Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · getbalance.ai

Balance

Graded against 809 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskMEDReviewed 2026-09-21
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

44 verified findings5 policy surfaces2/2 core docs verified
Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
2
medium
1
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Balance's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Terms of Service
    Verified - read in full - 0 citationsstaticLast captured 2026-08-21
  • Privacy Policy
    Verified - read in full - 44 citationsstaticLast captured 2026-09-21
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Describes the technical and organisational security measures the organisation takes to protect personal data, including encryption in transit and at rest, multi-factor authentication, role-based access controls, and use of a certified secrets manager, establishing protective obligations for data security.

" Keeping your data secure is important to us. We take the following steps to protect your personal data in line with good practice and GDPR requirements: Step 1: Encrypt everything. All data is encrypted both in transit (TLS) and at rest. ..."
📍 Privacy Policy › “Your Rights”Jump to exact text →
plan language
Privacy & data use

Establishes the procedure for policy updates, requiring notification of material changes via website posting and where appropriate by email, and identifies the effective date as the revision indicator.

" Balance is a business-to-business (B2B) service. We provide financial reconciliation services to businesses, not to individual consumers. Our customers interact with us through business communication channels (WhatsApp, Slack, and email) r..."
📍 Privacy Policy › “Nature of Service”Jump to exact text →
plan language
Privacy & data use

Restricts Gmail API data access to read-only, limits it to the specifically authorised mailbox, and confines use solely to financial document extraction and processing; explicitly states Balance cannot send, modify, or delete messages, and discloses adherence to Google's API Services User Data Policy including Limited Use requirements — all of which are user-protective restrictions on the scope of email data use.

" This access is read-only , limited to the specific mailbox authorised, and used solely for the purpose of financial document extraction and processing. Balance has no ability to send, modify, or delete messages. Google API Disclosure: Bal..."
📍 § 3.3 (Email Data)Jump to exact text →
plan language
Audit rights / DPA / residency

Discloses that primary data storage is hosted within the European Economic Area (Amsterdam region) and that customer data at rest remains within the EEA; also discloses that limited transfers to the United States occur specifically for AI processing, and states that AI providers operate under zero data retention agreements meaning no customer data is stored after the API call completes — addressing data residency and transfer safeguards.

" Balance Technologies, Inc. is incorporated in the United States. However, all primary data storage (databases and document storage) is hosted within the European Economic Area (EU, Amsterdam region). Customer data at rest remains within th..."
📍 Privacy Policy › “International Data Transfers”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 2
Tier-specific - 0
Total citations - 44
Severity
Surface
Document
Tier
Data retention
High
" We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure."
Privacy Policy › “Data Retention”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Imposes an obligation to retain personal data only as long as necessary for its collected purpose, and specifies that account data is retained for the duration of the account and deleted within 90 days of account closure.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We share personal data with third-party service providers (sub-processors) who assist us in delivering the Service. A complete list of our sub-processors is maintained separately and available upon request. Key categories include: Cloud infrastructure providers (hosting, storage, databases)."
Privacy Policy › “Sub-processors and Data Sharing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Discloses that personal data is shared with third-party sub-processors to deliver the Service, and states that a complete list of sub-processors is maintained and available upon request; identifies cloud infrastructure providers as a key category.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We do not sell personal data to third parties. We do not share personal data for advertising purposes."
Privacy Policy › “Sub-processors and Data Sharing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Expressly prohibits the sale of personal data to third parties and prohibits sharing personal data for advertising purposes — both are user-protective restrictions on data sharing practices.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This access is read-only , limited to the specific mailbox authorised, and used solely for the purpose of financial document extraction and processing. Balance has no ability to send, modify, or delete messages. Google API Disclosure: Balance's use of information received from the Gmail API adheres to Google's API Services User Data Policy, including the Limited Use requirements. We request only the https://www.googleapis.com/auth/gmail.readonly scope. This scope is read-only and is enforced by Google at the API level. Balance cannot send, modify, or delete email from your account, even in principle. Access is strictly limited to viewing email content, metadata, and attachments for the purpose of financial document extraction. We do not use Gmail data to develop, improve, or train generalised AI or machine learning models. Gmail data is only used to provide and improve the financial document extraction features of our Service. OAuth tokens are encrypted at rest using AES-128 symmetric encryption. 3.4 Communication Data When you interact with us via WhatsApp, Slack, or email, we process: Messages and queries sent to our AI assistant (Bea) and our team."
§ 3.3 (Email Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Restricts Gmail API data access to read-only, limits it to the specifically authorised mailbox, and confines use solely to financial document extraction and processing; explicitly states Balance cannot send, modify, or delete messages, and discloses adherence to Google's API Services User Data Policy including Limited Use requirements — all of which are user-protective restrictions on the scope of email data use.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Our internal platform generates technical logs (error logs, performance data) which may incidentally contain personal data. These logs are used for debugging and service reliability only."
§ 3.4 (Communication Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States that technical logs generated by the platform may incidentally contain personal data, and restricts their use solely to debugging and service reliability purposes — a user-protective limitation on log data use.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Keeping your data secure is important to us. We take the following steps to protect your personal data in line with good practice and GDPR requirements: Step 1: Encrypt everything. All data is encrypted both in transit (TLS) and at rest. Third-party integration credentials are stored using Fernet/AES-128 symmetric encryption. Secrets and API keys are managed through a SOC 2 certified secrets manager. Step 2: Control access. Multi-factor authentication (MFA) is enforced on all infrastructure and administrative accounts. We use role-based access controls with the principle of least privilege, so only employees who need access to your data to do their job have it. Step 3: Isolate your data. Each customer’s data is logically separated. Our customers cannot access each other’s data. User identity is managed through Firebase Authentication. Step 4: Minimise what we keep. AI processing logs are automatically deleted on a rolling basis. When a customer’s contract ends, all their data is deleted within 90 days (except where we are legally required to retain financial records). Step 5: Monitor and improve. We regularly assess our security measures and update them as needed. We have a documented data breach response procedure with clear escalation steps."
Privacy Policy › “Your Rights”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Describes the technical and organisational security measures the organisation takes to protect personal data, including encryption in transit and at rest, multi-factor authentication, role-based access controls, and use of a certified secrets manager, establishing protective obligations for data security.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Balance is a business-to-business (B2B) service. We provide financial reconciliation services to businesses, not to individual consumers. Our customers interact with us through business communication channels (WhatsApp, Slack, and email) rather than through a consumer-facing website or application. We do not knowingly collect personal data from children (individuals under 18). If we become aware that personal data of a child has been included in financial documents we process, we will notify the relevant customer. . Changes to This Policy"
Privacy Policy › “Nature of Service”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for policy updates, requiring notification of material changes via website posting and where appropriate by email, and identifies the effective date as the revision indicator.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Balance Technologies, Inc. ("Balance", "we", "us", or "our") operates the Balance financial reconciliation platform available at app.getbalance.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our Service. Balance Technologies, Inc. is a Delaware corporation. Services are delivered through our group companies, including Balance Technologies Ltd (United Kingdom) and Balance Technologies ApS (Denmark). References to Balance in this policy include all group entities. We are committed to protecting your privacy and complying with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR, Regulation 2016/679), and the Danish Data Protection Act (Databeskyttelsesloven)."
Privacy Policy › “Introduction”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the entity ('Balance Technologies, Inc.') operating the Service and the scope of the Privacy Policy, explaining that it covers how personal data is collected, used, disclosed, and protected; also identifies group companies included within 'Balance' for policy purposes.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" For personal data we collect about you as a user of our Service (such as your account information), Balance Technologies, Inc. is the Data Controller. Our contact details are: Balance Technologies, Inc."
Privacy Policy › “Data Controller”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Identifies Balance Technologies, Inc. as the Data Controller for personal data collected about users as part of account use, and provides contact details for data-related inquiries.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Data Protection Contact: Gus Levinson, CTO."
Privacy Policy › “Data Controller”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Names the Data Protection Contact (Gus Levinson, CTO) as part of identifying the responsible party for data protection matters.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Supplier and customer names, addresses, and identifiers."
§ 3.2 (Financial Data (Processed on Behalf of Customers))Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines further financial data categories processed: supplier and customer names, addresses, and identifiers.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" 3.3 Email Data Where a customer authorises Gmail or Google Workspace email integration, we access: Email body content (to identify and extract financial information)."
§ 3.3 (Email Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the scope of email data accessed when a customer authorises Gmail or Google Workspace integration, specifically email body content used to identify and extract financial information.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Email metadata (subject lines, sender information, timestamps)."
§ 3.3 (Email Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines a further category of email data accessed: metadata including subject lines, sender information, and timestamps.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Email attachments (invoices and receipts for processing)."
§ 3.3 (Email Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines an additional email data category accessed: attachments such as invoices and receipts for processing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Slack user IDs and WhatsApp phone numbers used for communication."
§ 3.4 (Communication Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines an additional category of personal data collected: Slack user IDs and WhatsApp phone numbers used for communication purposes.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We process personal data under the following lawful bases: Contract (Art. 6(1)(b)): Processing necessary for the performance of our contract with you, including providing the Service, managing your account, and processing financial data on your behalf. Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, including AI-assisted financial analysis, maintaining security of our systems, and improving our Service. We balance these interests against your rights and freedoms. Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with legal obligations, including financial record retention and regulatory compliance requirements."
Privacy Policy › “Lawful Basis for Processing”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Identifies the lawful bases under which personal data is processed — contract performance, legitimate interests (including AI-assisted analysis, security, and service improvement), and legal obligation — establishing the legal justification framework for each processing activity and indicating that legitimate interests are balanced against user rights and freedoms.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" 3.1 Customer and Contact Data When you engage Balance as a customer, we collect: Contact name and email address."
§ 3.1 (Customer and Contact Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the categories of customer and contact personal data collected (contact name, email address) when a customer engages with the Service.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" 3.2 Financial Data (Processed on Behalf of Customers) As a Processor acting on our customers' instructions, we process: Bank account details and transaction records (synced from accounting software such as E-conomic, Xero, or QuickBooks)."
§ 3.2 (Financial Data (Processed on Behalf of Customers))Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the categories of financial data processed on behalf of customers in the processor role, including bank account details, transaction records, and integration sources.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Balance's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Balance's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Balance's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Balance requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Balance's published policies yet.

What the policies actually cover

0 topics

None of Balance's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

144
clauses
36
patterns
36
stances
data retention · 12training use · 11privacy sharing · 10ip ownership · 2legal burden · 1
data retentionMEDIUMPrivacy Policy › “Data Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.
Open source citation
data retentionMEDIUM

The clause allows indefinite, perpetual, or necessity-based retention.

The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs. Where applicable, participation in the EU-US Data Privacy Framework. Data Retention We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure. Financial documents and transaction data: ...
Open source citation
data retentionMEDIUMPrivacy Policy › “Data Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.
Open source citation
data retentionMEDIUMPrivacy Policy › “Data Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.
Open source citation
data retentionLOWPrivacy Policy › “Data Retention”

The clause provides a deletion or time-bounded retention path.

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersdata retentionconditionalMEDIUM9
All applicable tiersprivacy data useworsensHIGH4
All applicable tiersprompt ownershipimprovesLOW2
All applicable tierssubprocessors data sharingworsensHIGH2
All applicable tierstraining useworsensHIGH3
Apidata retentionimprovesLOW4
Apitraining useconditionalMEDIUM8
Pro / Paidindemnity liabilityconditionalMEDIUM1
Team / Businesstraining useworsensHIGH3

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

worsenedmedium materialityAug 21Sep 21, 2026

retention worsened from low/deletion or time bound to medium/indefinite or necessity based.

Before · low
7.1 Term. These Terms begin on your first use of the Services and continue until terminated. 7.2 Termination. Either party may terminate on 30 days' written notice. Balance may suspend or terminate immediately for material breach (including non-payment more than 30 days overdue) or where required for anti-money-laundering compliance. 7.3 Effect of termination. Balance will provide an export of your Customer Data in a machine-readable format and delete Customer Data within 90 days (subject to backup cycles), except where legally required to retain: up to 7 years for UK clients (HMRC record-keeping rules) or 5 years for Danish clients (Bogføringsloven § 12). 7.4 Survival. Sections 4, 8, 9, 10, 11, 12, 13, 16, and 17 survive termination.
Before citation
After · medium
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.
After citation
improvedmedium materialityAug 3Aug 21, 2026

retention improved from medium/indefinite or necessity based to low/deletion or time bound.

Before · medium
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected: Account data: retained for the duration of your account and deleted within 90 days of account closure.
Before citation
After · low
7.1 Term. These Terms begin on your first use of the Services and continue until terminated. 7.2 Termination. Either party may terminate on 30 days' written notice. Balance may suspend or terminate immediately for material breach (including non-payment more than 30 days overdue) or where required for anti-money-laundering compliance. 7.3 Effect of termination. Balance will provide an export of your Customer Data in a machine-readable format and delete Customer Data within 90 days (subject to backup cycles), except where legally required to retain: up to 7 years for UK clients (HMRC record-keeping rules) or 5 years for Danish clients (Bogføringsloven § 12). 7.4 Survival. Sections 4, 8, 9, 10, 11, 12, 13, 16, and 17 survive termination.
After citation
worsenedhigh materialityJul 21Jul 21, 2026

data sharing worsened from medium/third party or vendor sharing to high/sale or sell.

Before · medium
6(1)(c)): Processing necessary to comply with legal obligations, including financial record retention and regulatory compliance requirements. Use of Artificial Intelligence Balance uses third-party AI services via API to provide automated receipt analysis, transaction matching, expense categorisation, journal entry creation, financial reporting, and to answer questions and analysis requests from our customers. Important information about our AI processing: All AI processing occurs via API calls with zero data retention (ZDR) agreements in place. No customer data is currently used to train AI models. We may review this position in the future and will update this policy and seek appropriate consent or lawful basis before any such change. For higher-complexity or higher-importance tasks, AI-generated results are reviewed by our internal team before being shared with customers. For routine, lower-complexity tasks, AI may communicate results directly to customers via WhatsApp, Slack, or email, with the AI escalating to our team when necessary. We retain AI processing logs for service improvement and debugging purposes. These logs are subject to our Data Retention Policy. Sub-processors and Data Sharing We share personal data with third-party service providers (sub-processors) who assist us in delivering the Service. A complete list of our sub-processors is maintained separately and available upon request. Key categories include: Cloud infrastructure providers (hosting, storage, databases).
Before citation
After · high
How we use it: extracted financial documents are stored and processed for your bookkeeping. Non-financial email content is not retained. Sharing: Google User Data is shared only with the sub-processors listed in our Privacy Policy. We do not sell, transfer, or use Google User Data for advertising, or use it to train AI models. Human access: Human review of Google User Data occurs only where necessary for Service delivery with your consent (our accountants reviewing AI-extracted financial documents before they are finalised), for security investigation, to comply with applicable law, or in aggregated/anonymised form for internal operations. Encryption: TLS 1.2+ in transit; AES-128 or stronger at rest. Retention and deletion: Google User Data is retained for the duration of your account. On request, Balance will delete all Google User Data within 7 business days. Contact privacy@getbalance.ai. 4.4 Reliance. Balance relies in good faith on the accuracy, completeness, and timeliness of information you provide. We do not independently verify facts, documents, or transactions you submit. 5. Customer Responsibilities You agree to: provide timely, accurate, and complete information; maintain the security of your account credentials; review and approve material outputs before relying on them for statutory purposes; retain responsibility for all tax submissions, statutory filings, and regulatory obligations in your jurisdiction; comply with anti-money-laundering checks we are legally required to perform (including identity verification and beneficial-ownership disclosure); use the Services only for lawful business purposes.
After citation
Sep 21, 2026model trainingLOW

Latest stance: no training claim on training use

This access is read-only , limited to the specific mailbox authorised, and used solely for the purpose of financial document extraction and processing. Balance has no ability to send, modify, or delete messages. Google API Disclosure: Balance’s use of information received from the Gmail API adheres to Google’s API Services User Data Policy, including the Limited Use requirements. We request only the https://www.googleapis.com/auth/gmail.readonly scope. This scope is read-only and is enforced by Google at the API level. Balance cannot send, modify, or delete email from your account, even in principle. Access is strictly limited to viewing email content, metadata, and attachments for the purpose of financial document extraction. We do not use Gmail data to develop, improve, or train generalised AI or machine learning models. Gmail data is only used to provide and improve the financial document extraction features of our Service. OAuth tokens are encrypted at rest using AES-128 symmetric encryption. 3.4 Communication Data When you interact with us via WhatsApp, Slack, or email, we process: Messages and queries sent to our AI assistant (Bea) and our team.
Open timeline citation
Sep 21, 2026model trainingHIGH

Latest stance: training permitted on training use

Balance uses third-party AI services via API to provide automated receipt analysis, transaction matching, expense categorisation, journal entry creation, financial reporting, and to answer questions and analysis requests from our customers. Important information about our AI processing: All AI processing occurs via API calls with zero data retention (ZDR) agreements in place. No customer data is currently used to train AI models. We may review this position in the future and will update this policy and seek appropriate consent or lawful basis before any such change. For higher-complexity or higher-importance tasks, AI-generated results are reviewed by our internal team before being shared with customers. For routine, lower-complexity tasks, AI may communicate results directly to customers via WhatsApp, Slack, or email, with the AI escalating to our team when necessary. We retain AI processing logs for service improvement and debugging purposes. These logs are subject to our Data Retention Policy.
Open timeline citation
Sep 21, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

We do not sell personal data to third parties. We do not share personal data for advertising purposes.
Open timeline citation
Sep 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We share personal data with third-party service providers (sub-processors) who assist us in delivering the Service. A complete list of our sub-processors is maintained separately and available upon request. Key categories include: Cloud infrastructure providers (hosting, storage, databases).
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-08-21· verified 2026-08-21
  • Privacy Policy:Last captured 2026-09-21· verified 2026-09-21

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

162 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Balance's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Balance's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.