Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · drillbit.com

Drillbit

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-20
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Privacy Policy · verbatim

c) We do not use this data for advertising purposes.

highest-risk verified finding on commercial use — tap for the citation
21 verified findings6 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
3
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Commercial use allowed
from 1 cited finding
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Drillbit's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 21 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 21 citationsLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines the categories of personal and business information collected (name, email, business details, inventory, employee and customer data, scheduling information, etc.) and states that voluntarily provided business information will be used solely to enable and support the user's services — limiting use to that stated purpose.

"Personal Information: We collect your name and email address during sign-up via Google sign-in. Business Information: As you use our app, you may provide details about your business. Voluntarily provided information will be used solely for ..."
📍 § 5 (Information Collection)Jump to exact text →
plan language
Privacy & data use

States that personal data is processed on the basis of consent and necessity to provide services, and that the information provided is used exclusively to deliver those services — defining the permitted legal basis and limiting the scope of data use.

"We process your personal data based on consent and as necessary to provide our services to you. The information you provide is used exclusively to deliver our services to you, enabling you to streamline your home services business operation..."
📍 § 7 (Legal Basis for Processing)Jump to exact text →
plan language
Data retention

Defines the controller's data retention obligations: personal information is retained as long as necessary for business purposes or by legal requirement, for the life of the account or as needed to provide services, and as needed to comply with legal obligations, resolve disputes, and enforce agreements.

"We retain personal information as long as necessary for our business purposes or as required by law. We will retain your information for as long as your account is active or as needed to provide you services. We will retain and use your inf..."
📍 § 9 (Data Retention)Jump to exact text →
plan language
Confidentiality

Describes security obligations including row-level security policies, access controls limiting employee access to user data, storage within a named cloud environment, and SOC2 compliance — establishing the controller's obligation to maintain confidentiality and integrity of user data.

"We employ row-level security policies for all information stored in our databases. Our commitment to data security ensures the confidentiality and integrity of your data. Your data is stored within supabase’s cloud environment. Our team pla..."
📍 § 11 (Data Security)Jump to exact text →
plan language
Subprocessors & data sharing

Declares adherence to the Google API Services User Data Policy, including its Limited Use requirements, incorporating that external policy's obligations into the controller's data-handling commitments for data received from Google APIs.

"If you choose to use our application features that connect with Google services, we adhere to the Google API Services User Data Policy. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, in..."
📍 § 6 (Google API Services and Data Usage)Jump to exact text →
plan language
Audit rights / DPA / residency

Disclaims current applicability of specific legal frameworks or regulations (named explicitly as GDPR and CCPA) based on the company's location in Austin, Texas, and notes SOC2 compliance of data storage — a disclaimer limiting the controller's represented compliance obligations.

"As a business operating out of Austin, Texas, we are not currently subject to specific legal frameworks or regulations like GDPR or CCPA. Your data is stored within supabase and is SOC2 compliant. ‍"
📍 § 12 (Compliance)Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 21
Severity
Surface
Document
Tier
Data retention
High
"We retain personal information as long as necessary for our business purposes or as required by law. We will retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. ‍"
§ 9 (Data Retention)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the controller's data retention obligations: personal information is retained as long as necessary for business purposes or by legal requirement, for the life of the account or as needed to provide services, and as needed to comply with legal obligations, resolve disputes, and enforce agreements.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"b) We do not transfer this data to third parties except with your explicit consent, for security purposes, to comply with laws, or as part of a merger/acquisition (with prior consent)."
§ 6 (Google API Services and Data Usage)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Prohibits transfer of Google API data to third parties except with explicit user consent, for security purposes, to comply with law, or in the context of a merger or acquisition with prior consent — user-favorable restriction on data sharing.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"We currently do not share personal data with third parties except as explicitly described in this policy. Any future changes to this practice will be reflected in updates to this policy. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties ‍"
§ 8 (Data Sharing)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts current sharing of personal data to only what is explicitly described in the policy, prohibits sharing mobile information with third parties or affiliates for marketing or promotional purposes, and prohibits sharing of text messaging opt-in data and consent with any third parties — user-favorable restrictions on data sharing.

AI-generated interpretation, not legal advice.

Commercial use
High
"c) We do not use this data for advertising purposes."
§ 6 (Google API Services and Data Usage)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Explicitly prohibits using Google API data for advertising purposes — protective of the user against commercial exploitation of that data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will take steps to delete the information promptly. ‍"
§ 3 (Children's Privacy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts the service from being used by individuals under 18, prohibits knowing collection of personal information from children under 13, and imposes an obligation to delete any such data if discovered — protective of minors.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"a) We only use the data to provide or improve features that are clearly visible in our application interface."
§ 6 (Google API Services and Data Usage)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts use of data received from Google APIs solely to providing or improving features that are visible in the application interface — prohibiting any other secondary use of that data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"d) Human access to your data is restricted and only permitted with your explicit consent, for security purposes, to comply with laws, or when aggregated for internal operations."
§ 6 (Google API Services and Data Usage)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts human access to Google API data, permitting it only with explicit user consent, for security purposes, to comply with law, or when aggregated for internal operations — user-favorable limitation on human review of data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We may use cookies and similar technologies for basic app functionality and user experience enhancement such as remembering whether you are signed-in. We do not use these technologies for tracking purposes. ‍"
§ 14 (Cookies and Tracking)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Permits use of cookies and similar technologies only for basic functionality and user experience, and explicitly restricts their use for tracking purposes — user-favorable restriction prohibiting tracking use.

AI-generated interpretation, not legal advice.

Confidentiality
High
"We employ row-level security policies for all information stored in our databases. Our commitment to data security ensures the confidentiality and integrity of your data. Your data is stored within supabase’s cloud environment. Our team plan with supabase is SOC2 compliant. We also employee access controls that limit employee access to user data. ‍"
§ 11 (Data Security)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes security obligations including row-level security policies, access controls limiting employee access to user data, storage within a named cloud environment, and SOC2 compliance — establishing the controller's obligation to maintain confidentiality and integrity of user data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Welcome to Drillbit Inc. We are committed to protecting the privacy and security of our users. This policy outlines how we collect, use, protect, and handle personal information through our web application and interactions with our company. ‍"
§ 1 (Introduction)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Introduces a commitment to protecting privacy and security, and outlines that the policy governs how personal information is collected, used, protected, and handled — establishing the controller's general obligation to manage personal data according to the policy's terms.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"This policy applies to all personal data processed by Drillbit Inc. through our web application, customer support, marketing activities, and other services. ‍"
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope of the policy by identifying the categories of activities (web application, customer support, marketing, other services) to which the data-processing rules apply.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Users outside the United States should note that their personal information may be processed in the United States, where privacy laws may differ from those in their home countries. By using our services, international users consent to this transfer and processing. ‍"
§ 4 (International Users)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Notifies international users that their data may be processed in the United States where privacy standards may differ, and treats continued use of services as consent to such cross-border transfer and processing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Personal Information: We collect your name and email address during sign-up via Google sign-in. Business Information: As you use our app, you may provide details about your business. Voluntarily provided information will be used solely for the purpose of enabling our services in order to support your business. Such information may include business details such as name, address, inventory, price book, service catalog, employee information, customer information, job scheduling information, job status information, and comments. ‍"
§ 5 (Information Collection)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the categories of personal and business information collected (name, email, business details, inventory, employee and customer data, scheduling information, etc.) and states that voluntarily provided business information will be used solely to enable and support the user's services — limiting use to that stated purpose.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We process your personal data based on consent and as necessary to provide our services to you. The information you provide is used exclusively to deliver our services to you, enabling you to streamline your home services business operations. ‍"
§ 7 (Legal Basis for Processing)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that personal data is processed on the basis of consent and necessity to provide services, and that the information provided is used exclusively to deliver those services — defining the permitted legal basis and limiting the scope of data use.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Data Access & Correction: You can access and modify your data within the app at any time. Data Deletion: You have the right to delete your data from the app. For complete account deletion, you may contact us, and we will process your request promptly. Data Portability: We support your right to data portability. You can export your data from our service by contacting us at alex@drillbit.com . ‍"
§ 10 (User Rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Grants users the right to access and modify their data within the app at any time, the right to delete their data (including full account deletion via contact request), and the right to export their data by contacting the company — establishing multiple user-favorable data rights.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We may disclose personal information if required by law or in response to valid requests by public authorities. ‍"
§ 13 (Disclosure)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Grants the company permission to disclose personal information when legally required or in response to valid requests from public authorities, establishing a conditional disclosure right.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We reserve the right to amend this policy. Users are encouraged to review this policy periodically. Continued use of our app constitutes acceptance of any changes. ‍"
§ 16 (Policy Amendments)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes a procedure for policy amendments by reserving the right to amend, encouraging periodic review, and defining continued use of the app as acceptance of changes.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"If you have any questions or concerns about your privacy, please contact us at alex@drillbit.com . Address: Drillbit Inc."
§ 17 (Contact Us)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Provides the physical mailing address of the company as part of the contact information procedure for privacy inquiries.

AI-generated interpretation, not legal advice.

Common questions about Drillbit's policies

Can you use Drillbit's output commercially?
Commercial use allowed — based on 1 verified finding from Drillbit's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Drillbit's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Drillbit's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Drillbit's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Drillbit requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Drillbit's published policies yet.

What the policies actually cover

0 topics

None of Drillbit's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

21
clauses
4
patterns
4
stances
privacy sharing · 2data retention · 1ip ownership · 1
data retentionMEDIUM§ 9 (Data Retention)

The clause allows indefinite, perpetual, or necessity-based retention.

We retain personal information as long as necessary for our business purposes or as required by law. We will retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. ‍
Open source citation
ip ownershipHIGH§ 16 (Policy Amendments)

The clause appears to reserve or claim ownership rights for the platform.

We reserve the right to amend this policy. Users are encouraged to review this policy periodically. Continued use of our app constitutes acceptance of any changes. ‍
Open source citation
privacy sharingMEDIUM§ 6 (Google API Services and Data Usage)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

b) We do not transfer this data to third parties except with your explicit consent, for security purposes, to comply with laws, or as part of a merger/acquisition (with prior consent).
Open source citation
privacy sharingMEDIUM§ 8 (Data Sharing)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

We currently do not share personal data with third parties except as explicitly described in this policy. Any future changes to this practice will be reflected in updates to this policy. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with an...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useworsensHIGH1
All applicable tierssubprocessors data sharingconditionalMEDIUM2
Team / Businessdata retentionconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026content ownershipHIGH

Latest stance: platform claims or reserves rights on privacy data use

We reserve the right to amend this policy. Users are encouraged to review this policy periodically. Continued use of our app constitutes acceptance of any changes. ‍
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

b) We do not transfer this data to third parties except with your explicit consent, for security purposes, to comply with laws, or as part of a merger/acquisition (with prior consent).
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

We currently do not share personal data with third parties except as explicitly described in this policy. Any future changes to this practice will be reflected in updates to this policy. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties ‍
Open timeline citation
Jul 20, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

We retain personal information as long as necessary for our business purposes or as required by law. We will retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. ‍
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

21 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Drillbit's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Drillbit's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Drillbit's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.