Greptile
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“Except as otherwise provided in an Order and subject to the other provisions of this Section 2.2, Company may (i) aggregate and anonymize Customer Data ("De-Identified Data") for analytical purposes and to monitor, improve, or expand the Services, Platform or Company's commercial offerings, and/or (ii) use such data to train and improve artificial…”
Watch: indemnity liability
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This clause limits each party's liability by excluding indirect, incidental, special, exemplary, and consequential damages regardless of theory of liability, and caps total aggregate liability at fees actually paid by Customer to Company, restricting the remedies available to either party.
This segment references the Data Processing Agreement as available on request, incorporating it as a related document governing data processing obligations, residency, and compliance rights, and provides contact information for questions about the terms.
Section heading introducing the data security provisions; scopes the security measures and disclaimer of absolute security guarantees that follow.
Scores derived from 28 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Greptile's training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
- Output ownership has conditions — review the commercial use and license carve-outs before building on these outputs.
- Data handling is conditional — 10 privacy or retention clauses warrant review before using Greptile at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Greptile's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 69 verified, verbatim-cited findings below — read the citations.
Based on 82 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 16 citationsstaticLast captured 2026-07-10
- Privacy PolicyVerified - read in full - 32 citationsstaticLast captured 2026-07-10
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This segment permits Company to use third-party cloud service providers (e.g., AWS, Microsoft Azure) to store and process Customer Data, requires Company to make available audit reports from subcontractors upon request, and references a list of subprocessors, establishing the framework for authorized data sharing with cloud subprocessors.
" Company will maintain reasonable and appropriate data safeguards and procedures designed to prevent the unauthorized use or disclosure of Customer Data in Company's possession or control and to comply with the DPA ("Data Safeguards"). Comp..."
Section heading only, carrying no independent legal obligation, right, or restriction.
" Under California Civil Code Section 1798.83, individual customers who reside in California and who have an existing business relationship with us may request information about our disclosure of certain categories of Personal Information to..."
Grants Greptile permission, to the extent permitted by applicable law, to use personal information for service delivery, personalization, payment processing, account maintenance, service optimization, and related business purposes, defining the lawful scope of data processing activities.
" To the extent permitted by applicable law, we use Personal Information: To provide and personalize our Site and Services, such as processing or fulfilling orders and transactions, providing and personalizing our Services, processing payme..."
Identifies specific third-party analytics and session replay subprocessors (including Google Analytics) that collect personal information via cookies, informing users of the entities processing their data and directing them to those parties' privacy policies and opt-out mechanisms, fulfilling transparency obligations regarding subprocessor data sharing.
" We may use analytics and session replay services, that use cookies and other technologies that collect your Personal Information, to assist us with analyzing our Site traffic and site usage to optimize, maintain, and secure our Site and in..."
Describes three specific methods of data collection—directly from users, from third parties (listing categories of third-party sources), and through online tracking technologies—establishing the procedural mechanisms by which Greptile acquires personal information.
" Directly From You – We collect Personal Information that you provide to us directly, for example, if you choose to contact us, request information from us, sign up to receive updates, or otherwise utilize our Site or Services. From Third ..."
This segment disclaims the standard warranty provisions for beta/trial services, limits Customer's remedy to cessation of use, and exempts beta services from the limited warranty in Section 5.2, restricting Customer's rights and Company's liability with respect to pre-release service offerings.
" In consideration for the rights granted, Customer will pay to Company, without offset or deduction, the fees and expenses described in the Order (or otherwise published on the Platform or stated during registration if no Order was executed..."
This segment enumerates specific prohibited actions by Customer and its affiliates, contractors, and users—including reselling, redistributing, or using the platform in ways that threaten its integrity—thereby restricting the permissible scope of commercial use of the platform and services.
" Customer will not (and will not permit any of its affiliates, contractors, or users to): (a) make the Platform, any Services, or any results of the Services available to any third party other than as contemplated by this Agreement or expre..."
Section heading introducing the third-party website links provisions; scopes the liability disclaimer and data handling disclosures regarding external sites that follow.
" If we have an ongoing business purpose for retaining your Personal Information, such as communicating with you about ongoing or prospective Services you requested"
Clause A mandates indemnification for direct intellectual property infringement, implying full coverage, while Clause B imposes a general cap on total liability and excludes certain types of damages, directly conflicting with the scope of indemnification.
" Each Party will indemnify, defend, and hold harmless the other Party for any direct infringement caused by such indemnifying Party's intellectual property provided under this Agreement, including the Platform in the case of Company as the indemnifying Party, and Customer Data in the case of Customer as the indemnifying Party."
" In no event will either Party be liable for any indirect, incidental, special, exemplary, or consequential damages (including without limitation any loss of opportunities, revenue or savings) arising in connection with this Agreement or the use of the Platform or any Services based on any theory of contract, tort, strict liability, negligence, or otherwise, even if advised of the possibility of such damages. Each Party's total liability under this Agreement or relating to the Platform or Services will under no circumstances exceed the fees actually paid by the Customer to Company during the prior twelve (12) months under this Agreement from the last event giving rise to liability (the "Cap"). The foregoing limitations of liability above will not apply to a Party's willful misconduct, unauthorized use or disclosure of the Platform or related intellectual property or information, or indemnification obligations. Company's total aggregate liability relating to its noncompliance with Data Safeguards (including the DPA) or Customer Data shall be limited to 1.5 times the Cap above."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Except as otherwise provided in an Order and subject to the other provisions of this Section 2.2, Company may (i) aggregate and anonymize Customer Data ("De-Identified Data") for analytical purposes and to monitor, improve, or expand the Services, Platform or Company's commercial offerings, and/or (ii) use such data to train and improve artificial intelligence algorithms and models ("AI Training and Learnings"). Company will implement appropriate measures and controls designed to remove personally identifiable information, customer-specific references, and sensitive data from De-Identified Data and AI Training and Learnings. Company will solely and exclusively own the De-Identified Data and AI Training and Learnings (but not the underlying Customer Data). However, if Customer does not desire to permit Company to engage in AI training, Customer may manage preferences and settings related to AI Training and Learnings accordingly within Customer's account on the Platform, and Company will thereafter cease further AI training under this Section 2.2. If you have questions related to opting out of AI training or managing your AI training preferences, please contact Company at security@greptile.com ."
This segment (continuation of 2.2) obligates Company to implement measures to remove PII and sensitive data from De-Identified Data used for AI training and analytics, qualifying the training-use permission with protective procedural requirements.
AI-generated interpretation, not legal advice.
" To manage your preferences with respect to these technologies, you can visit our preferences page, or customize your browser settings to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable certain cookies, please note that some parts of our Site may not function properly. These settings may be lost and require reconfiguration if you delete your cookies. Certain web browsers and other programs may transmit "opt-out" signals, sometimes referred to as Global Privacy Control or Do-Not-Track signals, to websites with which the browser communicates. Please note that we do not have the ability to recognize or honor such signals at this time."
Section heading introducing the data retention provisions; scopes the retention criteria and duration provisions that follow.
AI-generated interpretation, not legal advice.
" To the extent permitted by applicable law, we use Personal Information: To provide and personalize our Site and Services, such as processing or fulfilling orders and transactions, providing and personalizing our Services, processing payments, providing customer service, maintaining or servicing accounts, verifying customer information, creating and maintaining business records, verifying eligibility, and undertaking or providing similar services. To optimize, improve, and maintain our Services, including understanding how users interact with our Services, gauging user interest in certain Services or Site functionality, and troubleshooting problems. For internal research and development, such as testing, verifying, and improving the quality of our Services or developing new ones. For communicating with you, such as responding to your questions and comments or notifying you of changes to our Site or Services. For legal, security, or safety reasons, such as protecting our and our users' safety, property, or rights; complying with legal requirements; enforcing our terms, conditions, and policies; detecting, preventing, and responding to security incidents; and protecting against malicious, deceptive, fraudulent, or illegal activity. As part of a corporate transaction, such as in connection with the sale of part or all of our assets or business, the acquisition of part or all of another business or another business' assets, or another corporate transaction, including bankruptcy. "
Grants Greptile permission, to the extent permitted by applicable law, to use personal information for service delivery, personalization, payment processing, account maintenance, service optimization, and related business purposes, defining the lawful scope of data processing activities.
AI-generated interpretation, not legal advice.
" Communication Information – We may collect Personal Information contained within your communications with us via email, social media, telephone, or otherwise, and in certain cases we may use third-party service providers to do so. Where permitted by applicable law, we may collect and maintain records of calls and chats with our agents, representatives, or employees via message, chat, post, or similar functionality. Financial Information – If you use our Services, we may collect financial information such as credit card details via our third-party payment processor to facilitate online payments."
Describes Greptile's practice of collecting communication information and financial information via third-party payment processors, imposing a disclosure obligation to inform users of the categories and methods of personal data collection including call recording where permitted by law.
AI-generated interpretation, not legal advice.
" We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Site. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. We process the information collected through such technologies, which may include or be combined with Personal Information, to help operate certain features of our Site, to enhance your experience through personalization, and to help us better understand the features of our Site that you and other users are most interested in."
Describes the technical mechanisms (cookies, web beacons) used by Greptile and service providers to collect usage and browser data, and explains how that data is processed—including combination with personal information—to operate site features, personalize experience, and analyze usage patterns.
AI-generated interpretation, not legal advice.
" We collect several categories of Personal Information from and about users of our Site and Services. "Personal Information" means information that uniquely identifies, relates to, describes, or is reasonably capable of being associated with or linked to you. Under some privacy laws, Personal information may be referred to as "personal data." The categories of Personal Information we collect may include: Contact Information – If you submit an inquiry, register for an account, or provide information on or through our Site or Services, we may collect your contact information, including your name, mailing address, email address, and phone number. Commercial Information – If you submit an inquiry, or provide information on our Site, we may collect commercial information including information about your purchases, subscriptions, and Services you have shown interest in. Usage Information – When you use our Site, we may automatically record information, including your Internet Protocol address ("IP Address"), geolocation of your device, browser type, referring URLs (e.g., the website you visited before coming to our Site), domain names associated with your internet service provider, and any other information regarding your interaction with our Site. Employment Information – If you apply for employment with us, we may collect Personal Information related to your potential employment, including your education and employment history, address and contact information, demographic information, and any other information included in your resume or application. "
Defines 'Personal Information' as information that identifies, relates to, or is linkable to an individual, and enumerates the categories collected including contact and financial information, establishing the foundational data scope for all collection, use, and sharing obligations in the policy.
AI-generated interpretation, not legal advice.
" Directly From You – We collect Personal Information that you provide to us directly, for example, if you choose to contact us, request information from us, sign up to receive updates, or otherwise utilize our Site or Services. From Third Parties – We may collect Personal Information from third parties, including but not limited to business partners, advertising networks, social networks, data analytics providers, mobile device providers, Internet or mobile service providers, recruiters and job application portals, and background check providers. Through Online Tracking Technologies – We use cookies and similar technologies to collect Personal Information automatically as you navigate our Site. For additional information regarding our use of these technologies, see the Cookies and Other Tracking Technologies section below."
Describes three specific methods of data collection—directly from users, from third parties (listing categories of third-party sources), and through online tracking technologies—establishing the procedural mechanisms by which Greptile acquires personal information.
AI-generated interpretation, not legal advice.
" Please note that we may modify or update this Notice from time to time, so please review it periodically. If we make material changes to how we treat Personal Information, we will notify you according to applicable law. Unless otherwise indicated, any changes to this Notice will apply immediately upon posting to our Site. You are responsible for periodically visiting our Site and this Notice to check for any changes."
Section heading only, carrying no independent legal obligation, right, or restriction.
AI-generated interpretation, not legal advice.
" To comply with our legal obligations, resolve disputes, and enforce any agreements Criteria we will use to determine how long to retain your Personal Information include:"
Identifies the nature and length of the business relationship as a criterion used to determine how long personal information is retained, establishing a procedural factor in the retention decision-making framework.
AI-generated interpretation, not legal advice.
" If you are visiting our Site from outside of the United States, please note that our Site is hosted in the United States. Where permitted by applicable law, we may transfer the Personal Information we collect about you to the United States and other jurisdictions that may not be deemed to provide the same level of data protection as your home country, as necessary for the purposes set out in this Notice. For individuals in the European Union, European Economic Area, Switzerland, and United Kingdom: Greptile will transfer Personal Information to third parties located outside of this region only when it has ensured appropriate safeguards for such Personal Information through use of the standard contractual clauses or other lawful and approved methods."
Section heading introducing the data security provisions; scopes the security measures and disclaimer of absolute security guarantees that follow.
AI-generated interpretation, not legal advice.
" In no event will either Party be liable for any indirect, incidental, special, exemplary, or consequential damages (including without limitation any loss of opportunities, revenue or savings) arising in connection with this Agreement or the use of the Platform or any Services based on any theory of contract, tort, strict liability, negligence, or otherwise, even if advised of the possibility of such damages. Each Party's total liability under this Agreement or relating to the Platform or Services will under no circumstances exceed the fees actually paid by the Customer to Company during the prior twelve (12) months under this Agreement from the last event giving rise to liability (the "Cap"). The foregoing limitations of liability above will not apply to a Party's willful misconduct, unauthorized use or disclosure of the Platform or related intellectual property or information, or indemnification obligations. Company's total aggregate liability relating to its noncompliance with Data Safeguards (including the DPA) or Customer Data shall be limited to 1.5 times the Cap above."
This clause limits each party's liability by excluding indirect, incidental, special, exemplary, and consequential damages regardless of theory of liability, and caps total aggregate liability at fees actually paid by Customer to Company, restricting the remedies available to either party.
AI-generated interpretation, not legal advice.
" Subject to the other provisions of this Agreement, Company will make available to Customer on a non-exclusive and non-transferable basis access and use of the Subscription Services identified in an Order in accordance with Company's then current published documentation for the Subscription Services solely for Customer's internal purposes and any limitations or restrictions in this Agreement, including the applicable Orders."
This segment grants Customer a non-exclusive, non-transferable right to access and use the Subscription Services identified in an Order solely for Customer's internal purposes, thereby defining the permitted scope and conditions of commercial use of the platform.
AI-generated interpretation, not legal advice.
" To fulfill any other purpose for which you provide it, including purposes described when you provide the information or give your consent. If you are applying for employment with us, we may also use Personal Information to process your job application, to verify the information you have provided in your application, conduct interviews, perform background and reference checks, to communicate with you and answer your questions, to confirm your eligibility for employment, and improve our recruiting processes. We may also save your Personal Information for future employment opportunities with us."
Permits Greptile to use personal information for any purpose disclosed at the time of collection or consented to by the user, and specifically authorizes use of personal information for employment application processing, background checks, and retention for future job opportunities, broadening the permissible scope of processing.
AI-generated interpretation, not legal advice.
" We may use analytics and session replay services, that use cookies and other technologies that collect your Personal Information, to assist us with analyzing our Site traffic and site usage to optimize, maintain, and secure our Site and inform subsequent business decisions (including, e.g., advertising). These include, but are not limited to, the following third-party services: Google Analytics: To learn more about how Google uses data, visit Google's Privacy Policy and Google's page on "How Google uses data from sites or apps that use our services." You may download the Google Analytics Opt-out Browser Add-on for each web browser you use, but this does not prevent the use of other analytics tools. To learn more about Google Analytics cookies, visit Google Analytics Cookie Usage on Websites."
Identifies specific third-party analytics and session replay subprocessors (including Google Analytics) that collect personal information via cookies, informing users of the entities processing their data and directing them to those parties' privacy policies and opt-out mechanisms, fulfilling transparency obligations regarding subprocessor data sharing.
AI-generated interpretation, not legal advice.
" In consideration for the rights granted, Customer will pay to Company, without offset or deduction, the fees and expenses described in the Order (or otherwise published on the Platform or stated during registration if no Order was executed). Excess use beyond that set out in an Order (or published on the Platform or stated during registration if no Order was executed) will be subject to additional fees. Unless otherwise provided, all fees will be due and payable within thirty (30) calendar days after an invoice is issued by Company, and subscription fees may be invoiced in advance. Fees may increase annually or on each renewal term, but Company will provide notification of such increase at least thirty (30) days in advance; notification may occur on the Platform or through an invoice. The fees and other amounts payable by Customer to Company do not include any taxes of any jurisdiction that may be assessed or imposed upon the Services, excluding only taxes based upon Company's net income. Customer will directly pay any such taxes assessed. Customer will promptly reimburse Company for any taxes payable or collectable by Company (other than taxes based upon Company's net income). All fees and other amounts paid or payable by Customer under this Agreement are non-refundable and non-cancellable, except as otherwise expressly provided. In the event that Customer's account is overdue, Company will have the right, in addition to its remedies under this Agreement or pursuant to applicable law, to suspend Customer's access to or use of the Services, without further notice to Customer, until Customer has paid the full balance owed, plus any interest due at the rate of 18% per annum."
This segment disclaims the standard warranty provisions for beta/trial services, limits Customer's remedy to cessation of use, and exempts beta services from the limited warranty in Section 5.2, restricting Customer's rights and Company's liability with respect to pre-release service offerings.
AI-generated interpretation, not legal advice.
" If we have an ongoing business purpose for retaining your Personal Information, such as communicating with you about ongoing or prospective Services you requested"
Section heading introducing the third-party website links provisions; scopes the liability disclaimer and data handling disclosures regarding external sites that follow.
AI-generated interpretation, not legal advice.
" We have implemented commercially reasonable measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure. Unfortunately, the transmission of information via the internet is not completely secure. Despite these efforts to process your Personal Information in a secure environment, we cannot guarantee the security of Personal Information during its transmission or its storage on our systems."
Section heading introducing the user privacy rights provisions; scopes the rights and procedures for exercising those rights described in subsequent segments.
AI-generated interpretation, not legal advice.
" Company agrees to provide the Services and other related obligations in accordance with this Agreement, including related Orders and the DPA. The Services are designed and intended to facilitate understanding and reviewing Customer's codebase and development practices and may include artificial intelligence and machine learning technologies or chatbots ("AI" and "ML"). The Services may include recommendations and analysis generated through AI and ML, which may rely on statistics, probabilities, and data that may not be accurate, up-to-date, appropriate, or reliable. All decisions based on the Services are solely the Customer's, and Customer should not fully rely on the Services as accurate or complete. Customer will (a) be responsible for connecting to and using the Platform made available to it in accordance with this Agreement, (b) cooperate with Company to facilitate the provision of the Services, (c) use commercially reasonable efforts to prevent unauthorized access to or use of the Platform and notify Company promptly of any such unauthorized access or use, and (d) use the Services only in accordance with this Agreement and applicable laws and regulations."
This segment disclaims accuracy and reliability of AI/ML-generated recommendations and analysis, states that decisions based on the services remain the customer's responsibility, and incorporates the DPA, establishing that AI outputs may be unreliable and limiting Company's accountability for AI-generated content.
AI-generated interpretation, not legal advice.
Common questions about Greptile's policies
- Does Greptile train its AI models on your data?
- Training possible — conditions or opt-outs apply — based on 1 verified finding from Greptile's published policy. Informational only, not legal advice.
- Can you use Greptile's output commercially?
- Commercial use allowed — with conditions — based on 1 verified finding from Greptile's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Greptile's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
10 verified clausesClauses in Greptile's policies that work in your favour — commitments the platform made to you.
- Governing law & disputes
“The relationship between the Parties under this Agreement is that of independent contractors and not partners, joint venturers or agents. Customer may not assign this Agreement or its rights without the prior written approval of Company. This Agreement states…”
This clause establishes the independent contractor relationship, restricts Customer from assigning the Agreement without Company's prior written approval, affirms the Agreement as the entire understanding superseding pri…
- Terms changes: advance notice promised
- Auto-renew cancel window: 90 days before term end
📍 § 7 (Miscellaneous)Jump to exact text → - Privacy & data use
“To exercise any of the privacy rights afforded to you under applicable data protection laws, email us at support@greptile.com or call us at (866) 514-0605. You will not be discriminated against in any way by virtue of your exercise of the rights listed in thi…”
Establishes the procedure for exercising data subject privacy rights including contact details, non-discrimination assurance, consequences of withdrawal of consent, and authorization requirements for agents making reques…
- Designated security contact: support@greptile.com / (866) 514-0605
📍 Privacy Policy › “Exercising Your Privacy Rights”Jump to exact text → - Privacy & data usesale/sharing of personal data
“Depending on where you live, you may have the following rights with respect to your Personal Information under applicable data protection laws, each subject to certain exceptions: Access – The right to request access to and obtain a copy of any Personal Infor…”
Enumerates data subject rights (access, deletion, correction, objection/restriction of processing) granted to individuals under applicable data protection laws, each constituting a legally operative entitlement against t…
📍 Privacy Policy › “Exercising Your Privacy Rights”Jump to exact text → - Indemnity & liability
“Certain items of software code, data, or content provided with, or needed to access or use, the Services or Platform may be subject to "open source," "free software," "creative common" or similar licenses ("Third Party Material"), a list of which is available…”
This segment defines Third Party Materials (open source and similar licensed code/content), specifies they are not governed by the main Agreement terms (except limited carve-outs), and incorporates the separate license t…
📍 § 1.6 (Third Party Materials)Jump to exact text → - Prompt ownership
“Customer acknowledges and understands that use of the Services will permit or require Customer to provide certain Customer data, such as content, materials, and other information to Company (collectively, "Customer Data") for purposes of analysis relating to t…”
This segment defines Customer Data, designates it as proprietary to Customer, restricts Company's use of Customer Data solely to performing the Services or as authorized, and obligates Customer to obtain required third-p…
📍 § 2.1 (General)Jump to exact text → - Privacy & data usechildren's data
“We do not knowingly collect or solicit any Personal Information from children, as defined under applicable law, without verified written parental consent, and we have no actual knowledge of selling such Personal Information of minors under 16 years of age. If…”
Restricts collection of Personal Information from children without verified parental consent, prohibits knowing sale of minors' data under 16, and imposes an obligation to promptly delete any inadvertently collected chil…
- Designated security contact: support@greptile.com
📍 Privacy Policy › “Children's Privacy”Jump to exact text →
+ 4 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
1 verified clauseWhat Greptile requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcementconduct restrictions
“Customer will not (and will not permit any of its affiliates, contractors, or users to): (a) make the Platform, any Services, or any results of the Services available to any third party other than as contemplated by this Agreement or expressly authorized in wr…”
This segment enumerates specific prohibited actions by Customer and its affiliates, contractors, and users—including reselling, redistributing, or using the platform in ways that threaten its integrity—thereby restrictin…
📍 § 1.4 (Restrictions)Jump to exact text →
What the policies actually cover
15 topics- Product telemetry & usage tracking1 clause
- Advertising & tracking3 clauses
- Sale or sharing of personal data1 protective2 clauses
- Sensitive data (biometric, location, health)1 protective3 clauses
- Children's data1 protective1 clause
- Government & law-enforcement disclosure1 clause
- Data shared with other AI providers1 clause
- Trains by default, opt-out available1 clause
- Damages & liability cap2 clauses
- Indemnity direction1 protective1 clause
- Terms can change at any time2 clauses
- Deletion rights & post-termination survival1 clause
- Auto-renewal & cancel window1 clause
- Breach-notification promises1 clause
- Conduct restrictions1 obligation1 clause
26 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Fulfill the purposes outlined in this Notice” addresses how long content is retained, and the Terms of Service, § 2.2 (De-Identified Data and AI Training) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits commercial or business use.
“Company represents and warrants to Customer that: (a) to the best of Company's knowledge, it has sufficient rights to grant the subscriptions and licenses described in this Agreement, and it has obtained any required authorizations and consents from applicable individuals and organizations to provide such subscriptions and licenses, and (b) the Platform will perform substantially in accordance with the Compan...”Open source citation
The clause permits commercial or business use.
“Company represents and warrants to Customer that: (a) to the best of Company's knowledge, it has sufficient rights to grant the subscriptions and licenses described in this Agreement, and it has obtained any required authorizations and consents from applicable individuals and organizations to provide such subscriptions and licenses, and (b) the Platform will perform substantially in accordance with the Compan...”Open source citation
The clause includes sublicensable, transferable, or assignable rights.
“Subject to the other provisions of this Agreement, Company will make available to Customer on a non-exclusive and non-transferable basis access and use of the Subscription Services identified in an Order in accordance with Company's then current published documentation for the Subscription Services solely for Customer's internal purposes and any limitations or restrictions in this Agreement, including th...”Open source citation
The clause includes sublicensable, transferable, or assignable rights.
“Subject to the other provisions of this Agreement, Company will make available to Customer on a non-exclusive and non-transferable basis access and use of the Subscription Services identified in an Order in accordance with Company's then current published documentation for the Subscription Services solely for Customer's internal purposes and any limitations or restrictions in this Agreement, including th...”Open source citation
The clause includes sublicensable, transferable, or assignable rights.
“Subject to the other provisions of this Agreement, Company will make available to Customer on a non-exclusive and non-transferable basis access and use of the Subscription Services identified in an Order in accordance with Company's then current published documentation for the Subscription Services solely for Customer's internal purposes and any limitations or restrictions in this Agreement, including th...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | audit rights dpa residency | conditional | MEDIUM | 1 |
| All applicable tiers | commercial use | worsens | HIGH | 2 |
| All applicable tiers | data retention | worsens | HIGH | 2 |
| All applicable tiers | indemnity liability | conditional | MEDIUM | 2 |
| All applicable tiers | privacy data use | worsens | HIGH | 15 |
| All applicable tiers | training use | worsens | HIGH | 2 |
| Pro / Paid | commercial use | improves | LOW | 2 |
| Standard | privacy data use | conditional | MEDIUM | 1 |
| Team / Business | privacy data use | conditional | MEDIUM | 3 |
| Team / Business | subprocessors data sharing | conditional | MEDIUM | 5 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing worsened from medium/third party or vendor sharing to high/sale or sell.
“Company may use nationally recognized third party cloud service providers, such as Amazon Web Services or Microsoft Azure, to store and process Customer Data in accordance with industry standards. Upon Customer's reasonable request, Company will make available to Customer any audits reports or certifications that its subcontractor(s) providing hosting services generally make available to Company and its Customer's, subject to Customer's agreement to comply with any confidentiality or other terms or conditions required by such subcontractor or its auditors. A list of subprocessors is available at greptile.com/security/subprocessors .”Before citation
“Depending on where you live, you may have the following rights with respect to your Personal Information under applicable data protection laws, each subject to certain exceptions: Access – The right to request access to and obtain a copy of any Personal Information we may have about you. Deletion – The right to delete your Personal Information that we have collected or obtained. Correction – The right to request that we correct any inaccuracies in your Personal Information. Objection/Restriction of Processing – The right to object or restrict us from processing your Personal Information in certain circumstances. Withdraw Consent – The right to withdraw your consent where we are relying on your consent to process your Personal Information. Lodge a Complaint – The right to lodge a complaint with a supervisory authority or other regulatory agency if you believe we have violated any of the rights afforded to you under applicable data protection laws. We encourage you to first reach out to us so we have an opportunity to address your concerns directly before you do so. We do not (1) sell your Personal Information; (2) disclose your Personal Information to third parties for targeted or cross-context behavioral advertising; (3) use Personal Information for profiling or automated decision-making; or (4) use sensitive Personal Information outside of purposes permitted by law. We do not, therefore, recognize requests to opt out of these uses of Personal Information.”After citation
data sharing improved from high/sale or sell to medium/third party or vendor sharing.
“Depending on where you live, you may have the following rights with respect to your Personal Information under applicable data protection laws, each subject to certain exceptions: Access – The right to request access to and obtain a copy of any Personal Information we may have about you. Deletion – The right to delete your Personal Information that we have collected or obtained. Correction – The right to request that we correct any inaccuracies in your Personal Information. Objection/Restriction of Processing – The right to object or restrict us from processing your Personal Information in certain circumstances. Withdraw Consent – The right to withdraw your consent where we are relying on your consent to process your Personal Information. Lodge a Complaint – The right to lodge a complaint with a supervisory authority or other regulatory agency if you believe we have violated any of the rights afforded to you under applicable data protection laws. We encourage you to first reach out to us so we have an opportunity to address your concerns directly before you do so. We do not (1) sell your Personal Information; (2) disclose your Personal Information to third parties for targeted or cross-context behavioral advertising; (3) use Personal Information for profiling or automated decision-making; or (4) use sensitive Personal Information outside of purposes permitted by law. We do not, therefore, recognize requests to opt out of these uses of Personal Information.”Before citation
“Company may use nationally recognized third party cloud service providers, such as Amazon Web Services or Microsoft Azure, to store and process Customer Data in accordance with industry standards. Upon Customer's reasonable request, Company will make available to Customer any audits reports or certifications that its subcontractor(s) providing hosting services generally make available to Company and its Customer's, subject to Customer's agreement to comply with any confidentiality or other terms or conditions required by such subcontractor or its auditors. A list of subprocessors is available at greptile.com/security/subprocessors .”After citation
data sharing worsened from medium/third party or vendor sharing to high/sale or sell.
“Company may use nationally recognized third party cloud service providers, such as Amazon Web Services or Microsoft Azure, to store and process Customer Data in accordance with industry standards. Upon Customer's reasonable request, Company will make available to Customer any audits reports or certifications that its subcontractor(s) providing hosting services generally make available to Company and its Customer's, subject to Customer's agreement to comply with any confidentiality or other terms or conditions required by such subcontractor or its auditors. A list of subprocessors is available at greptile.com/security/subprocessors .”Before citation
“Depending on where you live, you may have the following rights with respect to your Personal Information under applicable data protection laws, each subject to certain exceptions: Access – The right to request access to and obtain a copy of any Personal Information we may have about you. Deletion – The right to delete your Personal Information that we have collected or obtained. Correction – The right to request that we correct any inaccuracies in your Personal Information. Objection/Restriction of Processing – The right to object or restrict us from processing your Personal Information in certain circumstances. Withdraw Consent – The right to withdraw your consent where we are relying on your consent to process your Personal Information. Lodge a Complaint – The right to lodge a complaint with a supervisory authority or other regulatory agency if you believe we have violated any of the rights afforded to you under applicable data protection laws. We encourage you to first reach out to us so we have an opportunity to address your concerns directly before you do so. We do not (1) sell your Personal Information; (2) disclose your Personal Information to third parties for targeted or cross-context behavioral advertising; (3) use Personal Information for profiling or automated decision-making; or (4) use sensitive Personal Information outside of purposes permitted by law. We do not, therefore, recognize requests to opt out of these uses of Personal Information.”After citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Under California Civil Code Section 1798.83, individual customers who reside in California and who have an existing business relationship with us may request information about our disclosure of certain categories of Personal Information to third parties for the third parties' direct marketing purposes, if any. To make such a request, please contact us at support@greptile.com . Please be aware that not all information sharing is covered by these California privacy rights requirements and only information on covered sharing will be included in our response. This request may be made no more than once per calendar year.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We may disclose de-identified and/or aggregated information about our users without restriction. We may disclose your Personal Information with your consent or in the following circumstances: Employees and Other Personnel – We may share Personal Information with our employees and personnel (such as contractors) who have a need to know the information for our business purposes. Affiliates and Subsidiaries – We may share Personal Information within our family of companies for their and our business and marketing purposes, including providing you with information about the Services we think may be of interest to you. Service Providers – We disclose your Personal Information with the service providers that we use to support our business, including but not limited to, data analytics providers, website hosting providers, and other technology providers. If you are applying for a job with us, this may include service providers such as background check providers and human resource providers. Business Partners – We may disclose Personal Information with trusted business partners. For example, we may disclose your Personal Information with a company whose products or services we think may be of interest to you or who we co-sponsor a promotion or service with. Legal Obligation or Safety Reasons – We may disclose Personal Information to a third party when we have a good faith belief that such disclosure of Personal Information is reasonably necessary to: (a) satisfy or comply with any requirement of law, regulation, legal process, or enforceable governmental request; (b) enforce or investigate a potential violation of any agreement you have with us; (c) detect, prevent, or otherwise respond to fraud, security or technical concerns; (d) support auditing and compliance”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Merger or Change of Control – We may disclose Personal Information to third parties as necessary if we are involved in a merger, acquisition, or any other transaction involving a change of control in our business, including but not limited to, a bankruptcy or similar proceeding. Where legally required, we will give you notice prior to such disclosure. Other – We may disclose Personal Information to third parties when explicitly requested by or consented to by you, or for the purposes for which you disclosed the Personal Information to us as indicated at the time and point of the disclosure (or as was obvious at the time and point of disclosure).”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Site. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. We process the information collected through such technologies, which may include or be combined with Personal Information, to help operate certain features of our Site, to enhance your experience through personalization, and to help us better understand the features of our Site that you and other users are most interested in.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-07-10· verified 2026-07-10
- Privacy Policy:Last captured 2026-07-10· verified 2026-07-10
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 134 more findings this quarter vs last (181 vs 47). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Greptile's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Greptile's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.