Carrot Labs
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
“Attribution metadata you attach (such as customer_id, feature, team, environment, prompt_key, prompt_version) By default the SDK does not collect, transmit, or store prompt content, response content, images, tool arguments, or your provider API keys. Organizations on Pro or Enterprise may opt in from the dashboard to sampled, encrypted capture of text…”
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Lower concern: Training use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Prohibits collection, transmission, or storage of prompt content, response content, images, tool arguments, or provider API keys by default — user-favorable restriction; permits Pro/Enterprise organizations to opt in to sampled, encrypted capture of text prompts and outcomes solely for offline recommendation analysis, with built-in redaction, image/audio stripping, and owner-controlled deletion, thereby limiting the scope of any prompt data capture to an explicit opt-in with defined safeguards.
Introduces and scopes the categories of telemetry data collected per LLM request via the SDK, establishing the data collection framework for subsequent enumerated items.
Provides the email address as the designated contact channel for privacy inquiries and data requests.
How to read this page: Overall risk rates what Carrot Labs's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 5 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 5 citationsstaticLast captured 2026-09-21
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Prohibits collection, transmission, or storage of prompt content, response content, images, tool arguments, or provider API keys by default — user-favorable restriction; permits Pro/Enterprise organizations to opt in to sampled, encrypted capture of text prompts and outcomes solely for offline recommendation analysis, with built-in redaction, image/audio stripping, and owner-controlled deletion, thereby limiting the scope of any prompt data capture to an explicit opt-in with defined safeguards.
" Attribution metadata you attach (such as customer_id, feature, team, environment, prompt_key, prompt_version) By default the SDK does not collect, transmit, or store prompt content, response content, images, tool arguments, or your provid..."
Defines the categories of personal data actively provided by users that the company collects, including account credentials, provider API keys (stored encrypted at rest), and communications content, establishing the scope of collection obligations.
" Account Information: When you create an account, we collect your name, email address, and authentication credentials. Provider API Keys: If you connect an OpenAI or Anthropic admin key for billing sync, we store those keys encrypted at re..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Attribution metadata you attach (such as customer_id, feature, team, environment, prompt_key, prompt_version) By default the SDK does not collect, transmit, or store prompt content, response content, images, tool arguments, or your provider API keys. Organizations on Pro or Enterprise may opt in from the dashboard to sampled, encrypted capture of text prompts and outcomes for offline recommendation analysis. Opt-in capture strips images and audio, applies built-in redaction, and is encrypted at rest. Owners may delete captured content at any time from Settings. Your organization is responsible for end-user data when opting in."
Prohibits collection, transmission, or storage of prompt content, response content, images, tool arguments, or provider API keys by default — user-favorable restriction; permits Pro/Enterprise organizations to opt in to sampled, encrypted capture of text prompts and outcomes solely for offline recommendation analysis, with built-in redaction, image/audio stripping, and owner-controlled deletion, thereby limiting the scope of any prompt data capture to an explicit opt-in with defined safeguards.
AI-generated interpretation, not legal advice.
" When you use the SuperPenguin SDK, the following cost metadata is collected for each LLM request:"
Introduces and scopes the categories of telemetry data collected per LLM request via the SDK, establishing the data collection framework for subsequent enumerated items.
AI-generated interpretation, not legal advice.
" If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:"
Provides the email address as the designated contact channel for privacy inquiries and data requests.
AI-generated interpretation, not legal advice.
" Carrot Labs AI, Inc. (“Carrot Labs,” “we,” “us,” or “our”) operates SuperPenguin , an AI cost management platform that helps teams track, attribute, and optimize LLM spend across providers like OpenAI, Anthropic, and Google Gemini. This Privacy Policy explains how Carrot Labs collects, uses, stores, and shares your personal information when you use SuperPenguin, our website, SDK, and any related services (collectively, the “Services”). If you have questions about this policy or your data, contact us at [email protected] ."
Defines the controller entity ('Carrot Labs AI, Inc.'), the platform ('SuperPenguin'), and the scope of the Privacy Policy, specifying which data activities (collection, use, storage, sharing of personal information) and which services the policy covers, and provides a contact channel for data questions.
AI-generated interpretation, not legal advice.
" Account Information: When you create an account, we collect your name, email address, and authentication credentials. Provider API Keys: If you connect an OpenAI or Anthropic admin key for billing sync, we store those keys encrypted at rest. Communications: When you contact us for support or inquiries, we collect the content of your messages and contact details."
Defines the categories of personal data actively provided by users that the company collects, including account credentials, provider API keys (stored encrypted at rest), and communications content, establishing the scope of collection obligations.
AI-generated interpretation, not legal advice.
Common questions about Carrot Labs's policies
- Does Carrot Labs train its AI models on your data?
- No training on your content by default — based on 1 verified finding from Carrot Labs's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Carrot Labs's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Carrot Labs's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Carrot Labs's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Carrot Labs requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Carrot Labs's published policies yet.
What the policies actually cover
0 topicsNone of Carrot Labs's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for ho...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for ho...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Carrot Labs and its service providers may process information in the United States and other countries where they operate. These countries may have data-protection laws different from those in your jurisdiction. Where required, we use contractual or other safeguards for international transfers.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | conditional | MEDIUM | 1 |
| Team / Business | privacy data use | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for hosting, databases, data processing, compliance, analytics, payments, email delivery, support, and hosted model processing. These include Vercel, Supabase, Google Cloud Platform, Vanta, Stripe, Resend, PostHog, and, when an optional hosted-AI feature is used, the configured model or gateway provider. They may process information only for the services we engage them to provide, subject to applicable contractual terms. Customer-directed integrations: We disclose information to AI providers, GitHub, Slack, Discord, and other services when a customer connects or directs use of that integration. Legal and safety reasons: We may disclose information when required by law or when reasonably necessary to protect the rights, safety, and integrity of Carrot Labs, our customers, users, or others. Business transfers: Information may be transferred in connection with a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable law and continued protection. With your direction: We may disclose information for another purpose when you or the customer directs or consents to it. We do not sell personal information, disclose it to data brokers, or share it for cross-context behavioral advertising. Our public Trust Center provides current security-control and published subprocessor information.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We may disclose information in the following circumstances: Customer organizations: Organization data is available to the customer and its authorized users according to organization membership, workspace roles, feature-specific permissions, and customer configuration. An organization may receive information about workforce use of connected AI coding tools. Service providers and subprocessors: We use vendors for hosting, databases, data processing, compliance, analytics, payments, email delivery, support, and hosted model processing. These include Vercel, Supabase, Google Cloud Platform, Vanta, Stripe, Resend, PostHog, and, when an optional hosted-AI feature is used, the configured model or gateway provider. They may process information only for the services we engage them to provide, subject to applicable contractual terms. Customer-directed integrations: We disclose information to AI providers, GitHub, Slack, Discord, and other services when a customer connects or directs use of that integration. Legal and safety reasons: We may disclose information when required by law or when reasonably necessary to protect the rights, safety, and integrity of Carrot Labs, our customers, users, or others. Business transfers: Information may be transferred in connection with a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets, subject to applicable law and continued protection. With your direction: We may disclose information for another purpose when you or the customer directs or consents to it. We do not sell personal information, disclose it to data brokers, or share it for cross-context behavioral advertising. Our public Trust Center provides current security-control and published subprocessor information.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“Carrot Labs and its service providers may process information in the United States and other countries where they operate. These countries may have data-protection laws different from those in your jurisdiction. Where required, we use contractual or other safeguards for international transfers.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-09-21· verified 2026-09-21
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
23 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Carrot Labs's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Carrot Labs's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Carrot Labs's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.