Is Salesforce Einstein safe with your data?
Salesforce Einstein
Salesforce
Weak disclosure · high confidence
Salesforce Einstein earns a D (47/100) because it leaves much about its data practices unstated.
Dealbreaker flag
- D1.4: you grant us, our agents, licensees, and assigns an irrevocable, perpetual (non-exclusive) right and permission to reproduce, encode, store, copy, transmit, publish, post, broadcast, display, publicly perform, adapt, modify, create derivative works of, exhibit, and otherwise use your Content
#122
of 211 apps ranked
47
score · Enterprise copilot avg 53
-6
vs category average
Salesforce Einstein discloses a strict zero-retention no-training policy for AI prompts and a named DPO, but its data-subject rights are hedged as conditional on local law, it shares identifiers with third-party advertisers for cross-site targeting, and its site terms take an irrevocable perpetual licence over user-submitted content.
What Salesforce Einstein's privacy policy and terms of service say about your data
Zero retention and no training, stated plainly
The Einstein Trust Layer text says prompts and generated responses are "never stored or used to train the underlying third-party large language models". That is a concrete named mechanism, not a general assurance.
Rights are conditional, not guaranteed
Access, deletion, portability, correction and objection all sit under "You may have certain rights ... subject to local data protection laws. Depending on the applicable laws these rights may include". Every one of them is qualified rather than promised.
No sale, but sharing for ad targeting
The CCPA section says "we do not sell Personal Data" then reserves sharing identifiers plus internet activity with "third party advertisers for purposes of targeting advertisements". A named opt-out is offered.
Perpetual content licence over what you post
Posting content grants Salesforce, "our agents, licensees, and assigns an irrevocable, perpetual (non-exclusive) right" that "continues even if you stop using our Sites". It is the one clause that reserves a lasting claim over user content.
What the policy is silent or vague on
- Not stated: whether training use differs by plan
- Not stated: your ownership of generated outputs
- Not stated: a deletion timeline after closure or request
- Not stated: shorter retention for AI conversation logs
Salesforce Einstein privacy rating
Details
- Category
- Enterprise copilot
- Modalities
- text
- Processes biometrics
- No
- Policy last updated
- Not stated
- Region scored
- Global / US-default
- Last assessed
- 2026-08-13
Documents examined
Other enterprise copilot apps
Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.