Raven logo

Raven

raven.build
High Risk
Updated September 5, 2026

Raven is an AI co-pilot for CAD/Rhino/Grasshopper (design-automation tooling), operated by Raven CAD GmbH in Switzerland. The supplied documents are actually the Privacy Policy (not the full Terms of Service) plus a Data Processing Addendum. The consumer posture is materially plan-dependent: Free and Personal plans are explicitly 'data-contribution' plans on which Raven trains its own models using raw prompts, files, and outputs; the Professional plan is a restricted, no-training plan. Because the default/free experience permits broad training and commercial research use of user content, and because the policy never names any third-party certification (SOC 2, ISO 27001, etc.) or a concrete retention schedule/deletion SLA, professional users should upgrade to Professional (or Enterprise) and rely on the DPA before submitting proprietary or client design data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The supplied Privacy Policy focuses on personal data and repeatedly refers to a separate Terms of Service to define contractual rights in 'Customer Content,' which was not provided. It confirms that on Free/Personal plans Raven takes broad rights to use submitted content, but the actual ownership grant is defined in a document not included here.

Confidence
45%

Output Data Ownership

Moderate Risk

Ownership of Generated Output is expressly assigned to the (unsupplied) Terms of Service. The Privacy Policy establishes that on Free/Personal plans Generated Output can be used for Raven's research and commercial products, but it does not state who owns the output.

Confidence
40%

Training Data Usage

High Risk

On the default Free and Personal plans, Raven explicitly uses raw user content — prompts, files, outputs — to train and fine-tune its own AI models and to build commercial research products. Personal users can limit this only to aggregated/synthetic use via a setting, and only the paid Professional plan carries a genuine no-training commitment. For the standard consumer tier this is a highly vendor-favorable term.

Confidence
92%

Data Retention & Deletion

Moderate Risk

Users can request deletion via legal@raven.build and the policy lists retention criteria by data type, but it provides no concrete retention periods and no deletion SLA. Notably, Free and Personal Contribution/Research Data 'may be retained and used after account closure,' meaning deletion of an account does not necessarily remove content already absorbed into research datasets.

Confidence
70%

Third-Party Data Sharing

Moderate Risk

Disclosure recipients are broadly and clearly enumerated (service providers, model providers, payment providers, integrations, research/business/technology partners, business-transfer recipients). Raven states it does not sell Account Data for money, but acknowledges that Free/Personal Research Data disclosures may qualify as a 'sale' or 'sharing' under U.S. law. Sharing of core content for inference is integral to the service, but the research-partner and 'valuable consideration' disclosures push this to moderate risk.

Confidence
78%

Opt-Out Rights

Moderate Risk

Meaningful opt-out mechanisms exist but are tiered and incomplete for the free tier. Personal users can enable a setting limiting research use to aggregated/synthetic data (but cannot fully opt out of research use), Professional customers can opt out of product-improvement use, and Raven honors GPC signals where required. Free users appear to have no equivalent research-use opt-out, and marketing opt-out is available.

Confidence
74%

Compliance & Certifications

Moderate Risk

The documents claim alignment with GDPR, UK GDPR, the Swiss FADP, and U.S. state privacy laws, and the DPA references standard contractual clauses and transfer mechanisms. However, no third-party certification or attestation (SOC 2, ISO 27001, ISO 27018, ISO 42001) is named anywhere, which is a gap for a developer-infrastructure/enterprise tool. Frameworks are asserted, not evidenced by an audit report or trust center.

Confidence
68%

Model Explainability & Auditability

Moderate Risk

The consumer Privacy Policy offers no model-explainability commitments. It discloses that model providers generate outputs and that logging exists, but transparency into model behavior for individual users is not addressed. (Enterprise/DPA audit rights are assessed separately in the enterprise object.)

Confidence
45%

Security Practices & Breach History

Moderate Risk

The policy describes a reasonable set of technical/organizational measures (access controls, encryption in transit, least-privilege, vulnerability management, incident response). However, it explicitly notes encryption in transit only — encryption at rest is not clearly committed in the Privacy Policy — and no penetration testing, bug bounty, breach history, or dedicated trust center/security page is referenced.

Confidence
66%

Enterprise vs. Consumer Risk Delta

High Risk

There is a large, material difference between tiers. Free and Personal are 'data-contribution' plans on which raw content trains Raven's models, while Professional is a 'restricted-data plan' with no-training commitments and DPA coverage. A user on the wrong plan exposes proprietary design data to model training and commercial research, so the delta itself is a significant risk to unaware consumer/free users.

Confidence
88%

Human Review of User Inputs

Moderate Risk

The policy does not contain an explicit statement that staff will read prompts/outputs, but it reserves broad rights to process content for support, debugging, abuse/fraud monitoring, safety testing, and research, which implies human access is possible. Personnel are bound by confidentiality obligations. Silence on an explicit human-review commitment lowers confidence.

Confidence
55%

Regulatory & Litigation Exposure

Moderate Risk

The policy discloses that Raven may share data with legal, regulatory, and law-enforcement recipients to comply with law, protect rights, or investigate fraud/security incidents. There are no references to specific active litigation or government-request transparency reporting, which is a disclosure gap.

Confidence
60%

PII & SPI Data Inventory

Moderate Risk

Raven collects significant PII — name, email, username, IP address, device identifiers, approximate geolocation, usage telemetry, billing contact data — plus content that may contain personal data. It expressly disclaims intending to process sensitive/special-category data unless agreed, and does not store full card numbers. Disclosure is adequate but the breadth of collected PII and content places this at moderate risk.

Confidence
78%

Policy–Product Currency

Low Risk

The Privacy Policy and DPA are both dated 15 June 2026, well within 12 months of the 5 September 2026 analysis date. The documents substantively cover the AI capabilities visible in the product surface — natural-language CAD generation, model providers/inference, third-party plugin integrations, and model training on user content — so both recency and coverage are satisfied.

Confidence
80%

Cross-Document Consistency

Low Risk

Multiple documents were supplied (Privacy Policy across several locale/URL variants, plus the DPA). The Privacy Policy's Professional no-training statements and the DPA's no-training clauses are mutually consistent, and the DPA includes an explicit precedence clause resolving conflicts. No contradictions were identified across the supplied documents.

Confidence
74%

You've read all 15 risk ratings for Raven. Create a free account to see the exact policy wording behind each rating.