Privacy Policy
Last updated on September 25, 2026.
Parla FM, Inc., doing business as General Input ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, and protect information when you interact with our websites, products, or services (collectively, the "Services").
Information We Collect and How We Use It
We collect the following kinds of information:
- Account information. Your name, email address, and anything you add to your profile, such as a picture, a short bio, your time zone, or how you heard about us.
- Content you give the Services. Your messages and conversations with specialists, files and photos you attach, what you dictate, the memory your specialists keep, and the workflows, apps, and records you create in a workspace, including contacts you store in its CRM.
- Data from connected services. When you connect a third-party service, the Services process the data your specialists, conversations, and workflows use from it (for example, messages, documents, calendar events, or spreadsheets), solely to do what you have asked.
- Mobile app information. A push notification token and an installation identifier, so we can send you notifications. The app uses your camera only to scan a sign-in code or take a photo you choose to attach, your photo library only for photos you choose to attach or save, and your microphone only while you dictate.
- Technical and usage information. Browser type, device and operating system details, IP address, and how you use the Services, as described under Cookies and Similar Technologies below.
- Marketing attribution. How you first arrived, such as a campaign link or an advertising click identifier, as described under Cookies and Similar Technologies below.
- Payment information. Payments are processed by Stripe. We do not store full card numbers.
We use this information to:
- Provide and maintain the Services
- Run the conversations, specialists, and workflows you use
- Send service emails and notifications, and occasional product emails you can unsubscribe from
- Respond to inquiries and communications
- Improve features and functionality
- Measure how well our own advertising works
- Keep the Services secure and prevent abuse
- Comply with applicable legal obligations
Cookies and Similar Technologies
We use a small number of cookies and similar browser storage technologies. Our public marketing website also uses a visitor identification service that works with third-party data partners, described below. This service does not run in the authenticated product.
- Strictly necessary. When you sign in, we set an
httpOnly,Securesession cookie (named__Secure-better-auth.session_token) that keeps you authenticated for up to 7 days. The dashboard also stores an authentication token in your browser's local storage. These are required for the Services to work and cannot be switched off. - Analytics. Our public marketing website uses Google Analytics to understand aggregate traffic and page usage. This sets Google Analytics cookies (such as
_ga) containing a randomly generated identifier. We use this only in aggregate to improve the site, and we have not enabled Google Analytics advertising or remarketing features. - Product analytics. The General Input web app uses PostHog to understand how features are used, such as which pages are opened and which buttons are pressed. We use this to improve the product, not for advertising.
- Marketing attribution. Our website sets first-party cookies on
generalinput.comand its subdomains to remember how you first arrived, such as a campaign link or an advertising click identifier:gi_aid(up to 400 days) andgi_src(up to 90 days). If you then create an account, we report that sign-up to the advertising platform the click came from (Google Ads or Reddit Ads) so we can measure our advertising. - Visitor identification. Our public marketing website uses RB2B to identify business visitors. It sets first-party cookies (such as
_reb2buid) and works with online data partners that may recognize your browser from identifiers those partners have already set elsewhere. We use this to understand which businesses are interested in General Input and for business-to-business outreach. It runs only ongeneralinput.comand is not present when you are signed in to the product.
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout. You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out.
You can block or delete cookies through your browser settings, and you can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on. Blocking strictly necessary cookies will prevent you from signing in.
How We Use AI Providers
General Input's AI features, including conversations, specialists, workflows, apps, and voice dictation, send the content involved to third-party AI providers so they can produce a response. That content can include your messages, files and photos you attach, what you dictate, your specialists' memory, and data your specialists read from services you have connected. The providers are listed under Subprocessors below. We configure them for zero data retention where supported, and their terms prohibit training on submitted content.
If you connect your own AI subscription, such as a Claude, ChatGPT, Gemini, or Grok account, content you send through it goes to that provider under your account's own terms. A workspace's administrators can also add AI services of their own choosing. Models that run on your own computer do not send that content to an AI provider.
Before the General Input mobile app sends anything to an AI provider, it tells you what it shares with AI providers and asks for your permission.
Google User Data
General Input's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account to General Input, you are granting us access to specific scopes that you select at authorization time. We may request the following scopes depending on which Google integrations you connect:
- Gmail (
gmail.readonly,gmail.send,gmail.modify): used to read messages, send mail, and triage your inbox (mark read, label, archive) only as your configured workflows require. We do not request permanent deletion or settings changes. - Google Drive (
drive,drive.readonly,drive.meet.readonly): used to read, create, and modify Drive content as your configured workflows require, and to access Google Meet recordings and transcripts when a workflow processes them. You select read-only or read/write at connection time. - Other Google services (Calendar, Sheets, Docs, Slides, Forms, Tasks, Contacts, Photos, YouTube, Analytics, Vault, Groups, Meet): scopes are requested per integration, scoped to the features you use.
Limited Use commitments. Information received from Google APIs is used solely to provide and improve user-facing features that are prominent in the Services. We do not:
- Use Google user data for advertising purposes.
- Use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models. AI features that operate on your Google data only do so to deliver the workflow you have configured for your own account.
- Sell, rent, or transfer Google user data to third parties except as required to deliver a feature you have requested, to comply with applicable law, or as part of a merger, acquisition, or sale of assets where we will require the receiving party to honor this policy.
- Allow humans to read Google user data, except (a) with your explicit consent for specific messages, (b) where required for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.
AI subprocessors and Google data. When you use General Input's AI features, including conversations, specialists, workflows, and apps, content from your connected Google accounts may be sent to large language models from providers including OpenAI, Anthropic, Google (Vertex AI), xAI, Fireworks AI, and the model gateways Vercel (AI Gateway) and OpenRouter. We configure these providers for zero data retention where supported and ensure their terms prohibit training on submitted content. Content from your connected Google accounts is sent to these providers only as needed to deliver the specific output you have requested.
How to revoke access and delete your Google data. You can delete any Google credential at any time from the Integrations page, which deletes the stored token from our systems and revokes the grant with Google. You can also revoke access directly at myaccount.google.com/permissions. To delete your General Input account and all associated Google-derived data, see How to Request Deletion of Your Data below.
Meta Platform Data
General Input offers optional integrations with Meta technologies — Meta Ads, Facebook Pages, and Instagram. If you connect one, we receive and process data from the Meta Platform ("Platform Data") solely to operate the workflows you configure. Our use of Platform Data complies with the Meta Platform Terms and Developer Policies.
You choose which permissions to grant at authorization time. We may request the following, depending on which Meta integrations you connect:
- Account identification (
public_profile,email): used to identify the connected account and display it in your credential list. - Meta Ads (
ads_read,ads_management,business_management,catalog_management,pages_show_list): used to read ad accounts, campaigns, ad sets, ads, and insights, and — where you grant write access — to create and update campaigns, creatives, custom audiences, and product catalogs. - Facebook Pages (
pages_show_list,pages_read_engagement,pages_read_user_content,read_insights,pages_manage_posts,pages_manage_engagement,pages_manage_metadata,pages_manage_cta,pages_messaging): used to read and publish Page content, read comments, visitor posts and Page insights, manage Page settings, and send or receive Messenger messages on behalf of Pages you manage. We access only Pages you administer — never personal Facebook profiles or your friends' data. - Instagram (
instagram_basic,instagram_manage_insights,instagram_content_publish,instagram_manage_comments,instagram_manage_messages): used to read profile information, media, and insights, publish posts, reels and stories, and manage comments and Direct messages for Instagram Business or Creator accounts linked to Pages you manage. Personal Instagram accounts are not accessed.
Our commitments for Platform Data. We use Platform Data only to provide and improve the user-facing features you have configured. We do not:
- Use Platform Data for advertising, ad targeting, or to build profiles of people for advertising purposes.
- Sell, license, or transfer Platform Data to data brokers, information resellers, or any third party, except to the subprocessors listed below acting on our behalf, to comply with applicable law, or as part of a merger or acquisition in which the receiving party is required to honor this policy.
- Use Platform Data to develop, improve, or train generalized or non-personalized AI or machine learning models. AI features operate on your Platform Data only to deliver the workflow output you requested for your own account.
- Allow humans to read Platform Data, except (a) with your explicit consent, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.
AI subprocessors and Platform Data. When you use General Input's AI features, including conversations, specialists, workflows, and apps, Platform Data may be sent to large language models from the providers listed under Subprocessors below. We configure these providers for zero data retention where supported and their terms prohibit training on submitted content. Platform Data is sent to them only as needed to produce the specific output you requested.
How to revoke access and delete your Meta data. You can delete any Meta credential at any time from the Integrations page, which permanently deletes the stored access token and credential from our systems and stops all further access to your Meta data. To additionally revoke the authorization at Meta, remove General Input from Facebook Settings → Apps and Websites. To have Platform Data deleted, see How to Request Deletion of Your Data below.
Subprocessors
We engage the following categories of subprocessors to deliver the Services. Each is bound by contractual data-protection obligations:
- Cloud infrastructure and hosting: Google Cloud Platform (compute, Cloud SQL, Cloud Storage), Cloudflare (object storage, DNS), Vercel (website and web app hosting).
- AI / model providers: OpenAI, Anthropic, Google (Vertex AI), xAI, Fireworks AI, and the model gateways Vercel (AI Gateway) and OpenRouter, configured for zero-retention use where supported; AssemblyAI (speech-to-text for voice dictation).
- Web search and browsing: Exa, Parallel, and Tavily (web search), ScrapingBee (web page retrieval), Google Maps Platform (place lookups), Kernel (remote browsers for web tasks).
- Code execution: E2B and Google Cloud (sandboxed code execution).
- Email delivery: Postmark.
- Push notifications: Expo, which delivers through Apple and Google push services.
- Payments: Stripe.
- Analytics and advertising measurement: Google Analytics and RB2B (website), PostHog (web app), Google Ads and Reddit Ads (sign-up measurement).
- Observability: Sentry (error reporting), Datadog and self-hosted Loki (logs and metrics).
- Secrets management: Infisical.
Sharing, Retention, and Security of Information
We do not sell your personal information. We share information with the subprocessors listed above only to the extent necessary for them to perform services on our behalf, and we share limited sign-up information with advertising platforms to measure our own advertising, as described under Cookies and Similar Technologies. To opt out of that measurement, email privacy@generalinput.com. We may also disclose information if required to do so by law or in response to valid legal requests.
We retain information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy or as required by law. Conversations, workflow runs, and other workspace content are kept until you or your workspace delete them, or until your account or workspace is deleted. Operational logs and database backups expire on a rolling schedule of about 30 days. Content from connected accounts is fetched on demand and cached only as needed to do what you have asked.
We take administrative, technical, and organizational measures designed to protect information from unauthorized access, use, alteration, or disclosure. Credentials such as OAuth tokens are encrypted at rest using AES-256-GCM with keys held separately in our secrets manager. Data in transit is encrypted using TLS. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
How to Request Deletion of Your Data
You can delete your data at any time, in any of the following ways.
1. Delete a single connected account. In General Input, open Integrations in the sidebar, find the connected account (for example your Meta Ads, Facebook Pages, Instagram, or Google credential), and choose Delete from its menu. This permanently deletes the stored access token and credential from our systems, disables any workflows that depended on it, and stops all further access to that service. For Google connections we additionally revoke the grant with Google directly.
2. Delete your account yourself. In the General Input web app, open Settings, then Profile, then Delete account. In the mobile app, open Preferences, then Account, then Delete account. Before anything is deleted, you see what goes, and for each workspace you share with others you choose whether what you made there, including connected accounts, goes to another member or is deleted. Your profile, sign-ins and devices, conversations, memory, and AI connections are deleted right away. A workspace that only you belong to is closed right away and permanently erased within 30 days.
3. Ask us to delete your account. Email privacy@generalinput.com from the address associated with your account, with the subject line "Data deletion request". You do not need an active subscription to make a request, and there is no charge.
We will acknowledge your request within 5 business days and complete deletion within 30 days. Deletion covers your account and profile, all stored third-party credentials and access tokens, all data received from connected services (including Meta Platform Data and Google user data), your workflows and agents, and workflow execution history and logs. We will email you to confirm once deletion is complete. We retain only the minimum records we are legally required to keep, such as billing and tax records, and encrypted backups purge on a rolling 30-day cycle.
If you connected a Meta service, you can additionally remove General Input from Facebook Settings → Apps and Websites, which revokes access at the Meta end. Removing the app there revokes access but does not by itself delete data already held by us. Delete your account or email us as described above to have it deleted.
Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
International Users
We are based in the United States, and we process and store information in the United States and wherever our subprocessors operate.
Your Choices, Updates, and Contact Information
You may choose not to provide certain information to us, though doing so may limit your ability to use some features of the Services. You can delete any third-party credential at any time from the Integrations page, or request deletion of your account and all associated data as described in How to Request Deletion of Your Data. Depending on your location, you may have additional rights regarding your personal information under applicable laws, including rights to access, correct, port, or restrict processing of your personal information, and to complain to your local data protection authority. You can unsubscribe from product emails using the link in any of them.
We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the Services after any changes indicates acceptance of the updated policy.
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Parla FM, Inc. (d/b/a General Input)
Email: privacy@generalinput.com