Kalinda
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
No verified risks yet
AIRIN has not published verified findings for this record yet. The page shows the gap instead of guessing.
How to read this page: Overall risk rates what Kalinda's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 0 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 0 citationsstaticLast captured 2026-07-20
Clause A states PHI is processed 'solely' at the direction of law firm customers, implying no other basis, while Clause B explicitly allows disclosure of personal information (which includes PHI) based on 'explicit consent' from the individual, presenting an opposing basis for handling the data.
" PHI is processed solely at the direction of our law firm customers for organizing, reviewing, and reporting on plaintiff records. We do not engage in automated decision-making that affects individuals. All uses are limited to providing the Service or resolving technical issues."
" With Consent: We may disclose personal information with your explicit consent or at the direction of our law firm customers."
Within one documentClause A states a blanket prohibition on sharing personal data, while Clause B describes a practice (processing PHI as a Business Associate) that inherently involves sharing (disclosing) a specific type of personal data (PHI) under HIPAA.
" Sensitive Data: We do not sell or share personal data, do not process biometric identifiers for identification, and do not conduct targeted advertising or profiling."
" This Privacy Policy applies to all users of the Platform, including our customers (law firms) and any individuals whose personal information is contained in the records uploaded to the Platform (e.g., plaintiffs). It describes our privacy practices in accordance with applicable laws, including the Health Insurance Portability and Accountability Act ("HIPAA") and its implementing regulations, as we process Protected Health Information ("PHI") as a subcontractor Business Associate of our law firm customers. We also comply with applicable U.S. state privacy laws, biometric privacy laws, and health privacy laws that supplement HIPAA. For data that our law firm customers upload to the Platform, Kalinda acts as a "service provider" or processor, processing such data only on behalf of and at the direction of our customer. In those cases, the law firm is the data controller responsible for the data. When Kalinda collects personal information directly from users (for example, account registration or billing information), Kalinda is acting as a data controller (a "business" under state law) for that information."
Within one document
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain personal information only as long as necessary to provide our services or fulfill legal obligations:”Open source citation
The clause provides a deletion or time-bounded retention path.
“Customers can request deletion of their data directly through the Platform or by emailing security@kalinda.ai . Upon a verified deletion request, or upon termination of our services, we will delete (or, if requested, return) that customer's personal data within 30 days, except where a longer retention is required by law or necessary for legitimate business purposes.”Open source citation
The clause permits sale of personal data or information.
“We operate in the United States and comply with state-specific laws in addition to federal requirements like HIPAA. We do not sell personal information or process data for targeted advertising.”Open source citation
The clause permits sale of personal data or information.
“Sensitive Data: We do not sell or share personal data, do not process biometric identifiers for identification, and do not conduct targeted advertising or profiling.”Open source citation
The clause permits sale of personal data or information.
“We do not sell, rent, or share personal information for marketing or cross-context behavioral advertising purposes. We share information only as necessary to provide the Platform and comply with laws:”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | data retention | conditional | MEDIUM | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 4 |
| All applicable tiers | training use | improves | LOW | 2 |
| Team / Business | data retention | improves | LOW | 1 |
| Team / Business | privacy data use | conditional | MEDIUM | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“Opt-Out: The right to opt out of certain types of processing or sharing. We do not sell personal data or use it for targeted advertising.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“This Privacy Policy applies to all users of the Platform, including our customers (law firms) and any individuals whose personal information is contained in the records uploaded to the Platform (e.g., plaintiffs). It describes our privacy practices in accordance with applicable laws, including the Health Insurance Portability and Accountability Act ("HIPAA") and its implementing regulations, as we process Protected Health Information ("PHI") as a subcontractor Business Associate of our law firm customers. We also comply with applicable U.S. state privacy laws, biometric privacy laws, and health privacy laws that supplement HIPAA. For data that our law firm customers upload to the Platform, Kalinda acts as a "service provider" or processor, processing such data only on behalf of and at the direction of our customer. In those cases, the law firm is the data controller responsible for the data. When Kalinda collects personal information directly from users (for example, account registration or billing information), Kalinda is acting as a data controller (a "business" under state law) for that information.”Open timeline citation
Latest stance: sale or sell on privacy data use
“We do not sell, rent, or share personal information for marketing or cross-context behavioral advertising purposes. We share information only as necessary to provide the Platform and comply with laws:”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“Service Providers: We may share personal information with trusted third parties such as AWS (cloud hosting), Microsoft Azure OpenAI (AI processing), and Stripe (payments). These providers are bound by confidentiality and security obligations, including Business Associate Agreements for PHI.”Open timeline citation
Latest stance: sale or sell on privacy data use
“We operate in the United States and comply with state-specific laws in addition to federal requirements like HIPAA. We do not sell personal information or process data for targeted advertising.”Open timeline citation
Latest stance: sale or sell on privacy data use
“Sensitive Data: We do not sell or share personal data, do not process biometric identifiers for identification, and do not conduct targeted advertising or profiling.”Open timeline citation
Latest stance: no training claim on training use
“AI Processing: Uploaded data, including PHI and PII, is passed through AI models solely to generate reports at the direction of our law firm customers. We do not use customer data to train, retrain, or improve AI models.”Open timeline citation
Latest stance: no training claim on training use
“Improvement: To analyze usage data for product enhancements. We never use customer data to train AI models.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
58 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Kalinda's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Kalinda's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Kalinda's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.