stratify
Graded against 809 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Establishes retention periods (campaign performance metrics stored maximum 90 days; cached API data deleted within 24–48 hours), identifies exceptions for billing or contractual purposes, and grants users the right to request account or data deletion by contacting a specified address.
Describes the procedure and conditions under which data may be processed in various jurisdictions, stating that all transfers comply with applicable data protection laws and that standard contractual clauses or equivalent safeguards are used where required — a user-protective procedural obligation on the controller.
Introduces the list of approved third-party service providers with whom data is shared, establishing the framework for subprocessor disclosure.
How to read this page: Overall risk rates what stratify's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 0 citationsstaticLast captured 2026-08-11
- Privacy PolicyVerified - read in full - 18 citationsstaticLast captured 2026-08-11
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Describes enterprise-grade security measures including AES-256 encryption with key management and role-based access control to restrict data access to authorized personnel only.
" We implement enterprise-grade security measures designed to protect data from unauthorized access or disclosure: Encryption: All sensitive data, including OAuth tokens, is encrypted using AES-256 with keys managed by AWS KMS. Access Cont..."
Describes data minimization standards and specific storage procedures, including encryption of OAuth tokens at rest using AES-256 stored in a designated secrets manager, prohibition on storing tokens in the application database, and automatic refresh or rotation, and caching of temporary campaign data only as needed — establishing operative data handling procedures.
" Stratify follows strict data minimization and retention standards across all integrations: We request only the minimal data necessary to perform campaign management and analytics. Integration tokens and credentials (e.g., OAuth tokens fr..."
Establishes retention periods (campaign performance metrics stored maximum 90 days; cached API data deleted within 24–48 hours), identifies exceptions for billing or contractual purposes, and grants users the right to request account or data deletion by contacting a specified address.
" We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtai..."
Identifies multiple named subprocessors and tools (Cloudflare, Sentry, PostHog, WorkOS) and their respective functions including network protection, monitoring, analytics, and authentication, and notes maintenance of internal audit logs for compliance and traceability.
" Network Edge: Cloudflare provides CDN, WAF, and DDoS protection. Monitoring: Sentry is used for performance monitoring and error logging; PostHog for anonymized analytics. Authentication: Enterprise SSO handled through WorkOS for secure ..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account or associated data at any time by contacting privacy@stratify.ai."
Establishes retention periods (campaign performance metrics stored maximum 90 days; cached API data deleted within 24–48 hours), identifies exceptions for billing or contractual purposes, and grants users the right to request account or data deletion by contacting a specified address.
AI-generated interpretation, not legal advice.
" CRM lifecycle or engagement data (e.g., opportunity stage, lead ID) We do not collect or store personally identifiable information (PII) of your customers, or LinkedIn member data beyond what is necessary for campaign management functionality."
Restricts collection and storage of personally identifiable information of customers and limits LinkedIn member data to what is necessary for campaign management, establishing protective boundaries on data collection — user-favorable restriction.
AI-generated interpretation, not legal advice.
" We never use integration data for advertising, prospecting, audience creation, or recruiting. Data is processed only to support your authorized use of Stratify and within the scope of the connected platform's permitted use cases."
Prohibits the use of integration data for advertising, prospecting, audience creation, or recruiting, and restricts processing to authorized use within connected platform permitted use cases — user-favorable restriction on secondary data use.
AI-generated interpretation, not legal advice.
" We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:"
Introduces the list of approved third-party service providers with whom data is shared, establishing the framework for subprocessor disclosure.
AI-generated interpretation, not legal advice.
" We may process data in the United States or other jurisdictions where our infrastructure or providers operate. All transfers comply with applicable data protection laws, and, where required, standard contractual clauses or equivalent safeguards are used."
Describes the procedure and conditions under which data may be processed in various jurisdictions, stating that all transfers comply with applicable data protection laws and that standard contractual clauses or equivalent safeguards are used where required — a user-protective procedural obligation on the controller.
AI-generated interpretation, not legal advice.
" Stratify ("we," "our," or "us") provides a B2B marketing automation and optimization platform that helps businesses manage and improve their digital marketing campaigns across multiple advertising and CRM platforms. We are committed to protecting your privacy and ensuring compliance with all applicable data protection laws and third-party platform terms, including those governing APIs such as LinkedIn, Google, Meta, Salesforce, and HubSpot. This Privacy Policy explains how Stratify collects, uses, and protects information when you use our website, platform, and related services."
Defines the entity ('Stratify'), describes the nature of the platform, and states the document's purpose of explaining how information is collected, used, and protected, establishing the scope of the privacy policy.
AI-generated interpretation, not legal advice.
" When you create or access a Stratify account, we collect: Name, email address, company name, and authentication credentials (including SSO via WorkOS) Payment or subscription details (processed by third-party billing partners)"
Defines the specific categories of account and contact data collected upon account creation or access, including authentication credentials and payment details processed via third-party billing partners, establishing the scope of personal data collection.
AI-generated interpretation, not legal advice.
" When you connect Stratify to integrated APIs (e.g., LinkedIn Ads, Google Ads, HubSpot, Salesforce), we may securely access limited campaign data strictly necessary to provide our services, including: Campaign, ad group, and performance metrics (e.g., spend, impressions, clicks, CTR)"
Defines the types of campaign and performance data accessed through connected APIs, specifying that access is limited strictly to what is necessary to provide services, establishing a data minimization principle for integration data.
AI-generated interpretation, not legal advice.
" We may collect standard technical data, such as IP addresses, browser type, and device information, for security and analytics purposes using PostHog and Sentry."
Defines the categories of automatically collected technical data (IP addresses, browser type, device information) and identifies the tools used (PostHog and Sentry) and purposes (security and analytics).
AI-generated interpretation, not legal advice.
" We implement enterprise-grade security measures designed to protect data from unauthorized access or disclosure: Encryption: All sensitive data, including OAuth tokens, is encrypted using AES-256 with keys managed by AWS KMS. Access Control: Role-based access control (RBAC) ensures only authorized personnel can access relevant data."
Describes enterprise-grade security measures including AES-256 encryption with key management and role-based access control to restrict data access to authorized personnel only.
AI-generated interpretation, not legal advice.
" Depending on your jurisdiction, you may have rights to:"
Establishes that users may hold certain data rights depending on their jurisdiction, conditionally granting the rights enumerated in the following segments.
AI-generated interpretation, not legal advice.
" To exercise these rights, please contact us at privacy@stratify.ai."
Sets out the procedure for exercising data rights, directing users to contact the controller at a specified email address.
AI-generated interpretation, not legal advice.
" We may update this Privacy Policy periodically to reflect operational, legal, or regulatory changes. Any updates will be posted here, and the "Last Updated" date will be revised accordingly."
Describes the procedure by which the privacy policy may be updated periodically to reflect changes, specifying that updates will be posted and the 'Last Updated' date revised — imposing a notice obligation on the controller.
AI-generated interpretation, not legal advice.
" If you have questions or concerns about this Privacy Policy or our data handling practices, please contact us at: Stratify AI, Inc. Email: privacy@stratify.ai"
Provides the contact details for directing questions or concerns about privacy practices to the controller, establishing a procedural channel for privacy-related communication.
AI-generated interpretation, not legal advice.
" Stratify follows strict data minimization and retention standards across all integrations: We request only the minimal data necessary to perform campaign management and analytics. Integration tokens and credentials (e.g., OAuth tokens from LinkedIn, Google, HubSpot, Salesforce) are encrypted at rest using AES-256 and stored exclusively in AWS Secrets Manager. Tokens are never stored in our application database (Supabase) and are automatically refreshed or rotated as required. Temporary campaign data and social activity metrics retrieved from advertising platforms are cached only as needed to complete requests and are deleted or refreshed within 24–48 hours in accordance with API data storage requirements. Redis is used only for ephemeral caching and queuing — it does not store PII or any persistent records. Campaign-level metrics (e.g., CTR, spend, cost per lead) may be retained in aggregated form for up to 90 days, configurable per tenant. Logs and analytics data are scrubbed of PII and retained for no more than 30 days. Data is never exported, redistributed, or combined with unrelated datasets to build profiles, leads, or audience segments."
Describes data minimization standards and specific storage procedures, including encryption of OAuth tokens at rest using AES-256 stored in a designated secrets manager, prohibition on storing tokens in the application database, and automatic refresh or rotation, and caching of temporary campaign data only as needed — establishing operative data handling procedures.
AI-generated interpretation, not legal advice.
" Network Edge: Cloudflare provides CDN, WAF, and DDoS protection. Monitoring: Sentry is used for performance monitoring and error logging; PostHog for anonymized analytics. Authentication: Enterprise SSO handled through WorkOS for secure identity management. We maintain internal audit logs of key system actions to ensure compliance and traceability."
Identifies multiple named subprocessors and tools (Cloudflare, Sentry, PostHog, WorkOS) and their respective functions including network protection, monitoring, analytics, and authentication, and notes maintenance of internal audit logs for compliance and traceability.
AI-generated interpretation, not legal advice.
" OpenAI, Anthropic Language model–based features (never involving user PII) "
Identifies OpenAI and Anthropic as subprocessors providing language model-based features and specifies that this never involves user PII, defining the scope and a protective restriction on data shared with these providers.
AI-generated interpretation, not legal advice.
" All third-party providers are bound by strict confidentiality and data-protection agreements."
Imposes an obligation requiring all third-party providers to be bound by strict confidentiality and data-protection agreements, protective of user data in the context of subprocessor relationships.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from stratify's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in stratify's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in stratify's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat stratify requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in stratify's published policies yet.
What the policies actually cover
0 topicsNone of stratify's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account o...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Governing Law and Disputes These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes arising from these Terms or your use of the Service will be resolved through binding arbitration in San Francisco, California. Severability If any provision of these Terms is found to be unenforceable or invalid, the remaining provisions will continue to be valid an...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes arising from these Terms or your use of the Service will be resolved through binding arbitration in San Francisco, California.”Open source citation
The clause grants a broad content license.
“Your Rights You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service. Research Data You own the research data and insights generated through your use of the Service. We may use aggregated...”Open source citation
The clause grants a broad content license.
“You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | governing law disputes | conditional | MEDIUM | 2 |
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 2 |
| Api | data retention | conditional | MEDIUM | 1 |
| Free | data retention | conditional | MEDIUM | 2 |
| Free | output ownership | conditional | MEDIUM | 2 |
| Free | subprocessors data sharing | worsens | HIGH | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: arbitration or waiver on governing law disputes
“These Terms are governed by the laws of the State of California, without regard to conflict of law principles. Any disputes arising from these Terms or your use of the Service will be resolved through binding arbitration in San Francisco, California.”Open timeline citation
Latest stance: broad license on data retention
“You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service.”Open timeline citation
Latest stance: user retains rights on data retention
“You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service.”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“We retain data only for as long as necessary to provide services or meet legal obligations. Campaign performance metrics are stored for a maximum of 90 days unless otherwise required for billing or contractual purposes. Cached data obtained via advertising or CRM APIs is refreshed or deleted within 24–48 hours, consistent with the storage requirements of our API partners. You may request deletion of your account or associated data at any time by contacting privacy@stratify.ai.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:”Open timeline citation
Latest stance: sale or sell on subprocessors data sharing
“We do not sell, rent, or trade your personal data. We only share data with trusted third-party service providers essential to delivering Stratify's functionality. These include:”Open timeline citation
Latest stance: broad license on output ownership
“Your Rights You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service. Research Data You own the research data and insights generated through your use of the Service. We may use aggregated, anonymized data for improving our Service and developing new features. Payment and Billing If you choose a paid subscription plan: You agree to pay all fees associated with your chosen plan Payments are processed through secure third-party payment providers Subscription fees are billed in advance on a recurring basis All fees are non-refundable unless otherwise specified We may change our pricing with reasonable notice Failure to pay may result in suspension or termination of your account Privacy and Data Protection Your privacy is important to us. Our collection and use of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference. By using the Service, you consent to the collection and use of your information as described in our Privacy Policy. Service Availability We strive to maintain high availability of our Service, but we do not guarantee uninterrupted access. The Service may be temporarily unavailable due to: Scheduled maintenance and updates Technical issues or system failures Third-party service dependencies Force majeure events beyond our control Disclaimers and Limitations of Liability Service Disclaimer The Service is provided "as is" and "as available" without warranties of any kind, either express or implied.”Open timeline citation
Latest stance: user retains rights on output ownership
“Your Rights You retain ownership of any content, data, or materials you upload to or create through the Service ("User Content"). By using the Service, you grant us a limited, non-exclusive, royalty-free license to use, process, and analyze your User Content solely to provide the Service. Research Data You own the research data and insights generated through your use of the Service. We may use aggregated, anonymized data for improving our Service and developing new features. Payment and Billing If you choose a paid subscription plan: You agree to pay all fees associated with your chosen plan Payments are processed through secure third-party payment providers Subscription fees are billed in advance on a recurring basis All fees are non-refundable unless otherwise specified We may change our pricing with reasonable notice Failure to pay may result in suspension or termination of your account Privacy and Data Protection Your privacy is important to us. Our collection and use of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference. By using the Service, you consent to the collection and use of your information as described in our Privacy Policy. Service Availability We strive to maintain high availability of our Service, but we do not guarantee uninterrupted access. The Service may be temporarily unavailable due to: Scheduled maintenance and updates Technical issues or system failures Third-party service dependencies Force majeure events beyond our control Disclaimers and Limitations of Liability Service Disclaimer The Service is provided "as is" and "as available" without warranties of any kind, either express or implied.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-08-11· verified 2026-08-11
- Privacy Policy:Last captured 2026-08-11· verified 2026-08-11verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
43 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of stratify's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from stratify's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.