Monitored company
Robin
clause.watch tracks 2 legal documents published by Robin, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy
Privacy Policy Overview
*Policy last updated July 29, 2025. This summary is informational and not legal advice.*
1. Data Collection & Use
Robin collects:
- Information you provide: Registration details, contact information, account profiles, “personas,” and information submitted through forms or other Service interactions.
- Usage and device data: Activities at Robin locations (limited to what you approved on arrival), IP address, device identifiers, browser and operating system, mobile network, referring website, Service activity, device location, and general device or usage characteristics.
- Tracking data: Cookies, web beacons, scripts, images, and similar technologies used for login functionality, security and fraud prevention, analytics, personalization, and marketing.
- Third-party data: Information from connected services—such as Google—or third-party records that Robin combines with information collected directly from you.
- User Content: Photos, profiles, audio, video, comments, questions, suggestions, and other content you submit, which may include Personal Data.
- Payment information: Payment vendors process card transactions on their own servers. Robin states that vendors do not provide Robin with complete financial account information.
Robin may use data to:
- Provide and administer the Service and process requested transactions.
- Verify accounts and enable features.
- Remember preferences, personalize content, analyze usage, improve existing services, and develop new offerings.
- Send service, administrative, promotional, and—where consent is given—third-party marketing communications.
- Conduct internal business operations, security, and fraud prevention.
- Use data to support workplace automation and AI modeling. Data stored in Robin’s EU hosting is expressly excluded from this use. The policy does not specify which data is used, whether data is anonymized, which models are involved, or whether data is retained in training systems.
2. User Rights
Depending on location and applicable law, users may:
- Request access to, correction of, or deletion of Personal Data.
- Withdraw consent or object to certain processing, including direct marketing.
- Restrict processing and request data portability under the GDPR.
- Opt out of certain marketing communications and, for California residents, request information about collection and disclosure, deletion, and opt-out of “sales.”
- Request correction under Australian and Canadian privacy laws.
- Submit requests to privacy@robinpowered.com. Identity verification may be required.
Robin distinguishes between:
- Controller data: For example, website information and responses to Robin communications; Robin handles deletion requests directly.
- Processor data: Data submitted to the platform by a customer organization; Robin generally forwards requests to that customer, who remains the controller.
Deletion is not necessarily immediate or complete. Organizational deletion requests are generally processed within 90 days, and backups or business records may retain residual data.
3. Third-Party Sharing
Robin may share data with:
- Service providers and subprocessors for hosting, logging, support, email, analytics, security, customer success, and data warehousing. Listed providers include AWS, Sumo Logic, Intercom, SendGrid, Looker, Gainsight, Sigma, Google, and Snowflake.
- Third parties you authorize, including connected accounts, requested communications, or approved integrations.
- Affiliates and corporate transaction participants, such as acquirers, successors, or entities involved in a merger or asset sale.
- Authorities or other parties when Robin believes disclosure is necessary for legal compliance or protection of rights, safety, or property. Robin states it may make such disclosures without notice.
- Aggregated or depersonalized statistics.
Robin says it does not share Personal Data collected through the Service for third parties’ direct marketing. However, third-party tracking technologies may independently collect information, track activity across sites, and apply their own policies. Robin disclaims responsibility for those practices.
4. AI/ML Training
The policy states that Robin may use data to “leverage the latest technical advances in AI modeling” to automate workplace experiences. It specifically excludes data stored in EU hosting, but does not clearly explain:
- Whether this means model training, fine-tuning, testing, or automated analysis.
- Whether data is anonymized or de-identified.
- Whether customers or users can opt out.
- How long AI-related data is retained or whether it can be removed from models.
This is a significant area of uncertainty for confidential or sensitive workplace information.
5. Key User Obligations and Restrictions
Users must:
- Provide accurate and current information.
- Protect information they choose to make public or share with others.
- Review third-party privacy policies before using integrations or links.
- Comply with the Terms of Service, Acceptable Use Policy, and restrictions on User Content and excluded data.
- Avoid using the Service if under 18; Robin does not permit use by minors.
- Understand that disabling cookies may impair Service functionality.
User Content may be stored, displayed, reproduced, published, distributed, or used in various media, potentially without attribution. Users should avoid submitting confidential or sensitive information unless authorized.
6. Liability & Disputes
Robin uses “commercially reasonable” security safeguards but does not guarantee absolute security and places transmission risk on the user. It disclaims responsibility for third-party services, tracking, links, communications, and publicly shared content.
Privacy complaints should first be sent to Robin. Robin states it will respond within 45 days. If unresolved, an individual may engage JAMS at no cost. The policy does not provide the complete arbitration, governing-law, or broader liability terms; those may appear in the Terms of Service.
7. Policy Changes
Robin may change the Policy at any time. Revisions become effective immediately when posted, and continued use constitutes consent to the posted version. Robin promises not to use previously collected data in a materially different way without consent, but users should monitor the page and its change log.
Terms
Robin Master Subscription Agreement: Key User Implications
*This overview is based only on the Master Subscription Agreement, last updated October 1, 2021. The Agreement references a separate Privacy Policy, Acceptable Use Requirements, Order Form, and—where applicable—a Data Processing Agreement (“DPA”). Those documents may contain important additional terms.*
1. Data Collection and Usage
What data may be collected
The Agreement defines “Customer Data” broadly as information or data:
- Provided by the customer or its users through the SaaS Services; or
- Collected from the customer or its users through the SaaS Services.
The document does not give a detailed list of ordinary personal data collected. The separate Privacy Policy is therefore important for understanding specific data categories, cookies, device data, location data, workplace usage data, retention, and similar practices.
How Robin may use it
Robin may use and disclose Customer Data, subject to confidentiality obligations, to:
- Provide the SaaS Services;
- Monitor and analyze service use;
- Improve the SaaS Services;
- Create aggregated and anonymized usage analyses and reports; and
- Enforce the Agreement.
Robin may monitor and maintain records of customer and user activity for security and system-protection purposes.
Sensitive data prohibition
Customers and users must not upload or provide:
- Health information;
- Biometric information;
- Social Security or government identification numbers;
- Credit, debit, payment-card, bank, or other financial information;
- Data legally classified as “sensitive”; or
- Data the customer lacks authority or consent to provide.
Robin disclaims obligations and liability for this prohibited “Excluded Data,” except where applicable law cannot permit that limitation.
2. User Rights
For EU/EEA personal information covered by a DPA:
- The customer is generally the data controller.
- Robin acts as the customer’s data processor and processes data according to the customer’s instructions.
- Robin must use reasonable security, encryption or equivalent protections, and appropriately bind subcontractors.
- Robin must use commercially reasonable efforts to assist with requests to access, correct, amend, or opt out of processing where required by law and Robin policy.
- After termination, Robin must cooperate to return or destroy personal information, unless retention is infeasible; retained data remains protected under the Agreement.
The Agreement does not independently provide a comprehensive set of rights for individual users. Rights may depend on applicable privacy law, the customer’s policies, the Privacy Policy, and the DPA.
3. Third-Party Sharing
Robin may disclose Customer Data to people or organizations with a need to know, provided they are under substantially similar confidentiality obligations. This may include:
- Robin’s service providers and subcontractors;
- Providers supporting hosting, security, maintenance, or service delivery; and
- Other parties where disclosure is legally required.
Robin remains responsible for requiring relevant subcontractors to apply consistent protections for EU/EEA personal information. The Agreement does not identify specific vendors or provide a detailed subprocessors list.
4. AI/ML Training
The Agreement does not expressly state that Customer Data is used to train artificial intelligence or machine-learning models.
However, Robin has a broad right to “analyze” and “improve” the SaaS Services and to create aggregated, anonymized reports. That language could permit service-improvement analytics, but it does not clearly authorize training general-purpose AI models or using identifiable customer data for that purpose. Users should review the current Privacy Policy, DPA, and any vendor or AI-specific terms for clarification.
5. Key Customer and User Obligations
Users must:
- Use the service only for the purpose in the applicable Order Form;
- Follow the Acceptable Use Requirements;
- Avoid unlawful, threatening, obscene, libelous, infringing, or abusive content;
- Not disable, modify, or circumvent Robin’s security safeguards;
- Protect account access and ensure authorized use; and
- Avoid uploading Excluded Data.
The customer is responsible to Robin for its users’ compliance. Robin may suspend access for misuse, abuse, nonpayment, or security reasons.
Fees are generally non-cancelable and non-refundable, subscriptions automatically renew unless timely notice is given, and quantities cannot normally be reduced during a subscription term.
6. Liability and Disputes
Liability limits
Neither party is generally liable for lost profits, revenue, goodwill, or indirect, consequential, exemplary, or punitive damages. Aggregate liability is generally capped at fees paid during the preceding 12 months.
Exceptions include fraud, willful misconduct, gross negligence, unpaid fees, and intellectual-property infringement or misappropriation.
Disputes
Disputes must generally be resolved through confidential JAMS arbitration in Boston, Massachusetts, under Massachusetts law. An arbitrator determines allocation of proceeding costs and attorneys’ fees. Courts may still be used for injunctions, provisional remedies, or enforcement of an award.
7. Changes
Robin endeavors to provide 30 days’ written notice of changes to the Acceptable Use Requirements. A customer may object within 15 days if changes materially and negatively affect it; if unresolved, the customer may terminate.
The Agreement itself may be amended only through a later signed writing. Renewal pricing may change, particularly for promotional subscriptions or changed volume/term. The referenced Privacy Policy is maintained on Robin’s website, but this Agreement does not specify how users will be notified of Privacy Policy changes.
Change history
2026-09-06 · Privacy
2026-09-05 · Privacy
2026-09-04 · Privacy
2026-09-03 · Privacy
2026-09-02 · Privacy
2026-08-29 · Privacy
2026-08-27 · Privacy
2026-08-26 · Privacy
2026-08-26 · Privacy
2026-08-25 · Privacy
2026-08-25 · Privacy
2026-08-23 · Privacy
2026-08-22 · Privacy
2026-08-22 · Privacy
2026-08-21 · Privacy
2025-07-29 · Privacy
The publisher records this document as revised on this date (“Last updated July 29th, 2025”).
Between 2019-12-11 and 2023-05-06 · Privacy
Between 2014-09-14 and 2023-05-06 · Terms
Summary
Diff Provided
- The diff states only: “Removed approximately 6 words from the document.”
- The actual deleted or added wording is not included.
Legal and Commercial Impact
- No reliable assessment can be made of changes to:
- Customer data rights or ownership
- Confidentiality obligations
- Data processing or sharing
- Liability or indemnification
- Security requirements
- Termination or deletion obligations
- Intellectual-property rights
AI Model Training
- The provided diff does not identify whether customer data may be used to train, fine-tune, evaluate, or otherwise improve AI models.
- It is therefore impossible to determine whether the amendment:
- Expands or restricts the provider’s right to use customer data;
- Allows use of data in aggregated, de-identified, or identifiable form;
- Permits use of prompts, outputs, uploaded content, telemetry, or usage data;
- Applies training rights by default or only with customer consent;
- Requires opting out, opting in, or paying for a no-training arrangement; or
- Requires deletion or exclusion of customer data from future training datasets.
Risk Assessment
- Assessment: Incomplete. The six-word deletion could be legally significant depending on its location and wording.
- The redline should include the exact deleted text and any surrounding clause. Without that context, no meaningful legal-risk conclusion can be reached.
Recommended Next Step
Provide the full redline, including the six deleted words and the affected provision. Particular attention should be given to clauses containing terms such as “customer data,” “content,” “inputs,” “outputs,” “service improvement,” “machine learning,” “train,” “fine-tune,” “de-identified,” or “aggregated data.”
2021-10-01 · Terms
The publisher records this document as revised on this date (“Last UPDATED OCTOBER 1, 2021”).
Between 2014-09-14 and 2019-12-11 · Privacy