All apps

Is Rippling safe with your data?

D
Rippling icon

Rippling

Rippling People Center, Inc.

44/100

Weak disclosure · high confidence

Rippling earns a D (44/100) because it leaves much about its data practices unstated.

Dealbreaker flag

  • D1.4: you hereby grant and will grant Rippling a nonexclusive, worldwide, royalty-free, fully paid-up, transferable, sublicensable (through multiple tiers) license to copy, display, upload, perform, distribute, model, index, store, modify, create derivative works from, and otherwise use your Customer Data

#140

of 211 apps ranked

44

score · HR & recruiting avg 55

-11

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Rippling publishes a detailed privacy notice with enumerated data categories, a purpose-to-legal-basis table and named transfer safeguards, but it is silent on whether customer data trains models and its customer terms grant Rippling a sublicensable licence to model and create derivative works from Customer Data.

What Rippling's privacy policy and terms of service say about your data

Sublicensable licence over customer data

The Customer Terms grant Rippling a worldwide, transferable licence, sublicensable through multiple tiers, to model, index, modify and create derivative works from Customer Data. It is the one clause in either document that reserves a right against the customer.

Rights list is conditional boilerplate

Access, deletion, portability and correction are each offered only as "Subject to applicable law, you may have the right to", with no submission route beyond a generic contact address. Only the CCPA sale and share opt-out names a real mechanism, Your Privacy Choices.

Retention has no number

Retention is "for as long as it is required" with an express statement that actual periods "can vary significantly" and no figure anywhere, giving the vague-ladder value of 0.2 with no deletion timeline and no shorter AI-log period disclosed.

No data-minimization commitment

The nearest clause promises "appropriate safeguards consistent with applicable laws", which speaks to de-identified data rather than limiting what is collected. Nothing in either document commits to collecting less.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: your ownership of generated outputs

Rippling privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inSilent
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsAdverse
Data-subject rights1 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingDisclosed
Retention and deletion0 of 4 disclosed
States a retention period for your dataSilent
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsSilent
Third-party sharing3 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementDisclosed
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessPartial
Transparency2 of 4 disclosed
Discloses that you are interacting with AIPartial
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children1 of 3 disclosed
Discloses automated decisions and a human-review pathSilent
Limits the use of special-category dataPartial
Governs biometric data specificallyNot applicable
States protections for children's dataDisclosed
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationPartial
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
HR & recruiting
Modalities
text
Processes biometrics
No
Policy last updated
2026-07-02
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Rippling safe with your data? Grade D | AI App Trust & Transparency Index