OpenArt
openart.aiOpenArt is a consumer-facing AI content generation platform (images, video, audio). Its Terms of Service are moderately vendor-favorable but reasonable on output ownership (OpenArt claims no ownership of Output). However, the Privacy Policy is severely outdated and internally alarming: it references defunct frameworks (EU-US Safe Harbor, which was invalidated in 2015), claims exemption from CCPA under GLBA (a claim that does not credibly apply to an AI art generator), permits broad sharing with 'business and third party marketing partners,' and discloses collection of highly sensitive data including social security numbers. The Privacy Policy (March 2026) is out of step with the current AI-first product and contradicts the Terms of Service on data retention and data sharing. The mandatory arbitration clause, class-action waiver, $100 liability cap, and broad perpetual license to User Content further disadvantage users. Not recommended for professional or sensitive use without contractual protections.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Terms do not explicitly assign ownership of user-submitted inputs (prompts, reference images), but grant OpenArt a broad, worldwide, perpetual, sublicensable, transferable license to User Content. Inputs are also shared with third-party AI model providers. Ownership is not clearly retained by the user in explicit terms.
Output Data Ownership
OpenArt explicitly disclaims ownership of AI-generated Output. Users may use Output for non-commercial purposes at all tiers, and for commercial purposes at the 'Plus' tier and above, subject to compliance with the Terms including watermark rules.
Training Data Usage
The Terms state inputs and Output are shared with third-party AI technology partners to 'operate and improve the Services,' which implies potential model improvement use, but no explicit statement confirms OpenArt trains its own models on user inputs. The Privacy Policy separately grants OpenArt rights to use personal information for 'research' and 'product...development.' There is no clear no-training commitment.
Data Retention & Deletion
The Terms provide a retention schedule: subscribers' private creations are kept until deleted or subscription ends; non-subscribers' creations are deleted after 7 days if unpublished. Users can delete their account at any time. However, there are no formal deletion SLAs, no security-related retention obligations, and deletions are described as final and irreversible with no backup/audit retention detail.
Third-Party Data Sharing
The Privacy Policy permits broad sharing of personal information with 'business and third party marketing partners' and with affiliates for marketing, and states users cannot limit some of this sharing. While inputs shared with AI model providers are integral to the service, the marketing-partner sharing goes beyond service necessity and the policy grants OpenArt rights to use personal data for marketing 'without restrictions.' This exceeds what the core service requires.
Opt-Out Rights
The Privacy Policy provides opt-out mechanisms for marketing communications and states users can limit sharing for marketing purposes and non-affiliate marketing. However, users cannot limit sharing for 'everyday business purposes,' affiliate marketing, or third-party service providers. Do Not Track signals are explicitly ignored. Opt-out rights exist but are limited in scope.
Compliance & Certifications
No relevant modern compliance frameworks are certified or credibly claimed. The Privacy Policy relies on the invalidated EU-US Safe Harbor framework and asserts that OpenArt is exempt from the CCPA under the Gramm-Leach-Bliley Act — a claim that does not credibly apply to an AI art generator and conflicts with the privacy laws that likely apply. No SOC 2, ISO, or AI-specific certifications are mentioned. GDPR is referenced only in a limited/garbled manner. This is a significant compliance red flag.
Model Explainability & Auditability
The documents provide no transparency into model behavior, no enterprise auditability provisions, and no explainability commitments. The Terms disclaim all warranties about Output accuracy and the accuracy of the optional 'IP Safety Check' feature. The policy is effectively silent on model transparency.
Security Practices & Breach History
Security disclosures are outdated and weak. The Privacy Policy references SSL/Private Communications Technology 'supported by Microsoft Internet Explorer 4.0 or later' — an obsolete standard — and a firewall, but no modern controls (encryption at rest, access controls, penetration testing, bug bounty, incident response). No breach history, no trust center, and no security page are referenced. The vendor explicitly does not guarantee security.
Enterprise vs. Consumer Risk Delta
The Terms describe differences between free and paid tiers: free-plan Output may carry a watermark and is limited to non-commercial use, while paid 'Plus' and above unlock commercial use and watermark-free output. Non-subscribers' creations are deleted after 7 days while subscribers' are retained. However, no separate enterprise data-handling protections are documented.
Human Review of User Inputs
OpenArt reserves the right to monitor and review User Content for moderation, and the license granted permits labeling, classifying, and moderating content. This implies staff or automated access to user inputs. The right is discretionary ('no obligation'), but the reservation is broad.
Regulatory & Litigation Exposure
The Privacy Policy discloses that OpenArt may release information to regulators and to law enforcement pursuant to official requests, and for court orders and legal investigations. The Terms impose mandatory individual arbitration, a class-action waiver, and a one-year claim limit, which shape litigation exposure. No specific pending disputes are disclosed.
PII & SPI Data Inventory
The Privacy Policy discloses collection of extensive PII (name, email, postal address, phone, IP address, ISP/carrier, usage behavior) and — notably — sensitive personal information including social security number and precise GPS/location data. This SPI collection is disclosed but with weak controls, broad marketing-sharing rights, and no clear purpose limitation, warranting a RED rating.
Policy–Product Currency
While the Terms are recent (Last Updated July 2026) and address AI model providers, the Privacy Policy (effective March 2026) is materially out of step with the AI-first product. It never addresses AI/ML processing of prompts, references defunct EU-US Safe Harbor, and reads as a generic e-commerce policy (shopping carts, SSNs, IE 4.0). The product ships numerous third-party AI models (Sora 2, Kling, Seedream, etc.) not reflected in the Privacy Policy's data-flow disclosures.
Cross-Document Consistency
Multiple documents were supplied and contain material contradictions. The Terms promise that private creations are stored during a subscription and creations are private by default, while the Privacy Policy grants broad rights to use and share personal information for marketing 'without restrictions.' The Terms state OpenArt does not share name/email/credentials with AI partners, but the Privacy Policy broadly permits sharing with marketing partners and affiliates. These create MATERIAL conflicts affecting user decisions.
You've read all 15 risk ratings for OpenArt. Create a free account to see the exact policy wording behind each rating.