expand.ai
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This segment describes the Owner's obligation to take appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of data, and discloses that internal staff and external third-party technical service providers may have access to data as part of the operation of the application, identifying data-sharing with subprocessors as part of processing procedures.
Specifies the exhaustive list of purposes for which the owner collects and processes user data, including service delivery, legal compliance, enforcement response, rights protection, fraud detection, and analytics — defining the permitted scope of data use.
Establishes two exceptions to standard retention limits: (1) the Owner may retain Personal Data longer if the User has consented, provided consent remains in force, and (2) the Owner may be obliged to retain Personal Data longer to fulfil a legal obligation or upon order of an authority.
How to read this page: Overall risk rates what expand.ai's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 51 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 51 citationsLast captured 2026-08-10
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This segment imposes obligations regarding data collection, stating that all requested data is mandatory unless specified otherwise, and that failure to provide it may prevent service delivery; it also describes that usage data may be collected automatically, defining the conditions of data collection.
" Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection. Personal Data may be freely provided by the Use..."
Describes the procedure for exercising User rights: requests may be directed via contact details in the document, are free of charge, must be answered as early as possible and within one month, and requires the Owner to communicate any rectification, erasure, or restriction to each recipient to whom Data was disclosed unless impossible or disproportionate.
" Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, p..."
Grants Users the right to object to processing for direct marketing purposes at any time, free of charge and without justification, and imposes an obligation on the Owner to cease such processing upon objection; also directs Users to the document for information on whether direct marketing processing occurs.
" Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to process..."
Clause A grants users the right to obtain the erasure of their data, while Clause B states that this right cannot be enforced after the retention period expires, creating an opposing claim about the right's practical existence and enforceability.
" Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Owner."
"Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time."
This segment describes the Owner's obligation to take appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of data, and discloses that internal staff and external third-party technical service providers may have access to data as part of the operation of the application, identifying data-sharing with subprocessors as part of processing procedures.
AI-generated interpretation, not legal advice.
" The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics."
Specifies the exhaustive list of purposes for which the owner collects and processes user data, including service delivery, legal compliance, enforcement response, rights protection, fraud detection, and analytics — defining the permitted scope of data use.
AI-generated interpretation, not legal advice.
" The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority."
Establishes two exceptions to standard retention limits: (1) the Owner may retain Personal Data longer if the User has consented, provided consent remains in force, and (2) the Owner may be obliged to retain Personal Data longer to fulfil a legal obligation or upon order of an authority.
AI-generated interpretation, not legal advice.
" Among the types of Personal Data that this Application collects, by itself or through third parties, there are: IP address."
This segment discloses that Personal Data collected by the application — either directly or through third parties — includes IP addresses, defining the categories of data subject to processing.
AI-generated interpretation, not legal advice.
" Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection. Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application. Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service. Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner. Any use of Cookies – or of other tracking tools — by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy."
This segment imposes obligations regarding data collection, stating that all requested data is mandatory unless specified otherwise, and that failure to provide it may prevent service delivery; it also describes that usage data may be collected automatically, defining the conditions of data collection.
AI-generated interpretation, not legal advice.
" Users are responsible for any third-party Personal Data obtained, published or shared through this Application."
This segment places responsibility on Users for any third-party Personal Data they obtain, publish, or share through the application, assigning a legal obligation to the User regarding third-party data handling.
AI-generated interpretation, not legal advice.
" This Application collects some Personal Data from its Users."
This segment states that the application collects Personal Data from Users, establishing the foundational data-collection obligation and scope of the policy.
AI-generated interpretation, not legal advice.
" processing is necessary for compliance with a legal obligation to which the Owner is subject;"
Permits processing where necessary to comply with a legal obligation applicable to the owner, establishing legal obligation compliance as a valid processing basis.
AI-generated interpretation, not legal advice.
" provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;"
Permits processing where it is necessary for the performance of a contract with the user or for pre-contractual obligations, establishing contractual necessity as a valid legal basis.
AI-generated interpretation, not legal advice.
" For specific information about the Personal Data used for each purpose, the User may refer to the section “Detailed information on the processing of Personal Data”."
Cross-references a detailed section on personal data processing, directing users there for purpose-specific information and incorporating that section's content by reference.
AI-generated interpretation, not legal advice.
" The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior."
Defines the function of analytics services in this section — enabling monitoring and analysis of web traffic and tracking user behavior — establishing the purpose and scope of the analytics processing category.
AI-generated interpretation, not legal advice.
" This Application uses Trackers. To learn more, Users may consult the Cookie Policy ."
Directs users to consult the Cookie Policy for details on trackers, incorporating that document by reference and establishing a procedural mechanism for user access to tracker information.
AI-generated interpretation, not legal advice.
" The Owner may process Personal Data relating to Users if one of the following applies:"
Introduces the enumeration of permissible legal bases for processing personal data, framing the conditions under which the owner may process user data.
AI-generated interpretation, not legal advice.
" Users have given their consent for one or more specific purposes."
Permits the owner to process personal data where the user has given consent for one or more specific purposes, establishing consent as a valid legal basis.
AI-generated interpretation, not legal advice.
" processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;"
Permits processing where it is related to a task carried out in the public interest or in exercise of official authority vested in the owner, establishing public interest as a valid legal basis.
AI-generated interpretation, not legal advice.
" processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party."
Permits processing where necessary for the legitimate interests of the owner or a third party, establishing legitimate interests as a valid legal basis for data processing.
AI-generated interpretation, not legal advice.
" In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract. "
Obliges the owner to clarify the specific legal basis applicable to any processing upon request, including whether data provision is a statutory or contractual requirement or necessary to enter a contract.
AI-generated interpretation, not legal advice.
" Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users’ request, the Owner will inform them about those recipients."
Describes the procedure for exercising User rights: requests may be directed via contact details in the document, are free of charge, must be answered as early as possible and within one month, and requires the Owner to communicate any rectification, erasure, or restriction to each recipient to whom Data was disclosed unless impossible or disproportionate.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from expand.ai's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in expand.ai's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in expand.ai's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat expand.ai requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in expand.ai's published policies yet.
What the policies actually cover
0 topicsNone of expand.ai's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Further information about retention time” describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Further information about retention time” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge,...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge,...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | conditional | MEDIUM | 3 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: third party or vendor sharing on privacy data use
“The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-10· verified 2026-08-10
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
94 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of expand.ai's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified expand.ai's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from expand.ai's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.