Monitored company
Constrafor
clause.watch tracks 2 legal documents published by Constrafor, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview
*This is a plain-English summary, not legal advice. The policy appears broad and leaves several important details unspecified.*
1. Data Collection & Use
Constrafor may collect:
- Identity and contact data: name, phone number, email, company, username, and profile information.
- Account credentials: usernames and passwords.
- Information about other users: details about people you add to the Services and their roles or permissions.
- Financial information: credit-card or other financial-account details for purchases.
- User content: anything uploaded, entered, posted, reviewed, or communicated through the Services.
- Communications and applications: customer-support requests, correspondence, survey responses, promotional sign-ups, and job applications.
- Technical and behavioral data: IP address, browser and device details, operating system, identifiers, timestamps, pages viewed, links clicked, features used, crash reports, and session data.
- Location data: precise physical location through GPS/satellite, cellular, Wi-Fi, Bluetooth, beacons, or similar technologies, if you opt in.
- Information from other sources: public websites, social networks, companies, organizations, and third-party partners.
The stated purposes include providing and monitoring the Services, processing orders, customer support, security and fraud prevention, analytics, research, service improvement, personalized advertising, promotions, legal compliance, and enforcing the Terms of Use.
Important risks: The policy does not provide a detailed data-retention schedule. It says information may be kept as long as needed for the collection purposes or legal compliance. Required cookies cannot be disabled through the Services, and disabling cookies through your browser may impair functionality. The company does not honor “Do Not Track” signals.
Gmail data
For Gmail API features, the company says it stores the minimum Gmail data needed to provide the authorized “Cru” functionality, does not sell, share, or use Gmail data for advertising, and allows deletion through the “Cancel Cru Subscription” button. Active data is removed promptly, backups within 25 days, but some data may remain for up to 180 days under Google-related retention practices. The reference to “Cru” appears inconsistent with the rest of the policy and should be clarified.
2. User Rights and Choices
The policy expressly provides or describes these choices:
- Location: withdraw access through mobile-device permissions.
- Cookies: manage or disable many cookies through browser settings, subject to functionality limitations.
- Analytics: opt out of Google Analytics using Google’s browser add-on.
- Behavioral advertising: opt out through industry tools such as AboutAds.info or the Network Advertising Initiative. This does not eliminate advertising entirely.
- Gmail data: request deletion using the specified subscription-cancellation control.
- California Shine the Light: California residents may request information about entities receiving personal information for their own direct-marketing purposes during the prior calendar year.
The policy does not clearly describe broad rights to access, correct, export, or delete ordinary account data, nor does it provide a general privacy-request procedure or response deadlines. It also does not clearly address rights under laws such as the CCPA/CPRA or GDPR.
3. Third-Party Sharing
Information may be shared with:
- Hosting, storage, security, analytics, customer-support, application-development, tracking, reporting, and quality-assurance providers.
- Advertisers and advertising networks for interest-based advertising across websites and services.
- Affiliates, business partners, researchers, publications, and others in aggregated or de-identified form.
- Companies offering financial, lending, insurance, or other products—even where the company does not control those parties’ subsequent use.
- Buyers or successor entities during a merger, acquisition, sale, or change of control.
- Government authorities, courts, or others where legally required or needed to address fraud, security, legal violations, or safety concerns.
- Parties you authorize or direct.
Social-media plug-ins may allow platforms such as Facebook, Twitter, or Instagram to collect information about your activity. Linked third-party sites are governed by their own policies.
4. AI/ML Training
The policy does not expressly state that personal data, uploaded content, communications, or Gmail data are used to train artificial-intelligence or machine-learning models. It does permit broad “research,” “data analysis,” service-improvement, aggregated, and de-identification activities. Users should obtain written clarification before entering confidential or proprietary information, because the policy does not specifically exclude such information from model training or product-development use.
5. Key User Obligations and Restrictions
- Users represent that they are at least 18, although the Services are also described as not intended for children under 13.
- You should have authority and appropriate consent before uploading information about other individuals or connecting another person’s data.
- You remain responsible for information and content you submit.
- You should protect account credentials and use caution because internet transmission is not guaranteed secure.
- Cookie or location restrictions may reduce functionality.
- Continued use after policy changes constitutes acceptance.
6. Liability and Disputes
The policy provides no specific arbitration, governing-law, venue, or dispute-resolution terms. Those provisions may appear in the separate Terms of Use.
Constrafor disclaims any guarantee that transmitted information will remain secure and says users provide information at their own risk. It does not state a specific damages cap or comprehensive liability disclaimer in this document. For third-party websites, advertisers, and financial/insurance providers, Constrafor disclaims responsibility for their privacy practices and use of data.
For FCRA-related consumer reports, the company states that it collects information only for a permissible purpose, with authorization, generally provides it only to the authorized requesting end user, and applies reasonable security measures. The policy does not explain how to submit a consumer-report dispute or exercise all FCRA rights.
7. Policy Changes
Changes may be made at any time. The company will post the revised policy on this page and identify the update date; material changes will also be indicated on the homepage. No separate notice is promised. Continued use of the Services after posting means acceptance, so users should review the policy periodically.
Terms of Use
Terms of Use: Key User Implications
> Scope: This agreement governs Constrafor’s SaaS services and support. It is primarily a commercial services contract and does not contain a complete privacy policy or detailed consumer-data rights framework.
1. Data Collection & Usage
What data is addressed
- Customer Data: Non-public data supplied by the customer to enable Constrafor to provide the services. The agreement does not specify categories of personal data, sensitive data, account information, usage logs, cookies, device data, or retention/security standards.
- Account information: Customers create administrative usernames and passwords. Customers are responsible for account and password security.
- Service and usage data: Constrafor may collect and analyze information relating to the provision, use, and performance of the services and related systems, including information concerning Customer Data and data derived from it.
How Constrafor may use it
Constrafor may use service-related information and data:
- To improve and enhance the services;
- For development, diagnostic, and corrective purposes; and
- For other Constrafor offerings.
Constrafor may disclose this information in aggregate or otherwise de-identified form in connection with its business. The agreement does not explain how de-identification is performed or whether data can be re-identified.
Important gap
There is no detailed privacy policy, data-processing addendum, breach-notification obligation, security standard, data-location provision, or specific treatment of sensitive or regulated data in the text provided. Customers handling personal, health, financial, government, or other regulated information may need additional contractual protections.
2. User Rights Regarding Data
The customer appears to retain its proprietary interest in Customer Data, while Constrafor retains ownership of the SaaS platform, software, improvements, and technology developed for the services.
Upon termination:
- Constrafor must make Customer Data available for electronic retrieval for 30 days.
- After that period, Constrafor may delete the data and is not required to retain it.
The agreement does not provide specific rights to:
- Correct, delete, or restrict processing during the subscription;
- Receive a portable copy in a particular format;
- Object to particular uses;
- Obtain confirmation of security incidents; or
- Exercise statutory privacy rights.
3. Third-Party Sharing
The agreement permits disclosure of service-related information in aggregate or de-identified form. It also anticipates third-party providers performing maintenance or supporting service availability, but does not identify those providers or describe their access to Customer Data.
Constrafor may use the customer’s name and trademarks in its marketing materials and website. It may not use them in press releases, references, or case studies without prior written consent.
Confidential information generally must be protected and not disclosed, but those obligations:
- End five years after disclosure; and
- Do not prevent legally required disclosure or disclosure of information already public or independently developed.
4. AI/ML Training
The agreement does not expressly state that Customer Data will or will not be used to train artificial-intelligence or machine-learning models.
However, Constrafor’s broad right to collect, analyze, and use information concerning Customer Data and derived data to improve services and for “other development” purposes could potentially encompass AI/ML development, depending on how the clause is interpreted. Customers concerned about model training should seek an express restriction, such as a prohibition on using identifiable Customer Data or prompts for training, and clarification regarding de-identified or aggregated data.
5. Key Customer Obligations and Restrictions
Customers must:
- Comply with Constrafor’s published policies, applicable laws, and regulations;
- Protect equipment, accounts, passwords, and files;
- Pay fees, taxes, overage charges, and invoices on time; and
- Use the service lawfully and according to the agreement.
Customers may not:
- Reverse engineer, decompile, disassemble, modify, or create derivative works from the service or software;
- Remove proprietary notices;
- Use the service for timesharing, service-bureau purposes, or another party’s benefit;
- Violate export-control laws.
The customer is responsible for all uses of its account and equipment, even without its knowledge or consent. It must indemnify Constrafor for claims arising from unlawful or improper use.
Billing disputes must be raised within 60 days of the relevant billing statement. Late amounts may incur 1.5% monthly interest, collection costs, and termination.
6. Liability and Disputes
- Services are provided largely “as is.”
- Constrafor does not guarantee uninterrupted, error-free service or particular results.
- Neither party is generally liable for indirect, consequential, special, incidental, exemplary damages, business loss, data loss/corruption, or substitute-service costs.
- Except for indemnity obligations and certain confidentiality or license-restriction breaches, liability is capped at fees paid in the preceding 12 months.
- The prevailing party in an enforcement action may recover attorneys’ fees and costs.
- Delaware law governs. The agreement does not specify an exclusive court or arbitration procedure.
- Either party may terminate for material breach with 30 days’ notice; nonpayment may permit termination without notice.
7. Changes and Notice
- Constrafor may change fees or add charges at the end of the initial or renewal term with 30 days’ notice, including by email.
- Customers must comply with Constrafor’s “standard published policies then in effect,” allowing those policies to change over time.
- The agreement does not provide a clear general process for amending the Terms or notifying customers of other substantive changes. Users should monitor email, published policies, and renewal notices.
Change history
2026-09-06 · Privacy Policy
2026-09-04 · Privacy Policy
2026-09-03 · Privacy Policy
2026-09-01 · Privacy Policy
2026-08-31 · Privacy Policy
2026-08-30 · Privacy Policy
2026-08-29 · Privacy Policy
2026-08-29 · Privacy Policy
2026-08-28 · Privacy Policy
2026-08-28 · Privacy Policy
2026-08-27 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-24 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-20 · Privacy Policy
2026-08-20 · Privacy Policy
2026-08-19 · Privacy Policy
2026-08-18 · Privacy Policy
2026-08-18 · Privacy Policy
Summary
The provided diff does not include the actual amended legal language. It only states:
> “Added approximately 721 words to the document”
Because the new or deleted wording is not provided, it is not possible to determine:
- What contractual terms changed;
- Whether obligations, rights, limitations, or remedies were added;
- Whether liability, indemnity, confidentiality, security, or termination provisions changed;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether the customer can opt out of AI training or data use;
- Whether data is shared with affiliates, vendors, or third-party model providers;
- Whether any new retention, deletion, anonymization, or ownership rules apply; or
- Whether the changes create additional privacy, regulatory, or intellectual-property risks.
AI-Training Review
No specific change concerning AI-model training or the use of customer data can be identified from the information supplied. The statement that approximately 721 words were added does not reveal whether those words:
- Authorize training on customer content, prompts, inputs, outputs, or usage data;
- Limit training to de-identified or aggregated information;
- Permit use for product improvement or benchmarking;
- Allow human review or access by service providers;
- Grant the provider rights to retain or reuse customer data after termination; or
- Give the customer any opt-out, deletion, or audit rights.
Information Needed
Please provide the full redlined text, including the wording shown in braces, brackets, and replacement notation. Once provided, the changes can be assessed for their legal effect and any new risks, particularly those relating to customer-data use in AI training.
2026-08-18 · Terms of Use
Diff Analysis
Summary
The provided diff contains only the statement:
> “Added approximately 970 words to the document”
It does not include the actual added language, deleted language, or replacement terms. Therefore, it is not possible to determine what contractual rights, obligations, liabilities, or data-use practices changed.
AI Training and Customer Data
No substantive language is provided addressing:
- Whether customer data may be used to train, fine-tune, or improve AI models
- Whether prompts, inputs, outputs, or metadata are retained
- Whether customer data is anonymized, aggregated, or de-identified
- Whether data is shared with affiliates, vendors, or third-party model providers
- Whether customers can opt out of AI training or request deletion
- Whether data may be used to develop products or services for other customers
- Security, confidentiality, ownership, or intellectual-property protections for training data
Accordingly, no conclusion can be reached about whether the customer’s data-use rights or risks have changed.
Other Legal Risks
The word-count statement alone does not reveal changes concerning:
- Limitation of liability or indemnification
- Confidentiality and security obligations
- Data retention and deletion
- Regulatory compliance
- Intellectual-property ownership or licenses
- Warranties and disclaimers
- Termination rights
- Governing law or dispute resolution
- Subcontractors or international data transfers
Conclusion
A substantive risk analysis requires the actual diff text, including the approximately 970 added words and any marked deletions or replacements. The current material supports only the conclusion that the document became longer; it does not identify the nature or legal effect of the changes.
2026-08-18 · Terms of Use
Summary of Important Changes
1. Terms and Conditions updated
- The heading now states: “Terms and Conditions Last Updated: August 17th, 2026.”
- This establishes a new version date but does not, by itself, explain whether other provisions were changed.
2. New Addendum A — Cru Accounting
A comprehensive addendum has been added for customers who activate or use Cru Accounting, Constrafor’s accounting and bookkeeping service.
Applicability and termination
- The addendum applies only if the customer adds, accesses, or uses Cru Accounting.
- It becomes part of the main agreement and controls if there is a conflict regarding Cru Accounting.
- The customer may cancel effective at the end of the following monthly billing period.
- Fees for the billing period and services already performed remain payable and are not prorated, credited, or refunded.
Risk: Customers may remain financially committed after giving notice and may not receive a refund for partial-period use.
3. Ownership and feedback rights
- The customer assigns to Constrafor rights in improvements or modifications to Cru Accounting, while preserving ownership of customer data, accounting outputs, and pre-existing intellectual property.
- Feedback may be used permanently and without payment.
- Constrafor and its service providers may independently use ideas and know-how reflected in feedback.
Risk: Broad assignment and feedback rights may give Constrafor substantial control over customer-originated suggestions and service improvements.
4. Customer data use and AI model training
- The customer retains ownership of Cru Accounting Data.
- Constrafor and service providers may access, process, host, and store the data to provide, secure, support, maintain, and improve Cru Accounting.
- Cru Accounting uses automated agents and AI/large-language-model providers to:
- Categorize transactions;
- Perform reconciliations;
- Detect anomalies;
- Generate analyses and insights; and
- Draft accounting outputs.
- Supporting personnel may access the data for review and service delivery.
- Aggregated, de-identified, or anonymized information may be used to operate, develop, train, evaluate, and improve products, services, algorithms, and AI/ML models.
- Non-de-identified data will not be used to develop, improve, or train generalized AI/ML models.
- Service providers may not use non-anonymized data after their engagement ends except as required by law.
- The data will not be sold, used for advertising or marketing, or disclosed to other customers.
AI/data risks: The definition of de-identified or anonymized data may leave room for interpretation, and the addendum permits AI training using derived data. Third-party AI providers and support personnel may process sensitive financial and personal information. The customer is responsible for obtaining legally required notices and consents.
5. Accounting disclaimers
- Cru Accounting is bookkeeping support, not audit, tax, legal, investment, or regulated professional advice.
- Outputs are generally prepared on a modified cash basis, not GAAP, unless otherwise agreed.
- Accuracy depends on customer-provided information and third-party data.
- Outputs are not guaranteed to be accepted by tax authorities, lenders, or others.
Risk: Customers remain responsible for verification and for obtaining qualified professional advice.
Between 2025-07-20 and 2025-10-04 · Privacy Policy
Summary of Important Changes
1. New Cru Accounting Supplement
- The policy now includes a separate “Cru Accounting Supplement” for users who enroll in Cru Accounting.
- The Supplement controls over conflicting provisions of the general Privacy Policy for that service.
- Cru Accounting data may include:
- Financial-account information, balances, transaction histories, and transaction data;
- Accounting records and uploaded documents, including invoices, receipts, bills, statements, ledgers, and supporting materials.
- Users may choose whether to enroll, which financial accounts to connect, and which documents to provide. They may disconnect accounts or end enrollment.
Risk: The scope of financial and business information covered by the service is substantially more specific and expansive than the prior consumer-reporting language.
2. AI and Automated Processing
- The revised policy expressly states that Cru Accounting is delivered using automated agents and artificial-intelligence models, with review by accounting personnel.
- Data is disclosed to categories of service providers that now expressly include:
- Artificial-intelligence and large-language-model providers;
- Cloud hosting, databases, data warehouses, financial-data connectivity providers, email providers, and accounting-operations providers.
Risk: Customer data may be processed by external AI/LLM vendors. The policy does not identify the vendors, specify whether they retain prompts or outputs, prohibit vendor model training generally, or describe security, location, or contractual controls applicable to those providers.
3. New AI Model-Training Permission
- Constrafor and its service providers may use, reproduce, and disclose data and materials derived from Cru Accounting use if they are aggregated, de-identified, or anonymized, to:
- Operate and develop the service;
- Train, evaluate, and improve products, services, models, and algorithms, including machine-learning and AI models.
- The permission is limited by applicable law and the terms governing the source of the data.
- Constrafor says it will not attempt to re-identify de-identified or anonymized information.
- Data that has not been de-identified or anonymized is stated not to be used to develop, improve, or train generalized AI/ML models.
Key risk: The training authorization is new and broad. “Derived from” and “aggregated, de-identified, or anonymized” are not precisely defined, and de-identification may not eliminate re-identification risk. The provision also permits training by both Constrafor and its service providers, potentially including AI vendors.
4. Retention and Deletion
- Account-associated data will generally be deleted from production systems within 25 days and backups within 90 days.
- Exceptions apply for legally retained information and data already aggregated, de-identified, or anonymized.
- Accordingly, deletion or account closure may not remove data already incorporated into datasets, models, or analytics.
5. Other Notable Changes
- The policy is dated August 17, 2026 and more clearly covers all products and services offered through the Sites or App.
- The prior FCRA consumer-reporting supplement is largely replaced for Cru Accounting, although a substantially similar FCRA policy is appended again later, creating potential drafting ambiguity.
- Gmail data is expressly limited to providing authorized Cru/Cru Accounting functionality and is not used for advertising.
Between 2023-09-27 and 2024-01-10 · Terms of Use
Summary
Document change
- The diff states only that approximately 970 words were added.
- The actual added language is not included, so the legal effect of those additions cannot be determined.
Customer data and AI training
- The provided diff contains no specific language addressing:
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether customer data is used for general model training or only to provide services;
- Whether data is anonymized, aggregated, or de-identified before such use;
- Whether the customer may opt out or object;
- Whether inputs, outputs, prompts, or usage data are retained;
- Whether data may be shared with AI providers or subprocessors; or
- Ownership, confidentiality, or deletion of data used in connection with AI systems.
- Accordingly, it is not possible to identify whether the contract expands or restricts AI-training rights.
Potential risks requiring review
Because the added text is unavailable, the following issues should be checked in the new language:
1. Broad usage rights
Look for permission to use customer data for “improvement,” “analytics,” “research,” “product development,” or “machine learning,” which may authorize AI training indirectly.
2. De-identification standards
Confirm whether data is truly anonymized or merely “de-identified,” and whether re-identification is prohibited.
3. Scope of data covered
Determine whether the permission covers customer content, personal information, prompts, outputs, metadata, telemetry, or account data.
4. Third-party access
Check whether data may be sent to external model providers or subprocessors and whether those parties may independently use it for training.
5. Opt-out and deletion
Confirm whether the customer can opt out, require deletion, or prevent future use of its data in model training.
6. Confidentiality and ownership
Verify that training-related use does not dilute the customer’s ownership rights or confidentiality protections.
Conclusion
No substantive legal changes can be reliably analyzed from the supplied diff. The complete text of the approximately 970 added words is necessary to assess changes to data rights, AI training permissions, confidentiality, security, and liability.