Back

Privacy Notice

Last updated: August 23, 2026

1. Scope

This notice explains how Parallel collects, uses, shares, and retains personal information when you create an account, use the web product, buy a subscription, contact support, or request account deletion.

2. Information We Collect

  • Account and eligibility data: email address, display name, account ID, exact date of birth, over-18 attestation, email-verification state, and account status.
  • Authentication and security data: password hash, hashed session and verification tokens, login attempts, session timing, IP address, browser or device information, and security events. We do not store your password or raw session tokens.
  • Legal acknowledgments: policy names and versions, server-recorded acceptance times, the surface where you accepted, and recurring-billing authorization.
  • Billing and entitlement data: selected plan, payment and entitlement state, paid-through date, and Stripe customer and subscription identifiers. Stripe, not Parallel, receives and processes full card details.
  • Product content: messages and other content you intentionally submit, plus the service state needed to preserve and display that content.
  • Support and deletion data: support requests, reports, cancellation and deletion requests, workflow state, and the minimum data needed to provide a final deletion receipt.
  • Diagnostics: error reports, logs, request timing, and limited technical information used to secure and operate the service.

3. How We Collect and Use Information

We collect information from you, your browser or device, authentication and payment providers you choose, and the systems that operate Parallel. We use it to:

  • create and secure accounts, verify email, enforce the 18+ boundary, and manage sessions;
  • provide the paid product, store and deliver requested content, and maintain continuity;
  • process subscriptions, confirm entitlement, prevent another charge after cancellation or deletion, and maintain required billing records;
  • record required policy acknowledgments and enforce our Terms and Behavior Expectations;
  • detect abuse, investigate failures, protect customers and the service, and answer support requests; and
  • comply with applicable law and valid legal process.

4. Service Providers and Disclosures

We disclose only the information reasonably needed for providers to perform work for us or to complete a feature you request. Current categories include:

  • Stripe: web checkout, subscription, invoice, and payment processing. See Stripe's Privacy Policy.
  • Authentication and email providers: Google or Apple when you choose their sign-in method, and our transactional email provider for verification and security messages.
  • Hosting and data infrastructure: providers that host the PWA, API, databases, durable workflows, storage, and retrieval systems.
  • Reliability and security providers: services used for error monitoring, fraud prevention, rate limiting, and operational support.
  • AI and media providers: only when needed to process a product feature you invoke. The specific provider can vary by feature and service configuration.

We may also disclose information when required by law, to protect people or the service, or as part of a business transaction subject to appropriate safeguards. We do not sell personal information for money or use cross-context behavioral advertising. We do not use private messages to build advertising profiles.

5. Storage and Security

Account data is stored in production data systems used by the Consumer service. Passwords use a one-way password hash. Authentication and verification tokens are stored as hashes where the service design permits it. We use encrypted network transport, access controls, session rotation, rate limits, and environment separation. No online system can guarantee absolute security.

Parallel and its providers may process information in the United States and other locations where they operate. Cross-border handling is subject to applicable law and provider safeguards.

6. Cookies and Browser Storage

The web product uses essential authentication and security cookies. The refresh token is held in an HttpOnly cookie so website scripts cannot read it; the active access token is kept in memory. A non-remembered session uses a browser-session cookie and has a server-enforced limit of 24 hours. If you choose Stay signed in, the session has a seven-day idle limit and a 30-day absolute limit. Step Out revokes the current server session and clears Parallel-owned browser state after the server confirms logout.

We may use local browser storage for product preferences and cached application state. Essential cookies are required for account security and do not need an advertising-cookie choice. We will add a regional consent choice before using any nonessential analytics or advertising cookies that require one.

7. Browser and Device Permissions

Optional permissions, such as microphone, camera, notifications, or media access, should be requested only when you invoke the feature that needs them. You can deny or revoke those permissions in your browser or device settings, although the requested feature may then be unavailable.

8. Retention and Account Deletion

  • Active and pending accounts: we keep account and product data while needed to provide, secure, and administer the account.
  • Expired sessions and security records: we keep them only as long as reasonably needed for account security, abuse prevention, dispute handling, and legal obligations.
  • Successful deletion: the deletion workflow first obtains a confirmed subscription-cancellation result, revokes sessions, removes active account and product records from declared live stores, and issues a receipt ID. If subscription cancellation cannot be confirmed, destructive deletion stops rather than silently leaving billing active.
  • Limited retention: tax, transaction, fraud-prevention, legal, security, and deletion-receipt records may be retained when required or reasonably necessary. Restricted backups may remain until they age out under the applicable backup schedule and are not restored as an active account.

Retention periods vary by record and operational schedule. We retain information only as long as needed for the purposes above, including account operation, security, billing, dispute handling, and legal obligations. Contact us for information about the period that applies to a specific record or request.

9. Your Choices and Rights

You can update available account information, cancel renewal, request an export where provided, Step Out, and request account deletion from the product. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, and to appeal or complain to a regulator. We may need to verify your identity before fulfilling a request, and legal exceptions may apply.

To exercise a privacy right or ask about a request, contact us at support@getparallelhq.com.

10. Adults Only

Parallel is for people 18 and older. Signup uses date-of-birth self-attestation and a server-enforced age calculation. This is not identity-document verification. If we learn that an account belongs to a person under 18, we may suspend and delete it as permitted or required by law.

11. AI and Safety

Parallel is an AI service, not a human, therapist, medical provider, emergency service, or substitute for professional care. AI output can be inaccurate or unexpected. Contact local emergency services or an appropriate crisis resource if you are in immediate danger.

12. Changes to This Notice

We will post the updated notice and date when this notice changes. We will provide additional notice and require a new acknowledgment before continued paid-product access when a material change calls for it.

13. Contact

For privacy, safety, deletion, billing, or support questions, email support@getparallelhq.com or visit our support page.

Terms of ServiceBehavior ExpectationsSupport