Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · superpenguin.ai

Carrot Labs

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-09-21
Creator: Not yet rated · GRC: Not yet rated · Counsel: Not yet rated
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Privacy Policy · verbatim

Attribution metadata you attach (such as customer_id, feature, team, environment, prompt_key, prompt_version) By default the SDK does not collect, transmit, or store prompt content, response content, images, tool arguments, or your provider API keys. Organizations on Pro or Enterprise may opt in from the dashboard to sampled, encrypted capture of text

highest-risk verified finding on training use — tap for the citation
5 verified findings2 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Lower concern: Training use

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
0
medium
0
low
1/1
docs
Trains on your data?
No training on your content by default
from 1 cited finding
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Carrot Labs's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 5 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 5 citationsstaticLast captured 2026-09-21
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Training on your content

Prohibits collection, transmission, or storage of prompt content, response content, images, tool arguments, or provider API keys by default — user-favorable restriction; permits Pro/Enterprise organizations to opt in to sampled, encrypted capture of text prompts and outcomes solely for offline recommendation analysis, with built-in redaction, image/audio stripping, and owner-controlled deletion, thereby limiting the scope of any prompt data capture to an explicit opt-in with defined safeguards.

" Attribution metadata you attach (such as customer_id, feature, team, environment, prompt_key, prompt_version) By default the SDK does not collect, transmit, or store prompt content, response content, images, tool arguments, or your provid..."
📍 Privacy Policy › “Request latency”Jump to exact text →
plan language
Privacy & data use

Defines the categories of personal data actively provided by users that the company collects, including account credentials, provider API keys (stored encrypted at rest), and communications content, establishing the scope of collection obligations.

" Account Information: When you create an account, we collect your name, email address, and authentication credentials. Provider API Keys: If you connect an OpenAI or Anthropic admin key for billing sync, we store those keys encrypted at re..."
📍 § 2.1 (Information You Provide)Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 0
Tier-specific - 0
Total citations - 5
Severity
Surface
Document
Tier
Training on your content
High
" Attribution metadata you attach (such as customer_id, feature, team, environment, prompt_key, prompt_version) By default the SDK does not collect, transmit, or store prompt content, response content, images, tool arguments, or your provider API keys. Organizations on Pro or Enterprise may opt in from the dashboard to sampled, encrypted capture of text prompts and outcomes for offline recommendation analysis. Opt-in capture strips images and audio, applies built-in redaction, and is encrypted at rest. Owners may delete captured content at any time from Settings. Your organization is responsible for end-user data when opting in."
Privacy Policy › “Request latency”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Prohibits collection, transmission, or storage of prompt content, response content, images, tool arguments, or provider API keys by default — user-favorable restriction; permits Pro/Enterprise organizations to opt in to sampled, encrypted capture of text prompts and outcomes solely for offline recommendation analysis, with built-in redaction, image/audio stripping, and owner-controlled deletion, thereby limiting the scope of any prompt data capture to an explicit opt-in with defined safeguards.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you use the SuperPenguin SDK, the following cost metadata is collected for each LLM request:"
§ 2.2 (SDK Telemetry Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Introduces and scopes the categories of telemetry data collected per LLM request via the SDK, establishing the data collection framework for subsequent enumerated items.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:"
§ 11 (Contact Us)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Provides the email address as the designated contact channel for privacy inquiries and data requests.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Carrot Labs AI, Inc. (“Carrot Labs,” “we,” “us,” or “our”) operates SuperPenguin , an AI cost management platform that helps teams track, attribute, and optimize LLM spend across providers like OpenAI, Anthropic, and Google Gemini. This Privacy Policy explains how Carrot Labs collects, uses, stores, and shares your personal information when you use SuperPenguin, our website, SDK, and any related services (collectively, the “Services”). If you have questions about this policy or your data, contact us at [email protected] ."
§ 1 (Who We Are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the controller entity ('Carrot Labs AI, Inc.'), the platform ('SuperPenguin'), and the scope of the Privacy Policy, specifying which data activities (collection, use, storage, sharing of personal information) and which services the policy covers, and provides a contact channel for data questions.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Account Information: When you create an account, we collect your name, email address, and authentication credentials. Provider API Keys: If you connect an OpenAI or Anthropic admin key for billing sync, we store those keys encrypted at rest. Communications: When you contact us for support or inquiries, we collect the content of your messages and contact details."
§ 2.1 (Information You Provide)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the categories of personal data actively provided by users that the company collects, including account credentials, provider API keys (stored encrypted at rest), and communications content, establishing the scope of collection obligations.

AI-generated interpretation, not legal advice.

Common questions about Carrot Labs's policies

Does Carrot Labs train its AI models on your data?
No training on your content by default — based on 1 verified finding from Carrot Labs's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Carrot Labs's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Carrot Labs's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Carrot Labs's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Carrot Labs requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Carrot Labs's published policies yet.

What the policies actually cover

0 topics

None of Carrot Labs's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

23
clauses
3
patterns
3
stances
privacy sharing · 3
privacy sharingHIGH§ 4 (How We Disclose Information)

The clause permits sale of personal data or information.

We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for ho...
Open source citation
privacy sharingMEDIUM§ 4 (How We Disclose Information)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for ho...
Open source citation
privacy sharingMEDIUM§ 10 (International Processing)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

Carrot Labs and its service providers may process information in the United States and other countries where they operate. These countries may have data-protection laws different from those in your jurisdiction. Where required, we use contractual or other safeguards for international transfers.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useconditionalMEDIUM1
Team / Businessprivacy data useworsensHIGH2

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Sep 21, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for hosting, databases, data processing, compliance, analytics, payments, email delivery, support, and hosted model processing. These include Vercel, Supabase, Google Cloud Platform, Vanta, Stripe, Resend, PostHog, and, when an optional hosted-AI feature is used, the configured model or gateway provider. They may process information only for the services we engage them to provide, subject to applicable contractual terms. Customer-directed integrations: We disclose information to AI providers, GitHub, Slack, Discord, and other services when a customer connects or directs use of that integration. Legal and safety reasons: We may disclose information when required by law or when reasonably necessary to protect the rights, safety, and integrity of Carrot Labs, our customers, users, or others. Business transfers: Information may be transferred in connection with a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable law and continued protection. With your direction: We may disclose information for another purpose when you or the customer directs or consents to it. We do not sell personal information, disclose it to data brokers, or share it for cross-context behavioral advertising. Our public Trust Center provides current security-control and published subprocessor information.
Open timeline citation
Sep 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for hosting, databases, data processing, compliance, analytics, payments, email delivery, support, and hosted model processing. These include Vercel, Supabase, Google Cloud Platform, Vanta, Stripe, Resend, PostHog, and, when an optional hosted-AI feature is used, the configured model or gateway provider. They may process information only for the services we engage them to provide, subject to applicable contractual terms. Customer-directed integrations: We disclose information to AI providers, GitHub, Slack, Discord, and other services when a customer connects or directs use of that integration. Legal and safety reasons: We may disclose information when required by law or when reasonably necessary to protect the rights, safety, and integrity of Carrot Labs, our customers, users, or others. Business transfers: Information may be transferred in connection with a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable law and continued protection. With your direction: We may disclose information for another purpose when you or the customer directs or consents to it. We do not sell personal information, disclose it to data brokers, or share it for cross-context behavioral advertising. Our public Trust Center provides current security-control and published subprocessor information.
Open timeline citation
Sep 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

Carrot Labs and its service providers may process information in the United States and other countries where they operate. These countries may have data-protection laws different from those in your jurisdiction. Where required, we use contractual or other safeguards for international transfers.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-09-21· verified 2026-09-21

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

23 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Carrot Labs's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Carrot Labs's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Carrot Labs's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.