n8n
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“When content you submit is removed from the forum, whether by you or by the company, the company’s special license ends when the last copy disappears from the company’s backups, caches, and other systems. Other licenses you apply to content you submit, such as Creative Commons licenses, may continue after your content is removed. Those licenses may give…”
Watch: governing law disputes
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Prohibits the user from assigning the agreement while permitting the company to assign it to affiliates, successors, or asset purchasers; declares any prohibited assignment void and of no legal effect.
Limits company and supplier liability by excluding breach-of-contract damages that were not reasonably foreseeable by company personnel at the time the user agreed to the terms.
Restricts continued forum use if the company has directly notified the user that they may not use it, granting the company a unilateral right to revoke access.
Scores derived from 33 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- n8n's terms explicitly protect your inputs from training use — the policy is affirmatively favorable on this point.
- Your outputs and prompts are explicitly yours — n8n's terms include affirmatively protective IP language.
- Data handling is conditional — 3 privacy or retention clauses warrant review before using n8n at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what n8n's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 96 verified, verbatim-cited findings below — read the citations.
Based on 99 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 55 citationsstaticLast captured 2026-08-28
- Privacy PolicyVerified - read in full - 29 citationsstaticLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Details processing of name, email, company and billing contact data for paid plans under contract performance, discloses Paddle as the Merchant of Record for credit card billing, identifies the telemetry data opt-out right, and references legitimate interests as the legal basis; establishes processing obligations and data subject rights.
"6 (1) lit. f GDPR. You can object to this data processing at any time with effect for the future by activating the opt-out, see our Docs page about telemetry data opt out . If you sign up for a paid plan , we process your name, email addre..."
Describes processing of personal data (name, address, email, phone, photos/videos) at company or third-party events on the basis of legitimate interests, and provides an opt-out right for photo/video capture; establishes processing obligations and data subject rights at events.
"When you attend one of our events or a third party event, we may process your personal information including your name, address, email address and phone number. We process this information because it’s in our legitimate interests to know wh..."
Describes the purposes for processing Contact, Professional, Communication, and Traffic and Device Data for website use, identifies legitimate interests, contract performance, and consent as GDPR legal bases; creates obligations and permissions tied to specific lawful processing grounds.
" Use of our Website Contact Data, Professional Data, Communication Data, Traffic and Device Data Ensuring the technical availability, stability, and security and providing access to our Website, Preventing misuse or attacks, Logging access ..."
This segment identifies the legal basis (Art. 6(1)(f) GDPR) for storing access data in server log files, enumerates the categories of data collected (date/time, data transferred, browser, OS, IP address, referrer URL), and explains the necessity of temporary IP address storage for website delivery, establishing an obligation to process and temporarily retain this data on the stated lawful basis.
" Every time you visit our website, we automatically store access data in so-called server log files.The legal basis for the temporary storage of your data and the log files is Art. 6 (1) lit. f GDPR. This includes the date and time of the ..."
Grants users the right to unsubscribe from marketing communications at any time; also describes processing of data for expert and affiliate program registration and job applications.
" You can unsubscribe from our updates at any time by clicking the unsubscribe link at the bottom of any of our emails, or by emailing [email protected] . When you register as an expert. We process your name, email address, and details abou..."
This segment establishes the obligation to retain personal data no longer than necessary for the purposes for which it was processed, identifies the criteria used to determine retention periods (amount, nature, sensitivity, risk of harm, purposes, legal requirements), and acknowledges that legal obligations and legitimate business interests may require retention, creating binding data minimization and retention obligations.
" We store your personal information for no longer than necessary for the purposes for which it was processed, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and leg..."
Grants the company a perpetual, royalty-free right to use, act on, and exploit user-submitted feedback and suggestions without notice, consent, or compensation, effectively transferring any ownership interest in feedback to the company; also restricts users from submitting confidential or proprietary feedback.
" You agree that the company will be free to act on feedback and suggestions you provide, and that the company won’t have to notify you that your feedback was used, get your permission to use it, or pay you. You agree not to submit feedback ..."
This segment enumerates the categories of third-party service providers (IT hosting, cybersecurity, analytics, marketing, billing, payment processing, CRM, collaboration tools) with whom personal data may be shared to support business operations, establishing the scope of permitted subprocessor data sharing.
" We may share personal data with carefully selected service providers that support our business operations. These include, in particular, providers of IT hosting and infrastructure services (e.g. cloud hosting and content delivery networks)..."
Clause A states the IP address is deleted or anonymized immediately after a visit, making it untraceable, while Clause B states it is stored in server log files, implying retention beyond the immediate visit.
" If you browse our Website, we may collect Traffic and Device Data that your browser sends to us. As a protective measure in favor of privacy, we delete or anonymize the IP address after your visit to our Website. This means that Traffic and Device Data can no longer be traced back to you and is only used for anonymous, statistical purposes to optimize our Website or Services. Our Website may use so-called cookies (i.e. small text files stored in your browser or on your device) and similar tracking technologies such as pixels or scripts, which are used to collect information about how our Website is used ("Cookies"). This information may be processed by us or transmitted to the relevant provider and may include a unique device identifier. Cookies contain information about the current or last visit to our Website (e.g., name of the Website, expiration date of the Cookie, other values). If Cookies do not contain an exact expiration date, they are stored only temporarily and are automatically deleted as soon as you close your browser or restart your device. Cookies with an expiration date will still be stored even when you close your browser or restart your device. Such Cookies will not be deleted until the specified date or if you delete them manually. We may use the following three types of Cookies: (a) Essential Cookies that are required for the functionality of our Website; (b) functional and performance-related Cookies that help us improve your experience; and (c) advertising and analytics Cookies that enable personalized ads and analytics. "
" Every time you visit our website, we automatically store access data in so-called server log files.The legal basis for the temporary storage of your data and the log files is Art. 6 (1) lit. f GDPR. This includes the date and time of the visit, the amount of data transferred and, if applicable, the name of the requested file, the browser used and its version, the operating system used, the IP address and the referrer URL (the URL you visited immediately before). The temporary storage of the IP address by the system is necessary to enable the website to be delivered to your end device. For this purpose, your IP address must remain stored for the duration of the session. Our website uses a content delivery network (CDN) and security service provider (category of recipient: IT infrastructure and security service provider). For this purpose, incoming requests are routed via the provider’s globally distributed edge servers (reverse proxy). In this context, access data - in particular IP address, request header information, and browser data - may already be processed by the provider before being forwarded to our web server. The temporary storage of the IP address by the system is necessary to enable the website to be delivered to your end device. This also applies where the delivery takes place via edge servers of the CDN provider. For this purpose, your IP address must remain stored for the duration of the session. This data is evaluated exclusively to ensure the permanent and trouble-free operation of the website and to improve the content of our website, as well as to transmit it to law enforcement authorities in the event of a cyber attack and to ensure the security of our information technology systems, which also constitute our legitimate interest in data"
Within one documentClause A states the IP address is deleted or anonymized immediately after a visit, making it untraceable, while Clause B states it is stored in server log files, implying retention beyond the immediate visit.
" If you browse our Website, we may collect Traffic and Device Data that your browser sends to us. As a protective measure in favor of privacy, we delete or anonymize the IP address after your visit to our Website. This means that Traffic and Device Data can no longer be traced back to you and is only used for anonymous, statistical purposes to optimize our Website or Services. Our Website may use so-called cookies (i.e. small text files stored in your browser or on your device) and similar tracking technologies such as pixels or scripts, which are used to collect information about how our Website is used ("Cookies"). This information may be processed by us or transmitted to the relevant provider and may include a unique device identifier. Cookies contain information about the current or last visit to our Website (e.g., name of the Website, expiration date of the Cookie, other values). If Cookies do not contain an exact expiration date, they are stored only temporarily and are automatically deleted as soon as you close your browser or restart your device. Cookies with an expiration date will still be stored even when you close your browser or restart your device. Such Cookies will not be deleted until the specified date or if you delete them manually. We may use the following three types of Cookies: (a) Essential Cookies that are required for the functionality of our Website; (b) functional and performance-related Cookies that help us improve your experience; and (c) advertising and analytics Cookies that enable personalized ads and analytics. "
" Every time you visit our website, we automatically store access data in so-called server log files.The legal basis for the temporary storage of your data and the log files is Art. 6 (1) lit. f GDPR. This includes the date and time of the visit, the amount of data transferred and, if applicable, the name of the requested file, the browser used and its version, the operating system used, the IP address and the referrer URL (the URL you visited immediately before). The temporary storage of the IP address by the system is necessary to enable the website to be delivered to your end device. For this purpose, your IP address must remain stored for the duration of the session. Our website uses a content delivery network (CDN) and security service provider (category of recipient: IT infrastructure and security service provider). For this purpose, incoming requests are routed via the provider’s globally distributed edge servers (reverse proxy). In this context, access data - in particular IP address, request header information, and browser data - may already be processed by the provider before being forwarded to our web server. The temporary storage of the IP address by the system is necessary to enable the website to be delivered to your end device. This also applies where the delivery takes place via edge servers of the CDN provider. For this purpose, your IP address must remain stored for the duration of the session. This data is evaluated exclusively to ensure the permanent and trouble-free operation of the website and to improve the content of our website, as well as to transmit it to law enforcement authorities in the event of a cyber attack and to ensure the security of our information technology systems, which also constitute our legitimate interest in data"
Within one documentClause A states that consent is required for data processing for statistics and optimization, while Clause B states that data used for these purposes is anonymized, which would typically negate the need for consent for personal data.
" Use of third-party tools for marketing, analysis and optimization purposes When you visit our websites, we process data for marketing purposes, statistics, optimization, and to ensure IT security, in some cases with the support of service providers (so-called third-party tools). We ask for your consent for this processing. Detailed information on the cookies and services used can be found in the settings options of the cookie banner, via the cookie button, which you will find at the bottom left, by clicking on the “Show Details” button. The legal basis for this data processing is §25 (1) TDDDG in conjunction with Art. 6 (1) a) GDPR. In particular, IP address, browser type and version, time zone setting, browser plugin types, geolocation, operating system and version, click behavior, return visits, transaction data, and use of third-party services are processed. The recipients of the data are the providers of the respective third-party tools used, our IT and hosting service providers, and marketing and analysis service providers. The data processed in this way is stored for the duration specified in the cookie banner and then irretrievably deleted. You can revoke your consent to this data processing at any time by adjusting the cookie settings accordingly by clicking the “Cookie Settings” button at the bottom left."
" If you browse our Website, we may collect Traffic and Device Data that your browser sends to us. As a protective measure in favor of privacy, we delete or anonymize the IP address after your visit to our Website. This means that Traffic and Device Data can no longer be traced back to you and is only used for anonymous, statistical purposes to optimize our Website or Services. Our Website may use so-called cookies (i.e. small text files stored in your browser or on your device) and similar tracking technologies such as pixels or scripts, which are used to collect information about how our Website is used ("Cookies"). This information may be processed by us or transmitted to the relevant provider and may include a unique device identifier. Cookies contain information about the current or last visit to our Website (e.g., name of the Website, expiration date of the Cookie, other values). If Cookies do not contain an exact expiration date, they are stored only temporarily and are automatically deleted as soon as you close your browser or restart your device. Cookies with an expiration date will still be stored even when you close your browser or restart your device. Such Cookies will not be deleted until the specified date or if you delete them manually. We may use the following three types of Cookies: (a) Essential Cookies that are required for the functionality of our Website; (b) functional and performance-related Cookies that help us improve your experience; and (c) advertising and analytics Cookies that enable personalized ads and analytics. "
Within one documentClause A states that consent is required for data processing for statistics and optimization, while Clause B states that data used for these purposes is anonymized, which would typically negate the need for consent for personal data.
" Use of third-party tools for marketing, analysis and optimization purposes When you visit our websites, we process data for marketing purposes, statistics, optimization, and to ensure IT security, in some cases with the support of service providers (so-called third-party tools). We ask for your consent for this processing. Detailed information on the cookies and services used can be found in the settings options of the cookie banner, via the cookie button, which you will find at the bottom left, by clicking on the “Show Details” button. The legal basis for this data processing is §25 (1) TDDDG in conjunction with Art. 6 (1) a) GDPR. In particular, IP address, browser type and version, time zone setting, browser plugin types, geolocation, operating system and version, click behavior, return visits, transaction data, and use of third-party services are processed. The recipients of the data are the providers of the respective third-party tools used, our IT and hosting service providers, and marketing and analysis service providers. The data processed in this way is stored for the duration specified in the cookie banner and then irretrievably deleted. You can revoke your consent to this data processing at any time by adjusting the cookie settings accordingly by clicking the “Cookie Settings” button at the bottom left."
" If you browse our Website, we may collect Traffic and Device Data that your browser sends to us. As a protective measure in favor of privacy, we delete or anonymize the IP address after your visit to our Website. This means that Traffic and Device Data can no longer be traced back to you and is only used for anonymous, statistical purposes to optimize our Website or Services. Our Website may use so-called cookies (i.e. small text files stored in your browser or on your device) and similar tracking technologies such as pixels or scripts, which are used to collect information about how our Website is used ("Cookies"). This information may be processed by us or transmitted to the relevant provider and may include a unique device identifier. Cookies contain information about the current or last visit to our Website (e.g., name of the Website, expiration date of the Cookie, other values). If Cookies do not contain an exact expiration date, they are stored only temporarily and are automatically deleted as soon as you close your browser or restart your device. Cookies with an expiration date will still be stored even when you close your browser or restart your device. Such Cookies will not be deleted until the specified date or if you delete them manually. We may use the following three types of Cookies: (a) Essential Cookies that are required for the functionality of our Website; (b) functional and performance-related Cookies that help us improve your experience; and (c) advertising and analytics Cookies that enable personalized ads and analytics. "
Within one documentClause A states that personal information for event attendance is processed solely based on legitimate interests, while Clause B lists both consent and legitimate interests as legal bases for the same activity, creating confusion about user rights and the company's obligations.
"When you attend one of our events or a third party event, we may process your personal information including your name, address, email address and phone number. We process this information because it’s in our legitimate interests to know who’s attending our events and to help promote our business at third party events. Where you attend one of our events we may take pictures or videos of you. We do this as we have a legitimate interest to promote our business. You can opt out of having your photo taken in this way both when you attend our events and at any time by contacting us at [email protected] . When you contact us. When you contact us either by email or via our website or product with general queries, we will usually process your name and contact details, because it’s in our legitimate interest to make sure we can properly respond to your query. On social media. When you connect with us on social media including on Facebook, Twitter, YouTube and LinkedIn we will process your handle, name and email address under our legitimate interest to respond to your comments and queries promptly. When you receive our news updates. We will handle your personal information (such as your name and email address) to provide you with our news updates in line with any preferences you have told us about. When we send you our news updates because you have opted-in to receive them, we rely on your consent to contact you. If you have not opted-in and we send you our news updates emails, we do this because of our legitimate interest to promote our business. "
"6 (1) (b) GDPR) Newsletter & Marketing Contact Data, Professional Data, Communication Data, Marketing Data, Traffic and Device Data Sending relevant updates and promotions to the recipient's interests, Sending newsletters and updates, Registrations and attendance for events, webinars, or seminars Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used), Legitimate interests (Art. 6 (1) (f) GDPR) Manage our Social Media Channels Contact Data, Professional Data, Communication Data, Marketing Data, Traffic and Device Data Operating and maintaining our social media profiles, Communicating with Users and responding to inquiries via social media, Increasing brand awareness and engagement, Analyzing interactions and reach of our social media content Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used), Legitimate interests (Art. 6 (1) (f) GDPR) Security, Compliance & Legal Obligations Contact Data, Professional Data, Communication Data, Account and Usage Data, Traffic and Device Data Ensuring IT and data security, Fulfilling statutory retention requirements, Preventing fraud, Cooperating with authorities, Protecting our rights and interests Compliance (Art. 6 (1) (c) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR) "
Within one documentClause A states that personal information for event attendance is processed solely based on legitimate interests, while Clause B lists both consent and legitimate interests as legal bases for the same activity, creating confusion about user rights and the company's obligations.
"When you attend one of our events or a third party event, we may process your personal information including your name, address, email address and phone number. We process this information because it’s in our legitimate interests to know who’s attending our events and to help promote our business at third party events. Where you attend one of our events we may take pictures or videos of you. We do this as we have a legitimate interest to promote our business. You can opt out of having your photo taken in this way both when you attend our events and at any time by contacting us at [email protected] . When you contact us. When you contact us either by email or via our website or product with general queries, we will usually process your name and contact details, because it’s in our legitimate interest to make sure we can properly respond to your query. On social media. When you connect with us on social media including on Facebook, Twitter, YouTube and LinkedIn we will process your handle, name and email address under our legitimate interest to respond to your comments and queries promptly. When you receive our news updates. We will handle your personal information (such as your name and email address) to provide you with our news updates in line with any preferences you have told us about. When we send you our news updates because you have opted-in to receive them, we rely on your consent to contact you. If you have not opted-in and we send you our news updates emails, we do this because of our legitimate interest to promote our business. "
"6 (1) (b) GDPR) Newsletter & Marketing Contact Data, Professional Data, Communication Data, Marketing Data, Traffic and Device Data Sending relevant updates and promotions to the recipient's interests, Sending newsletters and updates, Registrations and attendance for events, webinars, or seminars Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used), Legitimate interests (Art. 6 (1) (f) GDPR) Manage our Social Media Channels Contact Data, Professional Data, Communication Data, Marketing Data, Traffic and Device Data Operating and maintaining our social media profiles, Communicating with Users and responding to inquiries via social media, Increasing brand awareness and engagement, Analyzing interactions and reach of our social media content Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used), Legitimate interests (Art. 6 (1) (f) GDPR) Security, Compliance & Legal Obligations Contact Data, Professional Data, Communication Data, Account and Usage Data, Traffic and Device Data Ensuring IT and data security, Fulfilling statutory retention requirements, Preventing fraud, Cooperating with authorities, Protecting our rights and interests Compliance (Art. 6 (1) (c) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR) "
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" When content you submit is removed from the forum, whether by you or by the company, the company’s special license ends when the last copy disappears from the company’s backups, caches, and other systems. Other licenses you apply to content you submit, such as Creative Commons licenses, may continue after your content is removed. Those licenses may give others, or the company itself, the right to share your content through the forum again."
Defines when the company's special content license ends — upon removal of the last copy from backups and caches — and acknowledges that third-party licenses applied by users may survive content removal and permit resharing.
AI-generated interpretation, not legal advice.
" Content you submit to the forum belongs to you, and you decide what permission to give others for it. But at a minimum, you license the company to provide content that you submit to the forum to other users of the forum. That special license allows the company to copy, publish, and analyze content you submit to the forum."
Grants the company a special license to copy, publish, and analyze user-submitted content for the purpose of providing it to other forum users, establishing the scope of the platform's content license.
AI-generated interpretation, not legal advice.
" This Privacy Policy, which applies to all Users, is designed to explain why, how we and when we process personal data to offer and provide our Website and Services. It also describes the choices available to you regarding the processing of your personal data. This Privacy Policy is part of, and incorporated into, our Terms of Service. Capitalized terms not defined in this Privacy Policy have the meanings given in our Terms of Service. This Privacy Policy does not apply where separate privacy terms are provided. Our Website and Services may contain links to third-party websites and may integrate third-party functionalities, such as social media plug-ins, tools, or APIs, to enhance your experience. We do not control these third parties or how they process, or use personal data, and their privacy practices may differ from ours. Any personal data you provide or that is processed through such third-party websites or functionalities is governed solely by the respective third party’s privacy policy and terms. We may update this Privacy Policy from time to time without prior notice and immediate effect to reflect legal changes or enhancements to our Website or Services. The latest version is always available on our Website. The "last updated" date indicates if and as of when changes have been made to this Privacy Policy."
Establishes the scope of the Privacy Policy, incorporates it into the Terms of Service, clarifies that capitalized terms are defined therein, and sets out exclusions where separate privacy terms apply; creates a legal cross-reference binding these documents together.
AI-generated interpretation, not legal advice.
" We store your personal information for no longer than necessary for the purposes for which it was processed, including for the purposes of satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data; the potential risk of harm from unauthorized use or disclosure of your personal data; the purposes for which we process your personal data; and the applicable legal requirements. In some circumstances we may carefully anonymise your personal data so that it can no longer be associated with you, and we may use this anonymised information indefinitely without notifying you. We use this anonymised information to analyse our programmes and support other similar programmes around the world."
This segment establishes the obligation to retain personal data no longer than necessary for the purposes for which it was processed, identifies the criteria used to determine retention periods (amount, nature, sensitivity, risk of harm, purposes, legal requirements), and acknowledges that legal obligations and legitimate business interests may require retention, creating binding data minimization and retention obligations.
AI-generated interpretation, not legal advice.
" You agree that the company will be free to act on feedback and suggestions you provide, and that the company won’t have to notify you that your feedback was used, get your permission to use it, or pay you. You agree not to submit feedback or suggestions that you believe might be confidential or proprietary, to you or others."
Grants the company a perpetual, royalty-free right to use, act on, and exploit user-submitted feedback and suggestions without notice, consent, or compensation, effectively transferring any ownership interest in feedback to the company; also restricts users from submitting confidential or proprietary feedback.
AI-generated interpretation, not legal advice.
" You may no longer use the forum if the company contacts you directly to say that you may not."
Restricts continued forum use if the company has directly notified the user that they may not use it, granting the company a unilateral right to revoke access.
AI-generated interpretation, not legal advice.
" Neither the company nor its suppliers will be liable to you for breach-of-contract damages their personnel could not have reasonably foreseen when you agreed to these terms. "
Limits company and supplier liability by excluding breach-of-contract damages that were not reasonably foreseeable by company personnel at the time the user agreed to the terms.
AI-generated interpretation, not legal advice.
"The processing of data for the provision of the website and the storage of data in log files is essential for the operation of our website. Consequently, there is no possibility of objection. The use of the CDN and security service provider also serves the purposes of load balancing, protection against distributed denial-of-service (DDoS) attacks, bot detection, and safeguarding the integrity and confidentiality of our information technology systems. Insofar as personal data is processed by the CDN provider in its own responsibility (e.g., for network security purposes), the provider acts as an independent controller within the meaning of Art. 4 No. 7 GDPR. Where processing is carried out on our behalf, this is based on a data processing agreement pursuant to Art. 28 GDPR."
This segment asserts that log file processing is essential and cannot be objected to, identifies CDN and security service providers as subprocessors used for load balancing, DDoS protection, and bot detection, and clarifies that where the CDN provider processes data in its own responsibility it acts as an independent controller, restricting data subject objection rights and defining the scope of third-party data sharing obligations.
AI-generated interpretation, not legal advice.
" You may not assign your agreement with the company. The company may assign your agreement to any affiliate of the company, any other company that obtains control of the company, or any other company that buys assets of the company related to the forum. Any attempted assignment against these terms has no legal effect."
Prohibits the user from assigning the agreement while permitting the company to assign it to affiliates, successors, or asset purchasers; declares any prohibited assignment void and of no legal effect.
AI-generated interpretation, not legal advice.
" Traffic and Device Data (i.e. technical information generated when you access or use the Website or Services, such as IP address, device and browser type, operating system, language settings, access times, , device identifiers and tokens, instance and user identifiers, system diagnostic data, log files, and related technical and usage metadata, such as HTTP request data, workflow or lifecycle events, feature interactions, and associated usage metrics)."
Defines 'Traffic and Device Data' as a category of personal data processed, specifying technical metadata including IP address, device identifiers, and usage metrics.
AI-generated interpretation, not legal advice.
" If you browse our Website, we may collect Traffic and Device Data that your browser sends to us. As a protective measure in favor of privacy, we delete or anonymize the IP address after your visit to our Website. This means that Traffic and Device Data can no longer be traced back to you and is only used for anonymous, statistical purposes to optimize our Website or Services. Our Website may use so-called cookies (i.e. small text files stored in your browser or on your device) and similar tracking technologies such as pixels or scripts, which are used to collect information about how our Website is used ("Cookies"). This information may be processed by us or transmitted to the relevant provider and may include a unique device identifier. Cookies contain information about the current or last visit to our Website (e.g., name of the Website, expiration date of the Cookie, other values). If Cookies do not contain an exact expiration date, they are stored only temporarily and are automatically deleted as soon as you close your browser or restart your device. Cookies with an expiration date will still be stored even when you close your browser or restart your device. Such Cookies will not be deleted until the specified date or if you delete them manually. We may use the following three types of Cookies: (a) Essential Cookies that are required for the functionality of our Website; (b) functional and performance-related Cookies that help us improve your experience; and (c) advertising and analytics Cookies that enable personalized ads and analytics. "
This segment describes the procedure for handling Traffic and Device Data collected via cookies and similar tracking technologies, including the practice of deleting or anonymizing IP addresses after a website visit so that data is used only for anonymous statistical purposes, and identifies the types of tracking technologies used.
AI-generated interpretation, not legal advice.
"When you attend one of our events or a third party event, we may process your personal information including your name, address, email address and phone number. We process this information because it’s in our legitimate interests to know who’s attending our events and to help promote our business at third party events. Where you attend one of our events we may take pictures or videos of you. We do this as we have a legitimate interest to promote our business. You can opt out of having your photo taken in this way both when you attend our events and at any time by contacting us at [email protected] . When you contact us. When you contact us either by email or via our website or product with general queries, we will usually process your name and contact details, because it’s in our legitimate interest to make sure we can properly respond to your query. On social media. When you connect with us on social media including on Facebook, Twitter, YouTube and LinkedIn we will process your handle, name and email address under our legitimate interest to respond to your comments and queries promptly. When you receive our news updates. We will handle your personal information (such as your name and email address) to provide you with our news updates in line with any preferences you have told us about. When we send you our news updates because you have opted-in to receive them, we rely on your consent to contact you. If you have not opted-in and we send you our news updates emails, we do this because of our legitimate interest to promote our business. "
Describes processing of personal data (name, address, email, phone, photos/videos) at company or third-party events on the basis of legitimate interests, and provides an opt-out right for photo/video capture; establishes processing obligations and data subject rights at events.
AI-generated interpretation, not legal advice.
" Use of third-party tools for marketing, analysis and optimization purposes When you visit our websites, we process data for marketing purposes, statistics, optimization, and to ensure IT security, in some cases with the support of service providers (so-called third-party tools). We ask for your consent for this processing. Detailed information on the cookies and services used can be found in the settings options of the cookie banner, via the cookie button, which you will find at the bottom left, by clicking on the “Show Details” button. The legal basis for this data processing is §25 (1) TDDDG in conjunction with Art. 6 (1) a) GDPR. In particular, IP address, browser type and version, time zone setting, browser plugin types, geolocation, operating system and version, click behavior, return visits, transaction data, and use of third-party services are processed. The recipients of the data are the providers of the respective third-party tools used, our IT and hosting service providers, and marketing and analysis service providers. The data processed in this way is stored for the duration specified in the cookie banner and then irretrievably deleted. You can revoke your consent to this data processing at any time by adjusting the cookie settings accordingly by clicking the “Cookie Settings” button at the bottom left."
This segment states that third-party tools are used for marketing, analytics, and optimization purposes and that consent is obtained as the legal basis (§25(1) TDDDG), granting permission to process data for these purposes subject to prior user consent, and directing users to the cookie banner for detailed information.
AI-generated interpretation, not legal advice.
" Use of our Website Contact Data, Professional Data, Communication Data, Traffic and Device Data Ensuring the technical availability, stability, and security and providing access to our Website, Preventing misuse or attacks, Logging access data for troubleshooting, Conducting surveys and gathering feedback, Analyzing usage of our Website Legitimate interests (Art. 6 (1) (f) GDPR), Contract Performance (Art. 6 (1) (b) GDPR), Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data, Protection Act (TDDDG), insofar Cookies are used) Use, maintenance and improvement of our Services Account and Usage Data Creating, maintaining, and managing User accounts and fulfilling contractual obligations optimizing functionality and stability, correction errors, Analyzing usage of our services, improving services and user experience Legitimate interests (Art. 6 (1) (f) GDPR), Contract Performance (Art. 6 (1) (b) GDPR) Handling Contact and Support Requests Contact Data, Professional Data, Communication Data, Account and Usage Data, Traffic and Device Data Responding to enquiries, support requests, or other forms of communication, Operating internal business processes, Communicating with Users about their accounts or requests, Resolving disputes and managing customer relationships, Maintaining communication records where necessary Legitimate interests (Art. 6 (1) (f) GDPR), Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used) Payment Processing Contact Data, Credit card details or other payment details payment processing, fraud prevention, invoicing and tax compliance Contract Performance (Art. "
Describes the purposes for processing Contact, Professional, Communication, and Traffic and Device Data for website use, identifies legitimate interests, contract performance, and consent as GDPR legal bases; creates obligations and permissions tied to specific lawful processing grounds.
AI-generated interpretation, not legal advice.
"6 (1) (b) GDPR) Newsletter & Marketing Contact Data, Professional Data, Communication Data, Marketing Data, Traffic and Device Data Sending relevant updates and promotions to the recipient's interests, Sending newsletters and updates, Registrations and attendance for events, webinars, or seminars Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used), Legitimate interests (Art. 6 (1) (f) GDPR) Manage our Social Media Channels Contact Data, Professional Data, Communication Data, Marketing Data, Traffic and Device Data Operating and maintaining our social media profiles, Communicating with Users and responding to inquiries via social media, Increasing brand awareness and engagement, Analyzing interactions and reach of our social media content Consent (Art. 6 (1) (a) GDPR; Section 25 (1) German Telecommunications and Digital Services Data Protection Act (TDDDG), insofar Cookies are used), Legitimate interests (Art. 6 (1) (f) GDPR) Security, Compliance & Legal Obligations Contact Data, Professional Data, Communication Data, Account and Usage Data, Traffic and Device Data Ensuring IT and data security, Fulfilling statutory retention requirements, Preventing fraud, Cooperating with authorities, Protecting our rights and interests Compliance (Art. 6 (1) (c) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR) "
Describes newsletter and marketing data processing purposes, identifies consent and legitimate interests as GDPR legal bases, and covers social media channel management; establishes lawful processing obligations and conditions for marketing communications.
AI-generated interpretation, not legal advice.
" Every time you visit our website, we automatically store access data in so-called server log files.The legal basis for the temporary storage of your data and the log files is Art. 6 (1) lit. f GDPR. This includes the date and time of the visit, the amount of data transferred and, if applicable, the name of the requested file, the browser used and its version, the operating system used, the IP address and the referrer URL (the URL you visited immediately before). The temporary storage of the IP address by the system is necessary to enable the website to be delivered to your end device. For this purpose, your IP address must remain stored for the duration of the session. Our website uses a content delivery network (CDN) and security service provider (category of recipient: IT infrastructure and security service provider). For this purpose, incoming requests are routed via the provider’s globally distributed edge servers (reverse proxy). In this context, access data - in particular IP address, request header information, and browser data - may already be processed by the provider before being forwarded to our web server. The temporary storage of the IP address by the system is necessary to enable the website to be delivered to your end device. This also applies where the delivery takes place via edge servers of the CDN provider. For this purpose, your IP address must remain stored for the duration of the session. This data is evaluated exclusively to ensure the permanent and trouble-free operation of the website and to improve the content of our website, as well as to transmit it to law enforcement authorities in the event of a cyber attack and to ensure the security of our information technology systems, which also constitute our legitimate interest in data"
This segment identifies the legal basis (Art. 6(1)(f) GDPR) for storing access data in server log files, enumerates the categories of data collected (date/time, data transferred, browser, OS, IP address, referrer URL), and explains the necessity of temporary IP address storage for website delivery, establishing an obligation to process and temporarily retain this data on the stated lawful basis.
AI-generated interpretation, not legal advice.
" When you register for n8n cloud. When you sign up for an account with us, we process your name and email. We process these details to put the contract in place between us that enables you to access our platform. The legal basis for this data processing is Art. 6(1)(b) GDPR. We use third party providers in order to better understand how people use our product and to optimize our service and experience. Additional data including address and credit card information will be processed by our Merchant of Record in order to process your payment We do not transfer or disclose your information to third parties for purposes other than the ones provided. You can delete your n8n cloud account via the product. You can learn more about the data we process on cloud in our Documentation. When you use your own n8n self-hosted deployment. If you install n8n on your own server, and unless you opt out per our Documentation instructions at https://docs.n8n.io/hosting/securing/telemetry-opt-out/ , we process certain Usage Data (including user identifiers, account settings, user events, workflow usage metrics, enabled integrations) to improve our product and your customer experience. If you chose to submit your email address, we may use it to contact you about your usage of the product. Learn more on our privacy page about data collection . The legal basis for this data processing is our legitimate interests in the technical development of our products, the optimization of functionality and stability, error analysis and correction, and the improvement of the user experience on the basis of Art. "
Describes data processing at cloud account registration (name, email, payment data) under Art. 6(1)(b) GDPR, discloses use of third-party providers for product analytics, and discloses the Merchant of Record's role in payment processing; establishes processing obligations and subprocessor disclosure.
AI-generated interpretation, not legal advice.
" You can unsubscribe from our updates at any time by clicking the unsubscribe link at the bottom of any of our emails, or by emailing [email protected] . When you register as an expert. We process your name, email address, and details about your company in order to communicate with you about the n8n expert program When you register as an affiliate . We process your name and email address in order to communicate with you about the n8n affiliate program. When you apply for a job with us. When you enter into the recruitment process with us we may process your personal data as set forth in our n8n Privacy Policy for Recruiting https://n8n.io/legal/recruiting-privacy-policy /. If our business is sold. We process your personal information for this purpose because we have a legitimate interest to ensure our business can be continued by the buyer. If you object to our use of your personal information in this way, the buyer of our business may not be able to provide services to you."
Grants users the right to unsubscribe from marketing communications at any time; also describes processing of data for expert and affiliate program registration and job applications.
AI-generated interpretation, not legal advice.
Common questions about n8n's policies
- Does n8n train its AI models on your data?
- No training on your content by default — based on 3 verified findings from n8n's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from n8n's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
12 verified clausesClauses in n8n's policies that work in your favour — commitments the platform made to you.
- Model trainingdoes-not-train
“6 (1) lit. f GDPR. You can object to this data processing at any time with effect for the future by activating the opt-out, see our Docs page about telemetry data opt out . If you sign up for a paid plan , we process your name, email address, company address,…”
Details processing of name, email, company and billing contact data for paid plans under contract performance, discloses Paddle as the Merchant of Record for credit card billing, identifies the telemetry data opt-out rig…
📍 Privacy Policy › “Purpose Personal Data Description Legal Basis”Jump to exact text → - Audit rights, DPA & residency
“Such disclosures are carried out strictly in accordance with applicable legal provisions. Where legally permissible, we aim to ensure transparency towards data subjects. Some of the recipients listed above may be located outside the European Union (EU) or the…”
This segment obligates that disclosures to third parties comply with applicable legal provisions, identifies that some recipients are outside the EU/EEA, and requires that international transfers comply with GDPR Article…
📍 § 8 (Disclosure of Personal Data; International Transfers)Jump to exact text → - Privacy & data useproduct telemetry/usage tracking
“Due to legal requirements, our website provides information that enables you to contact us quickly and communicate with us directly. This includes both our email address and our contact form. If you contact us by email or via our contact form, the personal dat…”
This segment establishes the legal basis (Art. 6(1)(b) GDPR) for processing personal data submitted via email or contact form, identifies the categories of data collected, and states the purposes (contract performance, m…
📍 § 6 (Email and contact form)Jump to exact text → - Model trainingdoes-not-train
“We do not make decisions about you that are based solely on automated processing (including profiling) and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. If we were to introduce such auto…”
This segment disclaims that the organization does not make solely automated decisions with legal or similarly significant effects under Art. 22 GDPR, states that if such processing were introduced safeguards would be pro…
📍 § 10 (Automated Decision-Making and Profiling; Use of AI)Jump to exact text → - Privacy & data use
“You can contact us at any time if you have any questions about your rights regarding data protection or if you wish to exercise any of the following rights: Right to withdraw your consent (Art. 7 (3) GDPR); Right to access your data (Art. 15 GDPR); Right to…”
This segment enumerates the full set of data subject rights under GDPR (withdrawal of consent, access, rectification, erasure, restriction, portability, objection, complaint to supervisory authority) and provides the pro…
📍 § 12 (What are my rights under data protection laws?)Jump to exact text → - Privacy & data usebreach notification promises
“If you have any questions about this privacy notice, including requests to exercise your data subject rights , please contact us at [email protected] . Your request may be processed by automated means and forwarded to the relevant teams in order to fulfil it.…”
Provides the procedure for users to submit data subject rights requests and contact the Data Protection Officer, including that requests may be processed by automated means; establishes the operational process for exerci…
- Designated security contact: [email protected] (DPO contact); postal address at https://freshcompliance.de/en/legal-notice/
📍 Privacy Policy › “Germany”Jump to exact text →
+ 6 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
21 verified clausesWhat n8n requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcement
“You agree to be responsible for all action taken using your account, whether authorized by you or not, until you either close your account or notify the company that your account has been compromised. You agree to notify the company immediately if you suspect…”
Imposes obligations on the user to be responsible for all account activity, notify the company of compromise, and maintain a secure password, establishing account security duties.
📍 Terms of Service › “Your Account”Jump to exact text → - Moderation & enforcementconduct restrictions
“You may not automate access to the forum, or monitor the forum, such as with a web crawler, browser plug-in or add-on, or other computer program that is not a web browser. You may crawl the forum to index it for a publicly available search engine, if you run o…”
Restricts automated access and monitoring of the forum, while carving out an exception permitting crawling for publicly available search engine indexing.
📍 Terms of Service › “Acceptable Use”Jump to exact text → - Moderation & enforcementconduct restrictions
“You may not send advertisements, chain letters, or other solicitations through the forum, or use the forum to gather addresses or other personal data for commercial mailing lists or databases.”
Prohibits sending advertisements, chain letters, solicitations, or harvesting personal data for commercial mailing lists through the forum, restricting commercial exploitation of the platform.
📍 Terms of Service › “Acceptable Use”Jump to exact text → - Moderation & enforcementconduct restrictions
“You may not strain infrastructure of the forum with an unreasonable volume of requests, or requests designed to impose an unreasonable load on information systems underlying the forum.”
Prohibits placing unreasonable load on the forum's infrastructure through excessive requests, protecting system availability.
📍 Terms of Service › “Acceptable Use”Jump to exact text → - Moderation & enforcementconduct restrictions
“You may not submit content to the forum that violates the law, infringes anyone’s intellectual property rights, violates anyone’s privacy, or breaches agreements you have with others.”
Prohibits submitting content that violates law, infringes intellectual property rights, violates privacy, or breaches third-party agreements, imposing multiple legal compliance restrictions.
📍 Terms of Service › “Content Standards”Jump to exact text →
+ 16 more verified clauses of this kind on this platform, cited in full in the report.
What the policies actually cover
15 topics- Product telemetry & usage tracking1 protective6 clauses
- Advertising & tracking1 protective6 clauses
- Sale or sharing of personal data1 clause
- Children's data1 clause
- Government & law-enforcement disclosure1 clause
- Does not train on your content3 protective3 clauses
- Arbitration & class-action waiver1 protective2 clauses
- Damages & liability cap2 clauses
- Indemnity direction1 clause
- Terms can change at any time1 protective3 clauses
- Deletion rights & post-termination survival2 clauses
- License survival after account deletion1 clause
- Feedback ownership1 clause
- Breach-notification promises1 protective1 clause
- Conduct restrictions11 obligations11 clauses
42 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, § 11 (How long do we keep your data for?) addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Purpose Personal Data Description Legal Basis” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
The Terms of Service, Terms of Service › “Your Content” describes rights the platform takes in user content, and the Privacy Policy, § 5 (Data processing for payment processing) describes disclosure of data to third parties or subprocessors. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Other than to seek an injunction or for claims under the Computer Fraud and Abuse Act, you and the company will resolve any dispute by binding American Arbitration Association arbitration. Arbitration will follow the AAA’s Commercial Arbitration Rules and Supplementary Procedures for Consumer Related Disputes. Arbitration will happen in Berlin, Germany. You will settle any dispute as an individual, and not as part...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | conditional | MEDIUM | 2 |
| All applicable tiers | data retention | conditional | MEDIUM | 2 |
| All applicable tiers | governing law disputes | conditional | MEDIUM | 6 |
| All applicable tiers | indemnity liability | conditional | MEDIUM | 2 |
| All applicable tiers | privacy data use | conditional | MEDIUM | 2 |
| All applicable tiers | training use | improves | LOW | 4 |
| Pro / Paid | training use | conditional | MEDIUM | 4 |
| Team / Business | commercial use | conditional | MEDIUM | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: arbitration or waiver on governing law disputes
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open timeline citation
Latest stance: arbitration or waiver on governing law disputes
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open timeline citation
Latest stance: arbitration or waiver on governing law disputes
“Any arbitration award will include costs of the arbitration, reasonable attorneys’ fees, and reasonable costs for witnesses. You and the company may enter arbitration awards in any court with jurisdiction.”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“We use an external payment service provider for the processing of online payments and, where applicable, invoicing and tax handling for digital products. The legal basis for the processing of personal data is Art. 6 (1) b) GDPR, as the processing is necessary for the implementation of pre-contractual measures and for the performance of a contract. This includes, in particular, name, email address, billing address, payment information (e.g., credit card details or other payment details), IP address, transaction data, and, where applicable, company-related information. The processing is carried out for the purpose of payment processing, fraud prevention, invoicing and tax compliance (e.g., VAT determination) The payment service provider may act as an independent controller within the meaning of Art. 4 No. 7 GDPR, in particular where it processes payment data in its own name as a so-called “merchant of record.” The payment service provider may also process personal data in order to comply with legal obligations (e.g., commercial and tax law retention requirements) and for fraud prevention or the assertion and defense of legal claims. Personal data will only be disclosed to third parties if this is necessary for contract processing, required by law, or carried out within the framework of commissioned data processing. The storage period for personal data is determined by statutory retention obligations and contractual requirements. Data relevant under commercial and tax law is generally stored for the duration of the applicable statutory retention periods.”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“We may share personal data with carefully selected service providers that support our business operations. These include, in particular, providers of IT hosting and infrastructure services (e.g. cloud hosting and content delivery networks), cybersecurity and fraud prevention solutions, data storage and backup services, website analytics and performance monitoring tools, marketing and advertising platforms, subscription management, billing and revenue analytics systems, payment processing services, as well as customer relationship management software, internal collaboration and productivity tools, document management systems, and customer support and communication services (e.g. ticketing systems, live chat and email services). Where such service providers process personal data on our behalf, we conclude data processing agreements pursuant to Article 28 GDPR, ensuring that personal data is processed solely in accordance with our instructions and in compliance with applicable data protection standards. In some cases, third parties process personal data as independent controllers or joint controllers, in particular in the context of advertising and social media services. We may disclose personal data where required by law or where such disclosure is necessary to comply with legal obligations or lawful requests by public authorities, courts, or law enforcement agencies, enforce our commercial contracts or other agreements, investigate potential violations, prevent or address fraud, security, or technical issues, or protect our rights, property, users, or the public.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“This Privacy Policy, which applies to all Users, is designed to explain why, how we and when we process personal data to offer and provide our Website and Services. It also describes the choices available to you regarding the processing of your personal data. This Privacy Policy is part of, and incorporated into, our Terms of Service. Capitalized terms not defined in this Privacy Policy have the meanings given in our Terms of Service. This Privacy Policy does not apply where separate privacy terms are provided. Our Website and Services may contain links to third-party websites and may integrate third-party functionalities, such as social media plug-ins, tools, or APIs, to enhance your experience. We do not control these third parties or how they process, or use personal data, and their privacy practices may differ from ours. Any personal data you provide or that is processed through such third-party websites or functionalities is governed solely by the respective third party’s privacy policy and terms. We may update this Privacy Policy from time to time without prior notice and immediate effect to reflect legal changes or enhancements to our Website or Services. The latest version is always available on our Website. The "last updated" date indicates if and as of when changes have been made to this Privacy Policy.”Open timeline citation
Latest stance: third party or vendor sharing on data retention
“When you register for n8n cloud. When you sign up for an account with us, we process your name and email. We process these details to put the contract in place between us that enables you to access our platform. The legal basis for this data processing is Art. 6(1)(b) GDPR. We use third party providers in order to better understand how people use our product and to optimize our service and experience. Additional data including address and credit card information will be processed by our Merchant of Record in order to process your payment We do not transfer or disclose your information to third parties for purposes other than the ones provided. You can delete your n8n cloud account via the product. You can learn more about the data we process on cloud in our Documentation. We may derive de-identified data sets from your Customer Content and use such derived data to operate, enhance, improve, and develop n8n features and Cloud Services. The legal basis for this data processing is our legitimate interests in the technical development of our products, the optimization of functionality and the improvement of the user experience on the basis of Art. 6 (1) lit. f GDPR. When you use your own n8n self-hosted deployment. If you install n8n on your own server, and unless you opt out per our Documentation instructions at https://docs.n8n.io/hosting/securing/telemetry-opt-out/ , we process certain Usage Data (including user identifiers, account settings, user events, workflow usage metrics, enabled integrations) to improve our product and your customer experience.”Open timeline citation
Latest stance: third party or vendor sharing on training use
“If you chose to submit your email address, we may use it to contact you about your usage of the product. Learn more on our privacy page about data collection . The legal basis for this data processing is our legitimate interests in the technical development of our products, the optimization of functionality and stability, error analysis and correction, and the improvement of the user experience on the basis of Art. 6 (1) lit. f GDPR. You can object to this data processing at any time with effect for the future by activating the opt-out, see our Docs page about telemetry data opt out . If you sign up for a paid plan , we process your name, email address, company address, and the name and email address of others in your company (e.g. a billing contact). We process these details to put a contract in place between us. If you use our credit card billing feature, our Merchant of Record, Paddle, processes information including your address and credit card information, in order to process your payment. In addition, we process selected, anonymous information about how n8n is used. We use this information to improve your experience with our services and to protect from potential security attacks and abuse. We do not use any personal data, including data received through any third-party services, for developing, improving, or training AI and/or ML models. We do not transfer or disclose your information to third parties for purposes other than the ones provided.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-08-28· verified 2026-08-28
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 95 more findings this quarter vs last (183 vs 88). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of n8n's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from n8n's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.