Magnific AI
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“Copyright © 2010-2026 Freepik Company S.L.U.All rights reserved.”
Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.
Watch: audit rights dpa residency
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Under GDPR Chapter V, international transfers require an adequacy decision, SCCs, or other safeguards. The policy acknowledges transfers occur but does not enumerate the specific mechanisms relied upon, which is a material omission for data subjects assessing risk.
The absence of specific retention periods and the alternative of de-identification rather than deletion reduce user control. The 'protect, defend or establish our rights' carve-out is a broad and potentially indefinite retention justification under both GDPR and CCPA frameworks.
Platform collects identifiers and metadata from all users (including unauthenticated ones) under a legitimate-interest basis. Users have limited ability to object to this processing compared to consent-based processing.
Scores derived from 8 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Data handling is conditional — 1 privacy or retention clause warrant review before using Magnific AI at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Magnific AI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredIP/output assessment pending — terms of service not yet verified This lens receives a band only once its source document has been captured and read in full.
Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.
Based on 112 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Partially verified — Terms of Service — Capture under review; Privacy Policy — Verified (read in full, 1 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Needs review
A core policy document is captured but requires review before AIRIN can mark the corpus fully verified.
- Terms of ServiceCompleteness unconfirmedstatic-revalidated
- Privacy PolicyVerified - read in full - 1 citationsfirecrawlLast captured 2026-08-14
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Collection from third-party sources (data brokers, advertising networks, public databases) expands the profile the platform builds on each user beyond what they knowingly submit. GDPR Art. 14 requires transparency when data is not obtained directly from the data subject.
"We collect personal information from the following sources: directly from individuals, through our Services, service providers, business partners, advertising networks, Internet service providers, operating systems and platforms, social med..."
Using legitimate interests as the legal basis for intra-group sharing allows broad data flows without user consent. The scope of data shared (including biometric-adjacent data like image/audio/video) and the joint-controller arrangement for strategic decisions increases the risk surface.
"The Magnific Group of Companies, with the purpose and interest of centralising administrative and business infrastructure functions and to benefit from the functional specialisation and compartmentalisation inherent to these corporate struc..."
Clause A implies the AI assistant provides responses solely from a general knowledge base, whereas Clause B explicitly states it processes 'your data' and uses 'your account data' as a source for its operations, creating confusion about the scope of personal data usage.
" Description of the logic involved: The AI assistant analyses your query using natural language processing and predefined rules to identify its topic and provide the most suitable response from our knowledge base."
"#### 3.10.1. Support through AI assistant Similarly, based on your explicit consent provided by clicking the acceptance buttons, our AI assistant will process your data for the same purposes of support and information requests. The AI assistant operates through the fully automated analysis and comparison of your request and responses with a database generated from frequently asked questions, your account data, and predefined customer-support rules. If you believe that the assistant’s response is unsatisfactory or prejudicial, or if it is unable to provide you with a satisfactory answer or solution, you may challenge the decision or lodge a complaint at [support@magnific.com](mailto:support@magnific.com). Our human supervisor team will take into account any additional details and context you submit with your complaint before reaching a final decision. **Personal data processed:** content of your request, username, email address registered with Magnific, language preference, browser, time zone, and operating system. **Description of the logic involved:** The AI assistant analyses your query using natural language processing and predefined rules to identify its topic and provide the most suitable response from our knowledge base. **International data transfer and recipients** In order to provide this service, your data will be transferred outside the European Union in accordance with the terms set out in this privacy policy, but will not be disclosed to third parties."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"We collect personal information from the following sources: directly from individuals, through our Services, service providers, business partners, advertising networks, Internet service providers, operating systems and platforms, social media platforms, public and third-party databases, or other third parties."
Collection from third-party sources (data brokers, advertising networks, public databases) expands the profile the platform builds on each user beyond what they knowingly submit. GDPR Art. 14 requires transparency when data is not obtained directly from the data subject.
AI-generated interpretation, not legal advice.
"When you browse and use our Services, even if you do not register, identifiers such as your IP address, the unique ID of the device from which you access and certain metadata (such as your browser or HTTP headers) are automatically collected. This information is recorded for the purpose of monitoring compliance with the download limit authorised for each user category, thus allowing us to detect fraudulent or illegitimate use of our Services, and therefore ensure compliance with the applicable Conditions in each case, i.e. the management and fulfilment of our agreements with you."
Platform collects identifiers and metadata from all users (including unauthenticated ones) under a legitimate-interest basis. Users have limited ability to object to this processing compared to consent-based processing.
AI-generated interpretation, not legal advice.
"We retain the personal information we collect only for as long as is reasonably necessary for the purposes described above or as communicated to you. For example, we will retain information as necessary to comply with our tax, accounting and record-keeping obligations, to provide you with the Services, and for an additional period of time as necessary to protect, defend or establish our rights, defend against potential claims and comply with our legal obligations. In some cases, instead of deleting your personal information, we may de-identify or aggregate it and use it in accordance with the CCPA."
The absence of specific retention periods and the alternative of de-identification rather than deletion reduce user control. The 'protect, defend or establish our rights' carve-out is a broad and potentially indefinite retention justification under both GDPR and CCPA frameworks.
AI-generated interpretation, not legal advice.
"The Magnific Group of Companies, with the purpose and interest of centralising administrative and business infrastructure functions and to benefit from the functional specialisation and compartmentalisation inherent to these corporate structures, will carry out intra-group personal data processing of providers, users and employees based on our legitimate corporate interests. These processing operations, depending on the case, are carried out mainly as data processor and exceptionally as joint controller (for the execution of strategic decisions of the Group). **Data origin:** each of the Group’s subsidiaries collects the relevant data directly from the data subject in each case. **Personal data subject to processing:** depending on the processing: basic identification and contact data, data necessary to perform the login (single login), economic and professional data, image, audio and video (contractual management of providers –creators and models), data and metadata from web browsing (IT and web security processing). "
Using legitimate interests as the legal basis for intra-group sharing allows broad data flows without user consent. The scope of data shared (including biometric-adjacent data like image/audio/video) and the joint-controller arrangement for strategic decisions increases the risk surface.
AI-generated interpretation, not legal advice.
"This option is possible thanks to the collaboration between Magnific and Google as joint controllers of the processing of your personal data, so that (i) you can identify yourself directly on said platform, (ii) they confirm to us that you are who you say you are, and (iii) we facilitate your registration as a registered user on Magnific. Magnific obtains from this platform, with your consent, your username, image and your email address for the purpose of registering you as a Magnific user. On the other hand, these platforms capture online identifiers (IP address), technical identifiers (of your device, as well as its advertising identifiers such as "Google ID") and record, each time you use their login, the date and time of your access to Magnific."
Under GDPR Art. 26, joint controllers must have an arrangement defining responsibilities. Google captures device and advertising identifiers and logs each login event. Users should be aware that using Google login triggers data sharing with Google beyond what Magnific alone would collect.
AI-generated interpretation, not legal advice.
"Some of these external service providers are located outside the European Economic Area (EEA), so the processing of your personal data involves an international data transfer. Your data may be transferred outside the European Union in accordance with the terms established in this Privacy Policy, and in the specific information notices for certain tools, but will not be disclosed to third parties, except in cases expressly provided for in the applicable regulations or when necessary for the provision of the contracted services."
Under GDPR Chapter V, international transfers require an adequacy decision, SCCs, or other safeguards. The policy acknowledges transfers occur but does not enumerate the specific mechanisms relied upon, which is a material omission for data subjects assessing risk.
AI-generated interpretation, not legal advice.
"We offer you voluntary surveys to learn about your basic user profile and preferences, in order to personalise your experience on our websites as well as the advertising we show you or the information of interest we send you, based on the profile you place yourself in. The purpose of the processing is to personalise our advertising and information based on the information you decide to provide us and our legitimate interest is the continuous improvement of our products and services and obtaining relevant information in a transparent, respectful and approachable way. **Personal data subject to processing:** username, type of use of our products (personal, freelance, company and its approximate size and industry or activity of the user) and personal preferences included in the form."
The processing is voluntary and the opt-out mechanism (simply not responding) is straightforward. The legitimate interest basis is plausible for product improvement. Risk is low given the voluntary nature, but users should be aware their survey responses may profile them for advertising purposes.
AI-generated interpretation, not legal advice.
"In relation to the data necessary to manage and fulfil our contractual relationships with users, your personal data is processed while the contractual relationship continues, and is subsequently kept blocked for a period of five years (until the statute of limitations for possible contractual liabilities or intellectual property rights claims) or six years (in relation to documentation for accounting purposes)."
Post-contractual retention of up to 6 years is justified by statute of limitations for liabilities and accounting obligations under Spanish/EU law, but users should be aware their data persists significantly beyond account closure.
AI-generated interpretation, not legal advice.
"Copyright © 2010-2026 Freepik Company S.L.U.All rights reserved."
Copyright notice asserting that Freepik Company S.L.U. holds all rights reserved for the period 2010–2026, establishing the company's intellectual property ownership claim over platform content and outputs.
AI-generated interpretation, not legal advice.
"In relation to the sending of commercial communications, the data will be processed for three years from the last interaction with you, or until you decide to object, whichever occurs first."
The three-year rolling window from last interaction for commercial communications is a common GDPR-compliant approach. The right to object at any time mitigates the user risk.
AI-generated interpretation, not legal advice.
"personal data is retained for a maximum of 30 days after the generation of the Output."
Defines a clear 30-day maximum retention period at the sub-processor level for data processed by third-party AI model providers. Short retention periods are generally user-favorable.
AI-generated interpretation, not legal advice.
"Magnific enters into Standard Contractual Clauses (Art. 46.2.c) of the GDPR with all third-party model providers it offers."
Standard Contractual Clauses under Art. 46.2(c) GDPR are a recognized transfer mechanism for international data flows. Their use with all model providers is a positive compliance indicator, though they do not guarantee equivalent protection in practice.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Magnific AI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
4 verified clausesClauses in Magnific AI's policies that work in your favour — commitments the platform made to you.
- Data retentiondeletion rights & post-termination survival
“In relation to the data necessary to manage and fulfil our contractual relationships with users, your personal data is processed while the contractual relationship continues, and is subsequently kept blocked for a period of five years (until the statute of lim…”
Post-contractual retention of up to 6 years is justified by statute of limitations for liabilities and accounting obligations under Spanish/EU law, but users should be aware their data persists significantly beyond accou…
Location: exact-text link only — source has no section structureJump to exact text → - Data retentiondeletion rights & post-termination survival
“In relation to the sending of commercial communications, the data will be processed for three years from the last interaction with you, or until you decide to object, whichever occurs first.”
The three-year rolling window from last interaction for commercial communications is a common GDPR-compliant approach. The right to object at any time mitigates the user risk.
Location: exact-text link only — source has no section structureJump to exact text → - Audit rights, DPA & residency
“Magnific enters into Standard Contractual Clauses (Art. 46.2.c) of the GDPR with all third-party model providers it offers.”
Standard Contractual Clauses under Art. 46.2(c) GDPR are a recognized transfer mechanism for international data flows. Their use with all model providers is a positive compliance indicator, though they do not guarantee e…
Location: exact-text link only — source has no section structureJump to exact text → - Data retentiondeletion rights & post-termination survival
“personal data is retained for a maximum of 30 days after the generation of the Output.”
Defines a clear 30-day maximum retention period at the sub-processor level for data processed by third-party AI model providers. Short retention periods are generally user-favorable.
Location: exact-text link only — source has no section structureJump to exact text →
📋 Rules you must follow
0 verified clausesWhat Magnific AI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Magnific AI's published policies yet.
What the policies actually cover
3 topics- Product telemetry & usage tracking2 clauses
- Advertising & tracking1 clause
- Deletion rights & post-termination survival3 protective4 clauses
5 further verified clauses are cited on this page but not yet assigned a topic.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause restricts commercial use.
“In relation to your non-commercial enquiries, the data is deleted once they have been answered.”Open source citation
The clause permits sale of personal data or information.
“The CCPA defines "sale" as the disclosure or making available of personal information to a third party in exchange for monetary or other valuable consideration, and "sharing" includes the disclosure or making available of personal information to a third party for cross-context behavioural advertising purposes. Although we do not disclose personal information to third parties in exchange for monetary compensation, ...”Open source citation
The clause permits sale of personal data or information.
“We do not sell or share sensitive personal information, nor do we sell or share personal information about individuals we know to be under sixteen (16) years of age.”Open source citation
The clause permits sale of personal data or information.
“Right to Opt-Out of the Sale and Sharing of Your Personal Information: Although we do not "sell" personal information in the traditional sense (i.e., in exchange for money), our use of third-party analytics and advertising cookies may be considered "selling" and "sharing" under the CCPA.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“In order to provide this service, your data will be transferred outside the European Union in accordance with the terms set out in this privacy policy, but will not be disclosed to third parties.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | conditional | MEDIUM | 3 |
| All applicable tiers | privacy data use | worsens | HIGH | 3 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 1 |
| All applicable tiers | training use | worsens | HIGH | 2 |
| Team / Business | commercial use | conditional | MEDIUM | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: restricted on commercial use
“In relation to your non-commercial enquiries, the data is deleted once they have been answered.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“In order to provide this service, your data will be transferred outside the European Union in accordance with the terms set out in this privacy policy, but will not be disclosed to third parties.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“Some of these external service providers are located outside the European Economic Area (EEA), so the processing of your personal data involves an international data transfer.”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“12.1.2 Disclosure of personal information to third parties for commercial or business purposes”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“We may disclose each of the following categories of personal information to the following third parties for business or commercial purposes. We may disclose identifiers, professional information, Internet and other electronic activity information, and inferences to advertising networks, Internet service providers, data analytics providers, government entities, operating systems and platforms, social networks, data brokers and others, as permitted by law. We may disclose protected classifications and commercial information to advertising networks, Internet service providers, data analytics providers, government entities and others as permitted by law. We may disclose consumer records, characteristics of protected classifications, geolocation information, sensitive personal information and audio, electronic, visual or similar information to government entities and others as permitted by law.”Open timeline citation
Latest stance: sale or sell on commercial use
“The CCPA defines "sale" as the disclosure or making available of personal information to a third party in exchange for monetary or other valuable consideration, and "sharing" includes the disclosure or making available of personal information to a third party for cross-context behavioural advertising purposes. Although we do not disclose personal information to third parties in exchange for monetary compensation, we may "sell" or "share" the following categories of personal information: identifiers; commercial information; and Internet and network activity information. We may disclose these categories to third-party advertising networks, analytics providers and social networks for marketing and advertising purposes and to improve and measure our advertising campaigns.”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“The CCPA defines "sale" as the disclosure or making available of personal information to a third party in exchange for monetary or other valuable consideration, and "sharing" includes the disclosure or making available of personal information to a third party for cross-context behavioural advertising purposes. Although we do not disclose personal information to third parties in exchange for monetary compensation, we may "sell" or "share" the following categories of personal information: identifiers; commercial information; and Internet and network activity information. We may disclose these categories to third-party advertising networks, analytics providers and social networks for marketing and advertising purposes and to improve and measure our advertising campaigns.”Open timeline citation
Latest stance: sale or sell on privacy data use
“We do not sell or share sensitive personal information, nor do we sell or share personal information about individuals we know to be under sixteen (16) years of age.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-07-20· verified 2026-06-09verified once — no re-scan in 94 days
- Privacy Policy:Last captured 2026-08-14· verified 2026-08-14
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 83 more findings this quarter vs last (139 vs 56). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Magnific AI's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Magnific AI's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Magnific AI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.