Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · napkin.ai

Napkin AI

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskMEDReviewed 2026-08-31
Creator: medium · GRC: medium · Counsel: medium
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Terms of Service · verbatim

7.1.3 Where the Customer has not opted out, Napkin AI may use: (a) anonymized and aggregated interaction data, from which all personal identifiers have been removed; and (b) de-identified content data (visual and diagram content from which all personally identifiable information has been removed), solely for the purpose of improving the Services and Napkin

highest-risk verified finding on training use — tap for the citation
258 verified findings10 policy surfaces2/2 core docs verified
Risk triage

Watch: audit rights dpa residency

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
52
medium
173
low
2/2
docs
Trains on your data?
Training possible — conditions or opt-outs apply
from 6 cited findings
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Napkin AI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Privacy Policy
    Verified - read in full - 85 citationsstaticLast captured 2026-08-31
  • Terms of Service
    Verified - read in full - 173 citationsstaticLast captured 2026-08-17
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Training on your content

Grants the Customer the right to opt out of all non-essential data use; upon exercise of that opt-out, obligates Napkin AI to process Customer Personal Data solely for service delivery and prohibits use of any Customer interaction data beyond service delivery, with opt-out to be honored within two business days — user-favorable restriction on data use.

" 7.1.2 Napkin AI provides Customers with a mechanism to opt out of all non-essential data use. Where the Customer exercises such opt-out (via Account Settings, Teamspace settings), Napkin AI shall process Customer Personal Data solely to de..."
plan language
Privacy & data use

Defines 'public sources' as a third-party source category including government agencies, public records, and social media platforms from which Napkin may obtain personal information.

" Public sources , such as government agencies, public records, social media platforms, and other publicly available sources."
📍 Privacy Policy › “Personal information we collect”Jump to exact text →
plan language
Privacy & data use

Grants the Customer the right to opt out of all non-essential data use via Account or Teamspace settings, requiring Napkin AI to process Customer Personal Data solely for service delivery within two business days of the opt-out request.

" 7.1.2 Napkin AI provides Customers with a mechanism to opt out of all non-essential data use. Where the Customer exercises such opt-out (via Account Settings, Teamspace settings), Napkin AI shall process Customer Personal Data solely to de..."
plan language
Privacy & data use

Permits use of personal information for service analytics, improvement of the Service and business, user activity analysis, and development of new products, establishing a broad lawful processing purpose for analytics-driven use.

" Service improvement and analytics. We may use your personal information to analyze your usage of the Service, improve the Service, improve the rest of our business, help us understand user activity on the Service, including which pages are..."
📍 Privacy Policy › “How we use your personal information”Jump to exact text →
plan language
Privacy & data use

Introduces automatic data collection by Napkin, its service providers, and business partners, defining the scope of parties involved and the categories of automatically logged information about users and their devices.

" Automatic data collection. We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interaction over time with the Service, our communications and other onli..."
📍 Privacy Policy › “Personal information we collect”Jump to exact text →
plan language
Privacy & data use

Permits use of personal information for research and development, including creating aggregated, de-identified, or anonymized data derived from personal information, and sharing such data with third parties for lawful business purposes — directly relevant to training use and data transformation rights.

" Research and development. We may use your personal information for research and development purposes, including to analyze and improve the Service and our business and to develop new products and services. As part of these activities, we m..."
📍 Privacy Policy › “How we use your personal information”Jump to exact text →
plan language
Privacy & data use

Grants the company permission to use personal information to provide, operate, and improve the Service and business, defining a lawful processing purpose.

" provide, operate and improve the Service and our business;"
📍 Privacy Policy › “How we use your personal information”Jump to exact text →
plan language
Privacy & data use

Discloses that Napkin AI has not received government intelligence or security agency requests for Customer Personal Data and obligates Napkin AI, upon receiving any such future request, to notify the Customer to the extent permitted by law, use reasonable efforts to redirect the agency to request data directly from the Customer, and provide reasonable notice — user-favorable procedural protection.

" 5.5 Government Agency Requests. As of the Effective Date of this DPA, Napkin AI (and Second Layer, Inc.) has not received any formal legal requests from any government intelligence or security agency for access to Customer Personal Data. I..."

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 52
Tier-specific - 0
Total citations - 258
Severity
Surface
Document
Tier
Privacy & data use
High
" Your profile information may be visible to other users when you collaborate or share content. We do not make your personal information publicly available without your explicit choice to share it."
Privacy Policy › “OpenAI and Gemini (AI-powered generation and processing services)”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts the company from making personal information publicly available without the user's explicit choice to share it, while noting that profile information may be visible to collaborators, creating a conditional visibility rule.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"We currently do not respond to "Do Not Track" or similar signals. To find out more about "Do Not Track," please visit http://www.allaboutdnt.com ."
Privacy Policy › “Your choices”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Ignoring DNT signals is legal in most jurisdictions but reduces user control over tracking. Some U.S. state privacy laws (e.g., Colorado, Connecticut) require honoring universal opt-out signals, which may create compliance risk for the platform and uncertainty for users.

AI-generated interpretation, not legal advice.

Data retention
High
" 11.4 Where fulfilment of a data return or deletion request under Section 11.2 requires manual work exceeding two (2) person-hours, Napkin AI may charge the Customer its reasonable, documented costs at then-current professional services rates, except where such charges are prohibited by Applicable Data Protection Laws."
Source: Terms of Service- Snapshot 2026-06-10- View source
Permalink to this finding →
Automated analysis

This clause creates an exception allowing Napkin AI to charge the Customer reasonable documented costs for manual data return or deletion work exceeding two person-hours, except where such charges are prohibited by Applicable Data Protection Laws.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" 10.1 Each party’s total aggregate liability to the other party under or in connection with this DPA shall be subject to the liability limitations and caps set out in the Agreement. For the avoidance of doubt, the DPA is part of the Agreement for the purposes of any liability cap."
Source: Terms of Service- Snapshot 2026-06-10- View source
Permalink to this finding →
Automated analysis

This clause limits each party's total aggregate liability under the DPA to the caps established in the main Agreement, and incorporates the DPA into the Agreement for purposes of applying those liability caps.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
"Service providers. Third parties that provide services on our behalf or help us operate the Service or our business, such as: Google Cloud Platform (hosting and infrastructure) Intercom (customer support and communication) Sendgrid and Mailmodo (email delivery) Sentry (error and performance monitoring) Google Analytics (product analytics) OpenAI and Gemini (AI-powered generation and processing services) These service providers process personal data only on our instructions and under strict confidentiality agreements."
Privacy Policy › “How we share your personal information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Passing user-generated content (including prompts) to OpenAI and Gemini means those providers' own terms and privacy policies may govern how that data is used. Napkin's assertion of 'strict confidentiality agreements' does not eliminate the risk of downstream training or data retention by those providers under their own terms.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Linked third-party platforms. If you choose to connect to the Service through your social media account or other third-party platform, you may be able to use your settings in your account with that platform to limit the information we receive from it. If you revoke our ability to access information from a third-party platform, that choice will not apply to information that we have already received from that third party."
Privacy Policy › “Your choices”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Restricts retroactive effect of user revocation of third-party platform access rights, clarifying that previously received information from that platform is not subject to the revocation, limiting the scope of the user's opt-out right.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" 3.6.2 Napkin AI may satisfy the audit obligations under this Section 3.6 by providing the Customer with a current SOC 2 Type II report or equivalent third-party audit report, subject to the Customer’s written agreement to maintain such report as confidential."
Source: Terms of Service- Snapshot 2026-06-10- View source
Permalink to this finding →
Automated analysis

Permits Napkin AI to satisfy audit obligations by providing a current SOC 2 Type II or equivalent third-party report as an alternative to a direct audit, conditioned on the Customer agreeing in writing to maintain the report as confidential.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
"We are based in the United States and our data is currently hosted on secure cloud infrastructure based in the United States. This means that if you use the Service, your personal information will be transferred to and processed in the United States."
Privacy Policy › “International data transfers”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Processing personal data in the U.S. creates compliance obligations for EU/UK/other jurisdiction users under GDPR and similar laws. No mention of transfer mechanisms (SCCs, etc.) is made in this section, which is a notable gap.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
"We may use service providers that operate in various countries, and your personal information may be transferred to locations where privacy laws may differ from those in your jurisdiction."
Privacy Policy › “International data transfers”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

This broad transfer clause does not specify which countries data may be sent to or what legal mechanisms (e.g., Standard Contractual Clauses, adequacy decisions) are used to legitimize transfers, which is a gap relevant to GDPR, UK GDPR, and similar frameworks.

AI-generated interpretation, not legal advice.

Training on your content
High
" 7.1.3 Where the Customer has not opted out, Napkin AI may use: (a) anonymized and aggregated interaction data, from which all personal identifiers have been removed; and (b) de-identified content data (visual and diagram content from which all personally identifiable information has been removed), solely for the purpose of improving the Services and Napkin AI’s AI models (“Model Improvement Processing”). Such use shall not re-identify any individual or Customer."
Source: Terms of Service- Snapshot 2026-06-10- View source
Permalink to this finding →
Automated analysis

Permits Napkin AI, where the Customer has not opted out, to use anonymized aggregated interaction data and de-identified content data solely for improving the Services and Napkin AI's AI models, provided no re-identification of any individual or Customer occurs.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Teamspace content: If you create content within a Teamspace, other Teamspace members may have access to that content as determined by the Teamspace Administrator."
Privacy Policy › “OpenAI and Gemini (AI-powered generation and processing services)”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes that content created within a Teamspace is accessible to other Teamspace members as determined by the Teamspace Administrator, imposing a data-sharing rule governed by administrator settings.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection."
Privacy Policy › “Personal information we collect”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Catch-all provision defining an open-ended category of personal information not otherwise listed, with a forward-reference to uses described elsewhere in the policy, creating a broad definitional scope for data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Device data , such as your computer or mobile device's operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers, language settings, mobile device carrier, radio/network information (e.g., Wi-Fi, LTE, 3G), and general location information such as city, state or geographic area."
Privacy Policy › “Personal information we collect”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Defines 'device data' as a specific category of automatically collected personal information including hardware, software, IP address, and location data, specifying the technical scope of device-level data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Communication interaction data such as your interactions with our email, text or other communications (e.g., whether you open our emails) – we may do this through the use of pixel tags (which are also known as clear GIFs), which may be embedded invisibly in our emails."
Privacy Policy › “Personal information we collect”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Defines 'communication interaction data' as a category of automatically collected data including email open tracking via pixel tags, disclosing the use of tracking technologies embedded in communications.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Declining to provide information. We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services."
Privacy Policy › “Your choices”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Establishes that providing required personal information is a condition of receiving certain services, and that failure to provide mandatory information may result in inability to provide those services, creating a conditional data-collection obligation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We employ a number of technical, organizational and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal information."
Privacy Policy › “Security”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Disclaims any guarantee of security for personal information despite implemented safeguards, acknowledging inherent risk in internet technologies and limiting the company's liability for security breaches.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Third-party sources. We may combine personal information we receive from you with personal information we obtain from other sources, such as:"
Privacy Policy › “Personal information we collect”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Introduces third-party sources from which Napkin may combine personal information with data collected directly from users, establishing the legal basis for data aggregation and the categories of external sources involved.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Marketing. We, our service providers and our third-party advertising partners may collect and use your personal information for the following marketing purposes:"
Privacy Policy › “How we use your personal information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-06-07- View source
Permalink to this finding →
Automated analysis

Permits the company, its service providers, and third-party advertising partners to collect and use personal information for marketing purposes, identifying the parties involved and the lawful processing purpose.

AI-generated interpretation, not legal advice.

Common questions about Napkin AI's policies

Does Napkin AI train its AI models on your data?
Training possible — conditions or opt-outs apply — based on 6 verified findings from Napkin AI's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Napkin AI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

70 verified clauses

Clauses in Napkin AI's policies that work in your favour — commitments the platform made to you.

  • Audit rights, DPA & residency
    12.3 Amendments. Napkin AI may update this DPA from time to time. For changes required by applicable law or that expand privacy protections for Customers, updates take effect immediately upon publication at https://www.napkin.ai/data-processing-agreement/ . Fo…

    This clause establishes the amendment procedure for the DPA, distinguishing between immediate-effect changes required by law or expanding privacy protections and material changes (adding new data categories, new purposes…

    • Terms changes: advance notice promised
  • Audit rights, DPA & residency
    5.2 UK Transfers. To the extent that Napkin AI Processes UK Personal Data and transfers such data outside the United Kingdom, the parties agree that such transfers are governed by the UK IDTA. The UK IDTA is hereby incorporated into this DPA by reference, with…

    Incorporates the UK International Data Transfer Agreement into the DPA by reference for UK Personal Data transfers, specifying how each Table of the UK IDTA is completed by reference to existing DPA annexes and the EU SC…

  • Privacy & data usechildren's data
    4.2 The Customer shall be solely responsible for the accuracy, quality, and lawfulness of Customer Personal Data provided to Napkin AI. The Customer shall not submit to the Services any special category personal data (as defined in Article 9 GDPR) or criminal…

    Places sole responsibility on the Customer for accuracy, quality, and lawfulness of Customer Personal Data; restricts submission of special category or criminal conviction data without prior written agreement with Napkin…

  • Subprocessors & data sharinggovernment/law-enforcement disclosure
    5.5 Government Agency Requests. As of the Effective Date of this DPA, Napkin AI (and Second Layer, Inc.) has not received any formal legal requests from any government intelligence or security agency for access to Customer Personal Data. If Napkin AI receives…

    Discloses that no government agency requests for Customer Personal Data have been received as of the Effective Date, and obliges Napkin AI to notify the Customer, redirect government agencies to the Customer, and provide…

  • Subprocessors & data sharing
    3.3.1 The Customer grants Napkin AI general written authorization to engage the Sub-Processors listed in Annex 2 and at https://www.napkin.ai/sub-processors . Napkin AI shall provide at least ten (10) calendar days' prior notice of any intended addition or rep…

    Grants Napkin AI general written authorization to engage listed Sub-Processors and establishes the procedure for notifying the Customer of additions or replacements, including a 10-day advance notice requirement and subs…

  • Subprocessors & data sharingsale/sharing of personal data
    8.2 Service Provider Designation. For purposes of the CCPA/CPRA, Napkin AI is a “service provider” and “contractor” with respect to Customer Personal Data. Napkin AI shall not: (a) sell or share Customer Personal Data (as those terms are defined under CCPA/CPR…

    This clause designates Napkin AI as a 'service provider' and 'contractor' under CCPA/CPRA and imposes specific restrictions prohibiting Napkin AI from selling, sharing, retaining, using, or disclosing Customer Personal D…

+ 64 more verified clauses of this kind on this platform, cited in full in the report.

📋 Rules you must follow

1 verified clause

What Napkin AI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

  • Moderation & enforcement
    4.3 The Customer shall implement appropriate technical and organizational measures to secure Customer’s own systems, credentials, and any software integrations used to access the Services.

    Obliges the Customer to implement appropriate technical and organizational measures to secure its own systems, credentials, and software integrations used to access the Services.

What the policies actually cover

14 topics
  • Product telemetry & usage tracking17 clauses
  • Advertising & tracking1 protective8 clauses
  • Sale or sharing of personal data2 protective2 clauses
  • Sensitive data (biometric, location, health)1 clause
  • Children's data2 protective2 clauses
  • Government & law-enforcement disclosure1 protective4 clauses
  • Data shared with other AI providers2 protective4 clauses
  • Does not train on your content3 protective3 clauses
  • Trains by default, opt-out available1 clause
  • Damages & liability cap1 protective3 clauses
  • Indemnity direction4 protective8 clauses
  • Terms can change at any time1 clause
  • Deletion rights & post-termination survival3 protective8 clauses
  • Breach-notification promises7 protective8 clauses

188 further verified clauses are cited on this page but not yet assigned a topic.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Terms of Service, § 11.4 addresses how long content is retained, and the Terms of Service, § 7.1.3 addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Ambiguity — Cautionacross documents

Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Retention” describes broad or open-ended retention, while the Terms of Service, § 11.4 describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

515
clauses
52
patterns
52
stances
privacy sharing · 35training use · 8data retention · 5ip ownership · 2legal burden · 1tier conditionality · 1
data retentionMEDIUMPrivacy Policy › “Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the...
Open source citation
data retentionMEDIUMPrivacy Policy › “Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the...
Open source citation
data retentionMEDIUMPrivacy Policy › “Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the...
Open source citation
data retentionMEDIUMPrivacy Policy › “Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the...
Open source citation
data retentionMEDIUMPrivacy Policy › “Retention”

The clause allows indefinite, perpetual, or necessity-based retention.

We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersdata retentionconditionalMEDIUM5
All applicable tiersindemnity liabilityconditionalMEDIUM1
All applicable tiersprivacy data useconditionalMEDIUM19
All applicable tierssubprocessors data sharingconditionalMEDIUM4
All applicable tierstraining useimprovesLOW4
Team / Businessdata retentionworsensHIGH2
Team / Businessmoderation enforcementworsensHIGH1
Team / Businessprivacy data useworsensHIGH9
Team / Businesssubprocessors data sharingconditionalMEDIUM1
Team / Businesstier differencesconditionalMEDIUM1
Team / Businesstraining useconditionalMEDIUM3

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

improvedhigh materialityAug 17Aug 31, 2026

data sharing improved from high/sale or sell to medium/third party or vendor sharing.

Before · high
8.2 Service Provider Designation. For purposes of the CCPA/CPRA, Napkin AI is a “service provider” and “contractor” with respect to Customer Personal Data. Napkin AI shall not: (a) sell or share Customer Personal Data (as those terms are defined under CCPA/CPRA); (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement; or (c) combine Customer Personal Data received from the Customer with personal information received from other sources except as permitted by U.S. Privacy Laws.
Before citation
After · medium
We may use service providers that operate in various countries, and your personal information may be transferred to locations where privacy laws may differ from those in your jurisdiction.
After citation
worsenedhigh materialityAug 5Aug 17, 2026

data sharing worsened from medium/third party or vendor sharing to high/sale or sell.

Before · medium
Third parties designated by you. We may share your personal information with third parties where you have instructed us or provided your consent to do so, such as when you share content with collaborators, or connect third-party services. We only share information that is needed for these other companies to provide the services that you have requested.
Before citation
After · high
8.2 Service Provider Designation. For purposes of the CCPA/CPRA, Napkin AI is a “service provider” and “contractor” with respect to Customer Personal Data. Napkin AI shall not: (a) sell or share Customer Personal Data (as those terms are defined under CCPA/CPRA); (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA and the Agreement; or (c) combine Customer Personal Data received from the Customer with personal information received from other sources except as permitted by U.S. Privacy Laws.
After citation
improvedhigh materialityJun 17Jul 20, 2026

model training improved from high/training permitted to low/no training claim.

Before · high
We may use your personal information for research and development purposes, including to analyze and improve the Service and our business and to develop new products and services. As part of these activities, we may create aggregated, de-identified and/or anonymized data from personal information we collect. We make personal information into de-identified or anonymized data by removing information that makes the data personally identifiable to you. We may use this aggregated, de-identified or otherwise anonymized data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business.
Before citation
After · low
NOTE RE: AI SUB-PROCESSORS – ZERO DATA RETENTION: Napkin AI maintains zero-data-retention (ZDR) agreements with all AI inference sub-processors (currently Google Cloud AI and OpenAI). Customer Personal Data submitted to these providers is not retained beyond the immediate processing request and is not used for model training by those providers.
After citation
Aug 31, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We may use service providers that operate in various countries, and your personal information may be transferred to locations where privacy laws may differ from those in your jurisdiction.
Open timeline citation
Aug 31, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

These service providers process personal data only on our instructions and under strict confidentiality agreements.
Open timeline citation
Aug 31, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

We generally retain information for as long as necessary to provide the service, to fulfill the purposes outlined in this Privacy Policy, to comply with legal, accounting, contractual, or operational obligations, to establish or defend legal claims, or to prevent fraud. To determine the appropriate retention period for personal information, we may consider factors such as the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
Open timeline citation
Aug 31, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

Third parties designated by you. We may share your personal information with third parties where you have instructed us or provided your consent to do so, such as when you share content with collaborators, or connect third-party services. We only share information that is needed for these other companies to provide the services that you have requested.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-08-31· verified 2026-08-31
  • Terms of Service:Last captured 2026-08-17· verified 2026-08-17

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↑ 211 more findings this quarter vs last (453 vs 242). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Napkin AI's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Napkin AI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.