This is a print-friendly report. Click Print and choose “Save as PDF” in the destination dropdown to download.
SaaSGuard Risk Report
Replicate
replicate.com
Generated May 4, 2026
Grade F
Score: 37 / 100
Executive summary
We analyzed Replicate’s Terms of Service across 8 risk dimensions and found 26 flagged clauses across 8 categories.
Flagged clauses by category
AI training on your data (2)
Severity 5 · egregious
“Customer hereby grants Replicate a worldwide, non-exclusive, non-sublicensable (except for the purposes of making the Marketplace Models available to Customer and for purposes of the provision of the Services), royalty-free, license to use, publish, reproduce, copy, store, host, transmit, modify, process, make available, create derivative works of, and display its Customer Data to the extent necessary to provide the Output, train and generate Customer Derivative Models, provide the Services under these Terms, and create and compile Resultant Data.”
Replicate can use your data to provide services, train AI models, and create new data, with no restrictions on how long they keep it or what they do with it.
Anything you put into Replicate, including sensitive code, can be used to train their AI and potentially be seen by others.
Matches Andersen v. Stability AI, Midjourney, DeviantArt (2023)
Severity 5 · egregious
“If you decide to share a Community Model on our Website or through the Services, in addition to the license above, you grant (i) Replicate the right to process and redistribute the Community Model and share the resulting Output to each end user of the Service (“User”); and (ii) each User a perpetual, irrevocable, worldwide, royalty-free, non-exclusive license to access and use the Community Model through our Services.”
If you share a model, Replicate can use it to train their AI and give it to all their users, and each user gets a perpetual license to use it.
Your shared models become part of Replicate's offering, and you lose control over how they are used or distributed.
Matches Authors Guild v. OpenAI (2023)
Auto-renewal traps (2)
Severity 3 · notable
“Your account will be charged automatically on the Subscription Billing Date and thereafter on the renewal date of your Subscription for all applicable fees and taxes for the next Subscription Period. You must cancel your Subscription before it renews in order to avoid billing of the next periodic Subscription Period to your account.”
Replicate will automatically charge your account for subscription fees and taxes on the renewal date.
You must cancel your subscription before the renewal date to avoid being billed for the next period.
Matches FTC v. Amazon (Iliad Flow / Prime Enrollment) (2023)
Severity 3 · notable
“The Subscription will begin on the Subscription Billing Date and continue for the subscription period that you select on your Account (such period, the “Initial Subscription Period”), and will automatically renew for successive periods of the same duration as the Initial Subscription Period (the Initial Subscription Period and each such renewal period, each a “Subscription Period”) unless you cancel the Subscription or we terminate it.”
Your Replicate subscription renews automatically for the same period unless you cancel before the renewal date.
You will be charged for another subscription period if you forget to cancel in time.
Matches FTC v. Amazon (Iliad Flow / Prime Enrollment) (2023)
Surprise price hikes (3)
Severity 3 · notable
“Replicate will provide you with a reasonable prior notice of any change in Subscription fees to give you an opportunity to terminate your Subscription before such change becomes effective. Your continued use of Service after Subscription fee change comes into effect constitutes your agreement to pay the modified Subscription fee amount.”
Replicate will notify you before changing subscription fees, allowing you to cancel before the new price takes effect.
Continuing to use the service after a fee change means you agree to the new price.
Matches Netflix Price Hike Class Action (2023)
Severity 3 · notable
“We may in our sole discretion and at any time, modify fees for any Subscriptions we offer for any part of our Service. Any Subscription fee change will become effective upon the next renewal Subscription Period. Replicate will provide you with a reasonable prior notice of any change in Subscription fees to give you an opportunity to terminate your Subscription before such change becomes effective.”
Replicate can change subscription fees at any time, with changes taking effect at the next renewal period, but they will give you notice.
You might be charged more at renewal if you don't cancel after receiving notice of a price increase.
Matches Netflix Price Hike Class Action (2023)
Severity 3 · notable
“You may be charged fees for your use of the Services and for your use of Marketplace Models. We may in our sole discretion and at any time, modify Subscription fees for any subscriptions we offer for any part of our Service. Any Subscription fee change will become effective at the end of the then-current Subscription Period.”
Replicate can change subscription fees for any part of their service at any time, with changes effective at the end of the current subscription period.
Your subscription cost could increase at the end of your current term if you don't cancel.
Matches Netflix Price Hike Class Action (2023)
Data residency (1)
Severity 2 · minor
“Customer hereby grants Replicate a worldwide, non-exclusive, non-sublicensable (except for the purposes of making the Marketplace Models available to Customer and for purposes of the provision of the Services), royalty-free, license to use, publish, reproduce, copy, store, host, transmit, modify, process, make available, create derivative works of, and display its Customer Data to the extent necessary to provide the Output, train and generate Customer Derivative Models, provide the Services under these Terms, and create and compile Resultant Data.”
Replicate can use your data to provide services, train AI models, and create new data, with no restrictions on how long they keep it or what they do with it.
Anything you put into Replicate, including sensitive code, can be used to train their AI and potentially be seen by others.
Termination friction (2)
Severity 3 · notable
“If these Terms are terminated for any reason: (a) your use rights shall cease and you must immediately cease all use of the Services; (b) you may not be able to access your Account and all related information or files associated with or inside your Account (or any part thereof) may be deleted; and (c) you must pay Replicate any unpaid amount that was due prior to termination.”
If the terms are terminated, you must pay any outstanding amounts and may lose access to your account and data.
You could lose access to your work and owe money if you or Replicate terminate the agreement.
Matches Bungie / Destiny 2 Account Termination Litigation (2023)
Severity 3 · notable
“Notwithstanding the foregoing, if you delete your Account, Replicate may, but is not obligated to, retain and continue to host any Community Models you have previously shared or made public on the Services.”
If you delete your account, Replicate may keep and host any community models you previously shared.
Your shared models might remain publicly available even after you delete your account.
Matches Bungie / Destiny 2 Account Termination Litigation (2023)
Liability caps (5)
Severity 4 · material
“TO THE MAXIMUM EXTENT OF LAW, IN NO EVENT WILL REPLICATE OR ANY OF ITS LICENSORS BE LIABLE UNDER OR IN CONNECTION WITH THESE TERMS OR ITS SUBJECT MATTER UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, AND OTHERWISE, FOR ANY: (a) LOSS OF USE, BUSINESS, REVENUE, OR PROFIT OR DIMINUTION IN VALUE; (b) IMPAIRMENT, INABILITY TO USE OR LOSS, INTERRUPTION, OR DELAY OF THE SERVICES, OTHER THAN FOR THE ISSUANCE OF ANY APPLICABLE SERVICE CREDITS; (c) LOSS, DAMAGE, CORRUPTION, OR RECOVERY OF DATA, OR BREACH OF DATA OR SYSTEM SECURITY; (d) COST OF REPLACEMENT SERVICES; (e) LOSS OF GOODWILL OR REPUTATION; OR (f) CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, SPECIAL, ENHANCED, OR PUNITIVE DAMAGES, REGARDLESS OF WHETHER SUCH PERSONS WERE ADVISED OF THE POSSIBILITY OF SUCH LOSSES OR DAMAGES OR SUCH LOSSES OR DAMAGES WERE OTHERWISE FORESEEABLE, AND NOTWITHSTANDING THE FAILURE OF ANY AGREED OR OTHER REMEDY OF ITS ESSENTIAL PURPOSE.”
Replicate and its licensors disclaim all liability for any damages, including lost profits, data loss, or service interruptions, except for service credits.
You likely won't be able to recover significant financial losses if Replicate's service causes them.
Matches Yahoo! Customer Data Security Breach Settlement — settled for $118M (2019)
Severity 4 · material
“TO THE MAXIMUM EXTENT OF LAW, IN NO EVENT WILL REPLICATE’S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS, WHETHER ARISING UNDER OR RELATED TO BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL OR EQUITABLE THEORY, EXCEED THE LOWER OF THE TOTAL AMOUNTS PAID OR PAYABLE TO REPLICATE UNDER THESE TERMS BY CUSTOMER IN THE 6 MONTH PERIOD PRECEDING THE EVENT GIVING RISE TO THE CLAIM OR US$100.”
Replicate's total liability is capped at the lower of amounts paid in the last 6 months or $100.
Your ability to recover damages from Replicate is severely limited, even if their service causes major financial harm.
Matches Yahoo! Customer Data Security Breach Settlement — settled for $118M (2019)
Severity 4 · material
“THE MODELS AND OUTPUT ARE POWERED BY ARTIFICIAL INTELLIGENCE AND CUSTOMER ACKNOWLEDGES AND AGREES THAT ARTIFICIAL INTELLIGENCE TOOLS ARE NOVEL AND EXPERIMENTAL, AND THAT THEREFORE THERE IS SIGNIFICANT UNCERTAINTY REGARDING THE OPERATION OF SUCH TOOLS. MODELS MAY RETURN INACCURATE OUTPUT THAT DOES NOT ACCURATELY REFLECT REAL PEOPLE, PLACES, OR FACTS. THE MODELS DO NOT AND ARE NOT INTENDED TO PROVIDE ANY SAFETY, LEGAL, FINANCIAL, TAX, ACCOUNTING, OR OTHER PROFESSIONAL ADVICE.”
Replicate's AI models are experimental and may produce inaccurate output, and they do not provide professional advice.
You cannot rely on the AI output for factual accuracy or professional guidance, and must verify all results.
Severity 3 · notable
“REPLICATE SHALL NOT BE RESPONSIBLE OR LIABLE, DIRECTLY OR INDIRECTLY, FOR ANY DAMAGE OR LOSS CAUSED OR ALLEGED TO BE CAUSED BY OR IN CONNECTION WITH USE OF OR RELIANCE ON ANY CONTENT, GOODS OR SERVICES AVAILABLE ON OR THROUGH ANY SUCH THIRD-PARTY OFFERINGS, WEBSITES OR SERVICES AVAILABLE THROUGH OUR WEBSITE.”
Replicate is not responsible for any damage or loss caused by third-party offerings or services linked through their website.
You bear the risk if you rely on or use any third-party services or content found on Replicate's platform.
Severity 3 · notable
“REPLICATE AND ITS LICENSORS DISCLAIM ANY REQUIREMENT OR WARRANTY THAT THE SERVICES OR ANY MATERIALS OR CONTENT OFFERED THROUGH THE SERVICE, INCLUDING ANY COMMUNITY MODELS OR MARKETPLACE MODELS WILL BE RELIABLE, UNINTERRUPTED, FREE OF HARMFUL CODE, ACCORDING TO EXPECTATIONS, ERROR FREE, OR THAT ANY OF THOSE ISSUES WILL BE CORRECTED.”
Replicate and its licensors do not guarantee that their services or models will be reliable, uninterrupted, error-free, or meet your expectations.
You may experience service issues or errors without recourse, as Replicate disclaims responsibility for them.
Indemnification (1)
Severity 4 · material
“Customer shall indemnify, defend, and hold harmless Replicate and its Affiliates, officers, directors, employees, agents, successors, and assigns (each, a “Replicate Indemnitee”) from and against any and all Losses incurred by such Replicate Indemnitee resulting from Customer’s use of the Services, including in respect of any Action that relates to or arises out of or results from: (a) Customer Data, including any Inputs, Outputs, and processing of Customer Data by a Model; (b) Customer or its Authorized Users’ breach of Third Party Terms; (c) any other materials or information (including any documents, data, specifications, software, content, or technology) provided by or on behalf of Customer; (d) allegation of facts that, if true, would constitute Customer's breach of any of its representations, warranties, covenants, or obligations under these Terms; (e) negligence, or more culpable act or omission (including recklessness or willful misconduct) by Customer, any Authorized User, or any third party on behalf of Customer, in connection with these Terms.”
You must defend Replicate against any claims arising from your data, your breach of terms, or your negligence.
You could be responsible for paying Replicate's legal fees and damages if their platform is involved in a lawsuit due to your actions.
Matches T-Mobile Data Breach Settlement — settled for $350M (2022)
Right to silently change terms (10)
Severity 5 · egregious
“If you purchase access to the Flux API for your website and/or application that will allow end users to generate Output by submitting Inputs to the Flux AI Model via the Flux API, your usage is governed by the then-current version of the Flux Model API Agreement, currently available at: https://docs.bfl.ml/agreement/. By using and purchasing access to the Flux API, you hereby agree to the terms of such Flux Model API Agreement with respect to such use. You also agree and acknowledge that you are required to clearly inform any users of your application or product(s) that by using the Flux AI Model within your application, your users agree to be bound by the then-current version of the Flux Terms of Service available at https://blackforestlabs.ai/terms-of-service/.”
Using the Flux API means you agree to its specific terms, and you must inform your users they are also bound by Black Forest Labs' terms.
You are responsible for ensuring your users comply with external terms of service for the Flux AI Model.
Severity 5 · egregious
“In addition, with respect to the FluxDev Model or any similar Flux Models, you shall not: i. use, modify, copy, reproduce, create Derivatives of, or distribute any technology owned by Black Forest Labs (or any Derivative thereof, or any data produced by the FluxDev Model), in whole or in part, for (a) any military purposes, (b) purposes of surveillance, including any research or development relating to surveillance, (c) biometric processing, (d) in any manner that infringes, misappropriates, or otherwise violates any third-party rights, or (e) in any manner that violates any applicable law, including any privacy or security laws, rules, regulations, directives, or governmental requirements (including the General Data Privacy Regulation (Regulation (EU) 2016/679), the California Consumer Privacy Act, and any and all laws governing the processing of biometric information), as well as all amendments and successor laws to any of the foregoing; ii. use or access the Black Forest Lab’s models or Outputs to create, train or improve (direct or indirectly) a similar or competing product or service; or iii. for any purpose prohibited by export laws, including nuclear, chemical or biological weapons, or missile technology applications.”
You cannot use Black Forest Labs' technology for military, surveillance, biometric processing, infringing third-party rights, or violating laws.
Violating these restrictions could lead to legal action and termination of your access.
Severity 5 · egregious
“You shall not: i. modify, decompile, disassemble, create Derivative Works based upon, or otherwise alter any of the technology offering by Ideogram AI. “Derivative Works” means a revision, modification, translation, abridgment, condensation or expansion of software or other works of authorship or any form in which software or other works of authorship may be recast, transferred, or adapted, and which, if prepared without the consent of the party owning such software or work of authorship, would constitute copyright infringement.”
You cannot use Ideogram AI's technology to create competing products, or modify, decompile, or reverse-engineer their software.
Attempting to reverse-engineer or build a competing product using Ideogram's technology can result in legal action.
Severity 5 · egregious
“ii. use User Input or User Output to develop any product, service, or technology that competes with Ideogram and Ideogram AI Model or Ideogram API; iii. submit, transmit, display, perform, post or store any content that is inaccurate, illegal, unlawful (including, but not to limited to, uploading copyrighted images via the Ideogram AI Model without the consent of the copyright owner), defamatory, unethical, obscene, lewd, lascivious, filthy, excessively violent, pornographic, invasive of privacy or publicity rights (including, but not limited to, uploading images of individuals via the Ideogram AI Model without their consent), harassing, threatening, abusive, inflammatory, harmful, hateful, cruel or insensitive, deceptive, or otherwise objectionable (collectively and individually, “Objectionable”);”
You cannot submit illegal, defamatory, harmful, or objectionable content, or use Ideogram AI for bullying or political campaigning.
Submitting prohibited content or using the AI for restricted purposes can lead to account suspension or legal issues.
Severity 5 · egregious
“iv. use the Ideogram AI Model for bullying, disruptive or Objectionable purposes or for political campaigning or lobbying purposes; or otherwise use the Ideogram AI Model or Ideogram API in a manner that is fraudulent, inciting, organizing, promoting or facilitating violence or criminal or harmful activities, or Objectionable; v. use cheats, automation software (bots), hacks, modifications (mods) or any other unauthorized third-party software designed to modify the Ideogram AI Model or Ideogram API; vi. use any robot, spider, crawlers, scraper, or other automatic device, process, software or queries that intercepts, “mines,” scrapes, extracts, or otherwise accesses the Ideogram AI Model to monitor, extract, copy or collect information or data from or through the Ideogram AI Model, or engage in any manual process to do the same; or vii. use or distribute User Output in a misleading way, including, for instance, by representing that the User Output is entirely human generated or that the User Output depicts an actual photograph of a real event.”
You cannot use bots, hacks, or unauthorized software to modify Ideogram AI, nor scrape or collect data from the service.
Using unauthorized tools or scraping data can lead to your account being banned and potential legal consequences.
Severity 5 · egregious
“Further, if you distribute any User Output to others, you are encouraged to proactively disclose that such User Output was created using artificial intelligence technologies so as not to mislead others of its origin.”
You must disclose if your output was created using AI and cannot represent it as entirely human-generated.
Failing to disclose AI generation can mislead users and potentially violate platform policies or regulations.
Severity 5 · egregious
“You will not (and will not permit any third party to): (i) sell, lease, assign, license, sublicense, distribute, make available, or otherwise transfer in whole or in part the Stability AI Materials, or any component thereof, to any third party; (ii) create a derivative work based upon the Stability AI Materials or any component thereof (except that you may do so as long as you are in compliance with the Replicate Terms and the other additional terms set forth in these Additional Terms, and provided that, in event that you download the code or weights associated with any Stability Materials you have obtained a license directly through Stability as set forth above); (iii) encumber, time-share, rent or lease the rights granted under the Terms or these Additional Terms; (iv) remove, obscure, or alter any notice of intellectual property rights present on or in the Stability AI Materials; (v) make any representation or warranties regarding the Stability AI Materials that are false, misleading or which exceed those in this Agreement, the Documentation, or any marketing materials made available to you; and (vi) pre-install or authorize any original equipment manufacturer (OEM) to pre-install your service on any hardware device prior to its first sale, where hardware devices include, but are not limited to, PCs, mobile phones, consumer electronics, and medical devices.”
You cannot sell, lease, or distribute Stability AI materials to third parties, nor create derivative works without permission.
Distributing or modifying Stability AI materials without authorization can lead to copyright infringement claims.
Severity 4 · material
“Replicate reserves the right, in its sole discretion, to make any changes to the Services at any time (including by limiting or discontinuing certain features of the Service), temporarily or permanently, without notice to you. Changes may include modifications to: (a) maintain or enhance: (i) the quality or delivery of Services; (ii) the competitive strength of or market for the Services; or (iii) the Services’ cost efficiency or performance; or (b) to comply with Law.”
Replicate can change or discontinue any part of its services at any time without notice.
Features you rely on could be removed or changed without warning, disrupting your workflow.
Matches X Corp. Verified User Class Action (2024)
Severity 4 · material
“Replicate may suspend or disable access to a Marketplace Model through the Services at any time for any reason.”
Replicate can suspend or disable access to marketplace models at any time for any reason.
Models you depend on could become unavailable without notice, halting your projects.
Matches X Corp. Verified User Class Action (2024)
Severity 4 · material
“Replicate may amend these Terms at any time by posting the amended terms on the Website. The modifications will become effective as of the first day of the calendar month following the month in which they were first posted. It is your responsibility to review these Terms periodically. Your continued use of the Service following the posting of revised Terms means that you accept and agree to the changes. By continuing to access or use our Service after any revisions become effective, you agree to be bound by the revised terms. If you do not agree to the new terms, you are no longer authorized to use the Service.”
Replicate can change these terms at any time, and your continued use signifies acceptance of the new terms.
You may be bound by new terms you haven't read or agreed to simply by continuing to use the service.
Matches Italian DPA (Garante) v. WhatsApp — settled for $6M (2022)
Methodology
SaaSGuard uses an automated pipeline: a daily Playwright crawler captures each vendor’s public Terms of Service, Privacy Policy, and DPA. Google’s Gemini 2.5 Flash classifies each clause into one of 8 risk categories with a severity score (1–5). Clauses are cross-referenced against a curated database of real lawsuits and FTC actions via embedding-based similarity matching. Grades are computed from per-category max severity; full source code is available on request.