All apps

Is Garfield AI safe with your data?

B
Garfield AI icon

Garfield AI

Garfield Law Ltd

60/100

Good disclosure · high confidence

Garfield AI earns a B (60/100) because it discloses most of its data practices.

#53

of 211 apps ranked

60

score · Legal avg 47

+13

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Garfield AI publishes a detailed UK GDPR privacy policy with a contractual no-train commitment, named sub-processors, named transfer safeguards and itemised retention periods, but it is silent on breach notification, children's age gating, output ownership and security certifications, and it names no concrete security controls.

What Garfield AI's privacy policy and terms of service say about your data

Strong no-train commitment

AI processing runs server-side in UK and EU Google Cloud data centres under contractual terms that prohibit using client data to train AI models, with a stated zero-data-retention configuration for the drafting and document-reading models.

Retention is itemised but long

Claim records are kept fifteen years from last activity and identity verification records six years, so the headline retention period is far beyond ninety days even though every number is explicitly named.

Security disclosure is thin

The policy offers only "appropriately secured systems" with no encryption, access-control or certification detail, and says nothing at all about breach notification or a named DPO.

No automated-decision safeguard

The human-review language cited applies to the non-AI Estimator Tool, while the product-side statement that identity and other checks "may be carried out by automated means" grants no human-review right.

What the policy is silent or vague on

  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs
  • Not stated: automated decisions and a human-review path

Garfield AI privacy rating

Training-data use1 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inDisclosed
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsSilent
Data-subject rights4 of 5 disclosed
Grants a right to access your dataDisclosed
Grants a right to delete your dataDisclosed
Offers data portability in a usable formatDisclosed
Grants a right to correct your dataDisclosed
Grants a way to object to or opt out of processingPartial
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestPartial
Sets a shorter retention for AI conversation logsPartial
Commits to collecting only the data it needsPartial
Third-party sharing3 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementDisclosed
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessPartial
Transparency3 of 4 disclosed
Discloses that you are interacting with AIDisclosed
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children1 of 3 disclosed
Discloses automated decisions and a human-review pathSilent
Limits the use of special-category dataDisclosed
Governs biometric data specificallyNot applicable
States protections for children's dataSilent
Security and accountability0 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactPartial
DisclosedPartialSilentAdverseNot applicable

Details

Category
Legal
Modalities
text
Processes biometrics
No
Policy last updated
2026-08-07
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Garfield AI safe with your data? Grade B | AI App Trust & Transparency Index