All apps

Is Replit safe with your data?

D
Replit icon

Replit

Replit, Inc.

47/100

Weak disclosure · high confidence

Replit earns a D (47/100) because it leaves much about its data practices unstated.

Dealbreaker flag

  • D1.1: we have a legitimate interest in using Personal Data for product development and internal analytics purposes, to improve the accuracy of our machine learning technologies such as code generation
  • D1.4: you grant Replit the right to copy, display, distribute, perform, reformat, and modify your content as necessary, and the right to sublicense such rights to any third party provider for the Service

#123

of 211 apps ranked

47

score · Coding avg 47

+0

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Replit's policy discloses use of user data to improve its code-generation machine learning with no opt-out offered and takes a sublicensable content licence, while providing named rights channels, a Do Not Sell link, and a dated versioned policy.

What Replit's privacy policy and terms of service say about your data

Trains on user data with no opt-out

Replit claims a legitimate interest in using Personal Data "to improve the accuracy of our machine learning technologies such as code generation." No opt-out or opt-in mechanism appears anywhere in either document, so this is a reserved harm rather than mere silence.

Sublicensable content licence

The Terms grant Replit "the right to sublicense such rights to any third party provider for the Service," and separately reserve the right to "access the content of your private apps." Users retain ownership on paper, but the outbound licence is explicitly sublicensable.

Rights machinery is named and usable

Access, deletion, correction and opt-out of sale are all enumerated, with privacy@repl.it, account settings, a Do Not Sell footer link, and an authorized-agent path. Deletion is also wired to a concrete URL in the Terms.

No named transfer safeguard or breach notice

Cross-border transfers rest on user agreement alone with no SCCs, adequacy decision, or DPF named, and neither document states any breach notification duty or timeframe.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs

Replit privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inAdverse
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsAdverse
Data-subject rights3 of 5 disclosed
Grants a right to access your dataDisclosed
Grants a right to delete your dataDisclosed
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestPartial
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsPartial
Third-party sharing1 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementPartial
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersSilent
States a standard for government and law-enforcement accessPartial
Transparency2 of 4 disclosed
Discloses that you are interacting with AIPartial
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesPartial
Is versioned and dated, with change noticeDisclosed
Sensitive data and children1 of 2 disclosed
Discloses automated decisions and a human-review pathNot applicable
Limits the use of special-category dataPartial
Governs biometric data specificallyNot applicable
States protections for children's dataDisclosed
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Coding
Modalities
text
Processes biometrics
No
Policy last updated
2026-08-03
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Replit safe with your data? Grade D | AI App Trust & Transparency Index