Datafruit
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
“Our Services use artificial intelligence to process Customer Data and generate outputs. Here's how that works:”
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Lower concern: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Grants California residents specific rights over their personal information (right to know, right to delete, right to opt out of sale), disclaims the practice of selling personal information, and provides a procedure for exercising those rights via a contact address — establishing user-favorable privacy rights and a corresponding contact obligation.
Restricts the service from being directed to individuals under 18, prohibits knowingly collecting personal information from children, and establishes an obligation to promptly delete any such information if inadvertently collected — user-protective restriction on data collection from minors.
States that information may be transferred to and processed in a specific country (the United States) for users located elsewhere, and imposes an obligation on the company to take steps ensuring such transfers comply with applicable law and that information receives adequate protection — a user-favorable data transfer safeguard obligation.
How to read this page: Overall risk rates what Datafruit's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 13 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 13 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines the scope and purpose of the Privacy Policy, identifies the controller entity, defines 'Services' as the website, platform, and AI-powered services, and describes the general subject matter of data collection, use, disclosure, and protection.
" This Privacy Policy explains how Datafruit, Inc. ("Datafruit," "we," "us," or "our") collects, uses, discloses, and protects information when you use our website, platform, and AI-powered services (collectively, the "Services"). Our Servic..."
Defines the categories of information collected directly from users — account information, Customer Data (including an explicit definition of that term encompassing project documentation, requirements, scope documents, and related business information), communications, and payment information — establishing the scope of data collection.
" Account Information. When you create an account, we collect your name, email address, company name, job title, and password. Customer Data. Data you upload or input into the Services, including project documentation, requirements, scope d..."
Grants the company permission to use collected information to communicate with users about their account, updates, and support requests.
" Process and deliver AI-powered outputs such as business requirements documents, project scopes, and margin estimates Train and improve our AI models (see "AI and Machine Learning" below)"
Establishes the retention period for user information (duration of account activity or as needed for Services), states that Customer Data retention is governed by the service agreement, and defines a 90-day deletion or de-identification obligation upon account deletion, subject to legally required exceptions.
" Service Providers. With vendors who perform services on our behalf (hosting, analytics, payment processing, customer support), bound by confidentiality obligations. Integrations. With third-party tools you choose to connect, to the extent..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@datafruit.com."
Grants California residents specific rights over their personal information (right to know, right to delete, right to opt out of sale), disclaims the practice of selling personal information, and provides a procedure for exercising those rights via a contact address — establishing user-favorable privacy rights and a corresponding contact obligation.
AI-generated interpretation, not legal advice.
" The Services are not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it promptly."
Restricts the service from being directed to individuals under 18, prohibits knowingly collecting personal information from children, and establishes an obligation to promptly delete any such information if inadvertently collected — user-protective restriction on data collection from minors.
AI-generated interpretation, not legal advice.
" Our Services use artificial intelligence to process Customer Data and generate outputs. Here's how that works:"
Describes how Customer Data is processed: (1) submitted Customer Data is processed by the company's AI models to produce deliverables; (2) only de-identified and aggregated data derived from Customer Data may be used for model improvement — prohibiting use of identifiable Customer Data to train models serving other customers unless the user explicitly opts in (user-favorable restriction); (3) Enterprise customers may opt out of any model training on their data via account settings or email contact, establishing an opt-out procedure.
AI-generated interpretation, not legal advice.
" Depending on your location, you may have the following rights:"
Establishes the procedure for exercising data rights: users must contact the specified email address, and the company commits to responding within 30 days.
AI-generated interpretation, not legal advice.
" This Privacy Policy explains how Datafruit, Inc. ("Datafruit," "we," "us," or "our") collects, uses, discloses, and protects information when you use our website, platform, and AI-powered services (collectively, the "Services"). Our Services help enterprise software implementation teams with discovery, project scoping, margin estimation, and knowledge transfer."
Defines the scope and purpose of the Privacy Policy, identifies the controller entity, defines 'Services' as the website, platform, and AI-powered services, and describes the general subject matter of data collection, use, disclosure, and protection.
AI-generated interpretation, not legal advice.
" By accessing or using our Services, you agree to this Privacy Policy. If you do not agree, please do not use our Services."
Imposes an obligation on the user that by accessing or using the Services they agree to the Privacy Policy, and instructs non-consenting users to refrain from using the Services — functioning as acceptance of data processing terms.
AI-generated interpretation, not legal advice.
" Account Information. When you create an account, we collect your name, email address, company name, job title, and password. Customer Data. Data you upload or input into the Services, including project documentation, requirements, scope documents, engagement records, delivery artifacts, and related business information ("Customer Data"). Communications. Information you provide when you contact us for support, submit feedback, or communicate with us through any channel. Payment Information. Billing details such as company name, billing address, and payment method. Payment processing is handled by third-party processors; we do not store full credit card numbers."
Defines the categories of information collected directly from users — account information, Customer Data (including an explicit definition of that term encompassing project documentation, requirements, scope documents, and related business information), communications, and payment information — establishing the scope of data collection.
AI-generated interpretation, not legal advice.
" Process and deliver AI-powered outputs such as business requirements documents, project scopes, and margin estimates Train and improve our AI models (see "AI and Machine Learning" below)"
Grants the company permission to use collected information to communicate with users about their account, updates, and support requests.
AI-generated interpretation, not legal advice.
" Detect, prevent, and address security issues, fraud, and technical problems"
States that the company uses collected information to comply with legal obligations, establishing a legally compelled use basis.
AI-generated interpretation, not legal advice.
" We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of the Services after changes are posted constitutes acceptance of the revised policy."
Establishes the procedure by which the privacy policy may be updated, including notification via website posting and date update, and deems continued use of the services after changes as acceptance of the revised policy — creating a binding amendment mechanism.
AI-generated interpretation, not legal advice.
" Service Providers. With vendors who perform services on our behalf (hosting, analytics, payment processing, customer support), bound by confidentiality obligations. Integrations. With third-party tools you choose to connect, to the extent necessary to provide the integration. Legal Compliance. When required by law, regulation, legal process, or governmental request. Business Transfers. In connection with a merger, acquisition, reorganization, or sale of assets, with notice to you. With Your Consent. In any other situation where you have given us explicit permission."
Establishes the retention period for user information (duration of account activity or as needed for Services), states that Customer Data retention is governed by the service agreement, and defines a 90-day deletion or de-identification obligation upon account deletion, subject to legally required exceptions.
AI-generated interpretation, not legal advice.
" We retain your information for as long as your account is active or as needed to provide the Services. Customer Data is retained according to the terms of your service agreement. When you delete your account, we will delete or de-identify your personal information within 90 days, except where retention is required by law."
Describes the security measures implemented (encryption, access controls, security assessments, incident response) and disclaims absolute security by acknowledging that no transmission or storage method is 100% secure — limiting the company's liability for security failures.
AI-generated interpretation, not legal advice.
" If you are located outside the United States, your information may be transferred to and processed in the United States. We take steps to ensure that international transfers comply with applicable law and that your information receives adequate protection."
States that information may be transferred to and processed in a specific country (the United States) for users located elsewhere, and imposes an obligation on the company to take steps ensuring such transfers comply with applicable law and that information receives adequate protection — a user-favorable data transfer safeguard obligation.
AI-generated interpretation, not legal advice.
Common questions about Datafruit's policies
- Does Datafruit train its AI models on your data?
- No training on your content by default — based on 1 verified finding from Datafruit's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Datafruit's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Datafruit's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Datafruit's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Datafruit requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Datafruit's published policies yet.
What the policies actually cover
0 topicsNone of Datafruit's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “How We Share Your Information” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “AI and Machine Learning” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@datafruit.com.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@datafruit.com.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
14 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Datafruit's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Datafruit's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Datafruit's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.