Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · thebillow.ai

Billow AI Labs

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskUNRATEDReviewed 2026-08-31
Creator: Not yet rated · GRC: Not yet rated · Counsel: Not yet rated
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Privacy Policy · verbatim

Both providers operate under zero-retention agreements and do not train on or retain customer data.

highest-risk verified finding on training use — tap for the citation
11 verified findings4 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Lower concern: Privacy and data use

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
0
medium
0
low
1/1
docs
Trains on your data?
No training on your content by default
from 1 cited finding
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Billow AI Labs's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 11 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Why unrated?

Insufficient signal

The verified citations do not support a stronger high, medium, or low rating without overclaiming.

Document status
  • Privacy Policy
    Verified - read in full - 11 citationsstaticLast captured 2026-08-31
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Imposes an obligation on the provider to encrypt data in transit using TLS 1.2+ and data at rest using AES-256-GCM with PBKDF2 key derivation and AWS-managed encryption, specifying the technical security measures applied to user data.

" All data in transit is encrypted using TLS 1.2+. Data at rest is encrypted using AES-256-GCM via the Web Crypto API with PBKDF2 key derivation, with AWS-managed encryption at the database layer."
📍 Privacy Policy › “Encryption”Jump to exact text →
plan language
Privacy & data use

Obligates the provider to store API keys as encrypted secrets, restrict cross-origin access to trusted domains, apply least-privilege access principles, and enforce multi-factor authentication for production access, describing technical and organizational security controls over user data.

" API keys are stored as encrypted secrets in Cloudflare Workers. CORS is restricted to specific trusted domains. Production access follows least-privilege principles with MFA enforcement."
📍 Privacy Policy › “Access Controls”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 0
Tier-specific - 0
Total citations - 11
Severity
Surface
Document
Tier
Training on your content
High
" Both providers operate under zero-retention agreements and do not train on or retain customer data."
Privacy Policy › “Anthropic Claude model responses User prompts, cell context”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States that both AI providers operate under zero-retention agreements and do not train on or retain customer data — prohibits training use and data retention by subprocessors, a user-favorable restriction.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We generate anonymous user IDs and workbook IDs to associate preferences with your session without identifying you personally. We do not collect names, email addresses, or other personal identifiers."
§ 3 (Anonymous Identifiers)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Describes the use of anonymous user and workbook IDs to associate preferences without personally identifying users, and explicitly states that names, email addresses, or other personal identifiers are not collected — a restriction limiting the scope of personal data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Billow AI Companion (“the Add-in”) is a Microsoft Excel Add-in that provides AI-powered assistance for spreadsheet tasks. This Privacy Policy describes how we collect, use, and protect your information."
Privacy Policy › “Overview”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the product as a Microsoft Excel Add-in providing AI-powered assistance and identifies the document as describing collection, use, and protection of user information — a definitional framing clause that scopes the policy's subject matter.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you use the Add-in, we process your active selection, workbook structure (sheet names, table names, column headers), and cell values within ranges you interact with. Purpose: To provide contextual AI assistance for your spreadsheet tasks. Retention: Spreadsheet data is processed in memory and not permanently stored."
§ 1 (Spreadsheet Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines what spreadsheet data is processed (active selection, workbook structure, cell values), states the purpose of processing (contextual AI assistance), and establishes a retention obligation — spreadsheet data is processed in memory only and not permanently stored.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" All data in transit is encrypted using TLS 1.2+. Data at rest is encrypted using AES-256-GCM via the Web Crypto API with PBKDF2 key derivation, with AWS-managed encryption at the database layer."
Privacy Policy › “Encryption”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Imposes an obligation on the provider to encrypt data in transit using TLS 1.2+ and data at rest using AES-256-GCM with PBKDF2 key derivation and AWS-managed encryption, specifying the technical security measures applied to user data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" API keys are stored as encrypted secrets in Cloudflare Workers. CORS is restricted to specific trusted domains. Production access follows least-privilege principles with MFA enforcement."
Privacy Policy › “Access Controls”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Obligates the provider to store API keys as encrypted secrets, restrict cross-origin access to trusted domains, apply least-privilege access principles, and enforce multi-factor authentication for production access, describing technical and organizational security controls over user data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Request metadata is logged for security monitoring. PII is automatically redacted from logs. No raw user content is logged."
Privacy Policy › “Audit Logging”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Obligates the provider to log only request metadata for security monitoring, automatically redact personally identifiable information from logs, and prohibits logging of raw user content — protective of user data confidentiality.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" You can view your stored memory data using the memory viewer in the Add-in."
Privacy Policy › “Data Access”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Grants users the right to view their stored memory data through the memory viewer tool in the Add-in, establishing a user-facing access right over personal data held by the provider.

AI-generated interpretation, not legal advice.

Data retention
High
" All stored data has automatic expiration (TTL) configured and is automatically deleted after the retention period."
Privacy Policy › “Data Retention”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States that all stored data has automatic expiration (TTL) configured and is automatically deleted after the retention period — an operative deletion obligation applied to all stored data categories.

AI-generated interpretation, not legal advice.

Data retention
High
" We collect execution history (a log of actions performed, stored for 7 days) and user preferences (settings, stored for 30 days) to maintain context across sessions and improve user experience."
§ 2 (Usage Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Specifies that execution history is stored for 7 days and user preferences for 30 days, and states the purpose of this retention (maintaining context across sessions and improving user experience) — an operative retention obligation with defined periods.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Your prompts and spreadsheet context are sent to our AI providers for processing:"
Privacy Policy › “Third-Party AI Services”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Discloses that user prompts and spreadsheet context are transmitted to third-party AI providers for processing — an operative disclosure of data sharing with subprocessors.

AI-generated interpretation, not legal advice.

Common questions about Billow AI Labs's policies

Does Billow AI Labs train its AI models on your data?
No training on your content by default — based on 1 verified finding from Billow AI Labs's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Billow AI Labs's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Billow AI Labs's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Billow AI Labs's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Billow AI Labs requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Billow AI Labs's published policies yet.

What the policies actually cover

0 topics

None of Billow AI Labs's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Privacy Policy, § 2 (Usage Data) addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Anthropic Claude model responses User prompts, cell context” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

31
clauses
0
patterns
0
stances

Capture recency

  • Privacy Policy:Last captured 2026-08-31· verified 2026-08-31

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

31 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Billow AI Labs's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Billow AI Labs's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Billow AI Labs's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.