Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · trystratify.com

stratify

Graded against 809 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-08-11
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

18 verified findings4 policy surfaces2/2 core docs verified
Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
2
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what stratify's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Terms of Service
    Verified - read in full - 0 citationsstaticLast captured 2026-08-11
  • Privacy Policy
    Verified - read in full - 18 citationsstaticLast captured 2026-08-11
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Describes enterprise-grade security measures including AES-256 encryption with key management and role-based access control to restrict data access to authorized personnel only.

" We implement enterprise-grade security measures designed to protect data from unauthorized access or disclosure: Encryption: All sensitive data, including OAuth tokens, is encrypted using AES-256 with keys managed by AWS KMS. Access Cont..."
📍 § 4 (Data Security)Jump to exact text →
plan language
Data retention

Describes data minimization standards and specific storage procedures, including encryption of OAuth tokens at rest using AES-256 stored in a designated secrets manager, prohibition on storing tokens in the application database, and automatic refresh or rotation, and caching of temporary campaign data only as needed — establishing operative data handling procedures.

" Stratify follows strict data minimization and retention standards across all integrations: We request only the minimal data necessary to perform campaign management and analytics. Integration tokens and credentials (e.g., OAuth tokens fr..."
📍 § 3 (Data Handling and Storage Practices)Jump to exact text →
plan language
Data retention

Establishes retention periods (campaign performance metrics stored maximum 90 days; cached API data deleted within 24–48 hours), identifies exceptions for billing or contractual purposes, and grants users the right to request account or data deletion by contacting a specified address.

" We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtai..."
📍 § 5 (Data Retention and Deletion)Jump to exact text →
plan language
Subprocessors & data sharing

Identifies multiple named subprocessors and tools (Cloudflare, Sentry, PostHog, WorkOS) and their respective functions including network protection, monitoring, analytics, and authentication, and notes maintenance of internal audit logs for compliance and traceability.

" Network Edge: Cloudflare provides CDN, WAF, and DDoS protection. Monitoring: Sentry is used for performance monitoring and error logging; PostHog for anonymized analytics. Authentication: Enterprise SSO handled through WorkOS for secure ..."
📍 Privacy Policy › “Database hosted on Supabase (Postgres) with encryption at rest”Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 18
Severity
Surface
Document
Tier
Data retention
High
" We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account or associated data at any time by contacting privacy@stratify.ai."
§ 5 (Data Retention and Deletion)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Establishes retention periods (campaign performance metrics stored maximum 90 days; cached API data deleted within 24–48 hours), identifies exceptions for billing or contractual purposes, and grants users the right to request account or data deletion by contacting a specified address.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" CRM lifecycle or engagement data (e.g., opportunity stage, lead ID) We do not collect or store personally identifiable information (PII) of your customers, or LinkedIn member data beyond what is necessary for campaign management functionality."
Privacy Policy › “Account and campaign identifiers”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Restricts collection and storage of personally identifiable information of customers and limits LinkedIn member data to what is necessary for campaign management, establishing protective boundaries on data collection — user-favorable restriction.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We never use integration data for advertising, prospecting, audience creation, or recruiting. Data is processed only to support your authorized use of Stratify and within the scope of the connected platform's permitted use cases."
Privacy Policy › “Ensure platform security, reliability, and compliance”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Prohibits the use of integration data for advertising, prospecting, audience creation, or recruiting, and restricts processing to authorized use within connected platform permitted use cases — user-favorable restriction on secondary data use.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:"
§ 6 (Data Sharing)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Introduces the list of approved third-party service providers with whom data is shared, establishing the framework for subprocessor disclosure.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" We may process data in the United States or other jurisdictions where our infrastructure or providers operate. All transfers comply with applicable data protection laws, and, where required, standard contractual clauses or equivalent safeguards are used."
§ 7 (Data Transfers)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Describes the procedure and conditions under which data may be processed in various jurisdictions, stating that all transfers comply with applicable data protection laws and that standard contractual clauses or equivalent safeguards are used where required — a user-protective procedural obligation on the controller.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Stratify ("we," "our," or "us") provides a B2B marketing automation and optimization platform that helps businesses manage and improve their digital marketing campaigns across multiple advertising and CRM platforms. We are committed to protecting your privacy and ensuring compliance with all applicable data protection laws and third-party platform terms, including those governing APIs such as LinkedIn, Google, Meta, Salesforce, and HubSpot. This Privacy Policy explains how Stratify collects, uses, and protects information when you use our website, platform, and related services."
Privacy Policy › “Last updated: October 19, 2025”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Defines the entity ('Stratify'), describes the nature of the platform, and states the document's purpose of explaining how information is collected, used, and protected, establishing the scope of the privacy policy.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you create or access a Stratify account, we collect: Name, email address, company name, and authentication credentials (including SSO via WorkOS) Payment or subscription details (processed by third-party billing partners)"
§ 1.1 (Account and Contact Information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Defines the specific categories of account and contact data collected upon account creation or access, including authentication credentials and payment details processed via third-party billing partners, establishing the scope of personal data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When you connect Stratify to integrated APIs (e.g., LinkedIn Ads, Google Ads, HubSpot, Salesforce), we may securely access limited campaign data strictly necessary to provide our services, including: Campaign, ad group, and performance metrics (e.g., spend, impressions, clicks, CTR)"
§ 1.2 (Platform and Integration Data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Defines the types of campaign and performance data accessed through connected APIs, specifying that access is limited strictly to what is necessary to provide services, establishing a data minimization principle for integration data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may collect standard technical data, such as IP addresses, browser type, and device information, for security and analytics purposes using PostHog and Sentry."
§ 1.3 (Automatically Collected Information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Defines the categories of automatically collected technical data (IP addresses, browser type, device information) and identifies the tools used (PostHog and Sentry) and purposes (security and analytics).

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We implement enterprise-grade security measures designed to protect data from unauthorized access or disclosure: Encryption: All sensitive data, including OAuth tokens, is encrypted using AES-256 with keys managed by AWS KMS. Access Control: Role-based access control (RBAC) ensures only authorized personnel can access relevant data."
§ 4 (Data Security)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Describes enterprise-grade security measures including AES-256 encryption with key management and role-based access control to restrict data access to authorized personnel only.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Depending on your jurisdiction, you may have rights to:"
§ 8 (Your Rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Establishes that users may hold certain data rights depending on their jurisdiction, conditionally granting the rights enumerated in the following segments.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" To exercise these rights, please contact us at privacy@stratify.ai."
Privacy Policy › “Withdraw consent where processing is based on consent”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Sets out the procedure for exercising data rights, directing users to contact the controller at a specified email address.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may update this Privacy Policy periodically to reflect operational, legal, or regulatory changes. Any updates will be posted here, and the "Last Updated" date will be revised accordingly."
§ 10 (Updates to This Policy)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Describes the procedure by which the privacy policy may be updated periodically to reflect changes, specifying that updates will be posted and the 'Last Updated' date revised — imposing a notice obligation on the controller.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" If you have questions or concerns about this Privacy Policy or our data handling practices, please contact us at: Stratify AI, Inc. Email: privacy@stratify.ai"
§ 11 (Contact Us)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Provides the contact details for directing questions or concerns about privacy practices to the controller, establishing a procedural channel for privacy-related communication.

AI-generated interpretation, not legal advice.

Data retention
High
" Stratify follows strict data minimization and retention standards across all integrations: We request only the minimal data necessary to perform campaign management and analytics. Integration tokens and credentials (e.g., OAuth tokens from LinkedIn, Google, HubSpot, Salesforce) are encrypted at rest using AES-256 and stored exclusively in AWS Secrets Manager. Tokens are never stored in our application database (Supabase) and are automatically refreshed or rotated as required. Temporary campaign data and social activity metrics retrieved from advertising platforms are cached only as needed to complete requests and are deleted or refreshed within 24–48 hours in accordance with API data storage requirements. Redis is used only for ephemeral caching and queuing — it does not store PII or any persistent records. Campaign-level metrics (e.g., CTR, spend, cost per lead) may be retained in aggregated form for up to 90 days, configurable per tenant. Logs and analytics data are scrubbed of PII and retained for no more than 30 days. Data is never exported, redistributed, or combined with unrelated datasets to build profiles, leads, or audience segments."
§ 3 (Data Handling and Storage Practices)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Describes data minimization standards and specific storage procedures, including encryption of OAuth tokens at rest using AES-256 stored in a designated secrets manager, prohibition on storing tokens in the application database, and automatic refresh or rotation, and caching of temporary campaign data only as needed — establishing operative data handling procedures.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" Network Edge: Cloudflare provides CDN, WAF, and DDoS protection. Monitoring: Sentry is used for performance monitoring and error logging; PostHog for anonymized analytics. Authentication: Enterprise SSO handled through WorkOS for secure identity management. We maintain internal audit logs of key system actions to ensure compliance and traceability."
Privacy Policy › “Database hosted on Supabase (Postgres) with encryption at rest”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Identifies multiple named subprocessors and tools (Cloudflare, Sentry, PostHog, WorkOS) and their respective functions including network protection, monitoring, analytics, and authentication, and notes maintenance of internal audit logs for compliance and traceability.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" OpenAI, Anthropic Language model–based features (never involving user PII) "
Privacy Policy › “Resend Transactional email delivery”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Identifies OpenAI and Anthropic as subprocessors providing language model-based features and specifies that this never involves user PII, defining the scope and a protective restriction on data shared with these providers.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" All third-party providers are bound by strict confidentiality and data-protection agreements."
Privacy Policy › “PostHog, Sentry Product analytics and monitoring”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-08-11- View source
Permalink to this finding →
Automated analysis

Imposes an obligation requiring all third-party providers to be bound by strict confidentiality and data-protection agreements, protective of user data in the context of subprocessor relationships.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from stratify's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in stratify's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in stratify's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What stratify requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in stratify's published policies yet.

What the policies actually cover

0 topics

None of stratify's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

34
clauses
10
patterns
10
stances
ip ownership · 3dispute resolution · 2ip license · 2privacy sharing · 2data retention · 1
data retentionMEDIUM§ 5 (Data Retention and Deletion)

The clause allows indefinite, perpetual, or necessity-based retention.

We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account o...
Open source citation
dispute resolutionMEDIUM

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

Governing Law and Disputes These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes arising from these Terms or your use of the Service will be resolved through binding arbitration in San Francisco, California. Severability If any provision of these Terms is found to be unenforceable or invalid, the remaining provisions will continue to be valid an...
Open source citation
dispute resolutionMEDIUMTerms of Service › “Governing Law and Disputes”

The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.

These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes arising from these Terms or your use of the Service will be resolved through binding arbitration in San Francisco, California.
Open source citation
ip licenseMEDIUM

The clause grants a broad content license.

Your Rights You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service. Research Data You own the research data and insights generated through your use of the Service. We may use aggregated...
Open source citation
ip licenseMEDIUMTerms of Service › “Your Rights”

The clause grants a broad content license.

You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersgoverning law disputesconditionalMEDIUM2
All applicable tierssubprocessors data sharingworsensHIGH2
Apidata retentionconditionalMEDIUM1
Freedata retentionconditionalMEDIUM2
Freeoutput ownershipconditionalMEDIUM2
Freesubprocessors data sharingworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Aug 11, 2026dispute termsMEDIUM

Latest stance: arbitration or waiver on governing law disputes

These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes arising from these Terms or your use of the Service will be resolved through binding arbitration in San Francisco, California.
Open timeline citation
Aug 11, 2026content licenseMEDIUM

Latest stance: broad license on data retention

You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service.
Open timeline citation
Aug 11, 2026content ownershipLOW

Latest stance: user retains rights on data retention

You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service.
Open timeline citation
Aug 11, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account or associated data at any time by contacting privacy@stratify.ai.
Open timeline citation
Aug 11, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:
Open timeline citation
Aug 11, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:
Open timeline citation
Jul 21, 2026content licenseMEDIUM

Latest stance: broad license on output ownership

Your Rights You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service. Research Data You own the research data and insights generated through your use of the Service. We may use aggregated, anonymized data for improving our Service and developing new features. Payment and Billing If you choose a paid subscription plan: You agree to pay all fees associated with your chosen plan Payments are processed through secure third-party payment providers Subscription fees are billed in advance on a recurring basis All fees are non-refundable unless otherwise specified We may change our pricing with reasonable notice Failure to pay may result in suspension or termination of your account Privacy and Data Protection Your privacy is important to us. Our collection and use of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference. By using the Service, you consent to the collection and use of your information as described in our Privacy Policy. Service Availability We strive to maintain high availability of our Service, but we do not guarantee uninterrupted access. The Service may be temporarily unavailable due to: Scheduled maintenance and updates Technical issues or system failures Third-party service dependencies Force majeure events beyond our control Disclaimers and Limitations of Liability Service Disclaimer The Service is provided "as is" and "as available" without warranties of any kind, either express or implied.
Open timeline citation
Jul 21, 2026content ownershipLOW

Latest stance: user retains rights on output ownership

Your Rights You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service. Research Data You own the research data and insights generated through your use of the Service. We may use aggregated, anonymized data for improving our Service and developing new features. Payment and Billing If you choose a paid subscription plan: You agree to pay all fees associated with your chosen plan Payments are processed through secure third-party payment providers Subscription fees are billed in advance on a recurring basis All fees are non-refundable unless otherwise specified We may change our pricing with reasonable notice Failure to pay may result in suspension or termination of your account Privacy and Data Protection Your privacy is important to us. Our collection and use of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference. By using the Service, you consent to the collection and use of your information as described in our Privacy Policy. Service Availability We strive to maintain high availability of our Service, but we do not guarantee uninterrupted access. The Service may be temporarily unavailable due to: Scheduled maintenance and updates Technical issues or system failures Third-party service dependencies Force majeure events beyond our control Disclaimers and Limitations of Liability Service Disclaimer The Service is provided "as is" and "as available" without warranties of any kind, either express or implied.
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-08-11· verified 2026-08-11
  • Privacy Policy:Last captured 2026-08-11· verified 2026-08-11verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

43 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of stratify's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from stratify's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.