Privacy Policy

Effective July 28, 2026  ·  Onkura Inc d/b/a Parity  ·  Version 2026-07-28

This Privacy Policy explains how Onkura Inc, doing business as Parity (“Parity,” “we,” “us,” or “our”) collects, uses, and shares information when you use the Parity platform at parity.work and related services (the “Service”). Parity is an operations execution layer that lets users describe operational work in plain language and run it as structured, auditable flows with a record designed to be tamper-evident on every execution.

1. Information We Collect

Information you provide directly

  • Account information: Your name, email address, and password when you sign up.
  • Profile information: Your role category and how you heard about Parity (provided during onboarding).
  • Content you submit: Documents, prompts, workflow configurations, and any other content you upload or enter when using the Service (“Your Content”).
  • Connected-source data: Data pulled from a business system (for example a CRM, accounting, or storage tool) only after a workspace admin explicitly connects it via OAuth. A range of connectors is available; none flows any data until an admin connects it, and each connector touches only the data of the source you connect.
  • Communications: Messages you send us via email or support channels.

Information collected automatically

  • Usage data: Which features you use, flows you create or run, pages you visit, and actions you take within the Service.
  • Device and browser information: IP address, browser type and version, operating system, and referring URL.
  • Session data: Timestamps, session duration, and navigation paths.
  • Cookies and similar technologies: See Section 4 below.

Information from third parties

  • Authentication providers:If you sign in via Google (currently our only supported sign-in provider), we receive your name, email address, and profile picture from Google. See Google’s Privacy Policy at policies.google.com/privacy for details on how Google handles authentication data.

2. How We Use Your Information

We use the information we collect to:

  • Provide and operate the Service — create your account, process flow executions, store your workflow history, and display your results.
  • Send transactional communications — account confirmations, password resets, billing receipts, and important service updates.
  • Send product updates — feature announcements and tips about the Service. You can opt out at any time.
  • Improve the Service — understand how people use Parity, identify bugs, and prioritize improvements. This analysis uses aggregated or anonymized data.
  • Expand our workflow library (default-on, opt-out available): We may analyze the structureof flows you create — meaning the field mappings, extraction logic, and configuration schema, not your document content, extracted data, or any information specific to your business — to identify patterns that are missing from Parity’s public workflow library (the “Corpus”). If a flow structure is identified as a candidate, it undergoes an internal anonymization process that removes all company-specific and business-identifying configuration before any version is published to the Corpus. At no point is your document content, extracted data, or the results of any execution shared or reviewed as part of this process. This program is enabled by default.You may opt out at any time via Settings > Account > Workflow Library Contributions. Opting out prevents your flow structures from being analyzed going forward; it does not remove any specifications already incorporated.
  • Enforce our Terms — detect and prevent fraud, abuse, or violations of our Terms of Service.
  • Comply with legal obligations — respond to lawful requests from government authorities and protect our legal rights.

We do not use Your Content to train or fine-tune AI models, and neither does our AI sub-processor.Workflows run on Amazon Bedrock (AWS) within a United States region. Per AWS Bedrock’s published data-protection posture, Bedrock does not use your inputs or outputs to train models and does not retain them beyond serving the request; we do not enable Bedrock invocation logging. For regulated (covered-entity) data, processing is additionally covered by our AWS Business Associate Agreement (BAA), and covered-entity extraction is blocked by default by an automated, fail-closed governance check that runs before any model call.

3. How We Share Your Information

We do not sell your personal information. We share it only in these circumstances:

Service providers

We use third-party vendors to help operate the Service. These vendors process data only on our behalf, under contractual obligations to protect it:

VendorPurposeData shared
Amazon Web Services (AWS) — Bedrock, S3, RDS, KMS, SESCloud hosting and storage, AI inference (Bedrock), database, signing keys, and email intake/deliveryData stored on the platform (encrypted at rest); document and prompt content transits Bedrock for the model call and is not retained by Bedrock beyond serving the request
Google (OAuth)Sign-in identityName, email, profile picture (identity only — no mailbox or drive access)
PostHogProduct analyticsUsage events, session data (anonymized where possible)
SentryError and performance monitoringDiagnostic events and limited technical context when an error occurs
StripeBilling and paymentsAccount and billing data (not your workflow content)

All AI inference runs on Amazon Bedrock (AWS)— our only AI sub-processor. Per AWS Bedrock’s published data-protection posture, Bedrock does not use your inputs or outputs to train models and does not retain them beyond serving the request, and we do not enable Bedrock invocation logging. For a full list of the third parties we engage, see our Sub-processor List.

Parity team members may internally review your flow specifications under the Workflow Library Contributions program (default-on, opt-out available). See Section 2 for details.

Business transfers

If Parity is acquired, merges with another company, or sells substantially all its assets, your information may be transferred as part of that transaction. We will notify you via email before your information becomes subject to a different privacy policy.

Legal requirements

We may disclose your information if required to do so by law, subpoena, court order, or to protect the rights, property, or safety of Parity, our users, or the public.

With your consent

We may share your information for any other purpose with your explicit consent.

4. Cookies and Tracking

CookieTypePurposeDuration
Session cookie (auth token)EssentialKeeps you logged inSession / 7 days
CSRF tokenEssentialPrevents cross-site request forgerySession
PostHog analyticsAnalyticsMeasures feature usage and session behaviorUp to 1 year

We do not use advertising cookies or sell your browsing data to ad networks.

Do Not Track: We do not currently respond to browser Do Not Track (DNT) signals, as there is no uniform industry standard for how services should respond. To opt out of analytics tracking, see Section 6.

Managing cookies: You can clear cookies in your browser settings at any time. Clearing essential cookies will sign you out of the Service.

5. Data Retention

  • Uploaded documents: For a document you upload to run a flow, the Parity platform stores only a cryptographic hash and the extracted, provenance-tagged results— not the original file. There is no endpoint that returns your original document. The raw bytes transit to Amazon Bedrock for the model call (governed by the data posture in Section 2) and are not retained by Bedrock beyond serving the request.
  • Email-forward channel: If you forward a message to run a flow by email, the raw message is held by our AWS email-intake layer and auto-deleted within 14 days by an enforced lifecycle rule.
  • Outputs, evidence, and flow specifications:The outputs we produce, their Evidence Records, and the compiled logic and configuration of flows you create are retained for your account’s use until you delete them or close your account. Evidence Records document what ran, what was decided, and what the output fields were, and are not designed to retain your original document content.
  • Account deletion: When a workspace admin requests deletion, we run a 30-day deletion: after the window closes, an automated job purges your workspace’s data across our data stores and object storage. Two deliberate carve-outs, required for integrity: compliance and audit records of the deletion are retained as the record of the deletion, and user identifiers are anonymized in place (not row-deleted) so historical audit trails stay consistent.
  • GDPR erasure: Erasure requests are honored as pseudonymization of account identifiers plus the audit retention described above. We do not represent this as a total erasure of already-processed artifacts.
  • Analytics data: Aggregated or anonymized usage data may be retained for product improvement purposes.
  • Legal holds: If your data is subject to a legal hold, we may retain it beyond the periods above until the hold is released.

6. Your Rights and Choices

Regardless of where you are located, you may:

  • Access your data: Request a copy of the personal information we hold about you.
  • Correct your data: Update your account information in Settings at any time.
  • Delete your account: Delete your account via Settings > Account > Delete Account. This initiates the 30-day deletion described in Section 5: your workspace’s data is purged across our data stores and object storage after the window closes. Compliance and audit records of the deletion are retained and user identifiers are anonymized in place, as described in Section 5.
  • Export your data: Contact us at support@parity.work to request a copy of your execution history.
  • Opt out of product emails: Use the unsubscribe link in any marketing email.
  • Object to analytics: Contact us at support@parity.work to opt out of PostHog tracking.

To exercise these rights, contact us at support@parity.work. We will respond within 30 days.

California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you additional rights:

  • Right to know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, our business or commercial purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: You may request that we delete personal information we have collected from you, subject to certain exceptions (e.g., legal obligations, active transactions).
  • Right to correct: You may request that we correct inaccurate personal information we hold about you.
  • Right to opt out of sale or sharing: We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information: We do not use sensitive personal information for purposes beyond those necessary to provide the Service.
  • Right to non-discrimination: We will not discriminate against you for exercising any CCPA rights.

To submit a CCPA/CPRA request, contact us at support@parity.workwith the subject line “California Privacy Request.” We will respond within 45 days, with one 45-day extension if needed.

7. Data Security

We implement technical and organizational measures to protect your information, including:

  • Encryption at rest and in transit — our database (RDS) and object storage (S3) are encrypted at rest, and data is encrypted in transit (TLS).
  • Per-workspace-salted connector credentials — credentials for any business system you connect are encrypted with per-workspace-salted keys, so cross-workspace decryption is cryptographically impossible.
  • Tamper-evident execution records — execution records are SHA-256 content-addressed and bound by a KMS HMAC-SHA256 signed governance binding (symmetric integrity), verified fail-closed at both write and read.
  • Tenant isolation — each customer’s data is isolated by application-layer logical scoping.
  • Access controls and token expiry — access to user data is restricted, and authentication tokens expire and rotate.

No security measure is perfect. If you discover a security vulnerability, please report it to support@parity.work.

In the event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities as required by applicable law, including state breach notification laws.

8. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us at support@parity.work and we will delete it.

9. International Transfers

Parity is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By creating an account or using the Service, you acknowledge this transfer. We implement appropriate safeguards for international transfers to the extent required by applicable law.

10. Third-Party Links and Services

The Service may contain links to third-party websites or integrate with third-party tools. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through Parity. We are not responsible for the privacy practices of third-party websites or services.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy with a revised “Last Updated” date. For material changes, we will notify you by email or via an in-app notice at least 30 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance.

12. Governing Law

This Privacy Policy and any disputes arising from it are governed by the laws of the State of Delaware, without regard to its conflict-of-law principles, consistent with our Terms of Service. By using the Service, you consent to the exclusive jurisdiction of the state and federal courts located in Delaware for any disputes not subject to arbitration.

13. Contact Us

For privacy-related questions or to exercise your data rights:

support@parity.work353 Lexington Avenue4th Floor PMB441New York, NY 10016

Version 2026-07-28