Readyintelligence
readyintelligence.comReadyIntelligence is an AI agent platform that connects large language models to an organisation's own knowledge base, marketed to membership associations and public-sector bodies (including local councils). Only a Cookie Policy and a marketing case study were retrievable; the substantive legal documents — the data privacy policy, GDPR statement, terms of service, DPA and security page — were all inaccessible. As a result, nearly every governance category is effectively silent in the supplied text: there is no evidence on data ownership, training use, retention, deletion, third-party sharing, opt-out rights, security controls, or compliance certifications. The one policy document present (cookies) discloses third-party cookies and Google Analytics but says nothing about the core AI product. Because the material terms cannot be verified from the supplied text, this tool cannot be recommended for professional, enterprise, or regulated-industry use without obtaining and reviewing the missing agreements.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The supplied documents contain no statement addressing who owns user-submitted data, prompts, or uploaded files. The cookie policy and case study do not cover data ownership at all, and the privacy policy and terms of service were inaccessible. Silence on this fundamental question is a significant risk for any organisation uploading proprietary knowledge bases.
Output Data Ownership
There is no language in the supplied text addressing ownership of AI-generated outputs. The relevant terms of service were not accessible. Without an ownership clause, users have no assurance about rights to generated content.
Training Data Usage
The only relevant signal is a marketing case study stating that the platform lets an organisation keep control of its content and avoid it being uploaded into third-party AI tools outside its control; however, this is promotional language, not a binding policy commitment. No policy document in the supplied text confirms whether user inputs are or are not used to train models. The absence of a verifiable no-training clause leaves genuine uncertainty.
Data Retention & Deletion
The supplied text provides no data retention schedule, deletion mechanism, or deletion SLA for user data. The cookie policy only addresses browser-cookie deletion, not product data. No retention or deletion obligations for the AI service can be verified.
Third-Party Data Sharing
The only disclosed third-party data flow is website analytics: cookies provided by a third-party service provider and Google Analytics for site-usage reporting, which the policy says is not linked to personally identifiable information. There is no disclosure regarding sharing of product/AI data with third parties, including the model providers the platform evidently uses. The product-level position is unverifiable from the supplied text.
Opt-Out Rights
The only opt-out mechanism disclosed is the ability to reject cookies via browser settings, which the policy notes may reduce functionality. There is no statement of opt-out rights for model training use or product data sharing. Opt-out for the core AI service cannot be assessed from the supplied text.
Compliance & Certifications
No compliance frameworks or certifications are named in the supplied documents. The marketing copy uses the words "compliant" and "trusted AI" but cites no standard, audit, or attestation. Assessed against the universal baseline plus enterprise SaaS frameworks (SOC 2 Type II, ISO 27018), none are mentioned. The platform serves UK/EU associations and public bodies, so GDPR would apply, yet no GDPR alignment is verifiable from the accessible text (the GDPR statement page was inaccessible).
Model Explainability & Auditability
The case study describes source-linked answers so users can see where responses come from rather than treating them as a black box, which is a positive transparency signal — but this is marketing narrative, not an auditability commitment. There is no policy-level description of enterprise audit logging, model documentation, or evaluation processes. Formal auditability cannot be confirmed.
Security Practices & Breach History
No security controls (encryption, access controls, penetration testing, incident response) are disclosed in the accessible text, and the dedicated security page was inaccessible. The case study asserts the platform is "secure" and "permission-aware" as marketing claims, without technical detail. No breach history is disclosed, and no trust center content could be reviewed.
Enterprise vs. Consumer Risk Delta
The supplied text does not describe distinct free versus paid tiers or any difference in data handling between them. The case study notes AI is offered free as part of membership in one deployment, but this does not establish a tiered data-handling model. No delta can be assessed from the available documents.
Human Review of User Inputs
The supplied documents are silent on whether vendor staff may access, read, or review user prompts or outputs. No relevant policy language was accessible. This silence prevents any assurance on human access to inputs.
Regulatory & Litigation Exposure
The supplied text contains no references to government data requests, law enforcement cooperation, or legal disputes. The relevant privacy and terms documents were inaccessible. Exposure cannot be assessed from the available materials.
PII & SPI Data Inventory
The cookie policy indicates cookies can store account and log-in details and analyse user behaviour, but the full inventory of PII/SPI processed by the AI product is not disclosed in the accessible text (the data privacy policy was inaccessible). Because the platform ingests organisational knowledge bases and serves members, sensitive content could be involved, but this is not documented. Silence on the full data inventory drives a high-risk rating.
Policy–Product Currency
The product is explicitly AI-first (an AI agent platform running on multiple language models), yet the only accessible policy document — the cookie policy — carries no discoverable effective or last-updated date and never mentions AI/ML processing, model training, or third-party model providers. The case study is dated 18 Feb 2026, but that is marketing, not policy. An undated cookie policy that is silent on the core AI capabilities the product ships justifies a RED rating.
Cross-Document Consistency
Two documents were supplied — a cookie policy and a marketing case study — but they address entirely different subject matter, so a meaningful cross-document contradiction check against the substantive legal terms is not possible; the terms of service, privacy policy and DPA were all inaccessible. No contradictions were found between the two available documents. Confidence is low because the documents that would normally be compared could not be retrieved.
You've read all 15 risk ratings for Readyintelligence. Create a free account to see the exact policy wording behind each rating.