Lindy logo

Lindy

lindy.ai
Moderate Risk
Updated September 1, 2026

Lindy (Crivello Corp) is an AI workflow-automation platform that connects to a business's tools and acts as an AI agent. The consumer-facing Terms of Service and Privacy Policy are largely a generic template, favorable to the vendor on liability, arbitration, and content licensing. The Terms grant Lindy an irrevocable perpetual analytics license over Contributions and expansively assign ownership of user Submissions, while the Privacy Policy is comparatively thin and, notably, is over two years old (Feb 2024) versus the Terms (Mar 2025). The policies collect a broad range of PII plus health data as sensitive information, disclaim HIPAA/GLBA suitability absent a separate agreement, and name no formal compliance certifications in the consumer documents. Overall, moderate risk: acceptable for general professional use with caution, but not for regulated or highly sensitive data without the enterprise MSA/DPA in place.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The Terms state users retain ownership of their Contributions, but simultaneously grant Lindy a broad license including an irrevocable analytics license in perpetuity. Submissions (feedback/ideas) are assigned outright to Lindy. The result is user ownership on paper but expansive vendor usage rights.

Confidence
70%

Output Data Ownership

Moderate Risk

The consumer documents do not clearly address ownership of AI-generated outputs. Content generated by the Services is not explicitly assigned to the user, and Lindy asserts broad ownership over Content and Marks in the Services generally. This silence on output ownership is a risk for a tool that produces decks, reports, and drafts.

Confidence
40%

Training Data Usage

Moderate Risk

The Privacy Policy commits that data sourced from Google APIs will never be used to train generative AI, but is silent on whether other user inputs may be used for model training. The Terms grant an irrevocable perpetual analytics license over Contributions, which is broad and ambiguous. The absence of a general no-training commitment for non-Google data is a gap.

Confidence
55%

Data Retention & Deletion

Moderate Risk

The Privacy Policy uses generic 'as long as necessary' language with no fixed retention schedule or deletion SLA, though it does offer a mechanism to review, update, or delete data by email. The DPA section of the Terms commits Lindy to delete Company Personal Data after cessation of Services. No specific timelines or audit-log retention obligations are stated in the consumer documents.

Confidence
60%

Third-Party Data Sharing

Moderate Risk

Lindy states it does not sell personal information and shares data with named vendors/subprocessors (cloud, analytics, payment, communications providers) under contract. Sharing is disclosed and tied to service delivery, but the list is broad and includes business-transfer and affiliate sharing. Because the product inherently integrates with third-party tools, disclosed sharing is expected, but disclosure of specific data flows is limited.

Confidence
65%

Opt-Out Rights

Moderate Risk

The Privacy Policy provides some opt-out mechanisms: users can opt out of location data collection and can exercise rights (including deletion) by contacting privacy@lindy.ai. However, there is no explicit opt-out from model-usage/analytics or from third-party sharing, and consent-based sharing language is vague.

Confidence
55%

Compliance & Certifications

High Risk

The consumer documents name no security certifications (no SOC 2, ISO 27001, ISO 42001, etc.). They reference GDPR and Standard Contractual Clauses and California/US privacy rights, and explicitly state the Services are NOT tailored for HIPAA/FISMA/GLBA absent a separate agreement. Against the universal baseline and enterprise_saas frameworks, no relevant certification is evidenced, so this rates RED for the consumer tier.

Confidence
62%

Model Explainability & Auditability

Moderate Risk

The consumer documents provide no model transparency or explainability commitments. The DPA section does allow the Controller (customer) to request information and conduct audits regarding processing of personal data, which offers limited auditability of data handling but not model behavior.

Confidence
45%

Security Practices & Breach History

Moderate Risk

The Privacy Policy describes 'appropriate and reasonable technical and organizational security measures' but names no specific controls (no encryption, penetration testing, or bug bounty details) and disclaims any guarantee of security. The DPA commits to breach notification. No breach history is disclosed, and no trust center or security page is referenced in the consumer documents.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The consumer documents do not describe distinct free vs. paid data-handling tiers, though they reference a separate Business Associate Agreement path for regulated use. Material differences (e.g., Customer Data ownership, SOC 2/HIPAA alignment, deletion timelines) appear only in the enterprise MSA, indicating a meaningful delta between the consumer terms and enterprise agreements.

Confidence
50%

Human Review of User Inputs

Moderate Risk

The Terms reserve broad rights to monitor the Services and access/disable Contributions, and grant a license to 'monitor' Contributions. The documents do not explicitly commit that staff will not read user prompts/outputs, nor do they clearly describe a human-review process. This ambiguity leaves open the possibility of human access.

Confidence
45%

Regulatory & Litigation Exposure

Moderate Risk

The documents reference cooperation with law enforcement, processing to comply with legal requests, and mandatory binding arbitration with a class-action waiver. There is no disclosure of specific litigation or government data requests, but the vendor reserves broad rights to report users and pursue legal action.

Confidence
55%

PII & SPI Data Inventory

Moderate Risk

Lindy collects a range of PII (name, email, billing address, IP, device identifiers, precise/imprecise location, usage data) and processes health data as sensitive personal information with consent. Collection is disclosed with some controls (location opt-out, consent for SPI), but the inclusion of health data and precise geolocation warrants a YELLOW rating rather than GREEN.

Confidence
65%

Policy–Product Currency

High Risk

The product ships as an AI-first agent that connects to 1,000+ tools, retains editable memory, sits in on meetings, and runs scheduled automations. The Privacy Policy is dated February 13, 2024 — over two years before the analysis date — and never addresses AI/ML processing, model training on inputs, or third-party model providers, aside from a narrow Google-API carve-out. The Terms (March 14, 2025) are more current but still light on AI specifics. The stale privacy policy that fails to cover the shipped AI capabilities drives a RED rating.

Confidence
72%

Cross-Document Consistency

Moderate Risk

Two consumer documents were supplied (Terms and Privacy Policy). They are largely reconcilable but exhibit minor tensions: the Privacy Policy is dated over a year earlier than the Terms, and jurisdiction/registration references (Oregon registration, California governing law, France representative) differ across sections. No material or critical contradiction between the two consumer documents was found.

Confidence
50%

You've read all 15 risk ratings for Lindy. Create a free account to see the exact policy wording behind each rating.