Chestnut
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Lower concern: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Restricts disclosure of nonpublic customer information to third parties, permitting it only as allowed by law, and states that physical, electronic, and procedural safeguards are maintained to protect personal information — user-favorable restriction on third-party sharing.
Introductory statement affirming the company's obligation to maintain and preserve the confidentiality of customers' nonpublic personal information, establishing a protective commitment toward user data.
Imposes an obligation on the company and all employees to treat data as confidential and to adhere strictly to data protection and confidentiality policies.
How to read this page: Overall risk rates what Chestnut's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 15 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 15 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Restricts disclosure of nonpublic customer information to third parties, permitting it only as allowed by law, and states that physical, electronic, and procedural safeguards are maintained to protect personal information — user-favorable restriction on third-party sharing.
"We maintain physical, electronic and procedural safeguards designed to protect your personal information. We gather nonpublic personal information about our customers as may be necessary to conduct business with our customers. We do not d..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"We maintain physical, electronic and procedural safeguards designed to protect your personal information. We gather nonpublic personal information about our customers as may be necessary to conduct business with our customers. We do not disclose any nonpublic information about our customers or former customers to any third party, except as permitted by law."
Restricts disclosure of nonpublic customer information to third parties, permitting it only as allowed by law, and states that physical, electronic, and procedural safeguards are maintained to protect personal information — user-favorable restriction on third-party sharing.
AI-generated interpretation, not legal advice.
" ### If you're a California resident, you have the right to: Know what personal information we collect, use, or share about you. Request deletion of your information."
States that the company does not currently sell user data and provides California residents the right to opt out of any such sale — user-favorable restriction confirming no current data sale practice.
AI-generated interpretation, not legal advice.
"Your personal information will only be retained for the purpose of providing you with our response to your query and will not be made available to any third party except as necessary to be disclosed to any related entity for the purpose intended or as required to be disclosed under law."
Restricts retention of personal information to the purpose of responding to the user's query and restricts third-party disclosure to related entities for the intended purpose or as required by law — user-favorable limitation on retention scope and third-party sharing.
AI-generated interpretation, not legal advice.
"Safeguarding our customers' privacy is very important to us. As we continue to improve and expand our services, we recognize our customers' need and desire to preserve their privacy and confidentiality. We have adopted standards that help maintain and preserve the confidentiality of customers' nonpublic personal information. The following Statement affirms our continued efforts to safeguard customer information."
Introductory statement affirming the company's obligation to maintain and preserve the confidentiality of customers' nonpublic personal information, establishing a protective commitment toward user data.
AI-generated interpretation, not legal advice.
"We treat data as confidential within our firm and require strict adherence of all our employees to data protection and our confidentiality policies."
Imposes an obligation on the company and all employees to treat data as confidential and to adhere strictly to data protection and confidentiality policies.
AI-generated interpretation, not legal advice.
"All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties."
Prohibits sharing of text messaging originator opt-in data and consent with any third parties — user-favorable restriction on sharing of a specific category of sensitive consent data.
AI-generated interpretation, not legal advice.
"We collect nonpublic personal information about you from the following sources:"
Introduces the enumerated sources from which nonpublic personal information is collected, establishing the procedural framework for collection disclosure.
AI-generated interpretation, not legal advice.
"Information we receive from you on applications or other forms, over the telephone or in face-to-face meetings, and via the Internet. Examples of information we receive from you include your name, address, telephone number, social security number, credit history and other financial information."
Defines and lists examples of personal information collected directly from the customer through applications, telephone, in-person meetings, and the internet, including name, address, telephone number, social security number, credit history, and other financial information.
AI-generated interpretation, not legal advice.
"Information about your transactions with us or others. Examples of information relating to your transactions include payment histories, account balances and account activity."
Defines and lists examples of transactional information collected, including payment histories, account balances, and account activity.
AI-generated interpretation, not legal advice.
"Information we receive from a consumer reporting agency. Examples of information from consumer reporting agencies include your credit score, credit reports and other information relating to your creditworthiness."
Defines and lists examples of information received from consumer reporting agencies, including credit scores, credit reports, and creditworthiness data.
AI-generated interpretation, not legal advice.
"From employers and others to verify information you have given to us. Examples of information provided by employers and others include verification of employment, income or deposits."
Defines and lists examples of verification information received from employers and others, such as verification of employment, income, or deposits.
AI-generated interpretation, not legal advice.
" Non-discrimination for exercising these rights."
Grants users the right to exercise privacy-related rights without facing discrimination, establishing a protective obligation against differential treatment for invoking those rights.
AI-generated interpretation, not legal advice.
"with "CCPA Request" in the subject line or call (628) 213-8391. We'll confirm receipt within 10 days and respond within 45 days. We may need to verify your identity."
Defines the procedural steps for exercising privacy rights, including the subject line to use, the contact method, confirmation timeline of 10 days, response timeline of 45 days, and identity verification requirements.
AI-generated interpretation, not legal advice.
"We reserve the right to alter this privacy policy statement at our discretion. Any change to this policy statement will be posted on our web site in a timely manner."
Reserves the organization's right to modify the privacy policy at its discretion and specifies the procedure for doing so by posting changes on the website in a timely manner, affecting how users are informed of changes to data handling practices.
AI-generated interpretation, not legal advice.
" ### If you're a Colorado resident, you have the right to: Access the personal information we hold about you. Correct inaccuracies in your information. Delete your information. Opt out of targeted advertising or data sales."
Establishes the procedure for Colorado residents to exercise their privacy rights by emailing a designated address with a specified subject line, with an acknowledgment within 10 days and a response within 45 days.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Chestnut's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Chestnut's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Chestnut's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Chestnut requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Chestnut's published policies yet.
What the policies actually cover
0 topicsNone of Chestnut's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause appears to reserve or claim ownership rights for the platform.
“We reserve the right to alter this privacy policy statement at our discretion. Any change to this policy statement will be posted on our web site in a timely manner.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We maintain physical, electronic and procedural safeguards designed to protect your personal information. We gather nonpublic personal information about our customers as may be necessary to conduct business with our customers. We do not disclose any nonpublic information about our customers or former customers to any third party, except as permitted by law.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
| Team / Business | privacy data use | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: platform claims or reserves rights on privacy data use
“We reserve the right to alter this privacy policy statement at our discretion. Any change to this policy statement will be posted on our web site in a timely manner.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We maintain physical, electronic and procedural safeguards designed to protect your personal information. We gather nonpublic personal information about our customers as may be necessary to conduct business with our customers. We do not disclose any nonpublic information about our customers or former customers to any third party, except as permitted by law.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
16 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Chestnut's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Chestnut's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Chestnut's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.