Legal
Privacy Policy
Last updated: 11 August 2026
This Privacy Policy explains how Parasync (“we”, “us”, “our”) collects, uses, shares, retains, and protects information when you visit parasync.in, create an account, or otherwise use our website, application, APIs, and related services (together, the “Service”). It applies to visitors, account holders, members of organizations on Parasync, and end users who interact with an agent built on Parasync that they’ve connected to. By using the Service, you agree to the collection and use of information as described here. If you do not agree, please do not use the Service.
Capitalized terms not defined here have the meaning given to them in our Terms of Service.
1. Who we are
Parasync is operated from Bengaluru, Karnataka, India, with an additional office in San Francisco, California, USA. For the purposes of applicable data protection law, Parasync is the data controller for information described in this Policy, except where we act as a processor on behalf of an organization (for example, processing an organization’s Customer Data as directed by that organization’s admins). You can reach us using the details in Section 16 below.
2. Information we collect
We collect the following categories of information:
- Account information: name, email address, profile details, and authentication credentials, including via Google OAuth where you choose to sign in that way. Authentication itself is handled by our authentication provider (Supabase Auth) — we do not store your password in plaintext.
- Organization & agent configuration: organizations you create or join, and the agents, roles, goals, backstories, instructions, custom tools, and platform-tool settings you configure within them.
- Conversation data: messages exchanged between you and an agent, including content, status, and metadata, stored so your agents and chats persist across sessions and so Realtime updates can be delivered to your browser.
- Agent memory & profile data:where an agent you use maintains a running summary of your conversations with it (to give the agent continuity across sessions), that summary is stored internally and is not readable by the agent’s creator, other connected users, or Parasync staff outside of security or legal necessity.
- Workspace files: files an agent creates, reads, or is asked to process on your behalf are stored in a private, per-user storage location scoped to that specific agent — not shared with other users connected to the same agent.
- Connected third-party account data (e.g. Gmail, Outlook):if you choose to connect a third-party account so an agent can act on your behalf (for example, to send email as you), we store an encrypted OAuth access token and refresh token, the connected account’s email address, and the scope of access you granted. See Section 4 below for a dedicated explanation of how this data is used. This connection is scoped to one specific agent — connecting an account for one agent does not make it available to any other agent.
- Billing & wallet data: if you add funds to your Parasync wallet, we (and our payment processor) record the transaction amount, currency, timestamp, and a reference to the payment order. We do not store your full card number, UPI PIN, or netbanking credentials — those are collected and processed directly by our payment processor, Razorpay, under its own security controls.
- Usage & diagnostic data: log data such as timestamps, IP address, feature usage, browser and device information, and error diagnostics, used to operate and secure the Service.
- Cookies: as described in our Cookie Policy, used primarily to keep you signed in.
3. Data from connected Google & Microsoft accounts
Parasync offers optional “connectors” that let an agent send email on your behalf through a Google (Gmail) or Microsoft (Outlook) account you explicitly connect. This section describes that data flow in detail, in addition to the general description in Section 2.
- What we request: for Gmail, we request the
gmail.sendscope (permission to send mail on your behalf) and theopenid/emailscopes (used only to display which mailbox you connected). We do not request permission to read, search, delete, or otherwise access your existing inbox, contacts, or any Gmail content beyond what is necessary to send a message you or your agent initiates. For Outlook, we request the equivalentMail.Sendandoffline_accessscopes from Microsoft Graph, for the same purpose. - When it’s used: your connected account is only used to send an email when an agent you are actively chatting with takes that action as part of a conversation you initiated or a background task you configured — never automatically, in bulk, or independent of your own use of the Service.
- How it’s stored:access and refresh tokens are encrypted at rest and are only ever decrypted momentarily, server-side, to make the specific API call needed to send your message. Tokens are never exposed to the agent’s creator, to other connected users, or returned to any client application.
- Disconnecting:you can disconnect a connected account for a given agent at any time from that agent’s Connectors page. Disconnecting deletes the stored tokens for that agent immediately and revokes Parasync’s ability to act on that account going forward. You can also revoke access directly from your Google Account or Microsoft Account security settings at any time.
- What we don’t do: we do not use data obtained through Google or Microsoft APIs for advertising, do not sell it, do not use it to train generalized machine-learning models, and do not allow humans to read it except where necessary for security, legal compliance, or with your explicit consent (for example, to investigate a support request you raise).
Parasync’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use information
- To provide, operate, and maintain the Service, including running your agents and delivering their outputs;
- To authenticate you and secure your account, organizations, and connected third-party accounts;
- To process payments and maintain an accurate record of your wallet balance and transaction history;
- To maintain and improve reliability, performance, and security of the Service;
- To communicate with you about your account, security notices, billing, or material changes to our terms or policies;
- To detect, investigate, and prevent fraud, abuse, or violations of our Terms;
- To comply with legal obligations, including tax, accounting, and financial-services regulations applicable to payments made through the Service.
We do not sell your personal information, and we do not use your Customer Data to train models for other customers.
5. How information is shared
- Within your organization:data you create inside an organization (agents, chats, settings) is visible to members and admins of that organization according to its access rules. Where you connect to another organization’s agent by invite, that agent’s owner can see that you are connected and can see the tools/instructions their agent runs, but cannot see your private conversation content, your connected-account tokens, or your agent-memory data.
- Service providers (sub-processors): we use a limited set of infrastructure and processing providers to operate the Service, listed in Section 6 below, each bound by appropriate confidentiality and data-processing terms.
- Legal reasons: where required to comply with law, respond to a valid legal process, enforce our Terms, or protect the rights, safety, or property of Parasync, our users, or others.
- Business transfers: if Parasync is involved in a merger, acquisition, financing, or asset sale, information may be transferred as part of that transaction, subject to this Policy.
- With your direction: where you explicitly connect a third-party account or instruct an agent to take an action involving a third party (e.g. sending an email), the necessary data is shared with that third party (e.g. Google or Microsoft, and your intended recipient) to carry out that instruction.
6. Sub-processors we use
The table below lists the categories of infrastructure and processing providers we currently rely on to operate the Service. We select sub-processors that maintain security and privacy standards appropriate to the data they handle, and we update this list as our infrastructure evolves.
- Supabase — database, authentication, file storage, and real-time messaging infrastructure.
- Vercel — hosting for our web application and API routes.
- Railway — hosting for our agent-execution and sandboxed code-execution backend services.
- Razorpay — payment processing for wallet top-ups (India and international cards).
- Google LLC — OAuth sign-in, and the Gmail API where you connect a Gmail account to an agent.
- Microsoft Corporation — Microsoft Graph API where you connect an Outlook account to an agent.
- LLM/model providers — infrastructure that runs the language models powering agent responses. Prompts sent to these providers include only the context needed to generate a response and are not used by us to build cross-customer advertising profiles.
7. Data retention
We retain account, organization, and conversation data for as long as your account or organization remains active, or as needed to provide the Service. Some specific retention rules:
- If you disconnect from a shared agent (“Remove from My Agents”), your chat history and workspace files with that specific agent are deleted at that time.
- Settled invite records (accepted, declined, or cancelled) are automatically deleted after 5 days; pending invites are kept until acted on.
- Wallet transaction records are retained for as long as required by applicable financial and tax regulations, even after account deletion, where legally necessary.
- Connected third-party account tokens (Gmail/Outlook) are deleted immediately when you disconnect the account, or when the agent or your connection to it is deleted.
You may request deletion of your account and associated data at any time, subject to the legal and legitimate business retention requirements described above (e.g. financial records, security logs).
8. Data security
We apply technical and organizational measures appropriate to the sensitivity of the data involved, including: row-level access control at the database layer scoped by organization, role, and individual user; encryption of data in transit (TLS); encryption at rest for sensitive credentials, including admin-configured secrets, user-supplied API keys, and connected-account OAuth tokens; and least-privilege scoping so an agent only reaches the tools and credentials explicitly connected to it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. See our Security & trust page for more detail.
9. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, restrict or object to certain processing, or withdraw consent previously given. You can exercise most of these rights directly from your account settings (e.g. disconnecting a third-party account, leaving an agent’s network, deleting your organization) or by contacting us as described in Section 16; we aim to respond within a reasonable timeframe and in any event within the period required by applicable law.
If you are located in India, you additionally have rights under the Digital Personal Data Protection Act, 2023, including the right to obtain a summary of the personal data we process about you and the processing activities involved, the right to correction and erasure, and the right to grievance redressal as described in Section 10 below. If you are located in the European Economic Area or UK, you have rights under the GDPR or UK GDPR, including the right to lodge a complaint with your local supervisory authority.
10. Grievance officer
In accordance with applicable Indian law, including the Information Technology Act, 2000 and rules made thereunder, and the Digital Personal Data Protection Act, 2023, Parasync has designated a Grievance Officer to address complaints regarding this Policy or the handling of your personal data. You may contact the Grievance Officer at team@parasync.in. We will acknowledge complaints promptly and aim to resolve them within the timelines prescribed by applicable law.
11. International transfers
We are based in India and use service providers located in other countries, including the United States, to operate parts of the Service (see Section 6). Where we transfer personal information internationally, we take steps to ensure it remains protected consistent with this Policy and applicable law, including relying on our providers’ own contractual and technical safeguards.
12. Automated processing & AI-generated content
Agents on Parasync generate responses and take actions using large language models based on the configuration and instructions provided by the agent’s creator, and the conversation history and context you provide. Outputs may be inaccurate or unexpected. We do not use fully automated decision-making that produces legal or similarly significant effects concerning you without the involvement of a human (the agent’s creator, or you as the end user directing the agent).
13. Children’s privacy
The Service is intended for business and professional use and is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
14. Data breach notification
In the event of a data breach affecting your personal information, we will notify affected users and, where required, the relevant regulatory authority, without undue delay and in accordance with applicable law.
15. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our data practices, or legal requirements. Material changes will be communicated through the Service, by email, or by other reasonable means, before they take effect. The “Last updated” date above reflects the most recent revision.
16. Contact
For privacy questions or requests, reach us at team@parasync.in, or via our Contact page, which lists our current office addresses in Bengaluru and San Francisco.