Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · paywithlocus.com

Locus

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskUNRATEDReviewed 2026-07-20
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

0 verified findings0 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

No verified risks yet

AIRIN has not published verified findings for this record yet. The page shows the gap instead of guessing.

0
high
0
medium
0
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Locus's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 0 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 0 citationsLast captured 2026-07-20
Conflicting provisions (3)
  • Clause A explicitly states that KYC information (like date of birth, government-issued IDs, SSN/ITIN) is not collected, which directly conflicts with Clause B's claim that information is used to comply with legal and regulatory obligations and satisfy audit/tax requirements, as these often necessitate the collection of such KYC data.

    " Account & Profile: Email address (required), password hash, full name (optional), public wallet address, signup IP address, AWS Cognito User ID, account role (user, admin, superadmin), authentication credentials, last login timestamp, dashboard widget configurations, escrow expiry preferences, and onboarding completion status. Compliance: OFAC sanctions screening results. Note: Locus is a non-custodial platform and does not collect KYC information such as date of birth, government-issued IDs, SSN/ITIN, or nationality. Financial & Transactional: Transaction amounts (in USDC), wallet IDs and addresses, blockchain transaction hashes, counterparty addresses, memos, transaction status, and ledger entries. For Bring Your Own Card ( "BYOC" ) functionality, tokenized card references are stored by our third-party PCI-DSS Level 1 certified vault provider, Basis Theory . Locus never stores, processes, or has access to raw card numbers. Contacts & Counterparties: Contact names, wallet addresses, email addresses, phone numbers, descriptions, and whitelist relationships you create for approved recipients. Support & Communications: Messages to us (including recordings you share with support), bug reports, satisfaction surveys, and any files you upload. Developer & API Use: Agent IDs, agent names and descriptions, API key hashes and prefixes, API key creation timestamps, Model Context Protocol ( "MCP" ) OAuth credentials and scopes, usage logs, request/response metadata, webhook endpoints, IPs, event payloads, and error diagnostics. "
    " We use information for the following purposes: Provide the Service: Create and manage accounts, enable payments and transfers, initiate refunds, provide receipts, and operate dashboards/APIs. Risk & Security: Conduct OFAC sanctions screening, authenticate users, detect and prevent fraud, abuse, and unauthorized access, enforce spending policies and transaction limits, and manage disputes. Compliance & Reporting: Comply with legal and regulatory obligations, respond to lawful requests, maintain records, and satisfy audit and tax requirements. Customer Support & Communications: Respond to requests, send service/transactional messages, and communicate changes to terms, features, or security notices. Product Improvement & Research: Monitor usage, fix bugs, develop new features, and perform analytics. We may use deidentified or aggregated data to develop and improve machine-learning models that support fraud detection, risk scoring, and product features. When we use aggregator-derived financial data, we limit such use to the requested features, compliance, and security as stated above. Personalization & Marketing: With your consent or as permitted by law, personalize content, measure campaigns, and send promotional communications. Developer & API Operations: Provide API functionality, usage analytics, rate-limiting, abuse prevention, and webhook/event delivery. Agent Delegation & Pay-Per-Use Service. If you create Agent Access Keys to delegate spending authority to AI agents or third-party applications: We process and store API key hashes, agent configurations, MCP OAuth credentials, usage logs, and all transactions initiated by your agents; When your agent uses our pay-per-use Wrapped API proxy, we forward your request data to the upstream third-party API"
    Within one document
  • Clause A states Locus does not monitor, supervise, or control the behavior of AI agents, while Clause B indicates Locus uses information for risk and security purposes, including detecting fraud and enforcing spending policies related to agent activities, which inherently requires monitoring and control of their actions.

    " provider and store both the complete request and response payloads in our database; You acknowledge that AI agents may operate autonomously within the permissions you grant, and may initiate transactions, make API calls, send communications, or take other actions without your real-time supervision; You bear full responsibility for all transactions executed by agents you have authorized, including any errors, unauthorized actions within granted permissions, or unintended consequences; Locus does not monitor, supervise, or control the behavior of AI agents you authorize, and Locus is not liable for any losses, damages, or harms arising from agent actions; We process this data to provide the Service, enforce spending policies, maintain audit trails, and support dispute resolution. "
    " We use information for the following purposes: Provide the Service: Create and manage accounts, enable payments and transfers, initiate refunds, provide receipts, and operate dashboards/APIs. Risk & Security: Conduct OFAC sanctions screening, authenticate users, detect and prevent fraud, abuse, and unauthorized access, enforce spending policies and transaction limits, and manage disputes. Compliance & Reporting: Comply with legal and regulatory obligations, respond to lawful requests, maintain records, and satisfy audit and tax requirements. Customer Support & Communications: Respond to requests, send service/transactional messages, and communicate changes to terms, features, or security notices. Product Improvement & Research: Monitor usage, fix bugs, develop new features, and perform analytics. We may use deidentified or aggregated data to develop and improve machine-learning models that support fraud detection, risk scoring, and product features. When we use aggregator-derived financial data, we limit such use to the requested features, compliance, and security as stated above. Personalization & Marketing: With your consent or as permitted by law, personalize content, measure campaigns, and send promotional communications. Developer & API Operations: Provide API functionality, usage analytics, rate-limiting, abuse prevention, and webhook/event delivery. Agent Delegation & Pay-Per-Use Service. If you create Agent Access Keys to delegate spending authority to AI agents or third-party applications: We process and store API key hashes, agent configurations, MCP OAuth credentials, usage logs, and all transactions initiated by your agents; When your agent uses our pay-per-use Wrapped API proxy, we forward your request data to the upstream third-party API"
    Within one document
  • Clause B states the service is offered and supported only in North America, implying data processing is confined to those regions, while Clause A explicitly details global data transfers and processing for the service's infrastructure and third-party components.

    " We process and store information in the United States and we may transfer information globally to operate the Service. By using the Service, you understand your information may be transferred across borders. Specifically: (a) our primary infrastructure (RDS, S3, ElastiCache, KMS) is in the US; (b) CDN Service via AWS CloudFront and Cloudflare have global edge locations; (c) blockchain data on Base L2 is globally distributed, public, and immutable; and (d) third-party services (SendGrid, Twilio, Google Analytics, CDP, Wrapped API providers) may process data in various jurisdictions. We implement contractual, technical, and organizational safeguards appropriate to the sensitivity of the information and applicable law. If we later expand to additional regions, we will implement additional safeguards as required by the destination jurisdiction's laws and update this Policy."
    " This Policy applies to information processed in connection with your access to and use of the Service. It should be read with our Terms of Service and, where applicable, any product-specific Additional Terms or disclosures (together, the "Terms" ). Capitalized terms not defined here have the meanings given in the Terms. Geographic Scope (Current): North America (U.S. & Canada). Locus currently offers and supports the Service only in the United States and Canada. Jurisdiction-specific disclosures below focus on applicable U.S. federal and state laws and Canadian federal and provincial laws. If Locus expands to additional regions, we will update this Policy and provide any required regional notices. Non-Custodial by Default; Custodial Features via Partners. Locus is a non-custodial platform for its core products. To the extent custodial functionality is offered through the Service (e.g., stored balances, accounts, or investment features), that Service is provided solely by regulated third-party custodial partners, and your assets and related records are held by those partners pursuant to their terms of service and privacy policies. Locus does not take possession of, custody, or control over customer assets. Where custodial functionality is used, custody is provided solely by regulated third-party custodial partners pursuant to their terms. Locus is not the custodian."
    Within one document
No verified evidence citations are published for this platform yet - its complete governing documents are not yet publicly capturable. We never publish citations from a document we have not read in full.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

44
clauses
12
patterns
12
stances
privacy sharing · 10data retention · 2
data retentionMEDIUM§ 6 (Data Retention)

The clause allows indefinite, perpetual, or necessity-based retention.

We retain information as long as necessary to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce agreements. Specific retention practices include: (a) blockchain transaction data is immutable and permanently public on-chain; (b) wallets, agents, policy groups, and contacts are soft-deleted (data retained with deletion flag); (c) escrow wallets expire after a config...
Open source citation
data retentionLOW§ 6 (Data Retention)

The clause provides a deletion or time-bounded retention path.

We retain information as long as necessary to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce agreements. Specific retention practices include: (a) blockchain transaction data is immutable and permanently public on-chain; (b) wallets, agents, policy groups, and contacts are soft-deleted (data retained with deletion flag); (c) escrow wallets expire after a config...
Open source citation
privacy sharingHIGHPrivacy Policy › “Summary at a Glance”

The clause permits sale of personal data or information.

(not a substitute for the full policy) We collect information you provide, information collected automatically, and information from third parties (e.g., OFAC sanctions screening providers, transaction partners, blockchain infrastructure providers). We use data to operate the Service, enable payments through our partners, conduct OFAC sanctions screening, manage risk and fraud, comply with law, provide support, an...
Open source citation
privacy sharingHIGH§ 4 (When & With Whom We Share Information)

The clause permits sale of personal data or information.

Embedded Wallet Platforms: Third-party platforms may embed Locus wallet infrastructure into their products. When you use Locus functionality through such platforms, we share transaction data, wallet information, and user identifiers with the embedding platform as necessary to provide the integrated service. Affiliates: Within our corporate group for operations and support consistent with this Policy. Legal, Safety...
Open source citation
privacy sharingHIGH§ 8.1 (United States (Federal & State))

The clause permits sale of personal data or information.

Categories Collected: Identifiers; commercial information; internet/network activity; geolocation (approximate, inferred from IP); inferences (e.g., risk scores). Sources & Uses: As described above. Disclosures for Business Purposes: To service providers, transaction counterparties and affiliates. Sale/Sharing: We do not sell personal information. We do not engage in "sharing" for cross-context behavioral advertis...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useworsensHIGH2
Apidata retentionconditionalMEDIUM2
Apitraining useconditionalMEDIUM1
Team / Businesscommercial useworsensHIGH1
Team / Businessdata retentionworsensHIGH2
Team / Businessprivacy data useworsensHIGH4

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

This Privacy Policy (the "Policy" ) explains how Locus Technologies Inc. , a Delaware corporation, and its affiliates (collectively, "Locus," "we," "us," or "our" ) collect, use, disclose, store, and otherwise process information when you ( "you" or "your" ) use our services, including our websites: https://paywithlocus.com , https://beta.paywithlocus.com , https://app.paywithlocus.com , and https://buildwithlocus.com as well as any other websites associated with Locus from time to time (collectively, the "Site" ), our applications, dashboards, software development kits, including the Locus Agent SDK ( "SDKs" ), and application programming interfaces ( "APIs" ) (together the "Platform" ), and related technologies (collectively, the "Service" ). By using the Service, you agree to the practices described here. If you do not agree, do not use the Service. The Service is intended for business and developer users only. You may not use the Service for personal, family, or household purposes.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on data retention

(not a substitute for the full policy) We collect information you provide, information collected automatically, and information from third parties (e.g., OFAC sanctions screening providers, transaction partners, blockchain infrastructure providers). We use data to operate the Service, enable payments through our partners, conduct OFAC sanctions screening, manage risk and fraud, comply with law, provide support, and improve our products (including via deidentified/aggregated data). We share data with service providers (e.g., blockchain infrastructure providers, cloud hosting, communications providers), with your direction, to comply with law, and in business transfers. We do not sell personal information. You may have rights to access, correct, delete, or opt out of certain processing depending on where you live. See Your Rights & Choices .
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on data retention

(not a substitute for the full policy) We collect information you provide, information collected automatically, and information from third parties (e.g., OFAC sanctions screening providers, transaction partners, blockchain infrastructure providers). We use data to operate the Service, enable payments through our partners, conduct OFAC sanctions screening, manage risk and fraud, comply with law, provide support, and improve our products (including via deidentified/aggregated data). We share data with service providers (e.g., blockchain infrastructure providers, cloud hosting, communications providers), with your direction, to comply with law, and in business transfers. We do not sell personal information. You may have rights to access, correct, delete, or opt out of certain processing depending on where you live. See Your Rights & Choices .
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on training use

We may share information as follows: Service Providers / Sub-Processors: Vendors who host, process, or support the Service, including: AWS (cloud infrastructure, authentication via Cognito, key management via KMS, job scheduling), Cloudflare (CDN and file proxy), SendGrid (transactional email), Twilio (SMS notifications), Google Analytics (analytics), and Basis Theory (PCI-DSS Level 1 card tokenization vault). These parties are bound by contractual obligations to protect your data. Pay-Per-Use API Providers: When you use our Wrapped API proxy service, we forward your request data to third-party API providers and store both request and response payloads in our database. We provide access to over 40 third-party APIs across categories including providers such as OpenAI, Anthropic, Google Gemini, Mistral AI, Perplexity, Brave Search, Firecrawl, Deepgram, Stability AI, DeepL and others for AI, search, data enrichment, and productivity Services. The ownership of prompts you submit and outputs generated is governed by the applicable upstream provider's terms of service. Locus does not claim ownership of your prompts or AI-generated outputs. However, our storage of request and response payloads is subject to this Privacy Policy. Each upstream provider has its own privacy policy and terms governing how they process the data we send them on your behalf, intellectual property rights, training data usage and content policies.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

Embedded Wallet Platforms: Third-party platforms may embed Locus wallet infrastructure into their products. When you use Locus functionality through such platforms, we share transaction data, wallet information, and user identifiers with the embedding platform as necessary to provide the integrated service. Affiliates: Within our corporate group for operations and support consistent with this Policy. Legal, Safety & Compliance: To comply with law, regulation, legal process, or governmental request; to enforce our terms; to protect the rights, property, or safety of Locus, our Users, or the public. Business Transfers: In connection with a merger, acquisition, financing, restructuring, or sale of assets; your data may be transferred as part of that transaction. With Your Direction or Consent. No Sale of Personal Information: We do not sell personal information. If we ever engage in activities that qualify as "sharing" for cross-context behavioral advertising under applicable law, we will provide a method to opt out (including honoring Global Privacy Control ( "GPC" ) signals where required).
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on commercial use

Categories Collected: Identifiers; commercial information; internet/network activity; geolocation (approximate, inferred from IP); inferences (e.g., risk scores). Sources & Uses: As described above. Disclosures for Business Purposes: To service providers, transaction counterparties and affiliates. Sale/Sharing: We do not sell personal information. We do not engage in "sharing" for cross-context behavioral advertising or "targeted advertising" unless expressly stated in the Service. If we introduce such activities, we will provide a clear in-product method to opt out (including GPC signal recognition). Retention: See Section 6. Non-Discrimination: We will not discriminate against you for exercising your rights.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We use or disclose sensitive personal information for the following statutorily approved reasons ( "Permitted SPI Purposes" ): Performing actions that are necessary for our consumer relationship and that an average consumer in a relationship with us would reasonably expect. Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information. Defending against and prosecuting those responsible for malicious, deceptive, fraudulent, or illegal actions directed at us. Ensuring physical safety. Short-term, transient use, such as non-personalized advertising shown as part of your current interactions with us, where we do not disclose the sensitive personal information to another third party or use it to build a profile about you or otherwise alter your experience outside your current interaction with us. Services performed for us, including maintaining or servicing accounts, processing or fulfilling transactions, verifying consumer information, processing payments, or providing financing, analytic services, storage, or similar services. Activities required to verify or maintain the quality or safety of a product, service, or device that we own, manufacture, had manufactured, or control; or improve, upgrade, or enhance the service or device that we own, manufacture, had manufactured, or controlled. Collecting or processing sensitive personal information that we do not use for the purpose of inferring characteristics about a consumer. We do not use or disclose sensitive personal information for purposes other than the Permitted SPI Purposes.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

We have not disclosed consumers' personal information to third parties for a business purpose in the preceding 12 months beyond what is described in Section 4 of this Policy. We may disclose the personal information we collect to service providers and contractors for the business purposes described in the "How We Use Information" section, such as to support our business functions. We do not sell your personal information to third parties and have not sold it in the preceding 12 months. We do not share your personal information with third parties for cross-context behavioral advertising purposes and have not shared your personal information in the preceding 12 months.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

44 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Locus's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Locus's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Locus's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.