Nonlinear
nonlinear.buildNonlinear demonstrates strong privacy practices and user-favorable terms for professional AEC teams. Users retain ownership of all inputs and outputs, the platform only uses aggregated/anonymized data for improvements, and enterprise-grade security measures are in place. The policies are transparent and well-structured, with clear data controller/processor distinctions.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain full ownership of all data, files, and documents uploaded to the platform. Nonlinear only processes this data to provide services.
Output Data Ownership
Users own all AI-generated outputs and have perpetual, royalty-free license to use them without restrictions.
Training Data Usage
Nonlinear explicitly does NOT use identifiable customer data to train models. Only aggregated or de-identified data is used for improvements, ensuring customer data isolation.
Data Retention & Deletion
Clear deletion rights with data removed within commercially reasonable period upon request or contract termination. No specific retention schedules provided but commitment to delete unless legally required.
Third-Party Data Sharing
No selling or renting of personal information. Data shared only with essential service providers under strict confidentiality obligations, user-authorized integrations, or for legal compliance.
Opt-Out Rights
Users have GDPR/CCPA rights to object to processing activities and can revoke logo usage, but no explicit opt-out mechanism for aggregated data analysis is described.
Compliance & Certifications
References GDPR and CCPA compliance with Standard Contractual Clauses for international transfers, but no specific certifications (SOC 2, ISO 27001) are mentioned.
Model Explainability & Auditability
No specific provisions for model explainability or enterprise auditing rights mentioned in the policies.
Security Practices & Breach History
Industry-standard security measures including encryption at rest/in transit, access controls, monitoring, and least-privilege access. Uses trusted providers like AWS S3 and Clerk. No breach history mentioned.
Enterprise vs. Consumer Risk Delta
No explicit differentiation between free and paid tiers mentioned. Terms reference Order Forms which suggests enterprise agreements may have different terms.
Human Review of User Inputs
No explicit mention of human review rights or restrictions. Support communications are collected which may involve content review.
Regulatory & Litigation Exposure
Standard legal compliance provisions with notification where possible. Arbitration clause limits litigation exposure. No current disputes or regulatory issues mentioned.
PII & SPI Data Inventory
Collects minimal PII (name, email, company, IP address, device info). Explicitly prohibits uploading sensitive data like PHI, PCI data, or government-classified information.
You've read all 15 risk ratings for Nonlinear. Create a free account to see the exact policy wording behind each rating.