OneCLI
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Prohibits sale of personal data; permits disclosure only to: service providers bound by confidentiality agreements for operational purposes, law enforcement under valid legal process, and business-transfer counterparties with notice — restricting data sharing to these enumerated categories, which is user-favorable.
Restricts how Google API user data is handled: adherence to the applicable Google API user data policy including limited-use requirements; OAuth tokens stored solely to maintain connection; access limited to explicitly granted scopes; retrieved data used solely for user-requested features — prohibiting broader secondary use of Google user data, which is user-favorable.
States security and storage obligations: CLI credentials remain local, cloud tokens are stored encrypted, all transmitted data is encrypted in transit and at rest, and industry-standard security practices are followed; also includes a disclaimer that no system is fully secure, limiting implied warranty of perfect protection.
How to read this page: Overall risk rates what OneCLI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 11 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 11 citationsstaticLast captured 2026-08-17
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Restricts how Google API user data is handled: adherence to the applicable Google API user data policy including limited-use requirements; OAuth tokens stored solely to maintain connection; access limited to explicitly granted scopes; retrieved data used solely for user-requested features — prohibiting broader secondary use of Google user data, which is user-favorable.
" OneCLI Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. When you connect a Google service (such as Gmail, Google Drive, Google ..."
Prohibits sale of personal data; permits disclosure only to: service providers bound by confidentiality agreements for operational purposes, law enforcement under valid legal process, and business-transfer counterparties with notice — restricting data sharing to these enumerated categories, which is user-favorable.
" We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid l..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you."
Prohibits sale of personal data; permits disclosure only to: service providers bound by confidentiality agreements for operational purposes, law enforcement under valid legal process, and business-transfer counterparties with notice — restricting data sharing to these enumerated categories, which is user-favorable.
AI-generated interpretation, not legal advice.
" OneCLI Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. When you connect a Google service (such as Gmail, Google Drive, Google Calendar, or Google Sheets) through OneCLI Cloud: We store an encrypted OAuth refresh token on our servers solely to maintain your connection. We access only the Google API scopes you explicitly grant during the connection flow. Google user data retrieved by agents is used solely to provide and improve the user-facing features you requested. We do not use Google user data for advertising, and we do not sell it to third parties, advertisers, data brokers, or information resellers. We do not use Google user data for credit assessment, lending, or any purpose unrelated to the core functionality of OneCLI. Our employees do not read your Google user data unless (a) you provide explicit consent, (b) it is necessary for security or abuse investigation, (c) it is required by law, or (d) it is used in aggregated, de-identified form for internal operations. You can revoke access to your Google data at any time from the OneCLI Cloud dashboard, which deletes the stored refresh token and disconnects the service."
Restricts how Google API user data is handled: adherence to the applicable Google API user data policy including limited-use requirements; OAuth tokens stored solely to maintain connection; access limited to explicitly granted scopes; retrieved data used solely for user-requested features — prohibiting broader secondary use of Google user data, which is user-favorable.
AI-generated interpretation, not legal advice.
" ChartDB, Inc. ("we", "us", "our") operates OneCLI, including the onecli command-line tool, the cloud dashboard at app.onecli.sh , and the marketing site at onecli.sh . This Privacy Policy explains what data we collect, how we use it, and your choices."
Defines the operator entity ('ChartDB, Inc.'), the products covered (OneCLI CLI, cloud dashboard, marketing site), and states the purpose of the document — explaining data collection, use, and user choices — establishing the scope of all downstream obligations.
AI-generated interpretation, not legal advice.
" Account information: email address when you sign up for OneCLI Cloud. Authentication tokens (CLI): stored locally on your machine by the CLI; never sent to our servers. OAuth credentials (Cloud): when you connect a third-party service through OneCLI Cloud, we store an encrypted OAuth refresh token on our servers to maintain your connection. Usage and telemetry: anonymous command frequency, plugin usage counts, and error reports (opt-out available). Cloud dashboard analytics: page views, feature usage, and session metadata. Plugin connection metadata: which services you connect, connection status, and timestamps. We do not store the content flowing through plugins."
Enumerates the categories of personal and technical data collected (account email, authentication tokens, OAuth credentials, usage telemetry, dashboard analytics, plugin connection metadata), defines where each is stored (locally vs. servers), and notes an opt-out for telemetry, establishing the factual basis for subsequent use and retention obligations.
AI-generated interpretation, not legal advice.
" Operate and maintain the service. Authenticate you across CLI and cloud dashboard. Improve OneCLI based on aggregate usage patterns. Send product updates and security notices (you can unsubscribe). Detect and prevent abuse or unauthorized access."
Enumerates the specific purposes for which collected data is used (service operation, authentication, aggregate improvement, communications, abuse prevention), binding the operator to those stated use purposes and no others by implication.
AI-generated interpretation, not legal advice.
" You have the right to: Access the personal data we hold about you. Correct inaccurate information. Delete your account and associated data. Opt out of telemetry collection in the CLI. Export your data in a portable format. To exercise any of these rights, contact us at privacy@chartdb.io ."
Grants users enumerated data-subject rights: access to personal data held, correction of inaccurate data, account and data deletion, opt-out of telemetry, and export of data in a portable format; specifies the contact mechanism (email address) for exercising these rights.
AI-generated interpretation, not legal advice.
" Website: basic analytics cookies to understand traffic and improve the site. CLI: no cookies. The CLI does not use browser-based tracking. Cloud dashboard: session cookies for authentication only."
Describes tracking practices by context: website uses analytics cookies for traffic analysis; CLI uses no cookies or browser-based tracking; cloud dashboard uses session cookies for authentication only — limiting cookie and tracking use to stated purposes.
AI-generated interpretation, not legal advice.
" The OneCLI CLI stores authentication tokens and plugin credentials locally on your machine. OneCLI Cloud stores encrypted OAuth refresh tokens on our servers to maintain service connections on your behalf. All data transmitted to our servers is encrypted in transit (TLS) and at rest. We follow industry-standard practices to protect your information, but no system is 100% secure."
States security and storage obligations: CLI credentials remain local, cloud tokens are stored encrypted, all transmitted data is encrypted in transit and at rest, and industry-standard security practices are followed; also includes a disclaimer that no system is fully secure, limiting implied warranty of perfect protection.
AI-generated interpretation, not legal advice.
" We retain your account data for as long as your account is active. Anonymous telemetry data is retained for 12 months. You can request deletion of your data at any time by contacting us."
Establishes retention periods: account data retained for the life of the account; anonymous telemetry retained for 12 months; grants users the right to request deletion at any time by contacting the operator.
AI-generated interpretation, not legal advice.
" OneCLI acts as a gateway to third-party services through plugins. When you use a plugin, data flows directly between your machine and that service. We do not store, inspect, or log the content passing through plugins. Each third-party service has its own privacy policy, and we encourage you to review them."
Describes the operator's role as a gateway to third-party plugin services, disclaims any storage, inspection, or logging of content passing through plugins, and notes that each third-party service has its own privacy policy — limiting the operator's responsibility for plugin data flows and directing users to third-party policies.
AI-generated interpretation, not legal advice.
" We may update this policy from time to time. Changes will be posted on this page with an updated effective date. For questions or concerns, contact us at privacy@chartdb.io ."
Establishes the procedure for policy updates (posting changes with an updated effective date) and provides a contact mechanism for questions or concerns (email address), creating a notice obligation for changes and a channel for user inquiries.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from OneCLI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in OneCLI's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in OneCLI's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat OneCLI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in OneCLI's published policies yet.
What the policies actually cover
0 topicsNone of OneCLI's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“OneCLI Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. When you connect a Google service (such as Gmail, Google Drive, Google Calendar, or Google Sheets) through OneCLI Cloud: We store an encrypted OAuth refresh token on our servers solely to maintain your connection. We access only the Google API s...”Open source citation
The clause permits sale of personal data or information.
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open source citation
The clause permits sale of personal data or information.
“OneCLI Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. When you connect a Google service (such as Gmail, Google Drive, Google Calendar, or Google Sheets) through OneCLI Cloud: We store an encrypted OAuth refresh token on our servers solely to maintain your connection. We access only the Google API s...”Open source citation
The clause permits sale of personal data or information.
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| Api | commercial use | worsens | HIGH | 1 |
| Api | privacy data use | worsens | HIGH | 1 |
| Team / Business | privacy data use | worsens | HIGH | 2 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“OneCLI Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. When you connect a Google service (such as Gmail, Google Drive, Google Calendar, or Google Sheets) through OneCLI Cloud: We store an encrypted OAuth refresh token on our servers solely to maintain your connection. We access only the Google API scopes you explicitly grant during the connection flow. Google user data retrieved by agents is used solely to provide and improve the user-facing features you requested. We do not use Google user data for advertising, and we do not sell it to third parties, advertisers, data brokers, or information resellers. We do not use Google user data for credit assessment, lending, or any purpose unrelated to the core functionality of OneCLI. Our employees do not read your Google user data unless (a) you provide explicit consent, (b) it is necessary for security or abuse investigation, (c) it is required by law, or (d) it is used in aggregated, de-identified form for internal operations. You can revoke access to your Google data at any time from the OneCLI Cloud dashboard, which deletes the stored refresh token and disconnects the service.”Open timeline citation
Latest stance: sale or sell on subprocessors data sharing
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open timeline citation
Latest stance: sale or sell on commercial use
“OneCLI Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. When you connect a Google service (such as Gmail, Google Drive, Google Calendar, or Google Sheets) through OneCLI Cloud: We store an encrypted OAuth refresh token on our servers solely to maintain your connection. We access only the Google API scopes you explicitly grant during the connection flow. Google user data retrieved by agents is used solely to provide and improve the user-facing features you requested. We do not use Google user data for advertising, and we do not sell it to third parties, advertisers, data brokers, or information resellers. We do not use Google user data for credit assessment, lending, or any purpose unrelated to the core functionality of OneCLI. Our employees do not read your Google user data unless (a) you provide explicit consent, (b) it is necessary for security or abuse investigation, (c) it is required by law, or (d) it is used in aggregated, de-identified form for internal operations. You can revoke access to your Google data at any time from the OneCLI Cloud dashboard, which deletes the stored refresh token and disconnects the service.”Open timeline citation
Latest stance: sale or sell on privacy data use
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We do not sell your personal data. We may share information with: Service providers: hosting, analytics, and email providers that help us operate OneCLI, bound by confidentiality agreements. Law enforcement: only when required by valid legal process. Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to you.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-17· verified 2026-08-17
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
16 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of OneCLI's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified OneCLI's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from OneCLI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.