Dench.com
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Restricts disclosure of personal information to operational necessity, legal compliance, or business transactions; prohibits sale and cross-context behavioral advertising sharing; requires subprocessors to be bound by data protection terms no less protective than Dench's own; and references a maintained subprocessor list — user-protective direction.
Specifies the data residency location for Customer Data at rest and identifies that subprocessors handling Customer Data are based in the same location; discloses cross-border transfer implications for users accessing from other regions; and states reliance on recognized transfer mechanisms for personal data protected under specified legal frameworks, establishing the data residency and transfer compliance framework.
Grants users state-law privacy rights including access, correction, deletion, portability, and opt-out of targeted advertising or sale of personal information; affirmatively states the company does not sell personal information and does not share it for cross-context behavioral advertising, and does not use sensitive personal information in ways requiring an opt-out right — all user-favorable restrictions on data use practices.
How to read this page: Overall risk rates what Dench.com's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 23 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 23 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Defines the scope of the policy, identifies the controller entity ('Dench'), and enumerates the services and platforms to which the policy applies, establishing the legal boundary of data-handling obligations described throughout the document.
" This Privacy Policy explains how Merse Originals, Inc., a Delaware corporation doing business as "Dench" (" Dench," "we," "us," or "our") handles personal information. Dench is a customer relationship management (CRM) and agent workspace p..."
Defines the billing and subscription data collected, specifies that full card numbers are not stored on Dench servers (a user-protective limitation), and identifies the categories of billing metadata retained, establishing the scope of financial data handling.
" If you purchase a paid plan or use metered AI features, payment processing is handled by Stripe. We do not store full card numbers on our servers. We do store subscription and billing metadata such as Stripe customer and subscription IDs, ..."
Defines Customer Data as CRM records and other workspace content submitted by users, states it is processed on the customer's behalf to provide the Services, and places a responsibility notice on users to submit only data they have rights to process.
" When you use the Services, you and your team submit CRM records, contacts, companies, tasks, notes, files, emails, messages, and other workspace content. We process this Customer Data on your behalf to provide the Services. You decide what..."
Provides contact information and a designated channel for privacy questions, data requests, and enterprise privacy term discussions, and identifies the legal entity responsible for data processing — establishes a procedural mechanism for users to exercise privacy-related rights or inquiries.
" For privacy questions, data requests, or to discuss enterprise privacy terms, contact us at privacy@dench.com . Merse Originals, Inc. (doing business as Dench )"
Describes security safeguards in place, disclaims a guarantee of absolute security, and allocates responsibility to users for protecting their own devices and credentials — limiting Dench's liability for security breaches while setting out user responsibilities.
" We use administrative, technical, and organizational safeguards designed to protect the Services, including encryption of data in transit and at rest, cloud secret management for sensitive configuration, and encrypted storage of organizati..."
Defines the two data-controller/processor roles Dench occupies, specifies that Customer Data is processed only on the customer's instructions to provide the Services, and incorporates the Data Processing Addendum by reference to govern that processing relationship.
" Privacy law treats us differently depending on whose data is involved, so it helps to separate two roles: Dench as a processor / service provider. For the CRM records, contacts, files, messages, prompts, and other content that a customer ..."
Restricts disclosure of personal information to operational necessity, legal compliance, or business transactions; prohibits sale and cross-context behavioral advertising sharing; requires subprocessors to be bound by data protection terms no less protective than Dench's own; and references a maintained subprocessor list — user-protective direction.
" We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or c..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or complete a business transaction. We use vetted third-party providers (subprocessors) for hosting, AI inference, billing, email, analytics, sign-in, integrations, and messaging. Each is bound by data protection terms no less protective than ours. The current list, with each provider's purpose, location, and transfer mechanism, is maintained on our Subprocessors page . We may also disclose information to professional advisors, and to an acquirer or successor in connection with a merger, acquisition, financing, or sale of assets, and to regulators or authorities where required by law or to protect rights, safety, and security. Your use of third-party integrations you connect is also subject to those providers' own terms and privacy practices."
Restricts disclosure of personal information to operational necessity, legal compliance, or business transactions; prohibits sale and cross-context behavioral advertising sharing; requires subprocessors to be bound by data protection terms no less protective than Dench's own; and references a maintained subprocessor list — user-protective direction.
AI-generated interpretation, not legal advice.
" Depending on your state of residence (for example California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws), you may have rights to know or access the personal information we collect, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal information, or certain profiling. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that would require an opt-out right under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. To exercise your rights, email privacy@dench.com . You may use an authorized agent where permitted by law. We will not discriminate against you for exercising your rights, and we will verify your identity before acting on a request. If we deny a request, you may appeal by replying to our response."
Grants users state-law privacy rights including access, correction, deletion, portability, and opt-out of targeted advertising or sale of personal information; affirmatively states the company does not sell personal information and does not share it for cross-context behavioral advertising, and does not use sensitive personal information in ways requiring an opt-out right — all user-favorable restrictions on data use practices.
AI-generated interpretation, not legal advice.
" The Services are not directed to children under 13, and we do not knowingly collect personal information from them. You may not use the Services if you are not old enough to consent to the processing of your personal data under applicable law."
Restricts use of the Services by children under 13 and prohibits knowing collection of personal information from them; also restricts use by anyone not old enough under applicable law to consent to processing of their personal data — user-protective age-gating restriction on data collection.
AI-generated interpretation, not legal advice.
" Parts of our software are available under open-source licenses and can be run on infrastructure you control. When you self-host, data stored solely on your own systems is under your control, and this Policy does not apply to that data except to the extent you also use Dench-hosted features such as accounts, billing, hosted AI routing, or managed cloud. The open-source license governs your rights in the code itself."
Defines the boundary of this Privacy Policy's application: data stored solely on a user's own self-hosted infrastructure is under the user's control and the Policy does not apply to it, except when the user also uses hosted features; the open-source license separately governs rights in the code — carves out self-hosted data from the Policy's scope.
AI-generated interpretation, not legal advice.
" The hosted Services run in the United States (AWS US East, Northern Virginia / us-east-1) . Customer Data at rest is stored in the United States, and our subprocessors that handle Customer Data are based in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your home country. Where we transfer personal data that is protected by the laws of the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized transfer mechanisms such as the EU, UK, and Swiss Standard Contractual Clauses, and applicable Data Privacy Framework certifications, as further described in our Data Processing Addendum ."
Specifies the data residency location for Customer Data at rest and identifies that subprocessors handling Customer Data are based in the same location; discloses cross-border transfer implications for users accessing from other regions; and states reliance on recognized transfer mechanisms for personal data protected under specified legal frameworks, establishing the data residency and transfer compliance framework.
AI-generated interpretation, not legal advice.
" To create and secure accounts, organizations, sessions, and managed access. To operate the CRM, hosted APIs, cloud workspaces, AI routing, billing, credits, and subscription lifecycle. To send sign-in codes, transactional emails, receipts, support replies, reminders, and service notices. To measure usage, prevent abuse, investigate incidents, enforce limits, and improve reliability and product quality. To personalize the Services for your organization, including settings, roles, and current workspace context. To comply with legal obligations and protect the rights, safety, and security of Dench, our users, and third parties. Where the GDPR or similar laws apply to our controller processing, we rely on these legal bases: performance of a contract (to provide the Services you request), legitimate interests (to secure, operate, and improve the Services and prevent abuse), consent (for example, certain analytics or marketing where required), and compliance with legal obligations."
Enumerates the purposes for which collected personal information is used, including account operation, billing, communications, abuse prevention, personalization, and legal compliance, defining the operator's obligations and permitted uses tied to those purposes.
AI-generated interpretation, not legal advice.
" This Privacy Policy explains how Merse Originals, Inc., a Delaware corporation doing business as "Dench" (" Dench," "we," "us," or "our") handles personal information. Dench is a customer relationship management (CRM) and agent workspace platform, the second brain for a company's people, customers, and operations. We are headquartered in California, United States and incorporated in Delaware . This Policy applies to dench.com , our web and desktop applications, sign-in flows, hosted APIs and gateway, managed cloud workspaces and sandboxes, billing, support, and other services we operate under the Dench brand (collectively, the "Services"). If you use the open-source or self-hosted version of our software on infrastructure you control, much of your workspace data can stay on your own systems. Section 14 explains how this Policy applies in that case. This Policy, the Terms of Service , and (for customers who sign one) our Data Processing Addendum work together."
Defines the scope of the policy, identifies the controller entity ('Dench'), and enumerates the services and platforms to which the policy applies, establishing the legal boundary of data-handling obligations described throughout the document.
AI-generated interpretation, not legal advice.
" When you create an account or set up an organization, we collect information such as your name, email address, profile image, organization name and slug, membership role, invitation details, onboarding state, and current organization selection."
Enumerates the categories of account and organization data collected at sign-up, establishing what personal information is gathered and thereby the scope of data-use obligations.
AI-generated interpretation, not legal advice.
" We support Google sign-in and email one-time-password sign-in. Depending on the method you choose, we may receive basic Google profile information, your email address, verification codes, sign-in timestamps, session identifiers, device identifiers for desktop linking, OAuth state or pending sign-in records, and authentication cookies or tokens. Email sign-in codes expire after about 10 minutes, and session lifetimes can last up to about 90 days depending on activity and configuration."
Defines the categories of sign-in and verification data collected, including session lifetimes and expiry periods for sign-in codes, establishing the scope of authentication-related data handling.
AI-generated interpretation, not legal advice.
" If you purchase a paid plan or use metered AI features, payment processing is handled by Stripe. We do not store full card numbers on our servers. We do store subscription and billing metadata such as Stripe customer and subscription IDs, plan or tier, subscription status, quantities, billing period dates, credit grants, usage totals, and spend-limit settings."
Defines the billing and subscription data collected, specifies that full card numbers are not stored on Dench servers (a user-protective limitation), and identifies the categories of billing metadata retained, establishing the scope of financial data handling.
AI-generated interpretation, not legal advice.
" When you use the Services, you and your team submit CRM records, contacts, companies, tasks, notes, files, emails, messages, and other workspace content. We process this Customer Data on your behalf to provide the Services. You decide what to include, so please avoid submitting information you do not have the rights or a lawful basis to process."
Defines Customer Data as CRM records and other workspace content submitted by users, states it is processed on the customer's behalf to provide the Services, and places a responsibility notice on users to submit only data they have rights to process.
AI-generated interpretation, not legal advice.
" When you use AI or agent features, we process prompts, uploaded context, tool results, model responses, model and provider selection, request IDs, token counts, latency, estimated cost, billed amounts, error details, workspace and organization identifiers, and related operational metadata."
Defines the categories of AI-related inputs, outputs, and operational metadata processed when users engage AI or agent features, establishing the scope of data handling for those features.
AI-generated interpretation, not legal advice.
" We collect product analytics and operational data about how the Services are used, including page views, page-leave events, clicks, navigation flows, referrers, device and browser characteristics, organization context, and service performance. We use PostHog for browser and server-side analytics, and some areas enable session replay. Depending on the page and configuration, replay or autocapture may record on-screen activity and some information entered into the app, and not every input is guaranteed to be masked automatically."
Defines categories of usage, analytics, and device data collected, names PostHog as the analytics provider, and discloses that session replay may capture on-screen activity and form inputs that are not guaranteed to be masked, informing users of the scope of observational data collection.
AI-generated interpretation, not legal advice.
" If you use a managed cloud workspace or sandbox, we process infrastructure data such as sandbox subdomains, compute instance identifiers, network routing identifiers, storage volume identifiers, IP addresses, storage archive paths, provisioning state, stop or delete schedules, and backup or snapshot metadata. We may also store organization logos or similar uploaded assets."
Defines the infrastructure data categories processed for managed cloud workspaces and sandboxes, establishing the scope of data handling for cloud infrastructure operations.
AI-generated interpretation, not legal advice.
" We collect information from emails, support requests, onboarding reminders, budget alerts, invitations, and other communications you send to us or that we send to you."
Defines the communications and support data collected from emails, support requests, and other correspondence, establishing the scope of contact-data handling.
AI-generated interpretation, not legal advice.
" We use cookies and browser storage to keep you signed in, remember state, measure product usage, and improve the Services. These include authentication cookies or tokens, analytics cookies and storage (PostHog), session storage for onboarding and setup, and local storage for certain UI preferences. You can control cookies and storage through your browser or device settings, and we honor recognized opt-out signals such as Global Privacy Control where required. Some parts of the Services may not work correctly if you block essential cookies. For details, see our Cookie Policy ."
Defines the types of cookies and browser storage used, their purposes (authentication, analytics, session, preferences), discloses session replay capability, states that Global Privacy Control opt-out signals are honored where required, and warns that blocking essential cookies may impair service functionality.
AI-generated interpretation, not legal advice.
" When you apply to the Dench Creator Program at dench.com/creators , we collect your name, email address, social media handle, chosen platform, post URL, optional follower count, IP address, and user agent. We use this to review your application, contact you about its status, and detect duplicate or abusive submissions. Bank account information needed to send your payment is not stored in our application database. After approval, you provide it via email to creators@dench.com , and we use it solely to issue a one-time bank transfer. We delete that email after payment is complete and retain application records (excluding bank information) for record-keeping, payment audit, and one-payout-per-person enforcement."
Specifies what personal data is collected for Creator Program applicants, the purposes for which it is used (reviewing applications, detecting abuse, issuing payment), how bank account information is handled (not stored in the application database, transmitted via email solely for a one-time bank transfer), and that the payment email is deleted after the transfer is complete — establishes data collection, use, and deletion procedures for a specific program.
AI-generated interpretation, not legal advice.
" We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and may provide additional notice through the Services or by email. Your continued use of the Services after an update means you accept the revised Policy."
Establishes the procedure for updating the Privacy Policy, including updating the effective date and potentially providing notice via the Services or email for material changes; deems continued use of the Services after an update as acceptance of the revised Policy — governs how policy changes are communicated and how acceptance is implied.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Dench.com's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Dench.com's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Dench.com's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Dench.com requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Dench.com's published policies yet.
What the policies actually cover
0 topicsNone of Dench.com's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or complete a business transaction. We use vetted third-party providers (subprocessors) for hosting, AI inference, billing, email, analytics, sign-in, integrations, and messaging. Ea...”Open source citation
The clause permits sale of personal data or information.
“Depending on your state of residence (for example California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws), you may have rights to know or access the personal information we collect, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal information, or certain profiling. We do not sell personal informa...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or complete a business transaction. We use vetted third-party providers (subprocessors) for hosting, AI inference, billing, email, analytics, sign-in, integrations, and messaging. Ea...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“The hosted Services run in the United States (AWS US East, Northern Virginia / us-east-1) . Customer Data at rest is stored in the United States, and our subprocessors that handle Customer Data are based in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
| Standard | audit rights dpa residency | conditional | MEDIUM | 1 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on subprocessors data sharing
“We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or complete a business transaction. We use vetted third-party providers (subprocessors) for hosting, AI inference, billing, email, analytics, sign-in, integrations, and messaging. Each is bound by data protection terms no less protective than ours. The current list, with each provider's purpose, location, and transfer mechanism, is maintained on our Subprocessors page . We may also disclose information to professional advisors, and to an acquirer or successor in connection with a merger, acquisition, financing, or sale of assets, and to regulators or authorities where required by law or to protect rights, safety, and security. Your use of third-party integrations you connect is also subject to those providers' own terms and privacy practices.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We do not sell your personal information, and we do not " share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose information only as needed to run the Services, comply with law, or complete a business transaction. We use vetted third-party providers (subprocessors) for hosting, AI inference, billing, email, analytics, sign-in, integrations, and messaging. Each is bound by data protection terms no less protective than ours. The current list, with each provider's purpose, location, and transfer mechanism, is maintained on our Subprocessors page . We may also disclose information to professional advisors, and to an acquirer or successor in connection with a merger, acquisition, financing, or sale of assets, and to regulators or authorities where required by law or to protect rights, safety, and security. Your use of third-party integrations you connect is also subject to those providers' own terms and privacy practices.”Open timeline citation
Latest stance: third party or vendor sharing on audit rights dpa residency
“The hosted Services run in the United States (AWS US East, Northern Virginia / us-east-1) . Customer Data at rest is stored in the United States, and our subprocessors that handle Customer Data are based in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your home country. Where we transfer personal data that is protected by the laws of the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized transfer mechanisms such as the EU, UK, and Swiss Standard Contractual Clauses, and applicable Data Privacy Framework certifications, as further described in our Data Processing Addendum .”Open timeline citation
Latest stance: sale or sell on privacy data use
“Depending on your state of residence (for example California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws), you may have rights to know or access the personal information we collect, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal information, or certain profiling. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that would require an opt-out right under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. To exercise your rights, email privacy@dench.com . You may use an authorized agent where permitted by law. We will not discriminate against you for exercising your rights, and we will verify your identity before acting on a request. If we deny a request, you may appeal by replying to our response.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
24 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Dench.com's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Dench.com's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Dench.com's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.