Skip to main content
Platform Review
PricingSign in
← All platforms
CRM & Content Operations · framer.com

Framer AI

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskMEDReviewed 2026-08-10
Creator: low · GRC: medium · Counsel: low
creator band
Exemplary
enterprise · Exemplary
Exhibit A · Privacy Policy · verbatim

Our automated systems may analyze your Content using techniques such as machine learning in order to improve our Services and Software and the user experience. Google Workspace APIs are not used to develop, improve, or train generalized AI and/or ML models. Marketing or Promotional Communications: Only if you have subscribed to our newsletter, we may use

highest-risk verified finding on training use — tap for the citation
86 verified findings7 policy surfaces1/2 core docs verified

Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.

Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
22
medium
64
low
1/2
docs
Trains on your data?
Training possible — conditions or opt-outs apply
from 2 cited findings
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →
Risk by role
Select a role to tailor the summary and reorder the findings below.

Scores derived from 48 enriched findings — same verbatim citations as below. AI-generated, not legal advice.

What this means for you
  • Framer AI's terms explicitly protect your inputs from training use — the policy is affirmatively favorable on this point.
  • Data handling is conditional — 6 privacy or retention clauses warrant review before using Framer AI at scale.

Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.

How to read this page: Overall risk rates what Framer AI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Creator lens
Your prompts, your outputs, your IP
EXEMPLARY

Based on 113 verified, verbatim-cited findings below — read the citations.

Enterprise lens
Data use, retention, subprocessors, audit
EXEMPLARY

Based on 144 verified, verbatim-cited findings below — read the citations.

Automated assessment against a published rubric — not legal advice.

Partially verifiedCRM & Content Operations

Partially verified — Privacy Policy — Verified (read in full, 62 findings); Terms of Service — Capture pending. Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Capture blocked

A known core policy document could not be publicly captured after the available capture strategies were tried.

Blocked core document: Terms of Service

Document status
  • Privacy Policy
    Verified - read in full - 62 citationsstaticLast captured 2026-08-10
  • Terms of Service
    Capture blocked - document not publicly capturablestatic
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Training on your content

This segment discloses that automated systems may analyze user content using machine learning to improve services, but explicitly restricts Google Workspace API data from being used to develop, improve, or train generalized AI/ML models, and separately restricts marketing communications to opted-in users only, creating both a training-use restriction and a marketing communication limitation.

"Our automated systems may analyze your Content using techniques such as machine learning in order to improve our Services and Software and the user experience. Google Workspace APIs are not used to develop, improve, or train generalized AI ..."
📍 Privacy Policy › “Personal information we Collect automatically when you use our services”Jump to exact text →
plan language
Privacy & data use

This segment imposes an obligation on Framer to collect personal information only for the purposes described in the Privacy Statement (business operations, service administration, legal compliance) and prohibits processing for other purposes, establishing a purpose-limitation constraint.

" As part of our normal business operations, your usage of our Services, our administration of you as a customer and to comply with local laws and regulations we collect your Personal Information. We will not process Personal Information for..."
📍 Privacy Policy › “Personal information collection”Jump to exact text →
plan language
Privacy & data use

This segment defines the scope and purpose of the Privacy Statement, identifies the data controller entities (Framer B.V., Framer Inc., and affiliates), and specifies the services and platforms to which the statement applies, establishing the foundational legal context for all subsequent data processing obligations.

" This Privacy Statement explains how Personal Information about our (potential) customers and other individuals using our services is collected, used and disclosed by Framer B.V., Framer Inc. and its respective affiliates ("us", "we", "our"..."
📍 Privacy Policy › “January 11, 2021”Jump to exact text →
plan language
Privacy & data use

Permits Enterprise administrators to assign specific roles or revoke access for team members via the Framer account dashboard, establishing a tier-differentiated access control right for organizational management.

" Framer supports role-based access control, which means the access of team members within an organization are dictated by their role (viewer, collaborator, editor, or administrator). Administrators can assign team members specific roles or ..."
📍 “Role-based access control (RBAC)”Jump to exact text →
plan language
Privacy & data use

This segment enumerates California consumer rights under the CCPA—including rights to know, delete, opt out of sales, and non-discrimination—and describes the procedure for exercising those rights by contacting the Compliance team.

" Subject to certain limitations, the CCPA provides California consumers the right to request to know more details about the categories or specific pieces of Personal Information we collect (including how we use and disclose this information..."
📍 Privacy Policy › “Your california privacy rights”Jump to exact text →
plan language
Privacy & data use

Establishes the procedure for aggregating logs, triaging and escalating security alerts, encouraging responsible disclosure from customers and non-customers, and engaging external expertise to investigate and resolve serious security incidents.

" The security team at Framer aggregates logs and audit trails from various sources at a central location and uses tools to analyze, monitor and flag anomalous or suspicious activity. Framer’s internal processes define how alerts are triaged..."
📍 “Security incident management”Jump to exact text →
plan language
Privacy & data use

This segment explains that Framer no longer relies on Privacy Shield as a data transfer mechanism following the Schrems II ruling, and commits Framer to continue honoring existing Privacy Shield certification obligations, constituting an ongoing legal obligation regarding cross-border data transfers.

" The California Consumer Privacy Act (“CCPA”) regulates how organizations handle the personal information of Californian residents and gives them certain rights with respect to their personal information. Framer is committed to be compliant..."
📍 “CCPA”Jump to exact text →
plan language
Moderation & enforcement

Grants Enterprise customers the ability to implement role-based access control with defined roles (viewer, collaborator, editor, administrator) and administrator privileges to assign or revoke team member access, establishing a tier-specific permission and access control right.

" Framer supports single sign-on (SSO) for Enterprise customers. By using the customer’s existing identity management solution, Framer provides an easy and secure way for companies to manage their team members’ access. Framer supports identi..."
📍 “Single sign-on (SSO)”Jump to exact text →
Conflicting provisions (1)
  • Clause A implies that personal information will be deleted if it is no longer necessary, while Clause B explicitly states that the company does not have to honor such a request in all cases, even when the data is no longer necessary, creating an opposing claim about the certainty of this right.

    " - To delete your Personal Information (where it is no longer necessary in relation to the purposes for which it was collected or processed). We strive to anonymize your Personal Information within 30 days after your deletion request;"
    " Right to erasure . This concerns the right to request erasure of the data. This enables you to ask us to delete or remove personal data where: (i) the data is no longer necessary, (ii) the processing activities have been objected to, (iii) the data has been unlawfully processed, (iv) the data has to be erased on the basis of a legal requirement, or (v) where the data has been collected in relation to the offering of information society services. However, we do not have to honour such request in all cases. "
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 22
Tier-specific - 0
Total citations - 86
Severity
Surface
Document
Tier
Training on your content
CautionHigh
"Our automated systems may analyze your Content using techniques such as machine learning in order to improve our Services and Software and the user experience. Google Workspace APIs are not used to develop, improve, or train generalized AI and/or ML models. Marketing or Promotional Communications: Only if you have subscribed to our newsletter, we may use your Personal Information to contact you with marketing or promotional materials and other information communications related to Framer. If you no longer wish to receive marketing or promotional communications related to us, you can at any moment in time by using the unsubscribe button in the email or emailing support@framer.com to request us to stop sending you such communications. Such a request will be processed immediately by us, but in any event within two (2) business days."
Privacy Policy › “Personal information we Collect automatically when you use our services”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment discloses that automated systems may analyze user content using machine learning to improve services, but explicitly restricts Google Workspace API data from being used to develop, improve, or train generalized AI/ML models, and separately restricts marketing communications to opted-in users only, creating both a training-use restriction and a marketing communication limitation.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" - Operate, evaluate, maintain, improve, customize, and develop the Services (including by monitoring and analyzing trends, access to, and use of the Services for enhancing customer experience, security of our Services, advertising and marketing);"
Privacy Policy › “Personal information we use”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes an obligation and permission to use personal data to operate, evaluate, maintain, improve, customize, and develop the Services, including through monitoring and analytics, advertising, and marketing — defining broad data use purposes.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" - Situations where browsing data is sent to referral advertisers - when you click on an ad that sends you to our website, we send a hashed identifier to the referring site so they can receive credit for the referral. We, along with millions of other sites, use these services. While we limit the information sent to what is needed to properly record the referral, the fact that you clicked on the link and visited Revinate may be added to your profile by the ad publisher. You have the right to opt out of this by sending us a request as described below."
Privacy Policy › “Your california privacy rights”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment describes the procedure by which browsing/click data is shared with referral advertisers via hashed identifiers, explains the scope of information disclosed, and grants the user a right to opt out of this data-sharing practice.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" - The processing is in our legitimate interest, and this justified interest prevails over your privacy; and/or you have consented to the processing."
Privacy Policy › “Personal information we use”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment defines the third and fourth legal bases for processing personal information — legitimate interests (where they override privacy interests) and consent — establishing the remaining lawful grounds under GDPR for Framer's data processing activities.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" When you access or use our Services we automatically collect information about you, including: Log Information : We collect information about your use of the Services, including the type and version of browser, machine and device you use, access times, usage times, launches, pages viewed, debug, your IP address, the page you visited before navigating to our Services and other statistics. Information Collected by Cookies and Other Tracking Technologies: We use various technologies to collect information, and this may include sending cookies to your computer or mobile device. Cookies are small data files stored on your hard drive or in device memory that help us to improve our Services and your experience, see which areas and features of our Services are popular and count visits. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Services. Only if you have consented to this, we may also collect information using web beacons (also known as "tracking pixels"). Web beacons are electronic images that may be used in our Services or notifications and help deliver cookies, count visits, understand usage and campaign effectiveness and determine whether a notification has been opened and acted upon. In addition, we may use third party services such as Google Analytics, Intercom, and Mode that collect, monitor and analyze these statistics to better decipher and analyze the data. "
Privacy Policy › “Personal information we Collect automatically when you use our services”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment describes Framer's automatic collection of log information and cookie/tracking data when users access services, identifying specific data categories (browser type, IP address, pages viewed, usage times), which constitutes a disclosure obligation under privacy law and defines the scope of automatic data collection practices.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" This section provides additional details about the Personal Information we collect about California consumers and the rights afforded to them under the California Consumer Privacy Act or "CCPA". We do not sell the Personal Information we collect to third parties for money or any other consideration, as that term is generally understood. However, the CCPA’s definition of "sale" is very broad and might be construed to include the following:"
Privacy Policy › “Your california privacy rights”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Introduces the CCPA framework applicable to California consumers, clarifies that personal information is not sold for money or other consideration, and notes the broad statutory definition of 'sale' under CCPA that may encompass certain data sharing activities, defining the legal scope of the California privacy rights section.

AI-generated interpretation, not legal advice.

Privacy & data use
CautionHigh
" Social Sharing Features: Our Services may offer social sharing features, which let you share Framer prototypes from our Services with other media, and vice versa. The use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the company that provides the social sharing feature. We may (in accordance with this Privacy Statement) collect, store, and use Personal Information from other media if you use social sharing features. For more information about the purpose and scope of data collection, storage, and processing by other media in connection with social sharing features, please visit the privacy statements of the companies that provide these features. Third Parties: We may also obtain Personal Information about you from third parties, such as LinkedIn, Facebook, Dribbble, Twitter and other publicly accessible sources. Support and Service: When you contact us for support or other customer service requests, we can maintain records related to such requests, including any information provided by you related to such support or service requests. Our Access to Your Content: Where permitted by law, we will only access, view, or listen to your Content (defined in section 1.2 of our Terms of Service) in limited ways. For example, in order to successfully provide you with our Services we may need to access, view, or listen to your Content to (A) respond to Feedback or support requests; (B) detect, prevent, or otherwise address fraud, security, legal, or technical issues; and (C) enforce the Terms. "
Privacy Policy › “Personal information we Collect automatically when you use our services”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment permits Framer to collect, store, and use personal information from third-party social media platforms when users employ social sharing features, subject to the Privacy Statement, granting Framer a right to process externally sourced personal data.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" - We believe it’s needed to detect, prevent, or address fraud, security, or technical issues;"
Privacy Policy › “Personal information collection”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment establishes an exception permitting disclosure of personal information when needed to detect, prevent, or address fraud, security, or technical issues, creating a security and integrity carve-out to the general sharing restriction.

AI-generated interpretation, not legal advice.

Data retention
High
"In general the collected Personal Information is not stored by us for longer than three years, unless you do a prior deletion request. However, in some circumstances, we may retain certain Personal Information for other periods of time, for instance where we are required to do so in accordance with legal, tax, and accounting requirements, or if required by a legal process, legal authority, or other governmental entity having authority to make the request, for so long as required. In specific circumstances, we may also retain certain Personal Information for longer periods of time corresponding to a statute of limitation, so that we have an accurate record of your dealings with us in the event of any complaints or challenges."
Privacy Policy › “Retention of personal information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Three-year default retention is relatively long. The open-ended exceptions for legal, tax, accounting, and statute-of-limitations purposes mean data could be retained beyond three years without a clear upper limit, increasing user exposure.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"We operate worldwide and we may share your Personal Information with our affiliated businesses as part of our business operations, administration of the Services and to comply with local laws and regulations. We may also appoint third party service providers (who will operate under our instructions) to assist us in providing information, products or services to you, in conducting and managing our business, or in managing and improving our Services. We may share your personal data with these affiliates and third parties to perform services that the third parties have been engaged by us to perform on our behalf, subject to appropriate contractual restrictions and security measures, or if we believe it is reasonably necessary to prevent harm or loss, or if we believe that the disclosure will further an investigation of suspected or actual illegal activities."
Privacy Policy › “Personal information we disclose”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Personal data may be shared globally with affiliates and subprocessors. The triggers for sharing ('reasonably necessary to prevent harm or loss,' 'suspected illegal activities') are broad and subjective, giving Framer wide discretion.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"We may share Personal Information with third parties in connection with potential or actual sale of our company or any of our assets, or those of any affiliated company, in which case Personal Information held by us about our customers and/or users may be one of the transferred assets."
Privacy Policy › “Personal information we disclose”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

In the event of a sale or asset transfer, user personal data can be passed to a new owner without individual consent or guaranteed prior notice.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"In accordance with our legal obligations, we may also process Personal Information, subject to a lawful request, to public authorities for law enforcement or national security purposes. Further we may also disclose Personal Information where otherwise required by local law or regulations."
Privacy Policy › “Personal information we disclose”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Mandatory disclosure to public authorities under legal compulsion is standard, but the broad reference to 'national security purposes' and 'local law or regulations' provides wide latitude for disclosure without user consent.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
NeutralHigh
" - Otherwise protect our property, legal rights, or that of others."
Privacy Policy › “Personal information collection”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment establishes a residual exception permitting disclosure of personal information to protect Framer's or others' property and legal rights, creating a legal rights protection carve-out to the general sharing restriction.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
NeutralHigh
" - We believe it is needed to enforce our Terms of Service, or that it is legally required;"
Privacy Policy › “Personal information collection”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment establishes an exception permitting disclosure of personal information when needed to enforce the Terms of Service or when legally required, creating a legal compliance and contractual enforcement carve-out to the general sharing restriction.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" - Manage, protect against and investigate fraud, risk exposure, claims, and other liabilities, including but not limited to violation of our contract terms or (international) laws or regulations;"
Privacy Policy › “Personal information we use”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes an obligation to use personal data to manage, protect against, and investigate fraud, risk, claims, and liabilities including contract or legal violations, defining risk management as a lawful data processing purpose.

AI-generated interpretation, not legal advice.

Privacy & data use
NeutralHigh
" While using our Services, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. For example, we collect information when you create an account, request customer support or otherwise communicate with us. The types of information we may collect include basic user information (such as your name, email address, social media avatar, telephone number and photograph), company information and any other information you choose to provide. We will not collect financial information from you (such as your payment card number, expiration date or security code). All payments to us are handled via a third party, Paddle Ltd ( https://paddle.com ). We refer to their Privacy Statement https://paddle.com/gdpr ."
Privacy Policy › “Personal information you provide to us”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This segment describes Framer's practice of collecting personally identifiable information provided by users during account creation and support interactions, identifying the categories of data collected (name, email, social media avatar, phone, photo, company info) and explicitly restricting collection of financial information, creating both a data collection obligation and a limitation on scope.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We operate worldwide and we may share your Personal Information with our affiliated businesses as part of our business operations, administration of the Services and to comply with local laws and regulations. We may also appoint third party service providers (who will operate under our instructions) to assist us in providing information, products or services to you, in conducting and managing our business, or in managing and improving our Services. We may share your personal data with these affiliates and third parties to perform services that the third parties have been engaged by us to perform on our behalf, subject to appropriate contractual restrictions and security measures, or if we believe it is reasonably necessary to prevent harm or loss, or if we believe that the disclosure will further an investigation of suspected or actual illegal activities. We reserve the right to share any information that is not deemed Personal Information or is not otherwise subject to contractual restrictions. Where Personal Information is transferred outside the European Economic Area to our affiliated companies or to third party service providers, we will take steps to ensure that your Personal Information is protected by the same level of protection as if it remained within the European Economic Area, including by entering into data transfer agreements using the European Commission approved Standard Contractual Clauses. We contractually require agents, service providers, and affiliates who may process Personal Information related to the Services to provide the same level of protection for Personal Information as required under the European Union General Data Protection Regulation ("GDPR"). "
Privacy Policy › “Personal information we disclose”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants permission to share personal information with affiliated businesses and third-party service providers worldwide for business operations, service administration, local law compliance, and service provision, identifying the categories of recipients and purposes for data sharing.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We may share Personal Information with third parties in connection with potential or actual sale of our company or any of our assets, or those of any affiliated company, in which case Personal Information held by us about our customers and/or users may be one of the transferred assets. In accordance with our legal obligations, we may also process Personal Information, subject to a lawful request, to public authorities for law enforcement or national security purposes. Further we may also disclose Personal Information where otherwise required by local law or regulations."
Privacy Policy › “Personal information we disclose”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Grants permission to share personal information with third parties in connection with a potential or actual corporate sale or asset transfer, and to disclose to public authorities for law enforcement or national security purposes or as required by local law, identifying lawful bases for disclosure outside normal service operations.

AI-generated interpretation, not legal advice.

Common questions about Framer AI's policies

Does Framer AI train its AI models on your data?
Training possible — conditions or opt-outs apply — based on 2 verified findings from Framer AI's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Framer AI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

31 verified clauses

Clauses in Framer AI's policies that work in your favour — commitments the platform made to you.

  • Audit rights, DPA & residency
    The security of your Personal Information is important to us. We therefore aim to safeguard and protect your Personal Information from unauthorized access, improper use or disclosure, unauthorized modification, or unlawful destruction or accidental loss, and w…

    Establishes obligations to safeguard personal information against unauthorized access, improper use or disclosure, unauthorized modification, and unlawful destruction or accidental loss through reasonable processes, syst…

    📍 Privacy Policy › “Security”Jump to exact text →
  • Audit rights, DPA & residency
    As of July 16, 2020, we no longer rely on the Privacy Shield as a transfer mechanism for data transfers given the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield are no longer valid as a result of the CJEU ruling in Schrems II. However, to the extent…

    This segment explains that Privacy Shield is no longer relied upon as a transfer mechanism following the Schrems II ruling, but imposes an ongoing obligation on Framer to honor existing Privacy Shield certification commi…

    📍 Privacy Policy › “Privacy shield”Jump to exact text →
  • Privacy & data usebreach notification promises
    Personal Information Breach: In the case of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information transmitted, stored, or otherwise processed by us about our cus…

    Establishes a mandatory breach notification procedure requiring the company to notify the local supervisory authority without undue delay and within 72 hours of becoming aware of a personal information breach, subject to…

    • Breach notice window: not later than 72 hours after having become aware of it
    • Designated security contact: security page
    📍 Privacy Policy › “Security”Jump to exact text →
  • Privacy & data use
    In addition to the above rights, you have the right to object, on grounds relating to your particular situation, at any time to any processing of your Personal Information which we have justified on the basis of a legitimate interest, including profiling (as o…

    Grants data subjects the right to object to processing of personal information based on legitimate interest (including profiling) or for direct marketing and promotional purposes at any time, constituting the GDPR right…

    📍 Privacy Policy › “Your EU rights”Jump to exact text →
  • Audit rights, DPA & residency
    We are committed to processing personal data in accordance with our obligations as a data “processor” or “subprocessor” under applicable EU data protection laws. If your organization is based in the EU or is otherwise directly or indirectly subject to EU data…

    Establishes an obligation to comply with EU data protection laws as a data processor or subprocessor, including executing Standard Contractual Clauses approved by the European Commission for cross-border transfers, addre…

    📍 Privacy Policy › “Personal information we disclose”Jump to exact text →
  • Audit rights, DPA & residency
    Where Personal Information is transferred outside the European Economic Area to our affiliated companies or to third party service providers, we will take steps to ensure that your Personal Information is protected by the same level of protection as if it rema…

    Framer commits to using Standard Contractual Clauses and GDPR-equivalent contractual protections for international data transfers, which is a strong protective posture under EU law.

    📍 Privacy Policy › “Personal information we disclose”Jump to exact text →

+ 25 more verified clauses of this kind on this platform, cited in full in the report.

📋 Rules you must follow

1 verified clause

What Framer AI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

  • Moderation & enforcementconduct restrictions
    - Adhere to all our worldwide legal obligations.

    Establishes a legal obligation to process personal data as necessary to comply with worldwide legal obligations, grounding data use in legal compliance as a lawful basis.

    📍 Privacy Policy › “Personal information we use”Jump to exact text →

What the policies actually cover

11 topics
  • Product telemetry & usage tracking7 clauses
  • Advertising & tracking2 clauses
  • Sale or sharing of personal data2 protective3 clauses
  • Children's data1 protective1 clause
  • Government & law-enforcement disclosure6 clauses
  • Does not train on your content1 protective1 clause
  • Trains by default, opt-out available1 clause
  • Deletion rights & post-termination survival1 protective2 clauses
  • Human review of your content1 clause
  • Breach-notification promises3 protective3 clauses
  • Conduct restrictions1 obligation1 clause

58 further verified clauses are cited on this page but not yet assigned a topic.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Retention of personal information” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Personal information we Collect automatically when you use our services” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

206
clauses
40
patterns
40
stances
privacy sharing · 23tier conditionality · 5ip license · 3ip ownership · 3training use · 3dispute resolution · 2
data retentionMEDIUMPrivacy Policy › “How long do we keep your personal data?”

The clause allows indefinite, perpetual, or necessity-based retention.

Legal or dispute data – as long as necessary for legal proceedings or compliance.
Open source citation
dispute resolutionMEDIUMPrivacy Policy › “Privacy shield”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit https://www.jamsadr.com/eu-us-privacy-shield for more information or to file a complaint. The services of Jams ADR are provided at no cost to you. If your complaint still remains unresolved, then you have the right to invoke binding arbitration by the Priva...
Open source citation
dispute resolutionMEDIUMPrivacy Policy › “Privacy shield”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Framer has further committed to refer unresolved Privacy Shield complaints to Jams ADR, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit https://www.jamsadr.com/eu-us-privacy-shield for more information or to file a complaint. The se...
Open source citation
ip licenseHIGH§ 4.2

The clause includes sublicensable, transferable, or assignable rights.

Framer does not endorse the Content or any advice, suggestion, or opinion expressed in the Content. 4.3 Although Framer has no obligation to monitor Content, Framer may do so and may remove Content and/or prohibit any use of the Services it believes may be (or alleged to be) in violation of the license and use rights set out in Section 2 of this Agreement. 4.4 License to Display Content​. Customer grants: (a) Fram...
Open source citation
ip licenseHIGH§ 2.4

The clause includes sublicensable, transferable, or assignable rights.

m) assign, sublicense, sell, resell, lease, rent or otherwise transfer or convey, or pledge as security or otherwise encumber, Customer’s rights under Sections 2.1 and 2.2;
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tierscommercial useworsensHIGH2
All applicable tiersdata retentionconditionalMEDIUM1
All applicable tiersgoverning law disputesconditionalMEDIUM3
All applicable tiersprivacy data useworsensHIGH7
All applicable tierssubprocessors data sharingworsensHIGH7
All applicable tierstraining useimprovesLOW1
Enterprisetier differencesconditionalMEDIUM5
Freemoderation enforcementworsensHIGH2
Freeprivacy data useconditionalMEDIUM1
Governmentmoderation enforcementconditionalMEDIUM1
Governmentprivacy data useconditionalMEDIUM1
Standardaudit rights dpa residencyconditionalMEDIUM3

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Aug 10, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

Do Not Sell or Share My Personal Information. If you are a resident of a state with U.S. State Privacy Laws, you may have the right to opt out of the “sale” or “sharing” of your personal information, including the processing of your personal information for purposes of targeted advertising. Targeted advertising is when we or our partners display ads to you based on your personal information that is collected across different businesses. Residents of states with U.S. State Privacy Law states who would like to exercise their right to opt out of the “sale” or “sharing” of their personal information can do so by sending an email to legal@framer.com .
Open timeline citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We only share your personal data with third parties if: This is necessary for the provision of a service or the involvement of the third party. Sub-contractors, for example, will in principle only get access to the personal data that they require for their part of the service provision.
Open timeline citation
Aug 10, 2026model trainingLOW

Latest stance: no training claim on training use

Framer may use automated systems and artificial intelligence (" AI ") tools to support certain internal business operations, including customer support, troubleshooting, product improvement, security monitoring, analytics, and service optimisation. In connection with these activities, personal data submitted to or processed through our Service may be processed by such tools on our behalf and subject to applicable confidentiality, security, and data protection safeguards. We do not use customer personal data to train third-party general-purpose AI models unless expressly disclosed otherwise or permitted in our agreements with customers.
Open timeline citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

This website ( www.framer.com ) (the “ Website ”), is owned and operated by Framer B.V. Framer B.V. provides a platform for designing and publishing interactive websites (the “ Service ”). Framer B.V. is an entity incorporated under the laws of the Netherlands and registered in the Netherlands with the Dutch Chamber of Commerce under registration number 59920637. Framer B.V. has its registered office at Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands. This privacy statement (“ Privacy Statement ”) specifies how Framer B.V. and its affiliates (hereinafter referred to as “ Framer ”, " we ", " us ", " our ") process personal data of its Users in different contexts.
Open timeline citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on moderation enforcement

Authorized government institutions. Such as, courts, police, and law enforcement agencies. We may release information about our Website visitors, including IP address, when legally required to do so, at the request of governmental institutions conducting an investigation or to verify or enforce compliance with the policies governing the Website and applicable laws. We may also disclose such user information whenever we believe disclosure is necessary to protect the rights, property or safety of Framer, or any of our respective business partners, customers or others.
Open timeline citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We may also disclose non-identifying, aggregated user statistics to third parties for a variety of purposes, including describing our Service to prospective partners and other third parties. Examples of such non-personal data include the number of users who visited the Website during a specific time period.
Open timeline citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on commercial use

Framer may transfer personal data to third parties (e.g., our cloud service provider) located outside the EEA. This will involve transferring your data to countries outside the EEA and UK (“ Third Countries ”), including the United States of America (“ U.S. ”), where the servers we use are located. A list of countries to which Framer transfers personal data can be found in Framer’s Trust Center (available at https://trust.framer.com ). Any data transfer shall always take place in compliance with Chapter V of the GDPR and additional recommendation or decision issued in this regard by the European Data Protection Board (“ EDPB ”), European Commission, or other competent authority or body under the applicable laws. If you are a resident of a U.S. state with comprehensive privacy laws, including residents of California., you may have additional rights. Please see section 13 (“Your U.S. State Privacy Rights (California and other U.S. states”) for further details.
Open timeline citation
Aug 10, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

Transfers of your personal data to a country outside the EEA may in the first place be legitimized based on a so-called adequacy decision. This is a decision in which the European Commission states that e.g. a certain country offers a level of data protection similar to the GDPR. The current list of adequacy decisions of the European Commission is available here . An example of transfer of Framer based on an adequacy decision is the transfer of your personal data to the U.S. (insofar as the recipient is certified under the Data Privacy Framework). The transfer of your data from the UK to a third party outside the UK may primarily be legitimized based on an adequacy regulation of the UK government. An overview of the applicable adequacy regulations of the UK government is available here . If we transfer personal data to Third Countries to which no adequacy decision or adequacy regulation applies, we will conclude the applicable version of the model clauses to safeguard data protection as published by the European Commission, so called standard contractual clauses (“ Transfer SCCs ”). If deemed required under the applicable law, additional measures will be taken. This may concern technical, organizational and/or contractual measures. Where the UK GDPR is applicable, a UK Addendum will be added to the Transfer SCCs, as required by UK laws and regulations. Further information on our legitimization of data transfers to Third Countries will be provided upon your request. Please use our contact details to make such a request, as stated below.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-08-10· verified 2026-08-10
  • Terms of Service:Last captured 2026-07-20· verified 2026-06-10verified once — no re-scan in 92 days

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↓ 37 fewer findings this quarter vs last (91 vs 128). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Framer AI's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Framer AI's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Framer AI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.