Happenstance
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Defines 'sell' and 'sale' to encompass broad forms of transferring personal information for valuable consideration, then clarifies that the company does not sell personal information as the term is commonly understood while permitting Service Providers to use personal information under specified conditions — a partially protective disclosure limiting the scope of sale.
Grants the user the right to correct inaccurate personal information and obligates the company to use commercially reasonable efforts to correct the information and direct service providers to do the same, subject to exceptions.
Grants California residents with an established business relationship the right to request information once a year about sharing of their Personal Data with third parties for direct marketing purposes, and provides the mechanism to exercise that right via contact information.
How to read this page: Overall risk rates what Happenstance's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 147 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 147 citationsstaticLast captured 2026-08-05
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Segment defines 'Business' for purposes of a specific consumer-privacy statute as the company that collects consumers' personal information and determines the purposes and means of its processing; this definition is operative because it establishes the company's legal role and responsibilities with respect to personal data use.
" • Business , for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, or on behalf of ..."
Permits the company to use and transfer personal data in connection with mergers, acquisitions, asset sales, restructuring, bankruptcy, or similar proceedings, authorising data use for corporate transaction purposes.
" • For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part o..."
Identifies publicly available information from government records as excluded from the definition of personal information, creating an exception to the policy's personal information obligations.
" • Publicly available information from government records"
Grants the operator permission to use or disclose collected personal information for business or commercial purposes, listing illustrative examples of such uses.
" We may use or disclose personal information We collect for "business purposes" or "commercial purposes" (as defined under the CCPA/CPRA), which may include the following examples:"
Declares that the company may use or disclose, and may have used or disclosed in the prior twelve months, specified categories of personal information for business or commercial purposes, creating a disclosure obligation regarding the scope of data use practices.
" We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:"
Defines 'sell' and 'sale' to encompass broad forms of transferring personal information for valuable consideration, then clarifies that the company does not sell personal information as the term is commonly understood while permitting Service Providers to use personal information under specified conditions — a partially protective disclosure limiting the scope of sale.
" As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's person..."
Grants users the right to request disclosure of the company's collection, use, sale, and sharing practices, and obligates the company to confirm and respond to such requests by disclosing the specified information — a user-favorable access right with a corresponding company obligation.
" • The right to know/access. Under CCPA/CPRA, You have the right to request that We disclose information to You about Our collection, use, sale, disclosure for business purposes and share of personal information. Once We receive and confirm..."
Specifies that upon a confirmed access request the company will disclose its business or commercial purposes for collecting or selling personal information, detailing the scope of the right to know.
" - Our business or commercial purposes for collecting or selling that personal information"
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the Business to a third party for valuable consideration. This means that We may have received some kind of benefit in return for sharing personal information, but not necessarily a monetary benefit. We do not sell personal information as the term sell is commonly understood. We do allow Service Providers to use Your personal information for the business purposes described in Our Privacy Policy, for activities such as advertising, marketing, and analytics, and these may be deemed a sale under CCPA/CPRA. We may sell and may have sold (as deemed by CCPA/CPRA; not necessarily monetary benefit) in the last twelve (12) months the following categories of personal information:"
Defines 'sell' and 'sale' to encompass broad forms of transferring personal information for valuable consideration, then clarifies that the company does not sell personal information as the term is commonly understood while permitting Service Providers to use personal information under specified conditions — a partially protective disclosure limiting the scope of sale.
AI-generated interpretation, not legal advice.
" • The right to correct Personal Data. You have the right to correct or rectify any inaccurate personal information about You that We collected. Once We receive and confirm Your request, We will use commercially reasonable efforts to correct (and direct our Service Providers to correct) Your personal information, unless an exception applies."
Grants the user the right to correct inaccurate personal information and obligates the company to use commercially reasonable efforts to correct the information and direct service providers to do the same, subject to exceptions.
AI-generated interpretation, not legal advice.
" Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes. If you'd like to request more information under the California Shine the Light law, and if You are a California resident, You can contact Us using the contact information provided below."
Grants California residents with an established business relationship the right to request information once a year about sharing of their Personal Data with third parties for direct marketing purposes, and provides the mechanism to exercise that right via contact information.
AI-generated interpretation, not legal advice.
" • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purposes of the GDPR, Service Providers are considered Data Processors."
Segment defines 'Service Provider' as any natural or legal person who processes data on behalf of the Company, including third-party companies or individuals facilitating or providing the Service or assisting in analysis of Service use, and designates them as Data Processors under GDPR; this definition is operative as it scopes who qualifies as a subprocessor/data-sharing party under the policy.
AI-generated interpretation, not legal advice.
" • With Service Providers: We may share Your personal information with Service Providers to monitor and analyze the use of our Service, for payment processing, or to contact You."
Permits the company to share personal information with service providers for service monitoring, analytics, payment processing, and user contact, authorising disclosure to third-party subprocessors for defined purposes.
AI-generated interpretation, not legal advice.
" • With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us."
Permits sharing of personal information with affiliates (parent company, subsidiaries, joint ventures, and entities under common control), subject to an obligation that those affiliates comply with this Privacy Policy.
AI-generated interpretation, not legal advice.
" • With business partners: We may share Your information with Our business partners to offer You certain products, services or promotions."
Permits the company to share personal information with business partners to offer products, services, or promotions to users, authorising disclosure to commercial third parties.
AI-generated interpretation, not legal advice.
" We may share, and have shared in the last twelve (12) months, Your personal information identified in the above categories with the following categories of third parties:"
Declares that the company may share, and has shared in the prior twelve months, personal information from the above categories with specified categories of third parties, constituting a disclosure of data-sharing practices.
AI-generated interpretation, not legal advice.
" • Third party vendors to whom You or Your agents authorize Us to disclose Your personal information in connection with products or services We provide to You"
Identifies user-authorized third-party vendors as one category of third parties with whom personal information may be shared in connection with products or services, functioning as a definitional enumeration of authorized recipients.
AI-generated interpretation, not legal advice.
" • Limited Purpose: We use Gmail Headers, Calendar Data, and Contacts Data solely to provide or improve user-facing features you request (for example: showing calendar insights, syncing contacts, or providing email intelligence based on header metadata). We do not sell or use this data for determining credit-worthiness, lending purposes, or serving ads, including retargeting, personalized, or interest-based advertising."
Restricts human access to Gmail Headers to three narrow circumstances: explicit affirmative user agreement for specific items, security or legal compliance necessity, or aggregated and anonymized internal operations — user-favorable restriction on human review of personal data.
AI-generated interpretation, not legal advice.
" We do not knowingly collect personal information from minors under the age of 16 through our Service, although certain third party websites that we link to may do so. These third-party websites have their own terms of use and privacy policies and We encourage parents and legal guardians to monitor their children's Internet usage and instruct their children to never provide information on other websites without their permission. We do not sell the personal information of Consumers We actually know are less than 16 years of age, unless We receive affirmative authorization (the "right to opt-in") from either the Consumer who is between 13 and 16 years of age, or the parent or guardian of a Consumer less than 13 years of age. Consumers who opt-in to the sale of personal information may opt-out of future sales at any time. To exercise the right to opt-out, You (or Your authorized representative) may submit a request to Us by contacting Us. If You have reason to believe that a child under the age of 13 (or 16) has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information."
Restricts the company from knowingly collecting personal information from minors under 16 via the Service, and restricts the sale of personal information of consumers known to be under 16 unless affirmative authorization (opt-in) is received — user-protective restriction on data collection and sale involving minors.
AI-generated interpretation, not legal advice.
"• Calendar Data means event information you connect from Google Calendar."
Restricts the use of Gmail Headers, Calendar Data, and Contacts Data solely to providing or improving user-facing features requested by the user, and prohibits their sale or use for determining credit-worthiness, lending purposes, or serving advertisements including retargeting and interest-based advertising — user-favorable restriction on data use.
AI-generated interpretation, not legal advice.
" • Publicly available information from government records"
Identifies publicly available information from government records as excluded from the definition of personal information, creating an exception to the policy's personal information obligations.
AI-generated interpretation, not legal advice.
" • De-identified or aggregated consumer information"
Identifies de-identified or aggregated consumer information as excluded from the definition of personal information, creating an exception to the policy's personal information obligations.
AI-generated interpretation, not legal advice.
" • Information excluded from the CCPA/CPRA's scope, such as (a) Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data, and (b) Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994."
Identifies categories of information excluded from the policy's personal information scope, including health/medical information and information governed by certain sector-specific laws, thereby defining the outer boundary of the policy's data obligations.
AI-generated interpretation, not legal advice.
" • The right to say no to the sale or sharing of Personal Data (opt-out). You have the right to direct Us to not sell Your personal information. To submit an opt-out request, please see the "Do Not Sell My Personal Information" section or contact Us."
Grants the user the right to opt out of the sale or sharing of their personal information and directs them to a specific section for submitting such a request.
AI-generated interpretation, not legal advice.
" - Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties"
Prohibits the company from charging different prices or rates, or applying discounts, benefits, or penalties, as a form of discrimination for exercising consumer privacy rights.
AI-generated interpretation, not legal advice.
" - Providing a different level or quality of goods or services to You"
Prohibits the company from providing a different level or quality of goods or services as a form of discrimination for exercising consumer privacy rights.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Happenstance's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Happenstance's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Happenstance's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Happenstance requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Happenstance's published policies yet.
What the policies actually cover
0 topicsNone of Happenstance's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Retention of Your Personal Data” describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Your Rights under the CCPA/CPRA” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause requires defense, indemnity, or hold-harmless obligations.
“• Protect and defend the rights or property of the Company”Open source citation
The clause permits sale of personal data or information.
“• Limited Purpose: We use Gmail Headers, Calendar Data, and Contacts Data solely to provide or improve user-facing features you request (for example: showing calendar insights, syncing contacts, or providing email intelligence based on header metadata). We do not sell or use this data for determining credit-worthiness, lending purposes, or serving ads, including retargeting, personalized, or interest-based adverti...”Open source citation
The clause permits sale of personal data or information.
“As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the Business to a third party for valuable consideration. This means that We may have received some kind of benefit in return for sharing personal informat...”Open source citation
The clause permits sale of personal data or information.
“Please note that the categories listed above are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact sold, but reflects our good faith belief to the best of Our knowledge that some of that information from the applicable category may be and may have been shared for value in return.”Open source citation
The clause permits sale of personal data or information.
“We do not knowingly collect personal information from minors under the age of 16 through our Service, although certain third party websites that we link to may do so. These third-party websites have their own terms of use and privacy policies and We encourage parents and legal guardians to monitor their children's Internet usage and instruct their children to never provide information on other websites withou...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | conditional | MEDIUM | 1 |
| All applicable tiers | data retention | worsens | HIGH | 4 |
| All applicable tiers | indemnity liability | conditional | MEDIUM | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 17 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 7 |
| Team / Business | privacy data use | worsens | HIGH | 12 |
| Team / Business | subprocessors data sharing | conditional | MEDIUM | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing worsened from medium/third party or vendor sharing to high/sale or sell.
“• Third-Party Transfers: We transfer Gmail Headers, Calendar Data, and Contacts Data to third parties only as necessary to provide or improve user-facing features (for example, hosting or processing by Our Service Providers) and as required to comply with applicable law. Such recipients are bound by obligations consistent with this Privacy Policy.”Before citation
“We do not knowingly collect personal information from minors under the age of 16 through our Service, although certain third party websites that we link to may do so. These third-party websites have their own terms of use and privacy policies and We encourage parents and legal guardians to monitor their children's Internet usage and instruct their children to never provide information on other websites without their permission. We do not sell the personal information of Consumers We actually know are less than 16 years of age, unless We receive affirmative authorization (the "right to opt-in") from either the Consumer who is between 13 and 16 years of age, or the parent or guardian of a Consumer less than 13 years of age. Consumers who opt-in to the sale of personal information may opt-out of future sales at any time. To exercise the right to opt-out, You (or Your authorized representative) may submit a request to Us by contacting Us. If You have reason to believe that a child under the age of 13 (or 16) has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information.”After citation
Latest stance: third party or vendor sharing on privacy data use
“• Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purposes of the GDPR, Service Providers are considered Data Processors.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“• With Service Providers: We may share Your personal information with Service Providers to monitor and analyze the use of our Service, for payment processing, or to contact You.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“• Third-Party Transfers: We transfer Gmail Headers, Calendar Data, and Contacts Data to third parties only as necessary to provide or improve user-facing features (for example, hosting or processing by Our Service Providers) and as required to comply with applicable law. Such recipients are bound by obligations consistent with this Privacy Policy.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-05· verified 2026-08-05
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
258 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Happenstance's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Happenstance's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Happenstance's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.