parley can spell them consistently and answer questions about them.
- Ask Parley: your saved question and answer threads.
Notes are stored in Google Cloud Firestore in the EU, and are encrypted at rest by Google Cloud. They are not encrypted with a key that only you hold, so as the operator of the database we are technically able to read them. We do not, except where you ask us to for support, where security requires it, or where the law requires it.
One part of your account is encrypted on your device before it is stored, so that even we cannot read it: the private memory Parley keeps about you for Ask Parley.
5. Health data in the Journal
The Journal holds data about your health, and that is a special category under Art. 9 GDPR and under Art. 9 UK GDPR. We treat it accordingly.
- What it is: the mood you tap, a mood word that Parley's AI infers from a journal recording, the supplements and medication you log, and, in a recording you file under a health occasion (a doctor visit, for example), the symptoms, tests, treatment, and medicines with their doses that Parley picks out of what was said.
- Two separate yes buttons. The first time you choose a health occasion for a note, Parley asks for your explicit consent before it extracts any of that; until you say yes, the note gets a plain summary and the app does not classify a recording as medical on its own. The first time you save a mood check-in, a supplement or a medication while signed in, Parley asks separately whether the Journal may keep a copy in your account. Each answer is recorded with the date and the text you saw, and each can be changed later.
- Where the Journal goes: nowhere but your device, unless you say yes to the account copy. Say yes and your mood check-ins, supplements and medication list are stored in your account so they come back on a new phone and appear in the web app. It is off until you switch it on, and it stays off if you never answer. The legal basis is your explicit consent under Art. 9(2)(a) GDPR, or Art. 9(2)(a) UK GDPR in the United Kingdom, asked for on a screen that says so.
- Say no and the Journal still works in full on that device. It just will not follow you to a new phone or to the web app.
- Withdrawing: one switch in Settings turns the sync off, and a separate action in Settings deletes the copies already in your account. Delete all my data removes them too.
- The mood word is inferred by an AI model from what you said. It is a guess, not a measurement, and it is not a clinical assessment. What Parley extracts from a note you filed under a health occasion is part of that note: it follows the note into your account when you sync, like any other note, and it is deleted with the note. It is never included when a note is shared into a folder.
- Health data is never used to train anything and never sold. A health note is never shared into a folder: a note Parley wrote with health details switched on, and any note filed in a folder analysed as medical, stays private even inside a shared folder, and a folder analysed as medical cannot be shared at all. The Journal is never shared either. Without health details switched on, Parley writes a doctor visit as an ordinary personal note with no health sections, and it is shared like any other note in the folder you put it in; Parley does not run a separate check for health topics, because that check would itself process health data you have not agreed to.
6. Shared folders
You can share one of your folders with other Parley users through an invite code. A folder holds up to 25 members. This is the one case where somebody else can read something of yours, and it only happens because you chose it.
- What a member sees: the note's title, date and length, the summary, topics and tags, decisions, action items, open questions, checklists, insights, key takeaways, commitments, next touchpoints, the glossary, and the display names of the participants.
- What never travels: the audio, the verbatim transcript, your voice profile, the health sections of a note, your medication and supplement entries, and your mood check-ins.
- Leaving and revoking: the folder owner can revoke an invite code and remove a member, and any member can leave. Removing a note from the folder removes it for everyone.
- The legal basis is your consent, given by the act of sharing, Art. 6(1)(a) GDPR and Art. 6(1)(a) UK GDPR.
7. Optional connections
Each of these is off until you connect it, and each can be disconnected in Settings, which revokes the grant at the provider.
- Gmail (send only): Parley can email a summary from your own address. The scope is send-only, so we cannot read your inbox.
- Google Calendar and Outlook Calendar: Parley reads your upcoming events so it can offer to record them and can use the invitee names to spell speakers correctly, creates the events you approve, and reads a narrow time window when you ask it to check whether a slot is free.
- Google Meet: Parley fetches the transcripts of Meet calls you attended where transcription was enabled, and files them as meetings.
- Microsoft Teams: Parley fetches the transcripts of Teams calls you attended, and files them as meetings.
- Google Drive: the recording backup described in section 2. Parley uses Google's narrowest Drive permission, drive.file, which can only see files Parley itself created.
- Slack: react to a Slack message with the memo emoji and Parley turns that thread into a note. To do that, Slack grants Parley permission to see which messages you reacted to, to read the thread, and to look up display names. The permissions cover public channels, private channels, direct messages and group direct messages, because a thread you react to could be in any of them. Parley reads a thread only when you react to it. The thread text is sent to our AI provider to be summarised, and the summary is stored as a note in your account. Nothing is ever posted to Slack on your behalf. Disconnecting revokes the token at Slack.
- Email to Parley: you can be given a private forwarding address at in.parleynotes.com. Mail you forward there is parsed into the individual messages of the thread, summarised, and stored as a note that Ask Parley can search. The people who appear as senders or recipients in the forwarded chain are stored as participants of that note. Only your own address, and senders you explicitly add, may write to it. Our email provider, Resend, receives that mail on our behalf.
Where the keys are kept. This is worth being precise about, because it differs by surface.
- On the Android app, the Google connections run on the device: short-lived access tokens are minted on the phone, and no refresh token, password or client secret for those connections reaches us.
- For the web app's Google connection, and for Microsoft and Slack on every surface, we hold that connection's refresh token on our servers, encrypted at rest with AES-256-GCM under a key we control. We do this so that Parley can build your agenda and fetch your call transcripts when no Parley app is open. Tokens are used only by our backend to run the features you connected, are never returned to a client, and never appear in logs.
- Disconnecting in Settings revokes the grant at the provider and blocks the stored copy, including against a second device of yours that still holds its own.
8. Payments
- On the web, subscriptions are handled by Stripe. Stripe receives your email address and an account identifier, and holds the card details. We never receive or store your card number.
- On the phone, subscriptions are handled by Google Play. Google gives us a purchase token and the state of your subscription so we can unlock the right plan. We never see your payment method.
- The legal basis is performance of the contract with you, Art. 6(1)(b) GDPR and Art. 6(1)(b) UK GDPR. Billing and invoice records are kept for seven years to satisfy Dutch tax law, which applies to us as a Dutch company wherever you live, and which is an exception to "kept until you delete it" below.
9. Analytics we run ourselves
The apps contain no third-party analytics or advertising SDK. We measure the product with our own backend, and here is exactly what that means.
- Install record: a random install identifier generated on the device, the referrer that brought the install, the platform and the app version. Not your IP address, not a device identifier. After you sign in of your own accord, your account identifier is attached to that install record so we can tell whether a paid install became a user.
- Product events: the name of an event from a fixed vocabulary of eleven, plus the platform and that install identifier. The list is: app opened, recording started, recording completed, summary completed, share used, subscribe clicked, recording blocked because no model, model prompt shown, model download started, cloud default adopted, recording blocked because signed out. Never a title, never content.
- The legal basis is our legitimate interest in knowing whether the product works and where our marketing money goes, Art. 6(1)(f) GDPR and Art. 6(1)(f) UK GDPR. You can object at any time by writing to us.
- This website is different from the apps and it would be wrong not to say so on the page you are reading. If you accept the cookie banner, it loads Google's tag for Google Analytics and Google Ads conversion measurement; until you accept, that script is not even downloaded. Vercel Web Analytics counts page views without cookies and runs whether or not you accept; in the United Kingdom that rests on the statistical-purposes exception the Data (Use and Access) Act 2025 added to regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. None of them can see your notes, your recordings or your account. Storing or reading anything on your device for Google's tag needs your consent, under the national rules implementing the ePrivacy Directive in the EEA and under regulation 6 PECR in the United Kingdom. You give or refuse that consent in the banner, and you can change your answer from the "Cookie choices" link in the footer.
10. How Parley uses Google user data
Parley's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
- Sign in with Google (basic profile). What we access: your name, email address and Google account identifier. How we use it: to create and secure your Parley account and keep your notes private to you. Storage: held by Firebase Authentication for as long as your account exists, deleted when you delete your account. Sharing: none.
- Send email on your behalf (gmail.send). What we access: nothing, this permission only allows sending. How we use it: to send the email you composed and confirmed, from your own address. Storage: the message is handed to Gmail for delivery and is not stored by us. Sharing: none.
- Drive files created by Parley (drive.file). What we access: only files Parley itself created, nothing else in your Drive. How we use it: to keep a backup copy of your recordings, from the web app and from the phone, in a "Parley Recordings" folder in your own Drive, and to play one back when you ask. Storage: the files live in your Drive, not on our servers. Sharing: none.
- Calendar events (calendar.events). What we access: your upcoming events, including the names and email addresses of the people invited, so Parley can offer to record a meeting and spell its participants correctly; plus a specific time window when you ask it to check your availability. How we use it: to build your agenda, create events you approve, and answer availability questions. Storage: the upcoming agenda is mirrored into your account so it is there when no app is open; availability answers are transient. Sharing: none.
- Google Meet conference records (meetings.space.readonly). What we access: the conference records and transcripts of meetings you attended, from your own account. How we use it: to import those transcripts as meetings and generate your summaries. Storage: stored like your other notes and deletable at any time. Sharing: none.
For all Google user data: we do not sell it; we transfer it to third parties only as necessary to provide the feature you asked for (see section 12), to comply with the law, or as part of a merger or acquisition with prior notice to you; no human at Carbon Bridge Services reads it except with your explicit permission for support, for security purposes, or where the law requires it; and we never use it for advertising.
11. AI processing, and who processes it
Your data is never used to train AI. No data of yours, and no Google user data (raw, aggregated, anonymised or derived), is used by us, or transferred to anyone else, to create, train or improve machine-learning or artificial-intelligence models of any kind.
- On the phone, offline: speech-to-text, speaker separation and voice recognition can run entirely on your phone using models you download. What they process stays on the device and is never transmitted back to the model providers.
- In the cloud: transcription of uploaded audio, the written summary, the extracted action items, the inferred mood word and the answers Ask Parley gives are produced by our AI provider, which our backend calls as a paid service. The provider acts as our processor. Under its terms for paid services, it does not use these prompts or responses to train or improve its models.
- A search model on our own servers: so that Ask Parley can find the right note, our backend runs a small open-source model that turns each note into a numeric index. That model runs on our own backend and nothing leaves it for this step.
- What the AI writes is a machine's summary of a recording. It can be wrong, and it is not a decision about you. Parley makes no automated decision that produces legal effects for you or similarly significantly affects you. That is Art. 22 GDPR in the EEA. In the United Kingdom the same question is governed by Arts. 22A to 22D UK GDPR, which replaced Art. 22 on 5 February 2026, and our answer is the same: Parley makes no significant decision about you, so the safeguards those articles require are not engaged. If we ever build a feature that does, we will say so here first, and we will give you a way to ask for a human to look at it and to contest the result.
- The 24 hour cache. When a recording is written up, the finished result, including the transcript, is stored on our backend in the EU for 24 hours. It exists so that if the reply is lost on a bad connection your phone does not have to upload the same recording again, and so you are not charged twice for the same work. After 24 hours it is deleted. Delete all my data removes it immediately.
- Marked as AI-written. Every summary, action item and insight Parley writes is marked as generated by AI, in the note itself and in every memo, email and shared copy that leaves the app, as Art. 50(2) of the EU AI Act requires. The transcript is not marked, because it is a transcription of what was said rather than something the model made up.
- No other AI providers: we do not send your data to any other third-party AI service.
12. Who else touches your data
| Who | What they do for us | What they receive | Where |
| Google Cloud (Cloud Run, Firestore, Firebase Authentication) | Runs our backend, stores your notes, holds your sign-in | Everything you sync, your account identity | EU, Belgium (europe-west1) |
| AI provider | Transcribes audio, writes summaries, answers Ask Parley | The audio or the transcript of the recording being processed | Worldwide, see section 13 |
| Google Drive | Optional recording backup, in your own Drive | Your recordings, if you enable it | Google, your account |
| Google Play | Phone subscriptions | Your purchase, tied to your Google account | Google, EU and US |
| Stripe | Web subscriptions | Your email address, an account identifier, your card details | EU and US |
| Resend | Sends our emails to you, and receives mail you forward to Parley | Your email address, and any mail you forward | US |
| Microsoft | Teams and Outlook Calendar, if you connect them | The calls and events you asked Parley to fetch | Microsoft, EU and US |
| Slack | Slack threads, if you connect it | The threads you react to | US |
| Vercel | Hosts this marketing website | Website visits only, never your notes | EU and US |
We have a data processing agreement with each of them. Write to admin@parleynotes.com for the current list and the safeguard that covers each transfer. Our UK representative (section 1) is not on this list because they process nothing for us: they receive what you choose to send them and pass it on.
13. Data outside Europe
Your notes are stored in the EU. Two things cross the border and we would rather name them than leave you to guess.
- The AI step. Our backend calls our AI provider on a global endpoint. We do not pin it to a region, so the audio or transcript being processed may be handled in any country where the provider maintains facilities, including outside the EEA, and may be cached there transiently. This applies to the audio itself, not only the text, whenever transcription runs in the cloud. The transfer is covered by the provider's data processing terms, which carry the EU Standard Contractual Clauses, and by its certification under the EU-US Data Privacy Framework. You can ask us for a copy at admin@parleynotes.com.
- Some of our suppliers are in the United States, as marked in the table above. Those transfers rest on the same kind of safeguard.
If you are in the United Kingdom
The UK asks a separate question and answers it with its own paperwork, so here is the UK position on its own terms.
- From the UK to the EU. Your notes are stored in the EU. The UK has made adequacy regulations covering every country in the European Economic Area, so sending your data from the UK to our backend and database in Belgium is a transfer to an adequate country and needs no extra instrument.
- From the UK to the United States and elsewhere. For the suppliers marked US in the table above, and for the AI step, which is not pinned to a region, we rely on one of two things for each recipient. Either the UK Extension to the EU-US Data Privacy Framework, the UK-US data bridge, where the recipient is certified under the Framework and is specifically enrolled in the UK Extension, which we check rather than assume. Or the ICO's International Data Transfer Agreement, or the ICO's Addendum to the EU Standard Contractual Clauses where those clauses already exist, together with a transfer risk assessment. Since 5 February 2026, when s. 85 and Sch. 7 of the Data (Use and Access) Act 2025 amended Chapter V of the UK GDPR, that assessment asks whether the protection for your data in the destination country is not materially lower than it would be under UK law.
- For each of those recipients we rely on the UK Addendum to the EU Standard Contractual Clauses that their data processing terms carry, and, where the recipient is certified under the UK Extension to the Data Privacy Framework (Google, Microsoft, Stripe, Slack and Vercel are), on that certification as well.
Write to admin@parleynotes.com and we will tell you which instrument covers a given supplier and send you a copy of it.
14. How long we keep things
| What | How long |
| Your notes, transcripts, folders and settings | Until you delete them or delete your account |
| Recordings on your phone | Until you delete the meeting, or automatically after the write-up if "keep audio" is off |
| Your voice profile | On the phone, until you delete it or delete the app |
| Journal mood, supplements and medication | Until you delete them, switch health sync off and remove the copies, or delete your account |
| The finished write-up cached on our backend | 24 hours |
| Large audio staged with our AI provider before transcription | Deleted as soon as the transcript returns, and in any case within 48 hours |
| Server logs | 30 days |
| Install and product event records | Until you delete your account |
| Billing and invoice records | 7 years, required by Dutch tax law |
| A complaint you make to us, and our answer | 3 years, so that we can show how the complaint was handled. This is the complaints log s. 164A of the UK Data Protection Act 2018 expects, and we keep it the same way for everybody. |
| Record that you gave consent | Kept after account deletion, as proof we were allowed to process what we processed |
Delete all my data, in Settings, erases your local data, your cloud space and your Parley account itself, including the sign-in record, and revokes your connected integrations. The only things that survive are the billing records, the complaints records and the consent records named above, which we are required or entitled to keep. You can also email us to ask for deletion, and parleynotes.com/delete-account explains both routes.
15. Why we are allowed to process each thing
The article numbers below are the same under the EU GDPR and under the UK GDPR, so this one table serves both. Read "GDPR" as "UK GDPR" if you are in the United Kingdom.
| What we do | On what basis |
| Create and secure your account, sync your notes, transcribe and summarise your recordings, run Ask Parley | Performance of our contract with you, Art. 6(1)(b) GDPR |
| Take your subscription payment and keep the invoice | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c), for the tax records |
| Connect Gmail, Calendar, Drive, Meet, Teams, Slack or an inbound email address | Your consent, Art. 6(1)(a), withdrawable in Settings |
| Share a folder with other Parley users | Your consent, Art. 6(1)(a) |
| Create a voice profile of you | Your explicit consent, Art. 9(2)(a) |
| Store your Journal mood, supplements and medication in your account | Your explicit consent, Art. 9(2)(a) |
| Hold the personal data of other people who appear in your recordings, invites and forwarded emails | Our legitimate interest in giving a participant an accurate record of a conversation they took part in, Art. 6(1)(f). See section 17. |
| Measure installs and product events, and keep our marketing honest | Our legitimate interest in knowing whether the product works, Art. 6(1)(f) |
| Keep crash and error logs, and defend against abuse | Our legitimate interest in a working, secure service, Art. 6(1)(f) |
| Website analytics and advertising measurement | Your consent, given in the cookie banner, Art. 6(1)(a), and in the United Kingdom also reg. 6 PECR |
| Handle a complaint you make to us about your data | Legal obligation, Art. 6(1)(c) UK GDPR with s. 164A Data Protection Act 2018, for UK users. For everybody else, our legitimate interest in answering you properly, Art. 6(1)(f) |
Providing your data is not a statutory requirement. It is what the service needs in order to work: without a recording there is nothing to transcribe, and without an account there is nothing to sync to.
16. How we protect your data
- Encryption in transit: every connection between the apps, our backend and our suppliers uses HTTPS and TLS.
- Encryption at rest: your notes are encrypted at rest by Google Cloud. Connector refresh tokens held on our servers are separately encrypted with AES-256-GCM under a key we control. Your private Ask Parley memory is encrypted on your device before it is stored.
- Per-user isolation: database rules mean only your signed-in account can read or write your data. There is no public access path.
- Least permission: we ask each provider for the narrowest permission that makes the feature work, and we do not ask for permission to read your mailbox.
- Deletion controls: delete any meeting, disconnect any integration, delete your voice profile, remove the health copies from your account, or erase everything.
- Incident response: if a breach affecting your personal data occurs, we will notify you and the competent authority as Art. 33 and Art. 34 require. That is the Autoriteit Persoonsgegevens under the GDPR, and the Information Commissioner's Office under the UK GDPR where UK users are affected.
17. If you were recorded and you are not a Parley user
Somebody may have recorded a conversation you took part in. If so, your name, what you said, and any commitment or action item attributed to you may sit in that person's Parley account, and may appear in a summary they share with their team. A short version of this section, written for you, is at parleynotes.com/recorded.
The person who made the recording decided to make it. We hold the result on their behalf and we also decide how it is processed, so you have rights against both of us. You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to it. Write to admin@parleynotes.com with enough detail to find you, such as the name you were recorded under and, if you know it, who made the recording. We will act within one month.
If you are in the United Kingdom, those rights are the same under the UK GDPR, you can complain to us under s. 164A of the Data Protection Act 2018 and we will acknowledge that complaint within 30 days, and you can complain to the ICO.
Two honest limits. We cannot search inside every verbatim transcript for a passing mention of you, and where a voice profile exists it exists only on somebody's phone, where no search of ours can reach it. We will tell you what we could and could not do.
18. Your rights
Under the GDPR, and under the UK GDPR if you are in the United Kingdom, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to you in a portable form, or object to processing we base on legitimate interest. Where we rely on your consent, you can withdraw it at any time, and withdrawing it does not affect what we did before.
Inside the app you can delete a meeting, disconnect an integration, delete your voice profile, remove your health data from your account, download a copy of everything Parley holds about you as one file (Settings, then Download my data), and erase everything with Delete all my data. For correction or an objection, or for a copy in another form, email admin@parleynotes.com and we will answer within one month. If your request is complicated, or if you have made several, we can extend that by two months and we will tell you if we do. If we need to check who you are, or if we genuinely cannot tell what you are asking for, we will ask you, and in the United Kingdom the clock pauses while we wait for your answer.
You can also complain to a supervisory authority.
- In the EEA: ours is the Autoriteit Persoonsgegevens in the Netherlands, and you can go to it, or to the authority in your own country, such as the Data Protection Commission in Ireland or the Agencia Española de Protección de Datos in Spain.
- In the United Kingdom: the Information Commissioner's Office, at ico.org.uk/make-a-complaint. You can also complain to us first, and we have to acknowledge it within 30 days. Section 1 explains how.
19. Children
Parley is not for children. Wherever you are, you must be at least 16 to use Parley. We have deliberately set one minimum age rather than one per country, and we set it at the highest age the law uses across the places we operate, so the rule is the same for everybody.
For completeness, because it is what people usually want to know: the age at which somebody can consent for themselves to an online service, rather than needing a parent to do it, is set by national law and it differs. It is 16 in the Netherlands and Ireland, 14 in Spain, and 13 in the United Kingdom under Art. 8(1) UK GDPR. In Brazil the LGPD requires a parent's specific consent for a child under 12 and treats everyone under 18 with extra care, and Lei 15.211/2025 adds duties for services that minors use. Our own rule of 16 is stricter than the law in several of those places, on purpose.
If we learn that an account belongs to somebody younger, we will delete it.
20. What we never do
- We never sell your data, and we never share it with anybody for advertising.
- We never use your data, including any Google user data, to train AI models, ours or anyone else's.
- We never read your mailbox. Parley can send an email from your address and can read a thread you forward to it, and nothing more.
- The Parley apps show no ads and contain no third-party ad or tracking SDK. This website is the exception and section 9 says exactly what it loads.
21. Changes
If we change this policy we will update this page and, for material changes, tell you in the app before they take effect.