Augmenta
augmenta.aiAugmenta is a spatial-AI platform that automates building/construction (MEP electrical) design for professional VDC/contractor teams. The three supplied documents are all identical copies of a Privacy Policy (no Terms of Service, DPA, or security page was actually retrievable — the 'terms-conditions' URL served the same privacy text). The policy is recently dated (18 August 2026) and covers standard website/marketing data collection reasonably well, but it is almost entirely silent on the substance that matters most for a professional AI design tool: ownership of user-submitted project data and AI-generated outputs, whether inputs are used to train models, retention schedules and deletion SLAs, and any security certifications (no SOC 2, ISO, GDPR, or CCPA references appear). The policy notably collects screen recordings and generated output as 'usage data' used to 'update and improve the Platform,' which implies model/product improvement without an explicit opt-out for platform users. Business users handling proprietary building designs (including sensitive facilities such as data centers and hospitals) should obtain a contractual DPA and no-training commitment before submitting confidential project files.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The privacy policy never addresses ownership of user-submitted prompts, project files, or building models — it only speaks to 'personal information.' Absent a Terms of Service or MSA, there is no stated ownership grant either way, leaving input ownership unresolved.
Output Data Ownership
The policy references 'generated output' only as a category of usage data it collects, not as content the user owns. There is no statement assigning ownership of AI-generated models or designs to the user, which is a significant gap for a design-automation tool.
Training Data Usage
The policy states collected usage data — including generated output and screen recordings — is used to 'update and improve the Platform,' language that plausibly encompasses model/product improvement. It never explicitly says whether user inputs train AI models, nor does it offer an opt-out from this use, so the risk is ambiguous rather than clearly disclosed.
Data Retention & Deletion
The policy describes only a general 'no longer than necessary' retention standard with no concrete schedules, deletion SLAs, or self-service deletion mechanism. Users may withdraw consent and request access/correction in writing, but no defined timeline for deletion is given.
Third-Party Data Sharing
Augmenta states it does not sell or rent personal information and limits service-provider access to what is needed, but it also engages ad networks and advertising companies for interest-based advertising and may transfer data in a sale of business. Sharing is disclosed, but the advertising/tracking involvement and cross-border transfers add moderate risk beyond what the core design service strictly requires.
Opt-Out Rights
The policy provides real opt-out mechanisms for marketing email (unsubscribe) and interest-based advertising (DAAC), plus a general right to withdraw consent. However, there is no opt-out mechanism specific to platform usage-data collection or its use to 'improve the Platform,' limiting user control over the most sensitive processing.
Compliance & Certifications
The policy names no compliance frameworks or certifications whatsoever — no SOC 2, ISO 27001/27017/27018, GDPR, CCPA/CPRA, or NIST references appear. For a professional developer-infra/enterprise SaaS tool, the complete absence of any attested framework is a significant gap, and the policy's Canadian-privacy-law orientation leaves EU/US statutory posture unaddressed.
Model Explainability & Auditability
The documents are entirely silent on model transparency, explainability, or enterprise auditing capabilities. For an AI system generating construction-critical designs, the absence of any auditability commitment is a notable gap.
Security Practices & Breach History
The policy asserts 'reasonable administrative, technical and physical measures' and need-to-know access restrictions but discloses no specifics — no encryption at rest/in transit, penetration testing, bug bounty, incident response, or breach history, and no security page or trust center is referenced. The generic language provides little assurance for professional users.
Enterprise vs. Consumer Risk Delta
No enterprise agreement was retrievable, and the privacy policy makes no distinction between free/demo and paid tiers of data handling. It is oriented toward business users (work email, employer-provided accounts) but does not describe differentiated protections, so any enterprise-specific carve-outs cannot be confirmed.
Human Review of User Inputs
The policy grants employees and service providers need-to-know access and collects screen recordings for support and improvement, implying staff may view user activity. There is no explicit statement reserving or limiting human review of platform inputs/outputs, leaving the scope of human access ambiguous.
Regulatory & Litigation Exposure
The policy discloses that Augmenta may disclose personal information in response to legal process and to law enforcement or government authorities, including lawful access by U.S. and foreign courts. No active litigation is referenced, but the broad government-access language and cross-border exposure warrant attention for sensitive projects.
PII & SPI Data Inventory
Augmenta collects business-contact PII (name, work email/phone, company, job title), IP addresses, device/browser data, usage patterns, and screen recordings; for job applicants it may collect criminal-record checks (SPI) with consent. The collection is disclosed with purpose, but screen recordings and criminal-background data are meaningful additions that elevate the profile above minimal.
Policy–Product Currency
The policy is very recent (Last Updated 18 August 2026, days before the analysis date) and does describe the Platform as software that automates building/construction design. However, despite the product being an AI-native spatial-AI tool (ACP 2.0), the policy never explicitly addresses AI/ML model training, third-party model providers, or generative-output data flows in any depth — only generic 'improve the Platform' language. Coverage of the shipped AI capabilities is therefore only partial.
Cross-Document Consistency
Although three URLs were retrieved (including one labeled 'Terms of Service'), all three returned byte-for-byte identical copies of the same Privacy Policy. No genuine second document type (Terms, DPA, security page) was available, so no cross-document contradictions exist; the identical copies are fully consistent with each other. Effectively only one distinct document was analyzable.
You've read all 15 risk ratings for Augmenta. Create a free account to see the exact policy wording behind each rating.