OpenSpace
openspace.aiOpenSpace demonstrates strong enterprise security practices with comprehensive compliance certifications (SOC 2 Type 2, GDPR, CCPA, CPRA) and detailed privacy disclosures. However, the lack of accessible terms of service creates significant gaps in understanding data ownership, training usage rights, and opt-out mechanisms. The privacy policy shows enterprise-focused data handling but includes broad data sharing with advertising partners and lacks clear training data usage restrictions.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Privacy policy distinguishes between user data and Enterprise Customer Data, indicating some ownership protections for enterprise users. However, without accessible terms of service, full ownership rights remain unclear.
Output Data Ownership
No accessible terms of service means output data ownership rights are completely unclear. The privacy policy does not address ownership of AI-generated content or results.
Training Data Usage
Privacy policy allows broad data processing including improving services and product development, which could encompass model training. No explicit restrictions on using user inputs for AI model training are provided.
Data Retention & Deletion
Clear data retention policy with deletion capabilities. Data is retained as long as account is open, with longer retention only for legal compliance. Users can request deletion through privacy rights.
Third-Party Data Sharing
Extensive third-party data sharing including with advertising partners and analytics providers. While disclosed, the breadth of sharing goes beyond core service functionality and includes marketing purposes.
Opt-Out Rights
Multiple opt-out mechanisms provided including cookie controls, advertising opt-outs, and comprehensive EU/UK data subject rights. California and Nevada residents have specific opt-out rights for data sales.
Compliance & Certifications
Excellent compliance framework with multiple certifications including SOC 2 Type 2, SOC 3, GDPR, CCPA, CPRA, EU-US DPF, Swiss-US DPF, Global CBPR, CSA STAR Level 1, and others. Strong third-party attestations.
Model Explainability & Auditability
Security trust center mentions AI overview and model cards, suggesting some transparency efforts. However, detailed explainability and enterprise auditing capabilities are not clearly described.
Security Practices & Breach History
Comprehensive security program with dedicated trust center, penetration testing, incident response procedures, encryption, access controls, and multiple security certifications. No breach history disclosed.
Enterprise vs. Consumer Risk Delta
Clear distinction between individual user data and Enterprise Customer Data. Enterprise customers have greater control over their data through separate agreements and processing instructions.
Human Review of User Inputs
Privacy policy does not explicitly address human review rights or restrictions. Given the broad data processing purposes and third-party sharing, human access to user inputs cannot be ruled out.
Regulatory & Litigation Exposure
Privacy policy acknowledges potential legal obligations and government requests. Data Privacy Framework compliance includes Federal Trade Commission oversight and dispute resolution mechanisms.
PII & SPI Data Inventory
Collects significant PII including names, emails, phone numbers, addresses, IP addresses, device data, and geolocation. Also collects sensory data (photos, videos). No SPI explicitly mentioned, but broad data collection scope raises privacy concerns.
You've read all 15 risk ratings for OpenSpace. Create a free account to see the exact policy wording behind each rating.