Privacy Policy

Effective date: September 18, 2026

ParkourNote is a cloud research workspace operated by ParkourLabs, Inc., a Delaware corporation (“ParkourLabs”, “we”, “us”). This policy describes what we collect when you use ParkourNote at note.parkourlabs.io (the “Service”), how we use it, and the choices you have.

Questions or requests: privacy@parkourlabs.io.

What we collect

Account information. Your name, email address, and a hashed password (we never store your password in plain text). If you sign in with Google, we receive your Google account email, name, and profile image. Each signed-in session records an IP address and browser user-agent string for security purposes.

Your content. The documents you upload or import (e.g., PDFs), and everything you create in the workspace: annotations, notes, documents, chat conversations, and images you attach to chats. We also store content derived from your documents to make features work: extracted and OCR-processed text, translations, AI-generated outlines, and figure images extracted from your documents.

Voice input. If you use dictation, your audio is sent to a speech-recognition provider and the transcript is returned to your session. We do not store the audio or the transcript; we record only the duration for usage metering.

Audio notes. If you record audio in a note or upload a recording, we store the recording, its transcript and the AI-generated minutes as part of your content, for as long as the recording exists in your library. The complete recording is sent to our speech-recognition provider for transcription; the transcript text is sent to an AI model provider to write the minutes. We do not build voice profiles and do not identify people by their voice.

Usage information. We record product events tied to your account — for example that you imported a paper, requested OCR, sent a chat message, or completed a translation. To understand reading time and feature use, we also record in-app clicks and input-activity signals, the current interface, file/project identifiers and page/view, tab visibility and focus, timestamps, and periodic presence observations. These activity records do not contain clicked text, typed keys, search queries, message drafts or document content. We record that searches occurred, but not your search query text. We also keep per-request usage and billing records (feature used, AI model, token counts, credits charged).

Public page visits. When you visit our public pages (the home page, blog, legal pages, and the sign-in and sign-up pages), we record which page you viewed and when, which sign-up or sign-in buttons you clicked, the referring website (its domain only), and any campaign parameters (utm_*) or sharing code in the address. Each record carries the random visitor identifier from the cookie described below, so we can count unique visitors and see how many visits lead to a sign-up and to using the Service. If you create an account, that identifier is copied onto your account’s sign-up record, which links your earlier visits on that browser to your account. We do not store your IP address with visit records. If your browser does not keep our cookie, the visit instead carries a code computed from your IP address and browser user-agent together with a secret; that code changes every day and cannot follow you from one day to the next.

Error reports. When something breaks, we collect an error report that may include your account ID, the page you were on, a technical stack trace, your browser’s user-agent string, and recent in-app navigation steps. Error reports are processed entirely on our own infrastructure — we do not use any third-party error-tracking or analytics service. Reports are typically deleted within about 30 days of an issue going quiet, after which only de-identified aggregate records are kept.

Feedback. When you send feedback from inside the Service, we store what you write, the numbered markers and notes you add, and — unless you turn it off before sending — a screenshot of the ParkourNote window as it was when you opened feedback, including any documents, notes or chats visible on screen. Parts you cover with the blur tool are pixelated in the stored image; the original pixels are never uploaded. We also store the diagnostic details listed under “What’s included” in the feedback form: the page label and path, app release, browser user-agent, window size, theme, language and recent request identifiers. Feedback is visible only to you and to the ParkourNote team, and we may email you when we reply.

Server logs. Our servers keep short-lived technical logs, automatically rotated and kept only briefly, that may include fragments of request data.

Cookies and local storage. We use only first-party cookies: session and security cookies for signing you in, and a 30-day visitor cookie set when you first open one of our pages. The visitor cookie holds a random visitor identifier (used for the visit records described above) and, if you arrived through a sharing link, a campaign address or another website, that sharing code, the campaign parameters (utm_*) and the referring site, so that the account you create can be credited to it. The identifier is generated in your browser and contains nothing about you. You can block or delete this cookie in your browser settings; the pages and the Service keep working without it. We use your browser’s local storage for interface preferences (theme, layout, and similar). We temporarily queue account-scoped activity records in browser storage for retry when a connection is unavailable. Acknowledged records are removed; pending records expire after seven days when the queue is next processed, and the queue is limited in size. We use no advertising cookies, no third-party analytics, and no tracking pixels.

How we use your information

We do not sell your personal information, and we do not share it with advertisers or data brokers.

AI providers and your content

AI features are powered by third-party AI providers. When you invoke an AI feature, the relevant content is sent to a provider to generate the result:

We do not use your content to train AI models. AI providers process your content under their own terms; some may retain inputs or use them to improve their services. Our Subprocessor List states what each provider has published about this.

The current list of providers, and what each receives, is maintained on our Subprocessor List.

Where your data lives

Your data is stored on Tencent Cloud infrastructure in Hong Kong (application servers, database, and file storage). Traffic to certain AI providers is routed through a relay server we operate in Singapore; the relay does not log content. Our AI and email providers are located primarily in the United States and Europe; the speech-recognition provider for audio notes and dictation is StepFun’s international platform, whose processing location is not published. By using the Service you understand that your information is transferred to and processed in these locations.

Retention

Your rights

You can access, correct, export, or delete your data. In-app you can edit your profile, and delete files, notes, chats, and projects at any time. For anything the app doesn’t yet cover — including full account deletion and a complete export of your data — email privacy@parkourlabs.io from your account email and we will fulfil the request within 30 days, regardless of where you live.

Browser extension

The optional “ParkourNote” browser extension detects scholarly papers on pages you visit. Only when you click to import does it send the selected paper URL or PDF to ParkourNote. For local files or publisher PDFs, the extension reads the file in your browser, using your existing publisher access where available, then passes PDF chunks to the ParkourNote web app for upload to your account. It does not collect your browsing history or read or store your passwords or publisher cookies. It stores its settings and temporary transfer records (source URL, file label, and creation time) in your browser. Completed transfers are removed immediately; other records expire after 24 hours and are removed the next time the extension starts or you initiate a transfer. Uninstalling the extension removes its local records.

Extension diagnostics. So that we can see when the extension breaks, it sends error reports and usage counts to the ParkourNote installation you configured, and nowhere else. An error report carries the error message with any web addresses removed, a stack trace of the extension’s own code, which part of the extension failed and at which step, the extension version, and your browser engine and version; when the extension is signed in, the report is attributed to your account. A usage count records what kind of page the panel was used on (a video, a paper, or a web page), which action you took (clip, import, ask, note, message), whether it succeeded, and how long a save took. Diagnostics never include the address or title of the page you are on, the text you selected, or what you typed; they are not browsing history. They are processed entirely on our own infrastructure and deleted on the same schedule as other error reports (about 30 days after an issue goes quiet). A report that could not be sent waits in your browser’s extension storage for up to seven days. You can turn diagnostics off on the extension’s options page (“Send diagnostics to ParkourNote”).

Children

The Service is not directed to children under 13, and you may not use it if you are under 13. If we learn we have collected personal information from a child under 13, we will delete it.

Changes

We will post any changes to this policy on this page and update the effective date. For material changes we will notify you in the app or by email before they take effect.

Contact

ParkourLabs, Inc. privacy@parkourlabs.io (privacy requests) · support@parkourlabs.io (general support)