The Rundown AI
therundown.aiThe Rundown AI presents moderate risk for professional use, with some user-favorable terms but significant gaps in key areas. While the service offers reasonable data rights and doesn't sell personal information, it grants itself broad perpetual licenses to user content and lacks clear enterprise-grade security disclosures. The AI features have limited data retention (30 days), but the policy is vague on training data usage and enterprise protections.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain ownership of content they submit, but grant The Rundown AI a broad perpetual license to use, modify, and distribute user submissions globally. This license is extremely broad and may apply to professional or proprietary content shared through the platform.
Output Data Ownership
The policy does not explicitly address ownership of AI-generated outputs or content created through their AI features. This creates ambiguity about who owns the results of AI processing, which is concerning for professional users.
Training Data Usage
The policy states that user inputs to AI features are retained for up to 30 days for service improvement, with an opt-out available. However, the terms are somewhat vague about the extent of training data usage and whether user submissions outside of AI features are used for training.
Data Retention & Deletion
The service provides clear data retention policies with specific timelines. AI input data is retained for only 30 days, users can request deletion, and the company commits to responding to deletion requests within 30 days. The policy also addresses data handling upon account termination.
Third-Party Data Sharing
The company explicitly states they do not sell personal information and only share data with service providers necessary for operations (email management, payment processing, analytics). Educational partners receive only anonymized data, and all sharing appears to be for legitimate business purposes with appropriate safeguards.
Opt-Out Rights
Users have multiple opt-out options including email unsubscribing, AI training data usage opt-out, and comprehensive data rights under GDPR and CCPA. The policy provides specific mechanisms for exercising these rights and contact information for requests.
Compliance & Certifications
The policy claims compliance with major frameworks including GDPR, CCPA/CPRA, and mentions using GDPR-compliant providers and EU-approved Standard Contractual Clauses. However, no specific certifications or third-party attestations are provided, and there's no mention of security frameworks like SOC 2.
Model Explainability & Auditability
The policy provides no information about model transparency, explainability features, or enterprise auditing capabilities. AI features are described as provided 'as is' with no guarantees of accuracy or transparency into decision-making processes.
Security Practices & Breach History
Basic security measures are mentioned including SSL encryption, access controls, and employee training. However, the policy lacks details about advanced security practices, penetration testing, or comprehensive incident response procedures. No breach history is disclosed.
Enterprise vs. Consumer Risk Delta
The policy mentions Team Plans for organizations with additional terms and a Data Processing Addendum (DPA) available for organizations subject to data protection laws. However, specific differences in data handling between individual and enterprise accounts are not clearly detailed.
Human Review of User Inputs
The policy does not explicitly state whether staff can access or review user prompts and outputs. While there are references to data processing for service improvement and AI features accessing required data, specific human review practices are not clearly disclosed.
Regulatory & Litigation Exposure
The policy includes standard provisions for legal compliance and law enforcement cooperation but does not indicate unusual regulatory exposure. Legal disclosure is limited to standard scenarios like court orders and legal obligations.
PII & SPI Data Inventory
The policy collects standard PII including names, contact information, payment data, and company information, plus usage analytics and email engagement data. While payment information is processed through third parties, the breadth of data collection including social media profiles and detailed usage tracking presents moderate risk.
You've read all 15 risk ratings for The Rundown AI. Create a free account to see the exact policy wording behind each rating.