Lindy
lindy.aiLindy (Crivello Corp) is an AI workflow-automation platform that connects to a business's tools and acts as an AI agent. The consumer-facing Terms of Service and Privacy Policy are largely a generic template, favorable to the vendor on liability, arbitration, and content licensing. The Terms grant Lindy an irrevocable perpetual analytics license over Contributions and expansively assign ownership of user Submissions, while the Privacy Policy is comparatively thin and, notably, is over two years old (Feb 2024) versus the Terms (Mar 2025). The policies collect a broad range of PII plus health data as sensitive information, disclaim HIPAA/GLBA suitability absent a separate agreement, and name no formal compliance certifications in the consumer documents. Overall, moderate risk: acceptable for general professional use with caution, but not for regulated or highly sensitive data without the enterprise MSA/DPA in place.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Terms state users retain ownership of their Contributions, but simultaneously grant Lindy a broad license including an irrevocable analytics license in perpetuity. Submissions (feedback/ideas) are assigned outright to Lindy. The result is user ownership on paper but expansive vendor usage rights.
Output Data Ownership
The consumer documents do not clearly address ownership of AI-generated outputs. Content generated by the Services is not explicitly assigned to the user, and Lindy asserts broad ownership over Content and Marks in the Services generally. This silence on output ownership is a risk for a tool that produces decks, reports, and drafts.
Training Data Usage
The Privacy Policy commits that data sourced from Google APIs will never be used to train generative AI, but is silent on whether other user inputs may be used for model training. The Terms grant an irrevocable perpetual analytics license over Contributions, which is broad and ambiguous. The absence of a general no-training commitment for non-Google data is a gap.
Data Retention & Deletion
The Privacy Policy uses generic 'as long as necessary' language with no fixed retention schedule or deletion SLA, though it does offer a mechanism to review, update, or delete data by email. The DPA section of the Terms commits Lindy to delete Company Personal Data after cessation of Services. No specific timelines or audit-log retention obligations are stated in the consumer documents.
Third-Party Data Sharing
Lindy states it does not sell personal information and shares data with named vendors/subprocessors (cloud, analytics, payment, communications providers) under contract. Sharing is disclosed and tied to service delivery, but the list is broad and includes business-transfer and affiliate sharing. Because the product inherently integrates with third-party tools, disclosed sharing is expected, but disclosure of specific data flows is limited.
Opt-Out Rights
The Privacy Policy provides some opt-out mechanisms: users can opt out of location data collection and can exercise rights (including deletion) by contacting privacy@lindy.ai. However, there is no explicit opt-out from model-usage/analytics or from third-party sharing, and consent-based sharing language is vague.
Compliance & Certifications
The consumer documents name no security certifications (no SOC 2, ISO 27001, ISO 42001, etc.). They reference GDPR and Standard Contractual Clauses and California/US privacy rights, and explicitly state the Services are NOT tailored for HIPAA/FISMA/GLBA absent a separate agreement. Against the universal baseline and enterprise_saas frameworks, no relevant certification is evidenced, so this rates RED for the consumer tier.
Model Explainability & Auditability
The consumer documents provide no model transparency or explainability commitments. The DPA section does allow the Controller (customer) to request information and conduct audits regarding processing of personal data, which offers limited auditability of data handling but not model behavior.
Security Practices & Breach History
The Privacy Policy describes 'appropriate and reasonable technical and organizational security measures' but names no specific controls (no encryption, penetration testing, or bug bounty details) and disclaims any guarantee of security. The DPA commits to breach notification. No breach history is disclosed, and no trust center or security page is referenced in the consumer documents.
Enterprise vs. Consumer Risk Delta
The consumer documents do not describe distinct free vs. paid data-handling tiers, though they reference a separate Business Associate Agreement path for regulated use. Material differences (e.g., Customer Data ownership, SOC 2/HIPAA alignment, deletion timelines) appear only in the enterprise MSA, indicating a meaningful delta between the consumer terms and enterprise agreements.
Human Review of User Inputs
The Terms reserve broad rights to monitor the Services and access/disable Contributions, and grant a license to 'monitor' Contributions. The documents do not explicitly commit that staff will not read user prompts/outputs, nor do they clearly describe a human-review process. This ambiguity leaves open the possibility of human access.
Regulatory & Litigation Exposure
The documents reference cooperation with law enforcement, processing to comply with legal requests, and mandatory binding arbitration with a class-action waiver. There is no disclosure of specific litigation or government data requests, but the vendor reserves broad rights to report users and pursue legal action.
PII & SPI Data Inventory
Lindy collects a range of PII (name, email, billing address, IP, device identifiers, precise/imprecise location, usage data) and processes health data as sensitive personal information with consent. Collection is disclosed with some controls (location opt-out, consent for SPI), but the inclusion of health data and precise geolocation warrants a YELLOW rating rather than GREEN.
Policy–Product Currency
The product ships as an AI-first agent that connects to 1,000+ tools, retains editable memory, sits in on meetings, and runs scheduled automations. The Privacy Policy is dated February 13, 2024 — over two years before the analysis date — and never addresses AI/ML processing, model training on inputs, or third-party model providers, aside from a narrow Google-API carve-out. The Terms (March 14, 2025) are more current but still light on AI specifics. The stale privacy policy that fails to cover the shipped AI capabilities drives a RED rating.
Cross-Document Consistency
Two consumer documents were supplied (Terms and Privacy Policy). They are largely reconcilable but exhibit minor tensions: the Privacy Policy is dated over a year earlier than the Terms, and jurisdiction/registration references (Oregon registration, California governing law, France representative) differ across sections. No material or critical contradiction between the two consumer documents was found.
You've read all 15 risk ratings for Lindy. Create a free account to see the exact policy wording behind each rating.