POLICYPEEK

How a rating gets made

Every badge on PolicyPeek traces back to three separate steps, kept deliberately separate so no single step can quietly turn an opinion into a fact.

  1. Facts, extracted from the tool's own policy.We fetch the privacy policy the tool itself publishes and pull out a handful of factual claims — does it say it trains on your data, is there a stated retention period, does it mention GDPR. This step is not allowed to make a judgment call; it only reports what the text says.
  2. A fixed rule, not an opinion, decides the badge.The facts above run through one fixed rule, the same for every tool:
    • Compliant — doesn't train on user data, or lets you opt out.
    • Compliant with caveats — trains on your data by default, but a real opt-out exists somewhere in the policy.
    • Not compliant — trains on your data by default, with no opt-out.
    • Unrated — the policy is genuinely unclear either way. This is not a middle grade — it means we don't know, not that the tool is "somewhat okay."
  3. A human reviews it before it's published.Nothing reaches the tools list without someone checking the extracted facts against the actual source before approving it.

Why "compliant with caveats" isn't just a green pass

An opt-out is a real, meaningful protection — but it's a weaker one than "doesn't train on your data by default." GDPR generally expects opt-in consent, not an opt-out you have to go find in a settings page or a support form. So when a tool trains on your data unless you take action, PolicyPeek shows a distinct teal "Compliant with caveats" badge rather than the plain green "Compliant" one — same shape and border weight as every other badge on the site, deliberately not green, and paired with a one-line note on the tool's page explaining what the caveat actually is. It is also not a shade of amber: amber on this site always means "we don't know." Compliant with caveats means the opposite — we know exactly what the policy says, and it's a middle case, not an unknown one.

Why unrated isn't a guess

If a policy doesn't clearly say one way or the other, PolicyPeek marks it unrated rather than rounding it up or down. An amber badge means "read the source yourself before you decide," not "probably fine" — and it is a different kind of uncertainty than "compliant with caveats" above: unrated means we couldn't tell from the policy, while compliant with caveats means the policy told us exactly what happens and it's a conditional pass.

Sources

Every tool page links the exact policy page(s) the rating was built from. If a source is stale or wrong, that's a bug in our data, not the tool's fault — the fix is to re-check the source, not to guess.