Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · crimson.law

Crimson

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-08-18
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

13 verified findings5 policy surfaces2/2 core docs verified
Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
1
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Crimson's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Privacy Policy
    Verified - read in full - 13 citationsstaticLast captured 2026-07-20
  • Terms of Service
    Verified - read in full - 0 citationsstaticLast captured 2026-08-18
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Subprocessors & data sharing

Restricts data sharing by prohibiting sale of user information and limiting disclosure to specific circumstances: service providers for operational purposes, legal compliance, business transfers subject to confidentiality, and user-consented sharing; additionally imposes an obligation to ensure appropriate safeguards (such as Standard Contractual Clauses) when transferring data outside specified regions — user-favorable by constraining third-party disclosure.

" We do not sell your information. We only share it in the following circumstances: Service providers: With trusted vendors who assist with hosting, analytics, payment processing or marketing. Legal compliance: When required by law, regula..."
📍 Privacy Policy › “Sharing Your Information”Jump to exact text →
Conflicting provisions (3)
  • Clause A states no personal data requiring consent is collected, but Clause B lists 'your consent' as a legal basis for processing 'your data,' implying such data is collected and consent may be required.

    " We do not use any cookies or similar tracking technologies on our website that would require cookie consent. We use Vercel Analytics to collect aggregated and anonymised usage data (such as page views, referrers, browser type, and device type) to understand how visitors use our site and to improve performance. This data cannot be used to identify individual users and does not involve cookies or personal data collection. Crimson also maintains security logs to detect and prevent unauthorised access or suspicious activities. These logs do not involve storing personal browsing data and are regularly reviewed as part of our SOC 2 compliance framework."
    " We collect certain information to provide and improve our services. The legal basis for processing your data may include your consent, the performance of a contract, compliance with legal obligations or Crimson's legitimate interests in improving our services and ensuring their security."
    Within one document
  • Clause A states that collected data cannot identify individual users and does not involve personal data collection, while Clause B explicitly lists collecting IP addresses and device identifiers, which are considered personal data and can be used for identification.

    " We do not use any cookies or similar tracking technologies on our website that would require cookie consent. We use Vercel Analytics to collect aggregated and anonymised usage data (such as page views, referrers, browser type, and device type) to understand how visitors use our site and to improve performance. This data cannot be used to identify individual users and does not involve cookies or personal data collection. Crimson also maintains security logs to detect and prevent unauthorised access or suspicious activities. These logs do not involve storing personal browsing data and are regularly reviewed as part of our SOC 2 compliance framework."
    " Device Information: IP address, browser type, operating system and device identifiers. Usage Data: Pages visited, time spent on the site, links clicked, and other website interactions."
    Within one document
  • Clause A explicitly states that no personal data is collected or used to identify individuals, while Clause B implies personal data is collected by referencing a Privacy Policy that describes its collection, use, and protection.

    " We do not use any cookies or similar tracking technologies on our website that would require cookie consent. We use Vercel Analytics to collect aggregated and anonymised usage data (such as page views, referrers, browser type, and device type) to understand how visitors use our site and to improve performance. This data cannot be used to identify individual users and does not involve cookies or personal data collection. Crimson also maintains security logs to detect and prevent unauthorised access or suspicious activities. These logs do not involve storing personal browsing data and are regularly reviewed as part of our SOC 2 compliance framework."
    " Crimson's Privacy Policy describes how we collect, use, and protect personal data. By using the Site, you agree to the terms of the Privacy Policy."
    Across documents

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 13
Severity
Surface
Document
Tier
Data retention
High
" We retain your data only as long as necessary to fulfil the purposes outlined in this policy or comply with legal obligations."
Privacy Policy › “Data Retention”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Imposes an obligation on the controller to retain personal data only for as long as necessary to fulfil the stated purposes or comply with legal obligations, limiting the duration of data storage — user-favorable by restricting unnecessary retention.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We do not sell your information. We only share it in the following circumstances: Service providers: With trusted vendors who assist with hosting, analytics, payment processing or marketing. Legal compliance: When required by law, regulation or court order. Business transfers: In connection with a merger, acquisition or sale of assets, subject to confidentiality obligations. With your consent: In specific instances where you have agreed to data sharing. Where data is transferred outside the EEA/UK, Crimson ensures that appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions in line with GDPR."
Privacy Policy › “Sharing Your Information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts data sharing by prohibiting sale of user information and limiting disclosure to specific circumstances: service providers for operational purposes, legal compliance, business transfers subject to confidentiality, and user-consented sharing; additionally imposes an obligation to ensure appropriate safeguards (such as Standard Contractual Clauses) when transferring data outside specified regions — user-favorable by constraining third-party disclosure.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We do not use any cookies or similar tracking technologies on our website that would require cookie consent. We use Vercel Analytics to collect aggregated and anonymised usage data (such as page views, referrers, browser type, and device type) to understand how visitors use our site and to improve performance. This data cannot be used to identify individual users and does not involve cookies or personal data collection. Crimson also maintains security logs to detect and prevent unauthorised access or suspicious activities. These logs do not involve storing personal browsing data and are regularly reviewed as part of our SOC 2 compliance framework."
Privacy Policy › “Cookies and Tracking”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Prohibits use of cookies or tracking technologies requiring consent and restricts data collection to aggregated and anonymised usage data that cannot identify individual users; also describes security logs that do not store personal browsing data — user-favorable by disclaiming personal data collection through tracking mechanisms.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" If you have questions or concerns about this Privacy Policy, please contact us:"
Privacy Policy › “Contact Us”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Directs users to a contact channel for questions or concerns about the Privacy Policy, establishing a procedural mechanism for privacy-related communications.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Crimson LegalTech Ltd ("Crimson", "we", "our" or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use and protect your information when you interact with our website. By using our website, you agree to the practices described in this Privacy Policy."
Privacy Policy › “Introduction”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope and subject matter of the policy by identifying the data controller, stating its commitment to privacy protection, explaining that the policy governs collection, use, and protection of information on the website, and incorporates user agreement to the described practices upon use of the website.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We collect certain information to provide and improve our services. The legal basis for processing your data may include your consent, the performance of a contract, compliance with legal obligations or Crimson's legitimate interests in improving our services and ensuring their security."
Privacy Policy › “Information We Collect”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that the controller collects information to provide and improve services and identifies the legal bases for processing personal data, including consent, contractual performance, legal obligations, and legitimate interests in service improvement and security — establishing the foundational legal justification for data processing activities.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Contact Information: Name, email address, phone number and company details when you fill out a contact form or request a demo."
§ 2.1 (Information You Provide)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the categories of contact information (name, email, phone, company details) collected when users fill out forms or request demos, establishing the scope of personal data collected.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Device Information: IP address, browser type, operating system and device identifiers. Usage Data: Pages visited, time spent on the site, links clicked, and other website interactions."
§ 2.2 (Information We Collect Automatically)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the categories of automatically collected data — device identifiers and usage data — specifying what technical and behavioral information is gathered from users visiting the site.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Service Delivery: To provide and improve our website and related services. Customer Support: To respond to inquiries and resolve issues. Marketing: To send promotional emails or updates about Crimson's services. You can opt out at any time. Security: To monitor and protect against fraud, unauthorised access or illegal activities. Compliance: To comply with legal obligations and enforce agreements."
Privacy Policy › “How We Use Your Information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the permitted purposes for which collected information may be used — service delivery, customer support, marketing (with opt-out right), security monitoring, and legal compliance — defining the authorized scope of data processing by the controller.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We implement robust security measures to protect your information, including encryption, access controls, and regular security assessments. Crimson implements role-based access controls, encrypts all data in transit and at rest, and conducts regular vulnerability scans, penetration tests, and security audits to identify and mitigate risks. However, no system is completely secure, and we encourage you to protect your account credentials."
Privacy Policy › “Security”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States security measures implemented to protect user information — encryption in transit and at rest, role-based access controls, vulnerability scans, penetration tests, and security audits — while also including a disclaimer that no system is completely secure and encouraging users to protect their credentials, thereby combining a protective commitment with a limitation on absolute security guarantees.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. In particular, our Privacy Policy is reviewed periodically to align with evolving security and compliance standards, including SOC 2 and GDPR requirements. Updates will be communicated through our website."
Privacy Policy › “Updates to this Policy”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for updating the Privacy Policy — periodic review to align with evolving security and compliance standards — and specifies that updates will be communicated through the website, creating a notification mechanism for policy changes.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" Our website may include links to third-party websites or services. We are not responsible for their privacy practices or content. Please review their policies before sharing any information."
Privacy Policy › “Third-Party Links”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Disclaims responsibility for the privacy practices or content of linked third-party websites and advises users to review those sites' policies before sharing information, limiting the controller's liability with respect to external sites.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Under applicable data protection laws, you have the following rights: Access: Request access to the personal data we hold about you. Correction: Request corrections to inaccurate or incomplete data. Erasure: Request the deletion of your data, subject to legal retention requirements. Restriction: Request limits on how we process your data. Portability: Request a copy of your data in a machine-readable format. Objection: Object to certain data processing activities, including marketing. Withdraw consent: Where processing is based on your consent, you can withdraw it at any time. To exercise your rights, contact us at privacy@crimson.law . If you believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority. For UK residents, this is the Information Commissioner's Office (ICO)."
Privacy Policy › “Your Rights”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates data subject rights under applicable data protection laws — access, correction, erasure (subject to retention requirements), restriction, portability in machine-readable format, objection to processing including marketing, and withdrawal of consent — granting users legally recognized entitlements over their personal data and implying a procedure to exercise them.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Crimson's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Crimson's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Crimson's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Crimson requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Crimson's published policies yet.

What the policies actually cover

0 topics

None of Crimson's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

65
clauses
18
patterns
18
stances
ip license · 5tier conditionality · 4ip ownership · 2legal burden · 2privacy sharing · 2commercial use · 1
commercial useMEDIUM§ 4.2 (Licence to Use)

The clause restricts commercial use.

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open source citation
data retentionMEDIUMPrivacy Policy › “Data Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We retain your data only as long as necessary to fulfil the purposes outlined in this policy or comply with legal obligations.
Open source citation
dispute resolutionMEDIUM§ 11.2 (Arbitration)

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Any dispute arising from or relating to these ToS, including questions about their existence, validity, or termination, shall be referred to and finally resolved by arbitration administered by the London Court of International Arbitration ("LCIA") in accordance with the LCIA Rules, which are deemed to be incorporated by reference into this clause. The number of arbitrators shall be one (1). The seat, or legal plac...
Open source citation
ip licenseHIGH§ 4.2 (Licence to Use)

The clause includes sublicensable, transferable, or assignable rights.

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open source citation
ip licenseHIGH§ 4.2 (Licence to Use)

The clause includes sublicensable, transferable, or assignable rights.

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersdata retentionconditionalMEDIUM1
All applicable tiersgoverning law disputesconditionalMEDIUM1
All applicable tiersindemnity liabilityworsensHIGH3
All applicable tiersmoderation enforcementworsensHIGH1
Freeprompt ownershipconditionalMEDIUM1
Freetier differencesconditionalMEDIUM1
Pro / Paidtier differencesconditionalMEDIUM2
Team / Businesscommercial useconditionalMEDIUM3
Team / Businessprivacy data useworsensHIGH2
Team / Businesssubprocessors data sharingworsensHIGH2
Team / Businesstier differencesconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Aug 21, 2026content licenseMEDIUM

Latest stance: broad license on privacy data use

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open timeline citation
Aug 21, 2026content licenseHIGH

Latest stance: sublicensable or transferable on privacy data use

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open timeline citation
Aug 18, 2026content licenseMEDIUM

Latest stance: broad license on commercial use

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open timeline citation
Aug 18, 2026content licenseMEDIUM

Latest stance: broad license on prompt ownership

If you submit or post any content through the Site or Services (e.g. feedback or suggestions), you represent that you have the necessary rights to do so and grant Crimson a non-exclusive, worldwide license to use, copy, distribute and display that content solely for the purpose of providing the Services or improving the Site. You agree that we are free to use any content without any restriction or compensation to you.
Open timeline citation
Aug 18, 2026content ownershipHIGH

Latest stance: platform claims or reserves rights on indemnity liability

We reserve the right to modify or discontinue any part of the Site or Services at any time without notice.
Open timeline citation
Aug 18, 2026content ownershipHIGH

Latest stance: platform claims or reserves rights on moderation enforcement

Promote, encourage, or enable any other individual to perform any of the above activities. Crimson has no general obligation to monitor access to or usage of the Site. However, we reserve the right to do so for operational, security or compliance reasons (including enforcing these ToS or applicable law). If we suspect any violation, we may investigate and cooperate with relevant law enforcement agencies. Crimson may take any lawful action deemed necessary to address or prevent prohibited activities, which can include removing or refusing content, suspending or terminating accounts or seeking legal remedies.
Open timeline citation
Aug 18, 2026commercial useMEDIUM

Latest stance: restricted on commercial use

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open timeline citation
Aug 18, 2026content licenseHIGH

Latest stance: sublicensable or transferable on commercial use

Subject to these ToS, Crimson grants you a limited, non-exclusive, non-transferable licence to access and use the Site and any publicly available features of the Services for internal business or personal use only.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
  • Terms of Service:Last captured 2026-08-18· verified 2026-08-18verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

29 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Crimson's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Crimson's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.