All apps

Is Dust safe with your data?

C
Dust icon

Dust

Dust PBC

54/100

Partial disclosure · high confidence

Dust earns a C (54/100) because it discloses its data practices only in part.

#87

of 211 apps ranked

54

score · Enterprise copilot avg 52

+2

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Dust's platform privacy policy is a GDPR-shaped controller notice with strong sub-processor no-train and zero-retention language, a full rights list and a named DPO, while staying silent on user-input training opt-outs, output ownership, account-closure deletion timelines, breach notification and special-category data.

What Dust's privacy policy says about your data

Strongest disclosure

Named foundational model providers (OpenAI, Anthropic, Mistral, Google, Fireworks) are stated to be prohibited from training on customer data and to operate a Zero Data Retention policy where content is not logged for human review or saved to disk.

Retention is long and archival

Personal data is kept for the agreement duration and then archived for 5 years, with marketing data held 3 years from last contact, placing the retention ladder in the over-90-day tier with a named number.

Key silences

No training opt-out mechanism, no tier differences, no output ownership or licence terms, no deletion timeline after account closure, no breach notification commitment and no special-category data limits appear in the fetched text.

Scope caveat

The policy covers only Dust acting as Data Controller and expressly excludes Customer Personal Data processed as a Data Processor, so workspace content is governed by customer contracts that are not disclosed here.

What the policy is silent or vague on

  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs
  • Not stated: a deletion timeline after closure or request

Dust privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inPartial
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsSilent
Data-subject rights4 of 5 disclosed
Grants a right to access your dataDisclosed
Grants a right to delete your dataDisclosed
Offers data portability in a usable formatPartial
Grants a right to correct your dataDisclosed
Grants a way to object to or opt out of processingDisclosed
Retention and deletion1 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsDisclosed
Commits to collecting only the data it needsPartial
Third-party sharing2 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessPartial
Transparency1 of 4 disclosed
Discloses that you are interacting with AIPartial
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesPartial
Is versioned and dated, with change noticePartial
Sensitive data and children0 of 2 disclosed
Discloses automated decisions and a human-review pathNot applicable
Limits the use of special-category dataSilent
Governs biometric data specificallyNot applicable
States protections for children's dataPartial
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Enterprise copilot
Modalities
text
Processes biometrics
No
Policy last updated
Not stated
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Other enterprise copilot apps

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Dust safe with your data? Grade C | AI App Trust & Transparency Index