Is Robin AI safe with your data?
Robin AI
Robin AI Limited
Weak disclosure · high confidence
Robin AI earns a D (52/100) because it leaves much about its data practices unstated.
#96
of 116 apps ranked
52
score · Legal avg 59
-7
vs category average
Robin AI publishes a compact GDPR-style privacy notice that grants a full set of data-subject rights but stays silent on whether customer documents train AI models, on concrete retention periods, on breach notification, and on security or certification specifics. The grade of 52 (D) survives scrutiny: every claimed quote is present in the snapshot, the adequacy-based transfer safeguard is genuinely named, and no dealbreaker was raised because the policy contains no adverse reservation. The training silence is real silence rather than an adverse train-by-default clause, so it correctly carries no flag.
What Robin AI's privacy policy says about your data
Full data-subject rights
The notice grants access, deletion, portability, rectification, and objection. It lets you be provided with a copy of any personal data the company holds about you, require deletion without undue delay, and receive data in machine readable format so it can be ported to a replacement service provider.
Silent on AI training
The policy never states whether uploaded documents, labelled clauses, or accepted edits are used to train AI models, and it offers no training opt-out. Data use is framed only as data analysis, testing and research for the purpose of improving the functionality and usability of products and services or developing new features.
Vague retention, no numbers
Retention is described only as keeping personal data no longer than is necessary to fulfil the purpose for which it was collected. There is no day count, no deletion timeline, and no shorter log-retention window for AI interaction data.
Named transfer safeguard but thin security
International transfers rely on a country assessed by the European Commission or an equivalent UK body as ensuring an adequate level of protection. Security is described only as appropriate technical and organisational measures, with no named controls, no breach-notification commitment, and no certification or DPO.
What the policy is silent or vague on
- Not stated: keeping user inputs out of model training
- Not stated: a way to opt out of training
- Not stated: whether training use differs by plan
- Not stated: your ownership of generated outputs
Robin AI privacy rating
Details
- Category
- Legal
- Modalities
- text
- Processes biometrics
- No
- Policy last updated
- Not stated
- Region scored
- Global / US-default
- Assessed
- 2026-06-20
Other legal apps
Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.