Privacy Policy
How Parsley (operated by DoubleO Lab) handles your data.
Last updated: 13 July 2026.
Who we are
Parsley is an SEO analysis tool operated by DoubleO Lab ("we", "us"). For any privacy question, contact jas@oxfordcomma.digital.
What we collect
- Account details — your email address and a password stored only as a salted hash (we never store the plain password).
- Sites you analyse — the URLs you enter and the publicly available page content we fetch from them to run the analysis. Only analyse sites you own or have permission to analyse.
- Google Search Console data (optional) — if you
connect Search Console, we read your property's clicks, impressions,
average position and queries through Google's read-only API
(the
webmasters.readonlyscope). We request no write access and cannot change anything in your Search Console account. - Usage metadata — counts of analyses run and of calls made to the AI and keyword-data providers below, used to operate and meter the service.
How we use it
We use your data solely to produce the SEO analysis, briefs and recommendations you ask for, and to run and secure the service. We do not sell your data and do not use it for advertising.
Google Search Console data
- Access is read-only and limited to the properties you choose.
- Your Google authorisation (refresh token) is encrypted at rest and used only to fetch the metrics for your analyses.
- You can disconnect at any time from within the app, which deletes the stored token; you can also revoke access at your Google Account permissions.
- Parsley's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who we share it with (sub-processors)
We share the minimum necessary with the providers that power specific features:
- OpenAI — page content and prompts, to generate briefs and copy.
- Semrush — keywords, to fetch search-volume and ranking data.
- Google — your OAuth authorisation, to fetch your Search Console metrics.
- Perplexity and Google (Gemini) — prompts only, when we check how AI search assistants answer questions about your market (AI visibility features).
- Stripe — your email address and subscription status, to process payments when you subscribe.
- Shopify — store authorisation and catalogue data, if you connect a Shopify store.
- Sentry — error reports when something in the service breaks. Request contents and passwords are never sent, and error text is redacted first.
- Fly.io — our hosting provider.
- Tigris (via Fly.io) — encrypted object storage holding off-site backups of the service database.
- Supabase — managed database hosting for the shared crawl catalogue, and for the waitlist (your email address, browser user agent and referring page when you join it).
We do not share your data beyond the providers and purposes listed above.
Retention & your rights
Analysis results are kept until you delete them or close your account; deleting your account removes your runs and stored authorisations. You may request access to, or deletion of, your personal data by emailing jas@oxfordcomma.digital.
Encrypted off-site backups of the service database are kept for up to 35 days. Data you delete leaves the backups as they expire, and backups are used only for disaster recovery, never to restore deleted data into the live service.