Guardian
guardianThe only accessible document is a generic, template-based privacy policy belonging to 'Iconic BIM LLC' operating www.iconicBIM.com — NOT the tool under review, 'Guardian' at getguardian.tech. This is a critical mismatch: the supplied policy appears to govern an entirely different entity and website, and every getguardian.tech URL (terms, privacy, DPA, MSA) was inaccessible. As a result, there is effectively no governing legal documentation for Guardian available to analyze. The policy that was supplied is a boilerplate 'Free Privacy Policy' template last updated in November 2018 (nearly 8 years before the analysis date), makes no mention of AI/ML processing, model training, or any AI-specific data flows, and offers no compliance certifications. Absent any documents that actually govern Guardian, this tool cannot be recommended for professional, enterprise, or regulated use without obtaining and reviewing its actual terms.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The supplied document (belonging to Iconic BIM LLC, not Guardian) says nothing about ownership of user-submitted data, prompts, or files. No input-ownership terms exist in the accessible text, and the document does not appear to govern the Guardian tool at all.
Output Data Ownership
The document is silent on ownership of AI-generated output. It is a generic website privacy policy with no reference to generated content or AI outputs, and it does not appear to be Guardian's policy.
Training Data Usage
The policy makes no reference to AI or machine-learning training. It states data is used to 'improve the Service' generically, but there is no disclosure of whether user inputs feed model training. Silence on this for a purported AI tool is a significant risk.
Data Retention & Deletion
The document contains no retention schedule, no deletion SLA, and no self-service deletion mechanism. It only mentions removing children's data upon becoming aware of it. There are no retention or deletion commitments applicable to general users.
Third-Party Data Sharing
The policy discloses sharing with service providers and use of Google Analytics, and notes Google may use collected data to personalize its own advertising network. Sharing is disclosed but extends to an ad network, which goes beyond bare service provision. No selling of data is described.
Opt-Out Rights
The only opt-out mechanism disclosed is the Google Analytics browser add-on and the ability to refuse cookies. There is no opt-out from model training or broader data sharing, but a limited opt-out for analytics does exist.
Compliance & Certifications
No compliance frameworks or certifications from the universal baseline (GDPR, CCPA, SOC 2, ISO 27001, ISO 42001, etc.) are mentioned anywhere. The document is a generic template with no attestations, audit references, or trust center. Sector is unknown, so only the universal baseline was assessed — and none of it is present.
Model Explainability & Auditability
The document provides no information on model transparency, explainability, or enterprise auditing. It does not mention AI/ML at all, so no explainability or auditability commitments exist.
Security Practices & Breach History
Security disclosure is limited to a generic disclaimer that no method of transmission is fully secure, with no mention of encryption, access controls, penetration testing, or incident response. No breach history and no trust center/security page are referenced.
Enterprise vs. Consumer Risk Delta
No tiering, paid plans, or enterprise-versus-consumer distinctions are described in the document. The policy is silent on any differential data handling between tiers.
Human Review of User Inputs
The document does not address whether staff or the vendor may access, read, or review user prompts or outputs. It is entirely silent on human review.
Regulatory & Litigation Exposure
The policy contains a standard legal-disclosure clause allowing disclosure of Personal Data to comply with legal obligations and protect rights. There are no references to specific government requests, litigation, or law enforcement history, but the broad disclosure language is present.
PII & SPI Data Inventory
The policy discloses collection of standard PII: email, first and last name, phone number, IP address, device identifiers, browser data, and usage data. No SPI (financial, health, biometric) collection is described, and purposes are stated, but there is no purpose limitation or minimization commitment for AI processing.
Policy–Product Currency
The document is dated 'Last Updated: November 07, 2018' — nearly 8 years before the analysis date — far exceeding the 24-month staleness threshold. It also belongs to a different entity (Iconic BIM LLC / iconicBIM.com), never mentions AI/ML, and no product surface was supplied. This is a RED on recency grounds alone, independent of the missing coverage evidence.
Cross-Document Consistency
Only one document was retrievable, so a cross-document consistency check is impossible. Note, however, a critical documentary mismatch: the supplied policy governs 'Iconic BIM LLC' / iconicBIM.com, not the Guardian tool at getguardian.tech under review. No contradictions are reported because no second document exists to compare.
You've read all 15 risk ratings for Guardian. Create a free account to see the exact policy wording behind each rating.