Privacy Policy

How AILANG Parse handles your data.

1. Who We Are

AILANG Parse is operated by Holosun ApS (CVR 44324687), a company registered in Denmark. We provide a document parsing service that extracts structured content from Office documents, PDFs, images, and other file formats.

Privacy contact: docparse@sunholo.com

2. Data We Collect

What happens to your documents depends on how you run AILANG Parse:

How you parseWhat we keep
In your browser (WebAssembly) Nothing. The document never leaves your device.
Local CLI or self-hosted Nothing is sent to Holosun. The code runs on your machine or servers.
Hosted API (europe-west1) Uploaded files are not stored. Each request keeps a request record: its metadata and, unless you turn request history off, up to 10 KB of the parsed output for replay. Request records are deleted after 12 months. Google Gemini (only when you choose AI parsing) may process in the US, and Firebase sign-in runs in the US; see International Transfers.

In detail:

CategoryWhatRetention
Small documents Files sent via API for parsing Ephemeral — processed in memory, discarded after response is returned
Large files Files too large for in-memory processing Temporary storage, encrypted at rest (AES-256), auto-deleted after 1 day
AI-routed documents Content sent to your selected AI provider (e.g. Google Gemini) for PDF/image parsing Per AI provider’s terms. We do not retain AI inputs or outputs.
Browser / CLI parsing Documents parsed via WebAssembly in your browser or the local CLI No server involvement. Data never leaves your device.
Account & auth Email address, display name and profile photo URL, and the sign-in provider (Google or GitHub) with its user ID, via Firebase Authentication. Access keys issued to AI assistants you connect (stored hashed; see AI Assistant Connections) Until account deletion. Connection keys expire after 24 hours; refresh tokens after 30 days
API keys Key identifiers, labels, creation dates Until key revocation or account deletion
Request records Per API request: request ID, account and API key ID, endpoint, file name or source reference, input and output format, whether AI was used, file size, outcome and error code, timestamp. Request history: up to 10 KB of the parsed output, kept so you can replay the request. It’s on by default; turn it off in your dashboard or with POST /api/v1/account/history and new requests keep metadata only. The file name is stored as you send it; if it identifies a person, rename the file before upload. Automatically deleted 12 months after the request. Your history shows the last 30, 180 or 365 days depending on plan. You can delete all of your request history at any time from the dashboard (Delete history).
Usage metrics Request counts per API key and month. No document content. 12 months
Contact / email Name, email, message content when you contact us 24 months

Referrals: If you signed up through a partner’s referral link, that partner can see your email address, when you signed up, your plan, and how many documents you’ve processed. They never see the content of your documents.

Using AILANG Parse from Claude, ChatGPT or another AI assistant

You can connect AILANG Parse to an AI assistant that supports the Model Context Protocol (MCP), at https://docparse.ailang.sunholo.com/mcp/connect/. When you connect:

  • Sign-in. You sign in to AILANG Parse on our own page, with Google or GitHub through Firebase Authentication. The assistant never receives your Google or GitHub password or tokens. The sign-in page shows which app is asking and where it will send you back, and nothing is granted until you choose Allow.
  • What we store for a connection. We issue the assistant an access key for your account, labelled oauth: <app> (for example oauth: claude.ai). It expires after 24 hours. The assistant then uses a refresh token to get a new key, which replaces the old one. Refresh tokens are valid for 30 days and are replaced each time they are used. We store keys and refresh tokens only as SHA-256 hashes, never in readable form, in Google Cloud Firestore in the EU (Belgium). Expired sign-in and refresh records are deleted automatically, and an expired key stops working immediately.
  • What the assistant sends us. Only the tool call: the document or text you ask it to work on and the options for that request. We do not receive your conversation, your chat history or other files.
  • Files you create. When the assistant creates a document for you, we keep the file in Google Cloud Storage (EU) for up to 24 hours so you can download it from a private link that expires after one hour; it is then deleted automatically.
  • What the assistant receives. The tool’s result: parsed or converted content, estimates, or information about your account. From then on that content is handled under the assistant provider’s own privacy policy (for example Anthropic’s or OpenAI’s), not ours.
  • Requests made through an assistant are recorded like any other API request (see Request records above), and your request-history setting applies.
  • Disconnecting. Revoke the connection at any time from your dashboard (API keys labelled oauth: …), or remove the connector in the assistant. Revoking stops access at once. You can also ask us at docparse@sunholo.com.
  • Feedback tool. If you or the assistant use “Send feedback”, we store the report text and any contact detail you include, so a person can review it. Don’t include personal or confidential content.
No analytics on these pages. AILANG Parse pages do not load Google Analytics, tracking scripts, or advertising pixels. However, if you have previously visited www.sunholo.com, analytics cookies set by that site (e.g. _ga) may be visible in your browser since both sites share the sunholo.com domain. These cookies are not read or used by AILANG Parse.
  • Contract (Art. 6(1)(b)) — Processing documents you submit via the API is necessary to perform the service you requested.
  • Legitimate interest (Art. 6(1)(f)) — Usage metrics for service improvement and security monitoring.
  • Consent — Contact form submissions and optional communications.

4. Data Processor Role

When you upload documents containing personal data to our API, the GDPR roles are:

  • You (the API customer) are the data controller. You decide what data to upload and are responsible for having a lawful basis to process it.
  • Holosun ApS is the data processor. We process your documents only as instructed — to parse them and return results.

As data processor, we:

  • Process documents only to fulfil your API request
  • Do not use document content for training, analytics, profiling, or marketing
  • Do not anonymise, pseudonymise, or make decisions based on document content
  • Do not access or review document content except as required by automated processing

A Data Processing Agreement based on the Datatilsynet standard template governs our processor obligations.

Sensitive data recommendation: For documents containing special category personal data (GDPR Article 9 — health, biometric, racial/ethnic data, etc.), we recommend using browser-based or CLI parsing, which processes data entirely on your device without transmitting it to our servers.

5. AI Provider Data Handling

When you select AI-assisted parsing for PDFs, images, audio, or video:

  • Document content is sent to the AI provider you configure (currently Google Gemini via Vertex AI)
  • By selecting AI parsing, you instruct us to engage that provider as a sub-processor for your request
  • We use enterprise Cloud API endpoints — your data is not used for model training under Google Cloud’s data processing terms
  • We do not retain AI inputs or outputs after your response is delivered
  • Deterministic-format parsing (DOCX, PPTX, XLSX, ODT, ODP, ODS, HTML, Markdown, CSV, EPUB, EML, TEX, RTF) never involves AI — source bytes go in, structured blocks come out, no model calls

6. Sub-processors

ProviderPurposeLocation
Google Cloud Platform
Cloud Run, Cloud Storage, Firestore
API hosting, ephemeral compute, temporary file storage; API keys (hashed), usage counts and request records EU (europe-west1)
Firebase Authentication User authentication. Receives email, auth tokens, IP at login. No document content. US (EU-US DPF + SCCs)
Google Gemini
Vertex AI
AI-assisted PDF/image parsing. Only when you select AI parsing. No data retention, no model training. EU endpoint preferred; US fallback (EU-US DPF + SCCs)

We will notify customers before adding new sub-processors, with the right to object. See the DPA for details.

7. International Transfers

  • Primary infrastructure: EU (europe-west1, Belgium). All compute and document storage stays in the EU.
  • Firebase Authentication: US — covered by the EU-US Data Privacy Framework (Google is on the DPF list) + Standard Contractual Clauses as fallback.
  • Vertex AI: EU endpoint preferred. When US processing occurs, covered by EU-US DPF + SCCs.
  • Alternative regions available on request for customers with specific requirements.

A Transfer Impact Assessment has been conducted in accordance with EDPB Recommendations 01/2020 and is available on request.

8. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”)
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

To exercise these rights, contact docparse@sunholo.com. We will respond within 30 days.

To delete your account, email docparse@sunholo.com from the address you sign in with. We delete the account, its API keys and connections, and its request records within 30 days.

You also have the right to lodge a complaint with Datatilsynet (the Danish Data Protection Authority) at datatilsynet.dk.

9. Security

  • TLS 1.2+ encryption for all API communications
  • Ephemeral processing: most documents parsed in memory only
  • Large files: encrypted at rest (AES-256), auto-deleted after 1 day
  • Cloud Run ephemeral containers with no persistent disk
  • API key authentication for all API requests
  • No human review of uploaded document content
  • Access controls limited to authorised Holosun ApS personnel
  • Uploaded files are not stored; parsed output is kept only as request history (up to 10 KB per request, on by default, can be turned off), deleted after 12 months

10. Cookies

This site uses only essential cookies:

  • Firebase Auth session cookie — required for authentication. Expires when the session ends.

AILANG Parse does not set or use analytics cookies, tracking pixels, or advertising cookies.

Parent domain cookies: If you have visited www.sunholo.com, Google Analytics cookies from that site (e.g. _ga, _gid) may appear in your browser on these pages because both sites share the sunholo.com domain. AILANG Parse does not load, read, or interact with these cookies. They are set by the main Sunholo website, not by this service.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with an updated date. For significant changes affecting your rights, we will provide 30 days’ notice via email to registered users.

12. Contact

Holosun ApS
CVR 44324687
Denmark
Email: docparse@sunholo.com