Start free with 20 credits — no credit card required.Get started

Privacy Policy & Cookie Notice

Last updated: August 10, 2026

This Policy describes how AutoDocParse handles personal information across our marketing website, application, APIs, and related services.

1. Introduction

AutoDocParse ("AutoDocParse," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy and Cookie Notice ("Policy") explains how we collect, use, disclose, and safeguard personal information when you visit our website at https://autodocparse.com, use our document parsing application at https://app.autodocparse.com, access our APIs, or otherwise interact with our products and services (collectively, the "Services").

This Policy applies to personal information we process as a controller (or equivalent under applicable law). It does not cover information we process solely on behalf of business customers in our capacity as a service provider or data processor — that processing is governed by our agreements with those customers and their instructions.

By accessing or using the Services, you acknowledge that you have read and understood this Policy. Where required by law, we will obtain your consent before collecting or using personal information in certain ways. If you need this Policy in an alternative format, contact us at support@autodocparse.com.

2. Your privacy rights by jurisdiction

Depending on where you live, you may have specific rights regarding your personal information. The summary below is not exhaustive; see Section 12 for details on how to exercise your rights.

Summary of key consumer privacy rights

Jurisdiction / lawKey rights
California (CCPA / CPRA)Know; access; correct; delete; opt out of sale/sharing; limit use of sensitive personal information; non-discrimination; Shine the Light
European Union (GDPR)Access; rectification; erasure; restriction; portability; objection; rights related to automated decision-making; lodge a complaint with a supervisory authority
United Kingdom (UK GDPR)Same core rights as EU GDPR; supervised by the Information Commissioner's Office (ICO)
Canada (PIPEDA / Quebec Law 25)Access; correction; withdrawal of consent; complaint to the Office of the Privacy Commissioner of Canada (OPC) or Quebec's Commission d'accès à l'information (CAI)
Other U.S. states (VA, CO, CT, TX, OR, UT, and others)Access/confirmation; correction; deletion; portability; opt out of sale, targeted advertising, or certain profiling; right to appeal denials where applicable

3. Personal information we collect

Information you provide directly

We collect personal information you voluntarily provide when you:

  • Create an account or register for the Services (for example, name, email address, password, and workspace details);
  • Sign in using a third-party identity provider such as Google;
  • Subscribe to or purchase paid plans (billing name and contact details; payment card data is processed by our payment provider and is not stored on our servers);
  • Upload documents or configure parsers, schemas, webhooks, and automations;
  • Contact us for support, sales, or feedback (name, email, and message contents);
  • Participate in surveys, beta programs, or marketing events; and
  • Use interactive features that require you to submit content or preferences.

Document and workspace content

When you use AutoDocParse, you may upload documents and related files (for example, invoices, receipts, contracts, forms, and images). These files may contain personal information about you, your employees, customers, vendors, or other individuals. You are responsible for ensuring you have a lawful basis to upload and process such content.

We process uploaded content to extract structured data, run OCR where needed, generate confidence scores, route items for human review, deliver webhooks, and provide exports. Extracted results, audit metadata, and configuration data are stored in association with your workspace.

Information collected automatically

When you visit our website or use the Services, we and our service providers may automatically collect:

  • Usage data — pages viewed, features used, API calls, parsing activity, and in-app actions;
  • Device and technical data — IP address, browser type, operating system, device identifiers, and time zone;
  • Log data — server access logs, error reports, referring URLs, and request timestamps;
  • Approximate location inferred from IP address (country/region); and
  • Cookie and similar tracking data (see Section 7).

Information from third parties

  • Authentication providers (for example, Google) when you choose social login;
  • Payment processors when you complete a purchase or manage billing;
  • Integration partners when you connect third-party systems to your workspace; and
  • Referral or reseller partners, where applicable.

CCPA / CPRA categories of personal information

Categories collected in the preceding 12 months

CategoryExamplesBusiness purpose(s)Disclosed to
IdentifiersName, email, username, IP address, device ID, cookie IDAccount management; service delivery; security; analytics; supportService providers; infrastructure providers
Customer recordsName, billing contact details; payment data handled by payment processorBilling; subscription management; fraud preventionPayment processors; service providers
Commercial informationPlan tier, purchase history, credit usage, feature adoptionService delivery; billing; product improvementPayment processors; service providers
Internet / electronic activitySite and app usage logs, clickstream, API activitySecurity; debugging; analytics; product improvementAnalytics and infrastructure providers
Professional informationJob title or company name if you provide themAccount management; communications; personalizationService providers
InferencesUsage patterns, plan fit, engagement signalsProduct improvement; customer successService providers
Sensitive personal informationAccount credentials and authentication tokensAuthentication, security, and fraud preventionService providers only; we do not sell or share for advertising

We do not knowingly collect biometric identifiers, genetic data, health information, or data revealing racial or ethnic origin, religious beliefs, or sexual orientation, except where contained in documents you upload and process at your direction, or as required by law.

4. How we use personal information

Providing and improving the Services

  • Creating, verifying, and managing accounts and workspaces;
  • Processing documents, running AI extraction, OCR, review queues, and automations;
  • Delivering APIs, webhooks, exports, and integrations;
  • Processing subscriptions, credits, and billing;
  • Providing technical support and responding to requests;
  • Developing new features and improving accuracy, reliability, and performance; and
  • Personalizing your experience within the Services.

Communications

  • Sending transactional notices (account activity, billing, security alerts, and policy updates);
  • Responding to support and sales inquiries; and
  • Sending product updates or marketing communications where permitted by law, with an unsubscribe option in each marketing message.

Security, fraud prevention, and legal compliance

  • Detecting, investigating, and preventing unauthorized access, abuse, and fraud;
  • Enforcing our Terms of Service and acceptable use policies;
  • Complying with legal obligations, lawful requests, and record-keeping requirements; and
  • Establishing, exercising, or defending legal claims.

Analytics and business operations

  • Measuring usage trends and service performance;
  • Conducting research, surveys, and product testing; and
  • Supporting finance, audit, planning, and compliance functions.

6. How we share personal information

We do not sell your personal information for monetary consideration. We may share personal information as described below.

Service providers and subprocessors

We use trusted third parties to operate the Services, including providers for:

  • Cloud hosting and object storage (for example, Cloudflare R2 or compatible S3 storage);
  • Database and caching infrastructure;
  • AI model routing and inference (for example, OpenRouter and underlying model providers);
  • Document OCR and digitization (for example, Sarvam AI, where enabled);
  • Payment processing (for example, Dodo Payments);
  • Outbound transactional email (for example, Resend) and inbound document ingestion (for example, SendGrid Inbound Parse);
  • Authentication (for example, Google OAuth); and
  • Security monitoring, logging, and customer support tools.

These providers may process personal information only to perform services for us and are subject to contractual data protection obligations. Enterprise customers may request a current subprocessor list and Data Processing Agreement (DPA).

Business transfers

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate confidentiality protections and notice where required by law.

Legal requirements and protection of rights

We may disclose personal information when we reasonably believe disclosure is necessary to comply with law, respond to lawful requests, enforce our agreements, protect rights and safety, or detect and prevent fraud or security incidents.

CCPA / CPRA — sale and sharing

We do not sell personal information. Certain disclosures of cookie or usage data to analytics partners may be considered "sharing" for cross-context behavioral advertising under California law. Where applicable, California residents may opt out using the contact methods in Section 12. We honor Global Privacy Control (GPC) signals where required.

7. Cookies and tracking technologies

What we use

Cookies and similar technologies (pixels, local storage, and SDKs) help us operate the website and Services, remember preferences, measure performance, and — where permitted — support marketing.

CategoryPurposeConsent required?
Strictly necessaryAuthentication, session management, security, load balancing, and core functionalityNo — required for the Services to function
Functional / preferenceRemember settings such as theme, locale, or UI preferencesYes in the EU/UK; opt-out available elsewhere
Analytics / performanceUnderstand usage, diagnose errors, and improve the productYes in the EU/UK; opt-out available elsewhere
MarketingMeasure campaigns and deliver relevant communicationsYes where required by law

Managing cookies

  • Use your browser settings to block or delete cookies (this may affect functionality);
  • Opt out of interest-based advertising through industry tools such as NAI and DAA; and
  • Contact us at support@autodocparse.com if you have questions about our use of cookies.

Global Privacy Control (GPC)

Where required by applicable law, we recognize and honor the Global Privacy Control (GPC) signal as a request to opt out of the sale or sharing of personal information for cross-context behavioral advertising.

8. Data retention

We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required by law. Retention depends on the type of data:

  • Account data — for the life of your account, plus a reasonable period afterward to resolve billing or legal matters;
  • Uploaded documents and extraction results — according to your workspace retention settings and plan limits;
  • Billing and transaction records — typically up to seven years for tax and accounting compliance;
  • Support communications — generally up to 36 months after closure;
  • Cookie and analytics data — per cookie lifespan or platform configuration (often 13–26 months); and
  • Legal hold data — as long as needed to comply with obligations or resolve disputes.

When data is no longer needed, we delete it or irreversibly anonymize it. Data in backup systems may persist for a limited period before automatic deletion.

9. International data transfers

AutoDocParse may process and store personal information in the United States, India, and other countries where we or our service providers operate. These locations may not provide the same level of data protection as your home jurisdiction.

Where required, we use appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses (SCCs) for EEA transfers, the UK International Data Transfer Agreement or UK Addendum where applicable, and contractual protections for transfers from Canada and Quebec. Copies of relevant transfer mechanisms are available on request at support@autodocparse.com.

10. Data security

We implement technical and organizational measures designed to protect personal information, including:

  • Encryption in transit (TLS 1.2 or higher);
  • Encryption of sensitive data at rest where appropriate;
  • Workspace isolation for uploaded documents and extracted data;
  • Role-based access controls and least-privilege administrative access;
  • Authentication safeguards, including support for secure session management;
  • Monitoring, logging, and incident response procedures; and
  • Vendor due diligence and data processing agreements for subprocessors handling personal data.

No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at support@autodocparse.com. Where a personal data breach poses a risk to your rights, we will notify you and regulators as required by applicable law.

11. Children's privacy

The Services are not directed to children under 13 (or under 16 where required by applicable law, such as the GDPR), and we do not knowingly collect personal information from children without verified parental consent. If you believe a child has provided us personal information, contact support@autodocparse.com and we will delete it promptly.

12. Your privacy rights and how to exercise them

Rights you may have

Depending on your location, you may have the right to access, correct, delete, port, restrict, or object to certain processing of your personal information, and to opt out of sale, sharing, or targeted advertising where applicable.

Workspace owners and administrators can access, export, and delete much of their workspace data directly within the AutoDocParse application, subject to role permissions. For other requests, contact us using the details below.

How to submit a request

  • Email support@autodocparse.com with the subject line "Privacy Rights Request";
  • Or email support@autodocparse.com for general privacy questions.

We may need to verify your identity before fulfilling a request. Authorized agents may submit requests on your behalf where permitted by law, with proof of authorization.

Response timeframes

  • California (CCPA/CPRA) — generally within 45 days, extendable by 45 days with notice;
  • EEA/UK (GDPR) — generally within 30 days, extendable in complex cases;
  • Canada (PIPEDA) — generally within 30 days; and
  • Other U.S. state laws — generally within 45 days, subject to applicable extensions and appeal rights.

Non-discrimination

We will not discriminate against you for exercising privacy rights granted by applicable law.

Supervisory authorities

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where required, provide additional notice (for example, by email or in-product notification). Continued use of the Services after changes become effective constitutes acceptance of the updated Policy, to the extent permitted by law.

15. Who we are and how to contact us

For questions, concerns, or requests regarding this Policy or our privacy practices:

If you are an enterprise customer requiring a DPA, subprocessor list, or security questionnaire, include that in your message and our team will respond.

16. Key definitions

TermDefinition
Personal information / personal dataInformation that identifies or can reasonably be linked to an identifiable individual
ControllerThe entity that determines the purposes and means of processing personal data
Processor / service providerAn entity that processes personal data on behalf of a controller
GDPREU General Data Protection Regulation (EU) 2016/679
UK GDPRUK retained version of the GDPR
CCPA / CPRACalifornia Consumer Privacy Act, as amended by the California Privacy Rights Act
PIPEDAPersonal Information Protection and Electronic Documents Act (Canada)
GPCGlobal Privacy Control — a browser or device signal to opt out of certain data sharing