Parlane

Privacy Policy

Effective September 12, 2026

Parlane is a native client for servers you choose. There is no separate sign-up or profile screen. Our services still use installation and purchase identifiers to provide notifications, verify access, restore purchases, and meter hosted voice. These records can be linked to an installation or an app-specific purchase account; the absence of a name or email does not make them anonymous.

Connected servers and AI providers

Chat messages, voice transcripts, dashboard requests, action inputs, and shared attachments go directly from your phone to the server you connect. That server may pass them to AI providers or other processors. Its operator controls those uses and must provide its own privacy policy. Connecting also reveals network metadata, such as your IP address, to that operator.

The next iOS release requires a versioned server disclosure naming its operator, data types, purposes, additional recipients, retention, and training use. You must explicitly allow sharing before sending content. A changed disclosure requires another review. Settings → Sharing → Server data sharing lets you pause it. These controls require an updated app and a compatible server; older builds do not provide this consent gate.

Hosted voice and notifications use additional services below. Ordinary direct chat and dashboard requests do not pass through our notification relay. The app does not provide a relay tunnel to a private home server; remote access requires a reachable HTTPS server or a VPN you manage.

What stays on your phone

Connected-server credentials stay in Apple's Keychain. Chat history, cached dashboards, and connection preferences are stored locally. Delete individual messages or conversations in the app, or remove a connection in its Settings to delete that connection's local history and credentials. Removing a connection does not delete data already held by its server.

Shortcuts may save pending requests locally. The next release also keeps share-sheet handoffs under Settings → Sharing → Saved shares until sent or discarded. Unconfirmed deliveries require explicit review before retrying. These queues contain user content and local attachment copies. Uninstalling removes the app's ordinary local data; Keychain items and billing records may survive an uninstall. There is no “Erase local data” button in the current Settings screen.

Product analytics

We send limited product events to TelemetryDeck, such as an app launch or a connection succeeding. They exclude messages, voice, dashboard content, attachments, server addresses, authentication tokens, and connected-app data. A hashed identifier generated for analytics distinguishes installations. It is separate from billing identifiers, and we do not join these datasets.

Analytics is enabled by default. Turn off Share anonymous usage in Settings → Privacy to stop future events. We use these events to improve the app, not for advertising, data brokerage, or tracking across other companies' apps. Our app has no advertising identifier or ad SDK. Hashing an identifier does not by itself establish that all usage data is unlinked under App Store privacy definitions.

Subscriptions and purchases

Apple processes purchases through StoreKit. RevenueCat manages products, purchase history, subscription status, and restoration. The app initializes RevenueCat and checks entitlement on launch, including for people who have never opened the paywall. RevenueCat receives an app-user identifier and purchase/entitlement information; we do not receive your card details or Apple account password.

Our hosted services keep purchase bindings, transaction identifiers, character usage, and credit balances to enforce the paid voice allowance, restore purchased credits, prevent duplicate credits, and prevent repeated free trials. Billing and installation records are linked for those purposes. They are not used for advertising or cross-app tracking.

Installation verification and retention

Newer builds use Apple App Attest and signed StoreKit information to verify the installation. Verification proofs are processed without content logging. We store installation public keys, assertion counters, an app-specific Apple account identifier hash, and a verified RevenueCat binding where available. Short-lived challenges expire; durable billing, anti-fraud, and installation records currently have no automatic deletion date.

Removing a connection queues removal of its notification registration. Turning notifications off requests removal too; an offline phone or unavailable service can delay that request. These actions do not erase purchase history, unused voice credits, or required fraud-prevention records. Contact contact@parlane.ai for access or deletion requests. We may need to verify ownership and explain any billing or fraud-prevention records that must be retained. Do not email passwords or purchase receipts containing sensitive details.

Voice

In-app speech recognition uses on-device Apple speech recognition. The app sends the resulting transcript to the selected server; it does not upload your microphone recording. iOS Dictation used in your own Shortcuts follows Apple's settings and policies.

Device voice generates speech locally. A server-declared voice endpoint receives reply text under that server's policy. Optional Parlane voice sends reply text to our hosted voice service and Amazon Polly. Our gateway processes text in memory without storing or logging the text; character counts and billing identifiers are retained to manage usage.

Amazon's Polly privacy terms allow storage and service-improvement use unless an applicable opt-out is effective. We do not currently promise that Amazon processes text only transiently or excludes it from service-improvement use. The next release renews hosted-voice consent with this disclosure. Use Device voice to keep speech generation on your phone.

Notifications

The next release includes notifications with Free. Direct connections still do not require the relay. Pairing can contact the relay before notifications are enabled. Registration sends an APNs device token, local connected-app identifier, pairing credentials, and, on newer builds, a verified installation session. We retain routing records to deliver notifications and protect them with access controls and encryption at rest.

Standard previews are protected in transit, but their titles, bodies, deep links, and action metadata are readable by our relay and Apple. Our relay does not log preview text. An additional encrypted payload does not encrypt an otherwise visible preview.

Private previews require a compatible updated backend and app. The backend encrypts preview content to that phone, and the iOS notification extension opens it on the device. Routing metadata and a generic fallback remain visible to the relay and Apple. This does not encrypt processing on the connected server, hosted voice, or content already shown on an unlocked screen. See the private-preview guide.

Demo, support, and website

The bundled demo runs locally with scripted responses. The optional hosted demo runs on AWS and is a separate connection. Its updated research dashboard uses generic acknowledgment labels so shared text and filenames are not published to other visitors. Do not use the public demo for sensitive data.

Support email and optional developer feedback contain whatever you choose to submit. Feedback may include a message, contact address, category, and app description, and is kept in our support systems or AWS operational logs until reviewed and deleted. Avoid including secrets, receipts, or private conversation content. The static website has no analytics scripts or tracking cookies; it stores your theme choice in your browser. Hosting providers process ordinary request metadata.

Children and changes

This is a developer tool, not a service designed for children under 13. Operators of connected servers are responsible for their content and age suitability. Contact us if you believe a child has supplied personal information so we can investigate.

We update this page and its effective date when practices change. For privacy questions, contact contact@parlane.ai.