Parsley.
Parsley. — Privacy Policy
1. Data Controller
Maurice Heinze
Schmollerstraße 55, 74074 Heilbronn, Germany
Email:
parsleyextension@icloud.com
2. Purpose
Parsley. exists solely to turn recipe pages into a clean reading view (ingredients, steps, tips, FAQ) — using Schema.org Recipe data where available, plus optional AI-assisted extraction/enrichment.
3. Legal bases (Art. 6(1) GDPR)
| Processing | Legal basis |
|---|---|
| Local parsing of JSON-LD recipe data (no data sent) | No personal-data processing by us; happens locally in your browser |
| Sending page text/title/URL for extraction or AI enrichment | Art. 6(1)(b) GDPR — performing the service you actively requested |
| IP processing by the hosting provider for rate-limiting/abuse protection | Art. 6(1)(f) GDPR — legitimate interest in API stability and abuse prevention |
| Local cache in chrome.storage.local | Art. 6(1)(f) GDPR — legitimate interest in performance/offline use; never leaves your device |
You may object to processing based on (f) at any time (see Section 8); since IP processing is technically required to run the API, objecting effectively means the extension can't be used.
4. Data processed
- Website content — visible page text and Schema.org Recipe JSON-LD (ingredients, instructions, times, description, referenced images), as needed for the reader, extraction, or enrichment.
- URL and page title of the recipe page during extraction/enrichment — stored locally as a cache key and sent with API requests for context.
- IP address — seen by the API host (Vercel) as part of normal operation, used only for rate-limiting/abuse protection (per-IP daily limits). Not used to build advertising profiles.
- Optional API configuration — base URL and optional shared secret in Chrome storage. The OpenRouter API key lives server-side only, never in the extension.
- Local recipe cache — successful extract/enrich results stored in chrome.storage.local on your device, keyed by normalized URL.
We do not collect: names, email addresses, or user accounts · health, financial, or payment data · passwords or login credentials · private communications · continuous browsing history, clickstreams, mouse movement, or keystroke logs · analytics or advertising IDs within the extension.
5. When data leaves your browser
- JSON-LD reader only: structured recipe data is parsed and displayed locally — nothing is sent.
- AI enrichment (steps/tips/FAQ): recipe fields plus relevant page text, title, and URL are sent to our API.
- Manual extraction: page text, title, and URL for that single request are sent to our API.
- Cached results for a URL stay on your device and don't trigger another API call unless you force a reload.
6. Recipients, processors, and international transfers
| Provider | Role | Data processed | Location / transfer basis |
|---|---|---|---|
| Vercel Inc. | Hosts the extract/enrich proxy | IP address, request metadata | USA — transferred under EU Standard Contractual Clauses (SCCs); DPA: https://vercel.com/legal/dpa |
| OpenRouter | Runs AI models on submitted recipe/page text | Recipe/page content, title, URL | USA — transferred under SCCs; may route to further model providers. A DPA is incorporated by reference into OpenRouter's Terms of Service (https://openrouter.ai/terms); a mutually signed DPA document is, per OpenRouter, currently only issued to enterprise-tier customers — see https://openrouter.ai/privacy |
| Upstash Redis (if configured) | Stores rate-limit counters (e.g., per IP) | IP-based counters only, no recipe content | EU region — no international transfer |
| Supabase (if configured) | Shared recipe cache + per-URL visit totals | Normalized recipe page URL, cached LLM payload, visit count — no user identity | As configured on the Supabase project (prefer EU) |
Data processing agreements (Art. 28 GDPR) are in place with these providers, and, where data leaves the EU/EEA, appropriate safeguards under Art. 44 et seq. GDPR (in particular SCCs) apply.
Your data is never sold, never used for credit checks or lending, and never used outside recipe extraction and display.
7. Retention
- On your device: cache persists until you clear extension data, uninstall the extension, or entries are evicted under storage pressure.
- API/AI providers: request content is processed only to fulfill that specific extract/enrich call. We don't maintain a long-term archive of your recipe inputs beyond rate-limiting counters, shared cache entries, visit totals, and standard hosting logs.
- Rate-limit counters: roll over/are deleted at the end of each time window (day).
- Shared recipe cache / visit totals (Supabase): retained until deleted by the operator; keyed only by recipe URL.
- Hosting logs: subject to Vercel's standard log retention.
8. Your rights
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to legal retention duties), restriction of processing (Art. 18), data portability (Art. 20), object to processing based on legitimate interest (Art. 21), and withdraw consent for the future where processing relies on consent.
Because Parsley. keeps essentially no persistent identifiers tied to you (no accounts, no user IDs), matching past requests to your identity may be limited — please include relevant context (approximate date, affected URL) with any request.
Right to complain: you may lodge a complaint with a data protection supervisory authority, e.g. the one responsible for your place of residence, or with the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (competent authority for the controller, based in Heilbronn, Germany).
9. Automated decision-making
No automated decision-making under Art. 22 GDPR that produces legal effects or similarly significantly affects you takes place. AI enrichment only reformats text (recipe steps/tips/FAQ); it does not evaluate people.
10. Voluntariness
Using Parsley. and triggering extraction/enrichment is voluntary. Without sending page content, title, and URL to our API, extraction and AI enrichment cannot function — the local JSON-LD reader is unaffected.
11. Chrome permissions
- activeTab / scripting — reading the active recipe page during extraction/overlay
- storage / unlimitedStorage — settings and local cache
- Host access to our API (e.g., Vercel) and content scripts on web pages to detect Recipe JSON-LD and render the reader
12. Children
Parsley. is not directed at children under 13. We do not knowingly collect personal data from children.
13. Changes
This policy may change as the product evolves or for legal reasons; the date above will be updated accordingly. For material changes we'll aim to give reasonable notice (e.g., updated date, possibly a store notice). Continued use after a revised version is published constitutes acknowledgment.
14. Contact
For privacy questions: parsleyextension@icloud.com or via the support/contact option on Parsley.'s Chrome Web Store listing.