Credal
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Establishes an obligation to retain personal information only as long as necessary for stated purposes, then delete or anonymize it, subject to legal requirements, and enumerates factors considered when determining retention periods.
States that under certain conditions individuals may invoke binding arbitration for residual claims not resolved through other redress mechanisms, and references an external annex for the applicable arbitration rules — establishing a right to binding arbitration as a final dispute resolution mechanism.
Disclaims that while the company implements security measures to protect personal information, it cannot guarantee or warrant the security of information transmitted to it, limiting liability for security breaches while acknowledging an obligation to maintain appropriate technical and organizational measures.
Scores derived from 67 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Credal's training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
- Data handling is conditional — 5 privacy or retention clauses warrant review before using Credal at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Credal's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredIP/output assessment pending — terms of service not yet verified This lens receives a band only once its source document has been captured and read in full.
Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.
Based on 249 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Partially verified — Privacy Policy — Verified (read in full, 218 findings); Terms of Service — Capture under review. Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Capture blocked
A known core policy document could not be publicly captured after the available capture strategies were tried.
Blocked core document: Terms of Service
- Privacy PolicyVerified - read in full - 218 citationsstaticLast captured 2026-08-17
- Terms of ServiceCompleteness unconfirmedstatic-revalidated
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines Credal AI's business purpose and introduces the term 'Customers,' establishing the scope of who the policy governs and the context in which data is processed.
"Credal AI (“we,” “our,” “us”) provides software to help employers and developers leverage AI at enterprise scale. We assist employers and developers (our “Customers”) in using AI applications while keeping data secure."
Defines 'Customers' as a category of data subjects whose information is collected when they engage Credal AI for demos or paid services including training.
"\- Customers: when you engage Credal AI for a free demo or paid services for training,"
Defines the category of end-user information collected from employer-customers, establishing that Credal AI acts as a service provider to employers and may passively record employee data through browser interactions or software integrations.
"\- Information About End Users We Collect from Credal AI Customers. If your employer has engaged the services of Credal AI, we may collect information from you on their behalf as your employer’s service provider. This information may be pas..."
Specifies an obligation to disclose the business or commercial purposes for collecting, selling, sharing, or disclosing personal information and the categories disclosed for such purposes.
"\- The business or commercial purpose(s) for collecting, selling, sharing, or disclosing your personal information, and the categories of personal information disclosed for such purpose(s)."
Defines 'Customers' as those who engage Credal AI for a free demo or paid services including training, establishing this data-subject and contracting-party category whose personal information and service interactions (including AI training services) are subject to the policy's data-collection and use provisions.
" - Customers: when you engage Credal AI for a free demo or paid services for training,"
Identifies legitimate business interests (fraud prevention, security, direct marketing, service improvement) as a lawful basis permitting personal data processing without consent.
"● Our legitimate business interests. For example, fraud prevention, maintaining the security of our network and services, direct marketing to you, and improvement of our services."
Obligates the company to disclose the business or commercial purposes for collecting, selling, sharing, or disclosing personal information and the categories of information disclosed for those purposes in response to a California resident's request.
" - The business or commercial purpose(s) for collecting, selling, sharing, or disclosing your personal information, and the categories of personal information disclosed for such purpose(s)."
Describes Credal AI's role as a service provider to employer-customers, establishing an obligation to collect End User information on the Customer's behalf, and discloses that such data may be passively recorded from browser interactions or business software integrations.
" - Information About End Users We Collect from Credal AI Customers. If your employer has engaged the services of Credal AI, we may collect information from you on their behalf as your employer’s service provider. This information may be pas..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"\- Information About End Users We Collect from Credal AI Customers. If your employer has engaged the services of Credal AI, we may collect information from you on their behalf as your employer’s service provider. This information may be passively recorded from interactions on your browser or through integrations with your business management software."
Defines the category of end-user information collected from employer-customers, establishing that Credal AI acts as a service provider to employers and may passively record employee data through browser interactions or software integrations.
AI-generated interpretation, not legal advice.
"If you are an employee of one of our Customers, please contact your employer directly for information regarding how your employer uses and shares your personal information gathered from our Services."
Directs employees of Customers to contact their employer for information about how their personal information is used, establishing a procedural step for data-subject inquiries in the employer-employee context.
AI-generated interpretation, not legal advice.
"**Information We Collect From Third Parties**. If you access our Sites or Services through third parties (e.g., Facebook or Google), or if you share content from our Sites or Services to a third-party social media service, the third-party service may send us certain information about you if the third-party service and your account settings allow such sharing. The information we receive will depend on the policies and your account settings with the third-party service."
Defines the category of information collected from third-party services such as Facebook or Google when users access the platform via those services, establishing that third-party data sharing is contingent on those services' policies and the user's account settings.
AI-generated interpretation, not legal advice.
"We implement a variety of security measures to maintain the safety of your personal information when you enter, submit, or access your personal information. However, no website, application, or transmission can guarantee security. Thus, while we have established and maintain what we believe to be appropriate technical and organizational measures to protect the confidentiality, security, and integrity of personal information obtained through the Sites, we cannot ensure or warrant the security of any information you transmit to us."
Disclaims absolute security guarantees while acknowledging the company has implemented technical and organizational measures to protect confidentiality and integrity of personal information, limiting liability for security breaches.
AI-generated interpretation, not legal advice.
" Information We Automatically Collect . Like many website operators, we collect information that your browser sends whenever you visit our Sites. This includes log data, such as your computer’s IP address, browser type, browser version, the pages of our Sites that you visit, the time and date of your visit, the time spent on those pages and other statistics, and whether you reached our page via a social media or email campaign. This information may be collected via several technologies, including cookies, web beacons, clear GIFs, canvas fingerprinting and other means, such as Google Remarketing and Facebook Pixel. You can control cookies in your browser to enable or disable them. Learn more in our Cookie Policy."
Describes the automatic collection of technical and behavioral data from browser interactions with Credal AI's sites (log data, IP addresses, browser type/version, page visits, timestamps, time spent, traffic source), and enumerates the technologies used (cookies, web beacons, clear GIFs, canvas fingerprinting, Google Remarketing), defining the scope of passive data collection practices.
AI-generated interpretation, not legal advice.
"● Professional or employment-related information."
Defines 'Professional or employment-related information' as a sub-category of end-user data collected on behalf of employers.
AI-generated interpretation, not legal advice.
"Marketing: We may use your personal information to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe instructions provided in any email we send, or you can contact us using the contact details provided in the “Contact Information” section below. You will still continue to receive service-related messages concerning products and services you have purchased (unless we have indicated otherwise)."
Describes how personal information may be used for marketing communications and establishes the procedure by which users can opt out of such communications, while noting continued receipt of service-related messages.
AI-generated interpretation, not legal advice.
"● Internet or other electronic network activity information, such as website cookies."
Defines 'Internet or other electronic network activity information' as a sub-category of end-user data collected on behalf of employers, specifying website cookies as an example.
AI-generated interpretation, not legal advice.
"● Our legitimate business interests. For example, fraud prevention, maintaining the security of our network and services, direct marketing to you, and improvement of our services."
Identifies legitimate business interests (fraud prevention, security, direct marketing, service improvement) as a lawful basis permitting personal data processing without consent.
AI-generated interpretation, not legal advice.
"● To conduct market research and project planning."
Identifies market research and project planning as a permitted purpose for processing personal information, establishing the legal basis and obligation for using data in this manner.
AI-generated interpretation, not legal advice.
"Some browsers provide you with a way to signal that you do not want your browsing activity to be tracked. The Services may not currently respond to all Do Not Track (“DNT”) or similar signals, as we are awaiting consensus from the Internet policy and legal community on the meaning of DNT and the best way to respond to these signals."
Disclaims that the services may not currently respond to Do Not Track or similar signals, citing lack of consensus in the legal and policy community, and limits the platform's obligation to honor such signals.
AI-generated interpretation, not legal advice.
"\- Provide measurement services (you can opt out of these services at websites such as http://www.aboutads.info/choices and http://www.youronlinechoices.eu/);"
Identifies measurement services as a subprocessor function and provides users with opt-out mechanisms via external websites, establishing both a data-sharing obligation and a user right to opt out.
AI-generated interpretation, not legal advice.
" - Run email and mobile messaging campaigns;"
Identifies running email and mobile messaging campaigns as a permitted purpose for sharing data with third-party service providers.
AI-generated interpretation, not legal advice.
"\- The categories of personal information we have sold, if any, about you and the categories of third parties to whom your personal information was sold, by category or categories of personal information for each third party to whom the personal information was sold."
Specifies an obligation to disclose categories of personal information sold and the categories of third-party buyers, broken down by category, in response to a California resident's request.
AI-generated interpretation, not legal advice.
" - The categories of personal information we have sold, if any, about you and the categories of third parties to whom your personal information was sold, by category or categories of personal information for each third party to whom the personal information was sold."
Obligates the company to disclose the categories of personal information sold and the categories of third parties to whom it was sold, if any, in response to a California resident's request.
AI-generated interpretation, not legal advice.
"● To provide analytic services, such as analyzing customer usage and improving services offered."
Specifies providing analytic services, including analyzing customer usage and improving services, as a permitted purpose for which personal information may be used.
AI-generated interpretation, not legal advice.
" - Perform marketing analytics;"
Identifies performing marketing analytics as a permitted purpose for data sharing with third-party service providers.
AI-generated interpretation, not legal advice.
" - Information About End Users We Collect from Credal AI Customers. If your employer has engaged the services of Credal AI, we may collect information from you on their behalf as your employer’s service provider. This information may be passively recorded from interactions on your browser or through integrations with your business management software. "
Describes Credal AI's role as a service provider to employer-customers, establishing an obligation to collect End User information on the Customer's behalf, and discloses that such data may be passively recorded from browser interactions or business software integrations.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Credal's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
40 verified clausesClauses in Credal's policies that work in your favour — commitments the platform made to you.
- Audit rights, DPA & residency
“Credal AI complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF (“UK-U.S. DPF”), and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) (collectively, the “DPF”) as set forth by the US Department of Commerc…”
This segment states Credal AI's obligation to comply with EU-U.S. DPF, UK-U.S. DPF, and Swiss-U.S. DPF as certified with the U.S. Department of Commerce, establishing binding adherence to DPF Principles for processing pe…
📍 Privacy Policy › “Individuals”Jump to exact text → - Audit rights, DPA & residency
“Pursuant to the DPF Principles, EU, UK, and Swiss individuals have the right to obtain our confirmation of whether we maintain personal information relating to you in the United States. Upon request, we will provide you with access to the personal information…”
This segment grants EU, UK, and Swiss individuals the rights to access, correct, amend, or delete personal information held in the United States under the DPF, and establishes the procedure for exercising those rights vi…
- Designated security contact: privacy@credal.ai
📍 Privacy Policy › “Individuals”Jump to exact text → - Governing law & disputesarbitration & class-action waiver
“If your DPF-related complaint cannot be resolved through this channel, Credal AI commits to refer unresolved complaints to JAMS DPF Dispute Resolution, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowle…”
This segment establishes the second-step dispute resolution procedure by committing Credal AI to refer unresolved DPF complaints to JAMS DPF Dispute Resolution as an alternative dispute resolution provider, specifying th…
📍 Privacy Policy › “Individuals”Jump to exact text → - Audit rights, DPA & residency
“Data Privacy Frameworks & International Transfers of Data . We may transfer information from or about you or your devices to countries other than the country where you are located (including to the United States), which may not have the same data protection la…”
Discloses that personal data may be transferred internationally to countries with different data protection standards, and references the Data Privacy Frameworks used to authorize such cross-border transfers, informing d…
📍 Privacy Policy › “Individuals”Jump to exact text → - Audit rights, DPA & residency
“**Data Privacy Frameworks & International Transfers of Data**. We may transfer information from or about you or your devices to countries other than the country where you are located (including to the United States), which may not have the same data protection…”
This segment discloses that personal data may be transferred internationally and directs readers to DPF compliance disclosures, establishing the procedural framework for cross-border data transfers and referencing applic…
📍 Privacy Policy › “Individuals”Jump to exact text → - Audit rights, DPA & residency
“If your DPF complaint cannot be resolved through this channel, Credal AI commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities, the UK Information Commissioner’s Office and the Gibraltar Reg…”
This segment obligates Credal AI to cooperate with and comply with the advice of EU, UK, and Swiss data protection authorities regarding unresolved complaints about human resources data handled under the DPF in the emplo…
📍 Privacy Policy › “Individuals”Jump to exact text →
+ 34 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
0 verified clausesWhat Credal requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Credal's published policies yet.
What the policies actually cover
10 topics- Product telemetry & usage tracking16 clauses
- Advertising & tracking1 protective17 clauses
- Sale or sharing of personal data7 protective14 clauses
- Sensitive data (biometric, location, health)1 protective7 clauses
- Children's data1 protective1 clause
- Government & law-enforcement disclosure6 clauses
- Arbitration & class-action waiver3 protective4 clauses
- Damages & liability cap1 clause
- Terms can change at any time1 clause
- Deletion rights & post-termination survival1 clause
150 further verified clauses are cited on this page but not yet assigned a topic.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See DPF Annex 1 at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction .”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See DPF Annex 1 at https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf?tabset-35584=2.”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See DPF Annex 1 at [https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction](https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction).”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See DPF Annex 1 at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction .”Open source citation
The clause appears to reserve or claim ownership rights for the platform.
“Aggregated Data. We may also aggregate or otherwise strip information of all personally identifying characteristics and may share that aggregated, anonymized data with third parties or publish it. This data does not personally identify you and helps us to measure the success of our Sites and its features and to improve your experience. We reserve the right to make use of any such aggregated data as we see fit.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 16 |
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 25 |
| Government | governing law disputes | conditional | MEDIUM | 4 |
| Team / Business | privacy data use | worsens | HIGH | 1 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 4 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“Residents of California have the right to opt out of the sale or sharing of the consumer’s personal information. However, we do not sell your personal information, nor do we share your personal information to provide personalized or targeted advertising.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“parties for the third parties’ direct marketing purposes. However, we do not disclose your personal information to third parties for the third parties’ direct marketing purposes.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“As explained in this Privacy Policy, we sometimes provide your information to third parties to perform services on our behalf. If we transfer personal information received under the DPF to a third party, the third party's access, use, and disclosure of the personal data must also be in compliance with our DPF obligations, and we will remain liable under the DPF for any failure to do so by the third party unless we prove we are not responsible for the event giving rise to the damage. We may be required to disclose personal information that we handle under the DPF in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.”Open timeline citation
Latest stance: arbitration or waiver on governing law disputes
“If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See DPF Annex 1 at https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction .”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We will provide an individual opt-out or opt-in choice before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To request to limit the use and disclosure of your personal information, please submit a written request to privacy@credal.ai.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“● To share your website visitor activity, through website cookies, with third-party partners to analyze your usage of our Sites.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Some external service providers may also collect information directly from you (for example, a payment processor may request your billing and financial information) in accordance with their own privacy policy. These external service providers do not share your financial information, like credit card number, with us, but may share limited information with us related to your purchase, like your zip code.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Aggregated Data. We may also aggregate or otherwise strip information of all personally identifying characteristics and may share that aggregated, anonymized data with third parties or publish it. This data does not personally identify you and helps us to measure the success of our Sites and its features and to improve your experience. We reserve the right to make use of any such aggregated data as we see fit.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-17· verified 2026-08-17
- Terms of Service:Last captured 2026-07-20· verified 2026-06-08verified once — no re-scan in 94 days
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 46 more findings this quarter vs last (405 vs 359). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Credal's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Credal's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Credal's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.