Pavoot
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
No verified risks yet
AIRIN has not published verified findings for this record yet. The page shows the gap instead of guessing.
How to read this page: Overall risk rates what Pavoot's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 0 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 0 citationsLast captured 2026-07-20
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“Email correspondence: kept for as long as necessary to handle your request, then archived for up to 3 years. Demo and form submissions: retained while we evaluate the opportunity and for up to 2 years afterwards, unless you ask us to delete them sooner. Analytics data: aggregated and retained for up to 14 months. Server logs: retained by our hosting provider for up to 30 days for security and abuse prevention.”Open source citation
The clause permits sale of personal data or information.
“We process personal data for the following purposes and legal bases: To operate and improve the website (legitimate interest, Art. 6(1)(f) GDPR): aggregate analytics, performance monitoring, and security. To respond to you (legitimate interest or pre-contractual measures, Art. 6(1)(b) and (f) GDPR): handling your emails, demo requests, and form submissions. To send you information you asked for (consent, Art. 6(1)...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We share personal data only with service providers who help us run the website and our business. Each provider is bound by a data processing agreement and may only process data on our documented instructions. Cloudflare : website hosting, DNS, and edge security (USA / global edge). Google (Workspace, Apps Script, Sheets) : email inbox, form delivery, and storing form submissions (EU / USA). Cal.com : scheduling de...”Open source citation
The clause permits using submitted content for training, development, or model/service improvement.
“We apply appropriate measures to protect personal data, including sensitive personal data such as names, email addresses, and phone numbers: Encryption in transit: all data is transmitted over encrypted TLS/HTTPS connections. Encryption at rest: personal data is encrypted at rest on our infrastructure. Credential protection: passwords and OAuth tokens are hashed or encrypted at rest, never stored in plaintext. Acc...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | data retention | conditional | MEDIUM | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
| Api | training use | worsens | HIGH | 1 |
| Team / Business | privacy data use | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“We process personal data for the following purposes and legal bases: To operate and improve the website (legitimate interest, Art. 6(1)(f) GDPR): aggregate analytics, performance monitoring, and security. To respond to you (legitimate interest or pre-contractual measures, Art. 6(1)(b) and (f) GDPR): handling your emails, demo requests, and form submissions. To send you information you asked for (consent, Art. 6(1)(a) GDPR): event invitations, updates, or follow-ups you specifically requested. To comply with legal obligations (Art. 6(1)(c) GDPR): accounting, tax, and responding to lawful requests from authorities. We do not sell your personal data and we do not use it for automated decisions that have legal or similarly significant effects on you.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We share personal data only with service providers who help us run the website and our business. Each provider is bound by a data processing agreement and may only process data on our documented instructions. Cloudflare : website hosting, DNS, and edge security (USA / global edge). Google (Workspace, Apps Script, Sheets) : email inbox, form delivery, and storing form submissions (EU / USA). Cal.com : scheduling demo calls (EU / USA). Ploy : first-party website analytics and site hosting platform. YouTube (Google) : embedded launch video playback. When you click play, YouTube may set its own cookies under its privacy policy . For our product (the Pavoot platform) we use additional sub-processors. Those are listed in our Data Processing Agreement .”Open timeline citation
Latest stance: training permitted on training use
“We apply appropriate measures to protect personal data, including sensitive personal data such as names, email addresses, and phone numbers: Encryption in transit: all data is transmitted over encrypted TLS/HTTPS connections. Encryption at rest: personal data is encrypted at rest on our infrastructure. Credential protection: passwords and OAuth tokens are hashed or encrypted at rest, never stored in plaintext. Access controls: access is restricted under least-privilege controls and data is logically isolated per organization. Minimization: we do not collect financial, health, or precise-location data through this website. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to limit access to it. Limited Use. Pavoot's use and transfer of information received from Google APIs, including any raw or derived user data, will adhere to the Google API Services User Data Policy , including the Limited Use requirements. We do not transfer Google user data to third-party AI services to train or improve generalized AI or machine-learning models.”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“Email correspondence: kept for as long as necessary to handle your request, then archived for up to 3 years. Demo and form submissions: retained while we evaluate the opportunity and for up to 2 years afterwards, unless you ask us to delete them sooner. Analytics data: aggregated and retained for up to 14 months. Server logs: retained by our hosting provider for up to 30 days for security and abuse prevention.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
13 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Pavoot's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Pavoot's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Pavoot's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.