Ugo
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Absence of specific retention periods makes it difficult for users to exercise deletion rights meaningfully. GDPR Article 5(1)(e) requires data not be kept longer than necessary, with defined periods where possible.
This segment restricts the user's right to refunds by declaring all sales final, citing the immediate digital nature of services and autonomous server-side execution, thereby limiting UGO's liability for any refund obligations.
This segment limits carrier liability for delayed or undelivered SMS messages, functioning as a limitation-of-liability clause that excludes wireless carriers from responsibility for message delivery failures.
Scores derived from 16 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Your outputs and prompts are explicitly yours — Ugo's terms include affirmatively protective IP language.
- Data handling is conditional — 6 privacy or retention clauses warrant review before using Ugo at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Ugo's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 27 verified, verbatim-cited findings below — read the citations.
Based on 41 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 9 citationsstaticLast captured 2026-06-08
- Privacy PolicyVerified - read in full - 25 citationsstaticLast captured 2026-06-07
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This segment restricts the controller's Services to users aged 13 and above, prohibits knowing collection of children's personal data, and imposes a remediation obligation to delete any inadvertently collected children's data, creating compliance obligations under COPPA.
" UGO is an enterprise-grade autonomous marketing system designed for businesses. Our Services are not directed at children under the age of 13, and we do not knowingly collect personal identifiable information from anyone under the age of 1..."
This segment identifies business data categories collected (website URLs, business locations, industry context), disclosing the controller's data-collection practices relevant to brand scanning and marketing deployments.
" Business data: Website URLs for brand scanning, business locations, and industry context."
This segment discloses that social media API tokens are collected for autonomous publishing, which constitutes a sensitive system-access credential, creating an obligation of transparency regarding this category of data collected.
" System access: Social media API tokens required for autonomous publishing."
This segment grants users the right to cancel their subscription at any time via the UGO dashboard or Stripe Customer Portal with no-hassle policy, specifying that cancellation takes effect at the end of the current billing cycle, distinguishing subscriber rights across active plan tiers.
" Recurring billing applies to our active tiers, including Standard and Agency plans. We believe in providing immense value through autonomy, not locking users into complex long-term contracts."
This segment discloses that the controller does not store full payment card details and that all payment information is passed directly to Stripe, establishing the controller's data-minimization practice and identifying Stripe as the payment subprocessor whose own privacy policy governs that data.
" We provide paid products and subscription services. We do not store or collect your full payment card details on our servers. All payment information is provided directly to our third-party payment processor, Stripe, whose use of your pers..."
This segment identifies CRM tools and social media platforms as data-sharing recipients via API tokens strictly for autonomous content publishing, disclosing subprocessor relationships and imposing a purpose-limitation restriction on that sharing.
" Third-Party Integrations: CRM tools and social media platforms (via authorized API tokens) strictly for the purpose of autonomous content publishing."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"We will retain your personal data only for as long as your account is active, or as necessary to fulfill the purposes outlined in this Privacy Policy — ensuring seamless autonomous marketing execution. We will also retain and use your data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements."
Absence of specific retention periods makes it difficult for users to exercise deletion rights meaningfully. GDPR Article 5(1)(e) requires data not be kept longer than necessary, with defined periods where possible.
AI-generated interpretation, not legal advice.
" UGO provides immediate, fully autonomous content generation, structural SEO analysis, and publishing automation. Due to the digital nature of these services and the immediate execution of server-side generation tasks, all sales are final."
This segment restricts the user's right to refunds by declaring all sales final, citing the immediate digital nature of services and autonomous server-side execution, thereby limiting UGO's liability for any refund obligations.
AI-generated interpretation, not legal advice.
" Liability: Carriers are not liable for delayed or undelivered messages."
This segment limits carrier liability for delayed or undelivered SMS messages, functioning as a limitation-of-liability clause that excludes wireless carriers from responsibility for message delivery failures.
AI-generated interpretation, not legal advice.
" Legal Requirements: We may disclose your personal data if required to do so by law or in response to valid requests by public authorities."
This segment creates an exception to the general data-sharing limitations by permitting disclosure of personal data when required by law or in response to valid requests by public authorities, establishing a legal-compliance carve-out for mandatory disclosures.
AI-generated interpretation, not legal advice.
" Conversion tracking: Meta Pixel to measure the effectiveness of our own marketing campaigns."
This segment identifies Meta Pixel as a third-party subprocessor used for conversion tracking of the controller's own marketing campaigns, disclosing a data-sharing relationship with Meta.
AI-generated interpretation, not legal advice.
" Third-Party Integrations: CRM tools and social media platforms (via authorized API tokens) strictly for the purpose of autonomous content publishing."
This segment identifies CRM tools and social media platforms as data-sharing recipients via API tokens strictly for autonomous content publishing, disclosing subprocessor relationships and imposing a purpose-limitation restriction on that sharing.
AI-generated interpretation, not legal advice.
" Device data: IP addresses, browser types, and device cookies."
This segment discloses collection of device data including IP addresses, browser types, and cookies, satisfying transparency obligations regarding technical tracking data gathered from users.
AI-generated interpretation, not legal advice.
" This Privacy Policy describes how UGO / Boss Up Solutions ("we", "us", or "our") collects, uses, and shares your personal information when you use our autonomous marketing system, website, and associated services (collectively, the "Services"). By utilizing our Services, you agree to the collection and use of information in accordance with this policy."
This segment defines the scope of the Privacy Policy, identifies the data controller ('UGO / Boss Up Solutions'), and incorporates user consent to data collection and use by virtue of utilizing the Services, making it a foundational definitional and consent-incorporation clause.
AI-generated interpretation, not legal advice.
" You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept essential cookies, you may not be able to use certain dashboard features."
This segment grants users the right to instruct their browser to refuse cookies while also limiting that right by noting that refusal of essential cookies may prevent use of certain dashboard features.
AI-generated interpretation, not legal advice.
" Business data: Website URLs for brand scanning, business locations, and industry context."
This segment identifies business data categories collected (website URLs, business locations, industry context), disclosing the controller's data-collection practices relevant to brand scanning and marketing deployments.
AI-generated interpretation, not legal advice.
" System access: Social media API tokens required for autonomous publishing."
This segment discloses that social media API tokens are collected for autonomous publishing, which constitutes a sensitive system-access credential, creating an obligation of transparency regarding this category of data collected.
AI-generated interpretation, not legal advice.
" UGO is an enterprise-grade autonomous marketing system designed for businesses. Our Services are not directed at children under the age of 13, and we do not knowingly collect personal identifiable information from anyone under the age of 13. If we become aware that we have collected Personal Data from a child without verification of parental consent, we take steps to remove that information from our servers."
This segment restricts the controller's Services to users aged 13 and above, prohibits knowing collection of children's personal data, and imposes a remediation obligation to delete any inadvertently collected children's data, creating compliance obligations under COPPA.
AI-generated interpretation, not legal advice.
" You shall not engage in data scraping, the generation of unlawful or explicitly prohibited content, mass spamming via our automated publishing networks, or any activity that compromises our system integrity or violates the terms of connected third-party social platforms."
This segment explicitly prohibits users from engaging in data scraping, generating unlawful or prohibited content, mass spamming via automated publishing networks, or any activity that compromises system integrity or violates connected third-party platform terms, constituting binding use restrictions enforceable against users.
AI-generated interpretation, not legal advice.
" Recurring billing applies to our active tiers, including Standard and Agency plans. We believe in providing immense value through autonomy, not locking users into complex long-term contracts."
"Recurring billing applies to our active tiers, including Standard and Agency plans."
This span carries the plan-specific language - verbatim from the policy.
This segment grants users the right to cancel their subscription at any time via the UGO dashboard or Stripe Customer Portal with no-hassle policy, specifying that cancellation takes effect at the end of the current billing cycle, distinguishing subscriber rights across active plan tiers.
AI-generated interpretation, not legal advice.
" Personal details: Name, email address, and billing address."
This segment specifies the categories of personal data (name, email, billing address) that the controller collects, establishing an operative disclosure obligation regarding what personal details are gathered from users.
AI-generated interpretation, not legal advice.
" Essential cookies: Required for system operation, session management, and security."
This segment discloses the use of essential cookies for system operation, session management, and security, identifying a necessary data-processing activity the controller engages in.
AI-generated interpretation, not legal advice.
" As part of the UGO System Alerts, users may opt in via their account settings to receive deployment notifications and essential service updates via SMS text message."
This segment permits users to opt in to receive SMS deployment notifications and essential service updates via their account settings, establishing the consent-based channel for SMS communications.
AI-generated interpretation, not legal advice.
" Performance analytics: Google Analytics 4 (GA4) to understand system usage and optimize dashboard performance."
This segment identifies Google Analytics 4 (GA4) as a third-party analytics subprocessor used to understand system usage and optimize dashboard performance, disclosing a subprocessor relationship and associated data-sharing practice.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Ugo's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
11 verified clausesClauses in Ugo's policies that work in your favour — commitments the platform made to you.
- Privacy & data usechildren's data
“UGO is an enterprise-grade autonomous marketing system designed for businesses. Our Services are not directed at children under the age of 13, and we do not knowingly collect personal identifiable information from anyone under the age of 13. If we become aware…”
This segment restricts the controller's Services to users aged 13 and above, prohibits knowing collection of children's personal data, and imposes a remediation obligation to delete any inadvertently collected children's…
Location: exact-text link only — source has no section structureJump to exact text → - Privacy & data use
“If you are a resident of California or another US state with comprehensive data privacy laws, you may have specific rights regarding your personal information, including the right to request access to or deletion of your data. We will not discriminate against…”
This segment grants California and other qualifying US-state residents specific statutory rights including access and deletion rights, and prohibits the controller from discriminating against users who exercise those pri…
Location: exact-text link only — source has no section structureJump to exact text → - Moderation & enforcementauto-renewal & cancel window
“Users maintain full control over their infrastructure and may cancel their subscription at any time with our no-hassle policy. Cancellations can be processed instantly via the UGO dashboard or directly through the Stripe Customer Portal, taking effect at the e…”
This segment reiterates the user's right to cancel at any time and specifies the cancellation procedure and effective timing, reinforcing subscriber control across subscription tiers.
📍 § 4 (Subscriptions & Cancellation)Jump to exact text → - Subprocessors & data sharing
“We provide paid products and subscription services. We do not store or collect your full payment card details on our servers. All payment information is provided directly to our third-party payment processor, Stripe, whose use of your personal information is g…”
This segment discloses that the controller does not store full payment card details and that all payment information is passed directly to Stripe, establishing the controller's data-minimization practice and identifying…
Location: exact-text link only — source has no section structureJump to exact text → - Subprocessors & data sharingsale/sharing of personal data
“UGO is committed to transparency and security. We process payments securely via Stripe, use essential analytics to optimize your autonomous marketing deployments, and provide clear controls over your data. We do not sell your personal information.”
This segment disclaims the sale of personal information and describes at a high level how data is processed (payments via Stripe, analytics for marketing deployments), establishing the controller's general data-handling…
Location: exact-text link only — source has no section structureJump to exact text → - Subprocessors & data sharing
“All credit card, debit, and subscription payment processing is securely handled by our authorized third-party payment processor, Stripe, Inc. Payment credentials are processed directly by Stripe and are never stored on UGO servers.”
This segment discloses that payment processing is handled by Stripe, Inc. as an authorized third-party subprocessor and disclaims that UGO ever stores payment credentials on its own servers, defining the data-sharing rel…
📍 § 2 (Payment Processing & Authorization)Jump to exact text →
+ 5 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
1 verified clauseWhat Ugo requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcementconduct restrictions
“You shall not engage in data scraping, the generation of unlawful or explicitly prohibited content, mass spamming via our automated publishing networks, or any activity that compromises our system integrity or violates the terms of connected third-party social…”
This segment explicitly prohibits users from engaging in data scraping, generating unlawful or prohibited content, mass spamming via automated publishing networks, or any activity that compromises system integrity or vio…
📍 § 5 (Acceptable Use)Jump to exact text →
What the policies actually cover
10 topics- Product telemetry & usage tracking1 protective6 clauses
- Advertising & tracking2 protective3 clauses
- Sale or sharing of personal data1 protective1 clause
- Children's data1 protective1 clause
- Government & law-enforcement disclosure1 clause
- Data shared with other AI providers1 clause
- Damages & liability cap1 clause
- Deletion rights & post-termination survival1 clause
- Auto-renewal & cancel window1 protective3 clauses
- Conduct restrictions1 obligation1 clause
15 further verified clauses are cited on this page but not yet assigned a topic.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause limits liability or disclaims warranties.
“Liability: Carriers are not liable for delayed or undelivered messages.”Open source citation
The clause permits sale of personal data or information.
“UGO is committed to transparency and security. We process payments securely via Stripe, use essential analytics to optimize your autonomous marketing deployments, and provide clear controls over your data. We do not sell your personal information.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“UGO shares data only with necessary service providers to execute your autonomous marketing plan. We may share information with: Payment Processors: Stripe, for secure billing and subscription management. Third-Party Integrations: CRM tools and social media platforms (via authorized API tokens) strictly for the purpose of autonomous content publishing. Legal Requirements: We may disclose your personal data if requi...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“UGO shares data only with necessary service providers to execute your autonomous marketing plan. We may share information with:”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | indemnity liability | conditional | MEDIUM | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 1 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 1 |
| Api | subprocessors data sharing | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“UGO is committed to transparency and security. We process payments securely via Stripe, use essential analytics to optimize your autonomous marketing deployments, and provide clear controls over your data. We do not sell your personal information.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“UGO shares data only with necessary service providers to execute your autonomous marketing plan. We may share information with: Payment Processors: Stripe, for secure billing and subscription management. Third-Party Integrations: CRM tools and social media platforms (via authorized API tokens) strictly for the purpose of autonomous content publishing. Legal Requirements: We may disclose your personal data if required to do so by law or in response to valid requests by public authorities”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“UGO shares data only with necessary service providers to execute your autonomous marketing plan. We may share information with:”Open timeline citation
Latest stance: liability limited on indemnity liability
“Liability: Carriers are not liable for delayed or undelivered messages.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-06-08· verified 2026-06-08verified once — no re-scan in 94 days
- Privacy Policy:Last captured 2026-06-07· verified 2026-06-07verified once — no re-scan in 96 days
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↓ 43 fewer findings this quarter vs last (0 vs 43). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Ugo's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Ugo's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.