Raven
raven.buildRaven is an AI co-pilot for CAD/Rhino/Grasshopper (design-automation tooling), operated by Raven CAD GmbH in Switzerland. The supplied documents are actually the Privacy Policy (not the full Terms of Service) plus a Data Processing Addendum. The consumer posture is materially plan-dependent: Free and Personal plans are explicitly 'data-contribution' plans on which Raven trains its own models using raw prompts, files, and outputs; the Professional plan is a restricted, no-training plan. Because the default/free experience permits broad training and commercial research use of user content, and because the policy never names any third-party certification (SOC 2, ISO 27001, etc.) or a concrete retention schedule/deletion SLA, professional users should upgrade to Professional (or Enterprise) and rely on the DPA before submitting proprietary or client design data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The supplied Privacy Policy focuses on personal data and repeatedly refers to a separate Terms of Service to define contractual rights in 'Customer Content,' which was not provided. It confirms that on Free/Personal plans Raven takes broad rights to use submitted content, but the actual ownership grant is defined in a document not included here.
Output Data Ownership
Ownership of Generated Output is expressly assigned to the (unsupplied) Terms of Service. The Privacy Policy establishes that on Free/Personal plans Generated Output can be used for Raven's research and commercial products, but it does not state who owns the output.
Training Data Usage
On the default Free and Personal plans, Raven explicitly uses raw user content — prompts, files, outputs — to train and fine-tune its own AI models and to build commercial research products. Personal users can limit this only to aggregated/synthetic use via a setting, and only the paid Professional plan carries a genuine no-training commitment. For the standard consumer tier this is a highly vendor-favorable term.
Data Retention & Deletion
Users can request deletion via legal@raven.build and the policy lists retention criteria by data type, but it provides no concrete retention periods and no deletion SLA. Notably, Free and Personal Contribution/Research Data 'may be retained and used after account closure,' meaning deletion of an account does not necessarily remove content already absorbed into research datasets.
Third-Party Data Sharing
Disclosure recipients are broadly and clearly enumerated (service providers, model providers, payment providers, integrations, research/business/technology partners, business-transfer recipients). Raven states it does not sell Account Data for money, but acknowledges that Free/Personal Research Data disclosures may qualify as a 'sale' or 'sharing' under U.S. law. Sharing of core content for inference is integral to the service, but the research-partner and 'valuable consideration' disclosures push this to moderate risk.
Opt-Out Rights
Meaningful opt-out mechanisms exist but are tiered and incomplete for the free tier. Personal users can enable a setting limiting research use to aggregated/synthetic data (but cannot fully opt out of research use), Professional customers can opt out of product-improvement use, and Raven honors GPC signals where required. Free users appear to have no equivalent research-use opt-out, and marketing opt-out is available.
Compliance & Certifications
The documents claim alignment with GDPR, UK GDPR, the Swiss FADP, and U.S. state privacy laws, and the DPA references standard contractual clauses and transfer mechanisms. However, no third-party certification or attestation (SOC 2, ISO 27001, ISO 27018, ISO 42001) is named anywhere, which is a gap for a developer-infrastructure/enterprise tool. Frameworks are asserted, not evidenced by an audit report or trust center.
Model Explainability & Auditability
The consumer Privacy Policy offers no model-explainability commitments. It discloses that model providers generate outputs and that logging exists, but transparency into model behavior for individual users is not addressed. (Enterprise/DPA audit rights are assessed separately in the enterprise object.)
Security Practices & Breach History
The policy describes a reasonable set of technical/organizational measures (access controls, encryption in transit, least-privilege, vulnerability management, incident response). However, it explicitly notes encryption in transit only — encryption at rest is not clearly committed in the Privacy Policy — and no penetration testing, bug bounty, breach history, or dedicated trust center/security page is referenced.
Enterprise vs. Consumer Risk Delta
There is a large, material difference between tiers. Free and Personal are 'data-contribution' plans on which raw content trains Raven's models, while Professional is a 'restricted-data plan' with no-training commitments and DPA coverage. A user on the wrong plan exposes proprietary design data to model training and commercial research, so the delta itself is a significant risk to unaware consumer/free users.
Human Review of User Inputs
The policy does not contain an explicit statement that staff will read prompts/outputs, but it reserves broad rights to process content for support, debugging, abuse/fraud monitoring, safety testing, and research, which implies human access is possible. Personnel are bound by confidentiality obligations. Silence on an explicit human-review commitment lowers confidence.
Regulatory & Litigation Exposure
The policy discloses that Raven may share data with legal, regulatory, and law-enforcement recipients to comply with law, protect rights, or investigate fraud/security incidents. There are no references to specific active litigation or government-request transparency reporting, which is a disclosure gap.
PII & SPI Data Inventory
Raven collects significant PII — name, email, username, IP address, device identifiers, approximate geolocation, usage telemetry, billing contact data — plus content that may contain personal data. It expressly disclaims intending to process sensitive/special-category data unless agreed, and does not store full card numbers. Disclosure is adequate but the breadth of collected PII and content places this at moderate risk.
Policy–Product Currency
The Privacy Policy and DPA are both dated 15 June 2026, well within 12 months of the 5 September 2026 analysis date. The documents substantively cover the AI capabilities visible in the product surface — natural-language CAD generation, model providers/inference, third-party plugin integrations, and model training on user content — so both recency and coverage are satisfied.
Cross-Document Consistency
Multiple documents were supplied (Privacy Policy across several locale/URL variants, plus the DPA). The Privacy Policy's Professional no-training statements and the DPA's no-training clauses are mutually consistent, and the DPA includes an explicit precedence clause resolving conflicts. No contradictions were identified across the supplied documents.
You've read all 15 risk ratings for Raven. Create a free account to see the exact policy wording behind each rating.