Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · dedaluslabs.ai

Dedalus Labs

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-20
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

16 verified findings6 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Lower concern: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
0
medium
2
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Dedalus Labs's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 16 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 16 citationsLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines the scope of the Privacy Policy by enumerating the activities and contexts (website visits, account creation, API traffic, communications) to which it applies, and incorporates the Content Policy into the Terms of Service by reference, establishing the boundaries of the document's legal obligations.

" This Privacy Policy explains how we collect, use, disclose, and protect personal information when you: visit or interact with our websites, dashboards, or documentation; create a Dedalus account, purchase credits, or enable Auto-Reload; ..."
📍 § 2 (Scope of this policy)Jump to exact text →
plan language
Privacy & data use

Defines and categorizes the specific types of personal data collected (account data, payment data, usage data including prompts and outputs, support data), their constituent elements, and their sources, establishing the factual basis for downstream data-use obligations.

" Account Data Name, email, password hash, GitHub / OAuth ID, company name You Payment Data Last 4 digits of card, card brand, expiration month/year, Stripe customer ID Stripe Usage Data IP address, user-agent, request/response sizes, to..."
📍 Privacy Policy › “Category Data elements Source”Jump to exact text →
plan language
Privacy & data use

Enumerates the specific purposes for which collected personal information is used (service provision, security, communication, legal compliance), and references legal bases for processing, imposing obligations on the company to limit use to those stated purposes.

" Provide and maintain the Service: Authenticate you, route API calls, allocate credits, process payments. Improve and secure: Monitor performance, detect abuse, debug errors, run analytics, and A/B tests. Communicate: Send transactional e..."
📍 § 4 (How we use information)Jump to exact text →
plan language
Privacy & data use

Defines the identity and nature of the data controller — Dedalus Labs, Inc. — describing its business as a gateway-as-a-service for the Model Context Protocol, which establishes the legal entity responsible for personal data processing under this policy.

" Dedalus Labs, Inc. ("Dedalus Labs," "we," "our" or "us") provides a gateway-as-a-service for the Model Context Protocol ("MCP") that lets developers build and deploy agentic AI workflows through a single API endpoint. Our website is https:..."
📍 § 1 (Who we are)Jump to exact text →
plan language
Data retention

Specifies mandatory retention periods for distinct data categories: account and billing records retained up to 7 years after account closure, API logs retained 30 days by default (with enterprise plan variation), and support tickets archived 24 months; also establishes the procedure for earlier deletion of Content Data via a purge feature or owner email request.

" Account & billing records: Kept for as long as your account is active, then up to 7 years for tax/audit purposes. API logs: Retained for 30 days by default, unless you request a different window for enterprise plans. Support tickets & em..."
📍 § 9 (Data retention)Jump to exact text →
plan language
Subprocessors & data sharing

Identifies specific subprocessors and data-sharing recipients (payment processor, edge hosting provider, analytics/error monitoring providers, DPA-disclosed sub-processors, government/law enforcement), their processing purposes, and their locations, defining the permissible scope of data sharing.

" Stripe, Inc. Payment processing and fraud prevention (no raw card data ever hits our servers) USA Cloudflare, Inc. Edge hosting, routing, DDoS protection Global Analytics / error monitoring providers (e.g., PostHog, Sentry) Product ana..."
📍 Privacy Policy › “Recipient Purpose Location”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 0
Tier-specific - 0
Total citations - 16
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" We never sell personal data. We share it only with:"
§ 6 (When we share information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Prohibits the sale of personal data (user-favorable) and restricts sharing to only the enumerated categories that follow, limiting the scope of permissible disclosures.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We do not knowingly collect data from children under 13, and our Service is directed to developers and businesses."
Privacy Policy › “Support Data Chat logs, emails, bug reports You”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts the company from knowingly collecting personal data from children under 13, and limits the intended audience of the service to developers and businesses.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" We are a U.S. company. If you access the Service from outside the U.S., your data may be processed in the U.S. or other countries with different data-protection laws. Where required, we rely on Standard Contractual Clauses or equivalent safeguards."
§ 8 (International transfers)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Discloses that data may be processed outside the user's home country, identifies reliance on Standard Contractual Clauses or equivalent safeguards as the transfer mechanism where required, establishing the procedural framework for international data transfers.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Withdraw consent at any time. Submit requests via email to legal@dedaluslabs.ai . We may verify your identity before acting."
Privacy Policy › “Port data to another service; and”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for submitting data rights requests (via a specified email address) and notes that identity verification may be required before the company acts on such requests.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This Privacy Policy explains how we collect, use, disclose, and protect personal information when you: visit or interact with our websites, dashboards, or documentation; create a Dedalus account, purchase credits, or enable Auto-Reload; send API traffic through our MCP gateway; or communicate with us via email, Discord, support tickets, or social media. All content uploaded, published, or shared through the Service, including MCP servers, workflows, Marketplace listings, and comments, is subject to our Dedalus Content Policy, which is incorporated into our Terms of Service. If you're an enterprise customer with a separate data-processing agreement (DPA) in place, that DPA will control to the extent of any conflict."
§ 2 (Scope of this policy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope of the Privacy Policy by enumerating the activities and contexts (website visits, account creation, API traffic, communications) to which it applies, and incorporates the Content Policy into the Terms of Service by reference, establishing the boundaries of the document's legal obligations.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Account Data Name, email, password hash, GitHub / OAuth ID, company name You Payment Data Last 4 digits of card, card brand, expiration month/year, Stripe customer ID Stripe Usage Data IP address, user-agent, request/response sizes, token counts, model IDs, tool manifests Automatically through Cloudflare Workers, edge logs, and internal analytics Content Data Model prompts and outputs you send through our API (may include personal data at your discretion) You / your application "
Privacy Policy › “Category Data elements Source”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines and categorizes the specific types of personal data collected (account data, payment data, usage data including prompts and outputs, support data), their constituent elements, and their sources, establishing the factual basis for downstream data-use obligations.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Provide and maintain the Service: Authenticate you, route API calls, allocate credits, process payments. Improve and secure: Monitor performance, detect abuse, debug errors, run analytics, and A/B tests. Communicate: Send transactional emails (receipts, credit-low alerts), respond to support requests, and, if you opt in, product updates or newsletters. Legal & compliance: Satisfy record-keeping obligations, enforce our Terms (including our Content Policy), resolve disputes, and comply with lawful requests. For users in the EEA/UK, our legal bases are performance of a contract, legitimate interests (e.g., Service security), and, where required, your consent."
§ 4 (How we use information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the specific purposes for which collected personal information is used (service provision, security, communication, legal compliance), and references legal bases for processing, imposing obligations on the company to limit use to those stated purposes.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We use first-party cookies and local storage to keep you logged in, remember preferences, and measure site traffic. We do not serve third-party ad cookies. You can disable cookies in your browser, but the dashboard may not function correctly."
§ 5 (Cookies and similar technologies)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the use of first-party cookies and local storage, prohibits third-party advertising cookies (user-favorable restriction), and provides the procedure by which users may disable cookies via browser settings.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We employ TLS 1.3 encryption in transit, AES-256 encryption at rest, least-privilege access controls, automatic key rotation, and routine penetration testing. Stripe is PCI DSS Level-1 certified, and Cloudflare Workers isolates customer code per request. No method is 100% secure, but we work hard to protect your information."
§ 10 (Security)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the technical and organizational security measures employed to protect personal data (encryption in transit and at rest, access controls, key rotation, penetration testing) and includes a disclaimer that no method is completely secure, limiting implied security guarantees.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Depending on your jurisdiction, you may have rights to: Access, correct, or delete personal data; Object to or restrict processing;"
§ 11 (Your rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates jurisdiction-dependent individual rights over personal data, including rights to access, correct, delete, object to or restrict processing, establishing user entitlements against the company.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Dedalus Labs, Inc. ("Dedalus Labs," "we," "our" or "us") provides a gateway-as-a-service for the Model Context Protocol ("MCP") that lets developers build and deploy agentic AI workflows through a single API endpoint. Our website is https://dedaluslabs.ai , and our registered corporate address is 1395 22nd St, Suite 457, San Francisco, CA 94107, USA."
§ 1 (Who we are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the identity and nature of the data controller — Dedalus Labs, Inc. — describing its business as a gateway-as-a-service for the Model Context Protocol, which establishes the legal entity responsible for personal data processing under this policy.

AI-generated interpretation, not legal advice.

Data retention
High
" Account & billing records: Kept for as long as your account is active, then up to 7 years for tax/audit purposes. API logs: Retained for 30 days by default, unless you request a different window for enterprise plans. Support tickets & emails: Kept for the life of the issue and archived for 24 months. Content Data can be deleted sooner via our "purge log" feature or an email request from the account owner."
§ 9 (Data retention)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Specifies mandatory retention periods for distinct data categories: account and billing records retained up to 7 years after account closure, API logs retained 30 days by default (with enterprise plan variation), and support tickets archived 24 months; also establishes the procedure for earlier deletion of Content Data via a purge feature or owner email request.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" The Service may interoperate with or route traffic to Model Context Protocol ("MCP") servers, tools, plug-ins, or other services that we do not operate ("Third-Party Integrations"). We do not control, and are not responsible for, the content, security, or privacy practices of any Third-Party Integration. Your use of a Third-Party Integration is at your own discretion and subject to that provider's own terms and policies."
§ 7 (Third-Party Integrations)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Disclaims responsibility and control over third-party integrations (MCP servers, tools, plug-ins) that interoperate with the service, stating that use of such integrations is at the user's own discretion and subject to those providers' own terms, thereby limiting the company's liability for third-party data practices.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Stripe, Inc. Payment processing and fraud prevention (no raw card data ever hits our servers) USA Cloudflare, Inc. Edge hosting, routing, DDoS protection Global Analytics / error monitoring providers (e.g., PostHog, Sentry) Product analytics, crash reports USA/EU Service sub-processors disclosed in our DPA Contracted services that help us run the platform Various Government or law enforcement Where required by law or to protect rights and safety As mandated "
Privacy Policy › “Recipient Purpose Location”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Identifies specific subprocessors and data-sharing recipients (payment processor, edge hosting provider, analytics/error monitoring providers, DPA-disclosed sub-processors, government/law enforcement), their processing purposes, and their locations, defining the permissible scope of data sharing.

AI-generated interpretation, not legal advice.

Governing law & disputes
High
" We'll post any changes on this page and, for material changes, notify you by email or in-product notice at least 30 days before they take effect. Continued use after the effective date constitutes acceptance."
§ 12 (Changes to this policy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for policy amendments, requiring posting of changes and advance notice of at least 30 days for material changes, and deems continued use after the effective date as acceptance of the revised terms.

AI-generated interpretation, not legal advice.

Governing law & disputes
High
" Withdraw consent at any time. Submit requests via email to legal@dedaluslabs.ai . We may verify your identity before acting."
Privacy Policy › “Port data to another service; and”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for Privacy Policy amendments, requiring posting of changes and at least 30 days advance notice for material changes, and deems continued use after the effective date as acceptance of the revised policy.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Dedalus Labs's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Dedalus Labs's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Dedalus Labs's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Dedalus Labs requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Dedalus Labs's published policies yet.

What the policies actually cover

0 topics

None of Dedalus Labs's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

16
clauses
1
patterns
1
stances
privacy sharing · 1
privacy sharingHIGH§ 6 (When we share information)

The clause permits sale of personal data or information.

We never sell personal data. We share it only with:
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tierssubprocessors data sharingworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We never sell personal data. We share it only with:
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

16 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Dedalus Labs's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Dedalus Labs's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Dedalus Labs's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.