Who we are
Parley is a product of Collabsprint, a sole trader. In this policy, “we” and “us” mean Collabsprint. We decide how your personal data is used, so we are its controller.
Parley finds roles that fit your brief, prepares a tailored CV and drafted answers for each application, fills in application forms with a Chrome extension, and tracks the replies. It is open to people anywhere in the world.
For anything about your data, email privacy@collabsprint.academy.
What we collect
- Your account: your email address, your passkeys if you add them, your sign-in sessions, and your browser’s time zone and language.
- Your CV and profile: the CV you upload and its text, your name and contact details, and the facts Parley reads from your CV for you to confirm.
- Your brief: the titles, places, work mode and level you want, and your terms, such as pay, notice period and whether you need visa sponsorship.
- Your answers: the standard answers you save, and the answers Parley drafts for each form.
- Your applications: the roles you save, prepare or apply to, with their tailored CVs, cover letters, notes and stages.
- Email about your applications: from Gmail if you connect it, or the emails you forward to Parley (section 5).
- Calendar events: if you connect Google Calendar, the events that are interviews.
- From the extension: the text of job pages and the questions on application forms (section 6).
- Records of activity: what Parley did and when, so you can see it and undo it; a log of each AI call (the provider and model, what the call was for, how long it took, how many tokens it used, and any error), never the text sent or received; a record of each form fill (the site, how many fields were filled, and the labels of fields that failed), never what was typed; and an access log of who opened or changed your records and when, with no content, email address or IP address.
- Server logs: the address of each request without its query, and your IP address with its last part removed.
A CV can show things such as your health, ethnicity, religion or immigration status. Parley does not ask for these. Include only what you are happy for employers to see.
How we use it, and why
- To run Parley for you: to find and rank roles, prepare applications, fill forms, file replies, and send sign-in codes and the morning email. We do this to perform our contract with you.
- To keep Parley safe and working: sign-in checks, usage limits, logs, and fixing the form filler when a fill fails. We do this in our legitimate interest in a secure, reliable service.
- To read Gmail and Calendar, and to receive page data from the extension: with your consent. You can take it back at any time by disconnecting Google or by choosing “Stop sending page data” in the extension.
- To keep billing records once paid plans are on sale, because the law requires it.
We do not sell your data, show you ads, or use your data to train AI models. We look at your data ourselves only to answer a request from you, to fix a fault, or when the law requires it.
AI processing
Parley uses OpenAI’s API, with the models gpt-5-mini and gpt-5-nano, to read your CV, rank roles, tailor your CV, draft and review answers, read emails about your applications, and prepare you for interviews. Each call sends only what that task needs: for example your CV text and facts, your saved answers, the job posting, and the questions on the form.
OpenAI processes this data in the United States. OpenAI does not train its models on data sent through its API, because our organisation does not share data with OpenAI. OpenAI keeps API data for up to 30 days to detect abuse, then deletes it, unless the law requires it to keep it longer.
Parley ranks roles and drafts text for you. It can also move a role by itself when an email says you were turned down or invited to an interview; you can undo that. Nothing goes to an employer until you press Submit.
When you practise an answer out loud, your browser’s speech service turns your voice into text. In Chrome that service is Google’s. Parley receives only the words, never the audio.
If you run Parley on your own computer, you can use your own key from Anthropic or DeepSeek instead. The hosted service never sends your data to Anthropic or DeepSeek.
Gmail, Calendar and forwarded email
Gmail and Google Calendar
Connecting Google is optional. If you connect it, Parley asks for read-only access to Gmail and Calendar. Parley reads Gmail only to find replies about your applications and file them against the right role, and reads Calendar only to find your interviews. Parley never sends email from your account, and never changes or deletes your email or events.
Forwarding emails instead
You can forward emails about your applications to your own Parley address instead, which is in You › Sources and status. Cloudflare receives each email and passes it straight to our server without keeping a copy. Emails over 10 MB are refused.
When an email comes from a hiring system or a company you are applying to, or replies to a thread Parley already filed, Parley may send the sender’s name and address, the subject and up to 6,000 characters of the text to OpenAI to understand it. Parley then keeps the sender, the subject and up to 20,000 characters of the new part of the email, without the earlier messages quoted under it.
Any other email is not read by the AI and not stored. Parley keeps only an identifier, so it does not look at that email again. Forward only emails about your own applications: they carry the sender’s details too.
The Chrome extension
The Parley extension fills in application forms on employers’ sites. It never presses Submit: you check the form and submit it yourself.
The extension asks for your agreement before it sends anything. After that, it sends to your Parley account only:
- the address, title and text of a job posting you open, so Parley can add the role;
- the questions on an application form, with their options, so Parley can draft answers;
- the answers on the form, when you ask Parley to review or change them;
- a record of each fill: the site, how many fields were filled, and the labels of fields that failed, never what was typed;
- if a fill fails, a copy of the page as it was before filling, up to 3 MB, so we can fix the filler. The copy can include details the site itself shows, such as your name. We delete these copies after 30 days.
The extension sends nothing to anyone except Parley. To take back your agreement, choose “Stop sending page data” in the extension’s menu.
Where your data is
Our server and backups are in Germany. OpenAI processes data in the United States, and Cloudflare, Google and Stripe can process data outside your country. When data leaves the European Union, the United Kingdom or your own country, we rely on the safeguards in each provider’s data processing terms, such as the European Commission’s standard contractual clauses.
How long we keep it
- Your account, CV, profile, brief, answers, applications and filed emails: until you delete them or your account.
- Records of activity and the AI call log: 180 days. A record Parley still needs, such as a change you can still undo or one about a role you have not finished, stays until it is no longer needed.
- The description of a closed role you never took further: 30 days after it closed.
- Page copies from failed fills: 30 days.
- Server logs: 30 days.
- The access log: 12 months. When you delete your account, one record stays for those 12 months: that the account was deleted, and when.
- Backups: 30 days. What you delete leaves our backups within 30 days.
- At OpenAI: up to 30 days, as section 4 says.
Your rights and controls
In Parley, under You:
- Export: Your data › Export everything. Your applications as CSV, or everything as JSON.
- Delete your data: Your data › Delete everything.
- Delete your account: Account › Delete my account. This deletes your account and everything Parley keeps for you, signs out every device, and asks Google to remove Parley’s access.
- Disconnect Google or the extension: Sources and status.
- Correct your data: edit your profile, CV, brief and answers in their sections.
Wherever you live, you can ask us for a copy of your data, to correct it, to delete it, or to send it to you in a format you can move elsewhere. You can object to how we use it, ask us to restrict it, and take back any consent you gave. Email privacy@collabsprint.academy. We answer within one month.
You can also complain to the data protection authority where you live.
Security
Every connection to Parley uses HTTPS. You sign in with a code sent by email or with a passkey, never a password. Saved keys and Google access are stored encrypted. The database keeps each account’s records apart, so one account cannot read another’s, and the access log records who opened or changed them. If a breach puts your data at risk, we will tell you and the authorities as the law requires.
Minimum age
Parley is for people aged 16 or over. If we learn that an account belongs to someone under 16, we delete it.
Changes to this policy
When we change this policy, we update this page and its date. If a change matters to how we use your data, we email you before it takes effect.
Contact
Email privacy@collabsprint.academy with any question or request about your data. Our Terms say how you may use Parley.