Skip to content

Public beta · 21 August 2026

Privacy notice

This notice describes the information processed by the Parable public beta. It separates data kept in your browser from encrypted service data and public integrity records.

Google sign-in and account linkage

If you continue with Google, Google and the Ma’atara authentication service process the OAuth sign-in. The service derives a server-keyed HMAC-SHA3-384 handle from the normalized email address and can return a redacted address for account-choice screens. The handle is pseudonymous account data, not an anonymous value, and it is distinct from the passkey and signing keys that control your Ma’atara identity.

Information kept in your browser

Parable stores an identity record in IndexedDB. Private signing and encryption keys, the master notes key, recovery seed and recovery phrase are wrapped with a key derived from your passkey’s PRF or your Argon2id passphrase. Plaintext note mirrors and drafts are kept only in application memory for the current session; the persistent notes cache holds opaque synchronization stubs rather than note text or metadata. Plaintext signing and note keys are not retained in browser storage after lock or reload. Chat sessions, message text and topic metadata are a separate non-core product feature and are stored as plaintext objects in origin-local IndexedDB, not encrypted at rest by the application. Anyone who controls the browser profile or endpoint may be able to use or read that local state.

Encrypted notes and attachments

Note titles, bodies, tags, attachment names/types, plaintext hashes and attachment decryption metadata are encrypted in the browser before upload. The service stores encrypted envelopes and attachment ciphertext, plus public identity material, opaque envelope/ciphertext commitments, identifiers, timestamps, ciphertext sizes and indexing metadata needed to synchronize and verify them. It also processes fresh signed authorization assertions when the app reads or changes identity-scoped data. Encryption protects content, but it does not conceal every item of operational or relationship metadata. Native Notes accepts only ratcheted v2 envelopes. Older immutable records remain evidence but are not decrypted or adapted by the live product; migration starts from a user-controlled plaintext copy and a fresh native save.

Public identity and integrity records

Public DIDs, public keys, signatures, content hashes and chain metadata are designed for independent verification. Provenance features may also publish locally derived fingerprints and signed capsules. These records can remain available after account closure or content deletion; corrections, revocations and deletion events are generally represented by later signed records rather than by silently rewriting prior evidence.

AI chat and model providers

AI chat is a Parable notes-workspace feature, not a Ma’atara Protocol or Veritas core feature. When you use AI chat, title suggestions or topic clustering, Parable sends the prompt and the relevant conversation or title context as plaintext request content through Parable’s same-origin service to the selected model provider (currently Cloudflare Workers AI for GLM-4.7 Flash processing). Provider retention and training practices are governed by the deployment configuration and applicable Cloudflare terms. Local chat history is also stored as origin-local plaintext in browser IndexedDB; do not treat AI prompts as encrypted or as data that remains only on your device. The browser attempts to append new chat-turn integrity blocks containing a SHA3-384 content hash and limited non-content metadata, not message text. Earlier beta blocks may contain a plaintext excerpt of up to 720 characters; those signed integrity records may remain available under the public-record retention boundary described below.

Operations, providers and payments

Parable processes request timing, security events and source IP addresses in short-lived rate-limit keys to operate and defend the beta. Cloudflare provides application and storage infrastructure. Live web research is disabled in the current deployment. If enabled, search queries are sent to Cloudflare Web Search; selected public pages are fetched by the Prabl Worker and bounded text is sent to Workers AI for synthesis. Google provides the optional account sign-in, and Stripe processes payment details if you buy a plan; Parable receives subscription, transaction and entitlement records rather than full card details.

Retention and your choices

Local data remains in the browser until the app or browser removes it. Service records are retained for as long as needed to operate, secure and account for the beta, subject to public-chain integrity, fraud, payment and legal record-keeping constraints. You can export notes, revoke devices, clear local browser data and request access, correction or deletion. A request may not be able to erase a public integrity record without invalidating the evidence it supplies.

Contact

For privacy questions or requests, email trust@parable.social. The date above identifies this beta notice’s current version; material changes will be reflected here.