PRIVACY & SECURITY

Your data. Your business.

Parli holds your crew list, your schedule, your job costs, and your photos. We treat that like what it is — yours.

WALLED OFF PER COMPANYCARD NUMBERS NEVER TOUCH USNEVER SOLD · NEVER USED TO TRAIN AI

The short version.

Your company is walled off in the database — not just the screensISOLATION
Crew see their jobs. Owners see everything. Pay rates are the strictest of allROLES
Photos live in private storage with expiring linksFILES
Card numbers go straight to Stripe — we hold nonePAYMENTS
Your data never trains anyone’s AIAI
We test the locks before every releaseTESTED
HOW IT’S PROTECTED — THE DETAIL
Last updated: August 12, 2026

The short version

Parli holds your crew list, your schedule, your job costs and your photos. That is your business, and we treat it that way.

Your company’s data is walled off from every other company on Parli by the database itself, not just by the screens. Files are private. Card numbers never touch us. Nothing about your jobs is sold, advertised against, or used to train anybody’s AI.

What follows is the detail, in plain language. If your office needs something more formal for a vendor review, email support@parli.io and we will answer directly.

Your company’s data is separated from everyone else’s

Every company on Parli shares the same software, and every piece of information is tagged with the company it belongs to. The separation is enforced inside the database — every request carries who you are, and the database refuses to return another company’s rows even if the software asked it to.

This is deliberate: hiding a button is not a lock. As of the date on this page, all 60 tables in Parli enforce that rule, with no exceptions.

We also test it rather than trusting it. An automated check runs before every release: it signs in as real accounts at each role and tries to read and change things they should not be able to. If any door opens that was previously shut, the release stops.

Who can see what inside your company

Crew see the jobs they are assigned to. Foremen and supers run the jobs they are given and see the costs on those jobs. Admins and owners see the whole company. If you need something in between, you can build a custom role and take individual permissions away.

Pay rates are the strictest thing in Parli. They are visible to your administrators and to the person whose rate it is — and that is enforced in the database, so a foreman cannot reach a rate through any screen, any search, or the assistant.

Deleting things leaves a record. Each job keeps a log of what was removed, by whom, and when.

Files and photos

Photos and files are stored in private storage. They are not on the open internet and cannot be found by guessing an address. When you open a photo in Parli, the system issues a temporary link that works for you and expires shortly after.

The one exception is the share link you create on purpose — for sending a set of progress photos to a homeowner or a GC. That link works for anyone holding it, which is the point of it, and you can revoke it at any time from the File Manager. It stops working immediately.

Signing in

You can sign in with an email and password, with Google, with Apple, or with a one-time link sent to your email.

We never store your password. It is put through a one-way scramble before it is saved, so nobody at Parli can read it, and it cannot be recovered from our database — only reset.

Signing in with Google or Apple means your password is never given to us at all: those companies confirm it is you, and tell us only that you passed.

Payments

Subscriptions are billed through Stripe, one of the largest payment processors in the world. Card details go from your browser straight to Stripe. They never pass through Parli and are never stored by us — we hold nothing beyond the last four digits Stripe shows on your receipt.

That means a break-in at Parli exposes no card numbers, because there are none here to take.

Encryption, hosting and backups

Everything between your phone or computer and Parli travels encrypted. The information sitting in our database and file storage is encrypted as well.

Parli runs on Supabase and Vercel, on Amazon Web Services infrastructure in the United States (Ohio). The database is backed up automatically every day.

The keys and passwords our system needs to operate are held in encrypted storage separate from our code, and are not written down in the software itself.

The AI assistant and voice

When you ask the assistant something, the part of your workspace needed to answer — a schedule, a task, the report you asked it to draft — is sent to Anthropic or OpenAI to produce the reply. Voice mode sends your speech to OpenAI to be understood.

Under the commercial terms we use with both providers, your content is not used to train their models. It is processed to answer you, and that is all.

The assistant can only reach the company you are signed in to, and only the parts of it your role allows. A foreman asking a question gets an answer about their jobs, not somebody else’s numbers.

It is optional. A company that would rather send nothing to an AI provider can simply not use the assistant or voice mode.

What we do not do

We do not sell your data. There is no advertising in Parli and no advertising network attached to it.

There are no analytics or tracking packages in the app or on this website — not Google Analytics, not Facebook, not session recorders. Nobody is watching your crew use the software.

The mobile app does not track location. Job sites appear on the map from the address typed into the job, not from anyone’s phone.

Your data stays yours

You can take your yard out at any time — the owner of a workspace can export crew, equipment, attachments, tools, trailers and subcontractors to a spreadsheet, in the same format Parli imports.

Anyone can permanently delete their own account from Settings, without emailing anybody for permission. When a company closes its workspace, its records and files are removed from our systems, and its billing with Stripe is cancelled.

What we do not have yet

Parli does not hold a SOC 2 report or an ISO 27001 certificate today, and we would rather say so plainly than let a logo imply otherwise. Those are audits companies buy when their customers require them; we are a young product and no customer has yet needed one.

If your company requires one to sign, tell us. That is exactly the kind of thing that decides whether we start the process, and we will give you a straight answer about timing rather than a vague one.

Parli is also not built for regulated health information and should not be used to store it.

For your office manager

If someone in your office needs the formal version — what information Parli holds, who else touches it, what happens when you leave — that is our Data Processing Agreement, and it is published at parli.io/dpa.

Most vendor reviews are satisfied by the link. If yours needs a signed copy for the file, email support@parli.io and we will send one back signed the same day.

Found a problem?

If you believe you have found a security flaw in Parli, email support@parli.io and put "security" in the subject. Tell us what you found and how to reproduce it.

We will confirm we received it, look into it promptly, and tell you what we did. We will not pursue anyone who reports a genuine flaw to us in good faith and gives us a reasonable chance to fix it before telling the world.

THE PRIVACY POLICY
Last updated: August 10, 2026

Information We Collect

When you create an account we collect your name, email address, and the name of your company.

As you use Parli, we store the work you put into it: projects and their locations, tasks, schedules, crew and equipment records, field reports, costs, and any files or photos you upload. Job site addresses may include map coordinates so we can show them on a map.

If you use voice mode, we process the audio of what you say in order to understand the request and respond to it.

We also keep basic technical records — sign-in times and error reports — so we can keep the service working and investigate problems.

How We Use Your Information

We use your information to run the service: to show you your work, schedule crews and equipment, send the notifications you have asked for, process payments, and provide support.

We do not sell your information, and we do not use your project data to advertise to you.

AI Features

Parli includes an assistant that answers questions about your workspace, drafts field reports and photo captions, and can be spoken to by voice. These features are included on the paid plans that list them.

To produce a response, the relevant part of your workspace data — for example project names, task details, schedules, or the text of a report you asked us to draft — is sent to our AI providers, Anthropic and OpenAI. Voice mode sends your spoken audio to OpenAI to be transcribed and answered.

These providers process that content only to return a response to you. Under the commercial API terms we use, your content is not used to train their models.

The assistant can only read data from the organization you are signed in to. It never has access to another company’s workspace.

These features are optional. If you would prefer that no data be sent to an AI provider, do not use the assistant or voice mode, and ask your administrator about a plan that does not include them.

Service Providers

We run Parli on infrastructure operated by other companies. Each one receives only what it needs to do its job:

Supabase hosts our database, sign-in system, and file storage. Vercel serves the application and this website. Stripe processes subscription payments — card details go directly to Stripe and are never stored by us. Resend delivers our email, such as invitations and notifications. Anthropic and OpenAI power the AI assistant and voice mode, as described above. Google is involved only if you choose to sign in with a Google account.

When you type a job address, that address is sent to a mapping service to offer suggestions and to find the spot on the map — Photon (operated by Komoot) and OpenStreetMap’s Nominatim, or Google Places. Only the address text you typed is sent. Parli never reads your phone’s location: the app asks for no location permission at all, and a job address is a place of work, not where you are standing.

Files and Photos

Files and photos you upload are stored privately. They are not published on the internet and cannot be reached by guessing a web address. When you view a photo in the app, Parli issues a temporary link that works only for you and expires a short time later.

If you deliberately create a share link for a photo or a collection, that link is public to anyone who has it — that is its purpose. You can revoke a share link at any time from the File Manager, and it stops working immediately.

Photos taken on a phone are automatically reduced in size when uploaded, so we store a smaller copy rather than the full-resolution original.

The Parli Mobile App

The iPhone and Android apps are the same Parli as the website, signed in to the same account and showing the same data. Everything above applies to them too.

The app asks for a few things the website cannot use. Each is requested at the moment you first need it, and each can be turned off afterwards in your phone’s settings — the rest of Parli keeps working without it.

Camera and photo library: used only when you take or attach a photo for a task, note or field report, and when you save a photo back to your phone. Parli does not read your photo library in the background.

Microphone: used only while you are actually talking to the assistant in voice mode.

Notifications: if you allow them, your phone gives us an anonymous device token so we can deliver alerts about your work. It identifies the device, not you personally, and it is deleted when you sign out or turn notifications off.

Parli does not track your location. Job sites appear on a map from the address typed into the job, not from your phone’s GPS, and the app does not ask for location access.

The app carries no advertising, no analytics SDKs, and no third-party trackers.

Apple and Google distribute the app. They do not receive your Parli data — but your use of their storefront is covered by their own terms and privacy policies.

Data Security

Your data is encrypted in transit. Each company’s workspace is isolated at the database level, so one customer cannot read another customer’s records, and access inside your own company is limited by the role your administrator assigns you.

No system is perfectly secure, but we review these protections regularly and fix what we find.

Data Retention and Deletion

We keep your information for as long as your organization has an account with us.

When you delete a project, its tasks, reports, documents, and photos are permanently removed, including the underlying files. Deleting an organization removes its entire workspace the same way. Deletion is immediate and cannot be undone.

If you would like your organization’s account closed and its data deleted, contact us and we will take care of it.

Your Rights

You can view and update your own profile information at any time in the app. You may also ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it.

Your employer controls the workspace you belong to, so some requests — such as removing project records — may need to go through your administrator.

Changes to This Policy

If we change how we handle your information, we will update this page and change the date above. Significant changes will also be announced in the app.

Contact Us

If you have any questions about this Privacy Policy, or want to make a request about your information, email us at support@parli.io.

Vendor review? Office manager with a checklist?

Email support@parli.io — a person answers. Formal paperwork lives at Terms and DPA.