All apps

Is Pigment safe with your data?

D
Pigment icon

Pigment

Pigment SAS

39/100

Weak disclosure · high confidence

Pigment earns a D (39/100) because it leaves much about its data practices unstated.

#161

of 211 apps ranked

39

score · Finance avg 38

+1

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Pigment's public privacy policy and master services agreement cover GDPR rights, recipient categories, transfer safeguards and a named DPO, but stay silent on training opt-outs, deletion timelines, breach notification, children's protections and automated decision-making.

What Pigment's privacy policy and terms of service say about your data

Rights listed without a mechanism

The rights section is a bare seven-item list qualified by "Within the limits and conditions of applicable data protection laws", with no request timeline or verification process, so access, erasure, portability and rectification each drop to half; only the objection right is tied to the named dpo@pigment.com channel.

AI use disclosed only in a definitions clause

AI Features appear as a defined term inside the Solution definition and the policy notes inputs and outputs are processed "to provide, develop and improve our Pigment AI Features", but there is no user-facing AI-interaction disclosure, no opt-out mechanism and no tier differences.

Government access is a bare permission

"We may also have to share your personal data with a regulator or to otherwise comply with the law" reserves disclosure without any legal threshold, user-notice commitment or challenge process, which is not a disclosed government-access standard.

Security and retention thinly specified

The only named control is "Website SSL" with no cipher, key length or access-control scheme, there is no breach-notification clause at all, and the shortest stated retention is 3 years from contract end or last positive engagement.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: a deletion timeline after closure or request

Pigment privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inSilent
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsPartial
Data-subject rights1 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsSilent
Third-party sharing2 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outSilent
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessSilent
Transparency2 of 4 disclosed
Discloses that you are interacting with AIPartial
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children0 of 3 disclosed
Discloses automated decisions and a human-review pathSilent
Limits the use of special-category dataSilent
Governs biometric data specificallyNot applicable
States protections for children's dataSilent
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Finance
Modalities
text
Processes biometrics
No
Policy last updated
June 2026
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Pigment safe with your data? Grade D | AI App Trust & Transparency Index