ParrotIt

For data companies

Your customers’ form answers.
In your product.

Give your customers a way to send their ParrotIt form answers straight to your software. They choose what to share. You receive answers sealed to your own key.

Connect with ParrotIt · Available on Enterprise

Create your account, then tell us about your company through our contact form. We’ll discuss Enterprise access and partner approval.

How it works

One approval. New answers arrive from then on.

01

You add the button.

Put Connect with ParrotIt in your product. Your customer follows it to ParrotIt.

02

Your customer chooses.

The account owner chooses specific forms or all forms, including new ones. They tap Allow once on a trusted device.

03

You collect the answers.

New answers are encrypted on the person’s device, before upload, and sealed to your public key. Your software opens them with your private key.

The customer stays in control

They choose the forms.
They see who can read them.

Riverside Swim Club wants its answers in Acme Data. The club’s account owner picks the forms and taps Allow.

If they choose All forms, forms they publish later join automatically. They can include earlier answers too.

Only the account owner can approve the connection, on a device ParrotIt already trusts.

ParrotItAcme Data

Acme Data wants your form answers

Website checked by ParrotIt · acme-data.com

All formsand new ones
Choose

Earlier answers too

  • Acme Data can read them
  • People filling them in are told
  • Disconnect any time
CancelAllow
Example approval screen. Your company’s name and checked website appear here.

What reaches your software

The answers, with the fields they belong to.

  • The connected forms and their questions, including wording, types, choices and required fields.
  • Answers under standard field names, with any attached files.
  • Each answer’s ID, form, submission time and the key it was sealed to.
  • The IDs of answers deleted since you last checked.

With All forms, the list grows when your customer publishes another form.

Example answer, opened by Acme Data
{
  "subject.child.firstName": "Mia",
  "personal.child.dateOfBirth": "2016-04-12",
  "personal.applicant.fullName": "Sam Taylor",
  "contact.applicant.email": "sam@example.com"
}

Only what was shared.

No device, location or ParrotIt card details. No forms outside the customer’s choice. No customer master key, signing history or certifying history.

People are told

Your name is there before they send.

People see that their answers also go to your company. After you collect an answer, their record names you again.

Example form

Riverside Swim Club

Also sends answers to Acme Data.

Copied to Acme Data
Example notice and record. People see your company’s name.

A connection you control

Your keys. Your responsibility.

Your private keys stay with you.

ParrotIt holds only your public keys. It cannot open the answers sealed to your key.

Your website is checked.

A DNS record proves control of your domain. A person at ParrotIt approves your application before customers can connect.

No client secret to leak.

Your server proves who it is with a short token signed by your own key.

Change keys without reconnecting.

Your customers stay connected when you change keys. If a key is stolen, ask us to pause collection while you replace it.

For developers

A familiar connection flow.

OAuth 2.0 is the approval flow behind familiar “Sign in with” buttons. PKCE ties the returned code to the request that started it.

Your server uses the API, the interface your software calls, to collect encrypted answers and confirm receipt. It also checks for deleted answer IDs.

The developer kit includes an opener library for JavaScript and Python, a small example server and an OpenAPI description of the interface. The developer guide and kit are not public yet.

Talk to us about your integration

The connection at a glance

  • Signed authentication with private_key_jwt and EdDSA.
  • PKCE with S256.
  • Answers sealed using RSA-OAEP-256 and AES-GCM.
  • Collection uses a cursor and a list of deleted IDs.

600 requests a minute per connection. 600 token requests an hour per network.

See the button link and API calls

Your button is an ordinary link. This example shows the structure; your registered details and generated values replace the examples.

https://parrotit.app/setter/authorize?response_type=code&client_id=pc_…&redirect_uri=https%3A%2F%2Fapp.acme-data.com%2Fparrotit%2Fcallback&state=…&code_challenge=…&code_challenge_method=S256
POST /v1/oauth/token
GET  /v1/connections
GET  /v1/submissions
GET  /v1/submissions/removed
POST /v1/submissions/ack

The one time code lasts ten minutes. An access token lasts an hour. A refresh token lasts 90 days and is replaced each time it is used. Reusing a refresh token ends the connection.

Become a partner

Start with an account. Then talk to us.

What partner setup involves

Setup runs through the ParrotIt partner skill in Claude Code. It makes your keys on your computer and asks for your company name, logo, website, privacy policy, return addresses and a contact email.

You add a DNS record to prove control of your domain. ParrotIt reviews your application. Once approved, you can test the connection with a form and an answer.

Before you start

A few practical details.

Can ParrotIt read the answers?

No. New answers are encrypted on the person’s device before upload and sealed to your public key. ParrotIt never holds your private key and cannot open those answers.

Who chooses the forms?

Your customer’s account owner chooses on a device ParrotIt already trusts. They can choose specific forms or all forms, including forms they publish later. They can also include earlier answers. Each form supports up to three connections, partners included.

Do people know about us?

Yes. Before sending, people see “Also sends answers to Acme Data.” with your company’s name in place of Acme Data. Once you collect an answer, their record says “Copied to Acme Data”.

What happens when an answer is deleted?

The API supplies the IDs of answers deleted since you last checked. Your software uses those IDs to remove its copies. Disconnecting stops new answers at once, but does not remove answers you already hold.

What if our key leaks?

Ask ParrotIt to pause your partner access. That stops every access token at once, while your customers stay connected. Make new keys. Collection can resume after ParrotIt approves them.

What if a customer’s account is paused?

Your refresh token works again when the account reopens, within its 90 day lifetime.

Which plan do we need?

Partner access is available on Enterprise. Create your account, then use our contact form to tell us about your company. Opening an account does not enable partner access or approve your application.

Is there a contract?

Yes. You accept our Partner Terms when you apply. Contact us to discuss Enterprise access. Any agreement covering the answers you hold for your customer, usually a data processing agreement, is between you and that customer. ParrotIt is not a party to it.

Partners · Enterprise

Put your customers’ answers to work in your product.

Create your account, then tell us about the connection you want to build.

Create an account

Already have an account? Contact us