Public beta · 2 August 2026
Privacy notice
This notice describes the information processed by the Parable public beta. It separates data kept in your browser from encrypted service data and public integrity records.
Google sign-in and account linkage
If you continue with Google, Google and the Ma’atara authentication service process the OAuth sign-in. The service derives a server-keyed HMAC-SHA3-384 handle from the normalized email address and can return a redacted address for account-choice screens. The handle is pseudonymous account data, not an anonymous value, and it is distinct from the passkey and signing keys that control your Ma’atara identity.
Information kept in your browser
Parable stores an identity record in IndexedDB. Private signing and encryption keys, the master notes key, recovery seed and recovery phrase are wrapped with a key derived from your passkey’s PRF or your Argon2id passphrase. Parable can also keep decrypted note mirrors, drafts, preferences and short-lived unlock state in the browser profile. Chat sessions, message text and topic metadata are stored as plaintext objects in origin-local IndexedDB, not encrypted at rest by the application. Anyone who controls the browser profile or endpoint may be able to use or read that local state.
Encrypted notes and attachments
Note bodies and attachments are encrypted in the browser before upload. The service stores encrypted envelopes and attachment ciphertext, plus the identifiers, hashes, sizes, timestamps and indexing metadata needed to synchronize and verify them. It also processes fresh signed authorization assertions when the app reads or changes identity-scoped data. Encryption protects content, but it does not conceal every item of operational or relationship metadata.
Public identity and integrity records
Public DIDs, public keys, signatures, content hashes and chain metadata are designed for independent verification. Provenance features may also publish locally derived fingerprints and signed capsules. These records can remain available after account closure or content deletion; corrections, revocations and deletion events are generally represented by later signed records rather than by silently rewriting prior evidence.
AI chat and model providers
When you use AI chat, title suggestions or topic clustering, Parable sends the prompt and the relevant conversation or title context to the configured model provider for processing. The current deployment uses Cloudflare Workers AI and may use the RME gateway when the heavy model tier is selected. Provider retention and training practices are governed by the deployment configuration and applicable provider terms. Local chat history is also stored as origin-local plaintext in browser IndexedDB; do not treat AI prompts as encrypted or as data that remains only on your device. New chat-turn integrity blocks include a SHA3-384 content hash and limited non-content metadata, not message text. Earlier beta blocks may contain a plaintext excerpt of up to 720 characters; those signed integrity records may remain available under the public-record retention boundary described below.
Operations, providers and payments
Parable processes request timing, security events and source IP addresses in short-lived rate-limit keys to operate and defend the beta. Cloudflare provides application and storage infrastructure. Web search queries are sent to DuckDuckGo Lite and its response is returned to the chat tool. Google provides the optional account sign-in, and Stripe processes payment details if you buy a plan; Parable receives subscription, transaction and entitlement records rather than full card details.
Retention and your choices
Local data remains in the browser until the app or browser removes it. Service records are retained for as long as needed to operate, secure and account for the beta, subject to public-chain integrity, fraud, payment and legal record-keeping constraints. You can export notes, revoke devices, clear local browser data and request access, correction or deletion. A request may not be able to erase a public integrity record without invalidating the evidence it supplies.
Contact
For privacy questions or requests, email trust@parable.social. The date above identifies this beta notice’s current version; material changes will be reflected here.