HubSpot AI (Breeze) can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. It operates inside a CRM you already govern under a signed DPA, and HubSpot’s Product Specific Terms carry a dedicated HubSpot AI section — but that section governs inputs, outputs, credits and third-party AI providers without committing either way on model training, so a training exclusion has to come from your contract rather than from the published terms. The approval should name the surface: HubSpot AI on CRM data inside the portal — not "any AI tool that touches customer data."
This verdict reflects HubSpot’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.
| Vendor | HubSpot |
|---|---|
| Category | CRM / marketing AI |
| Our tier verdict | Limited (assessed 29 July 2026) — It operates inside a CRM you already govern under a signed DPA, and HubSpot’s Product Specific Terms carry a dedicated HubSpot AI section — but that section governs inputs, outputs, credits and third-party AI providers without committing either way on model training, so a training exclusion has to come from your contract rather than from the published terms. source |
| Trains on your data? | Not established from a primary source Unsettled by the terms — but not because HubSpot is silent on AI. Its Product Specific Terms contain section 7, "HUBSPOT AI", which defines your AI Input and AI Output, states that "Some HubSpot AI settings may be on by default; you can manage these settings at any time in your account", and provides at 7.5 that "your AI Input and AI Output, including Customer Data, will be shared with and processed by our AI service providers". What none of section 7’s subsections says is whether that data is used to train models, in either direction. Section 7.5 points to the DPA for "additional information about HubSpot AI and related data handling"; the DPA we read contains no AI-specific section at all. So: sharing with AI providers is documented, training is not addressed. Ask HubSpot for the model-training commitment in writing before you classify this as "no". source |
| Data retention | Follows your existing HubSpot data retention terms and DPA rather than a separate AI retention policy. source |
| Admin controls | Managed through existing HubSpot seat and user administration — the Product Specific Terms govern how you add, remove and audit Users and point to HubSpot’s user-permissions documentation for the per-user controls. For the AI features specifically, section 7.1 states that some HubSpot AI settings may be on by default and that you can manage them at any time in your account, pointing to HubSpot’s "Manage your AI settings" knowledge-base article. Treat "on by default" as the operative phrase: someone has to go and look. source |
| Compliance certifications | HubSpot’s DPA states its hosting sub-processors maintain independently validated security programmes including SOC 2 and ISO 27001, and that HubSpot’s systems are audited annually as part of SOC 2 compliance source |
| HIPAA / BAA | Not publicly documented — Neither of the two documents we read end to end — the Data Processing Agreement and the Product Specific Terms, section 7 on HubSpot AI included — contains the words HIPAA, business associate, or protected health information anywhere. That is a checked absence in those two documents, and we are not claiming anything about what HubSpot may publish elsewhere. If PHI has to live in a CRM, put the question to HubSpot directly and get the answer in writing. |
Unsettled by the terms — but not because HubSpot is silent on AI. Its Product Specific Terms contain section 7, "HUBSPOT AI", which defines your AI Input and AI Output, states that "Some HubSpot AI settings may be on by default; you can manage these settings at any time in your account", and provides at 7.5 that "your AI Input and AI Output, including Customer Data, will be shared with and processed by our AI service providers". What none of section 7’s subsections says is whether that data is used to train models, in either direction. Section 7.5 points to the DPA for "additional information about HubSpot AI and related data handling"; the DPA we read contains no AI-specific section at all. So: sharing with AI providers is documented, training is not addressed. Ask HubSpot for the model-training commitment in writing before you classify this as "no".
Retention: Follows your existing HubSpot data retention terms and DPA rather than a separate AI retention policy.
Neither of the two documents we read end to end — the Data Processing Agreement and the Product Specific Terms, section 7 on HubSpot AI included — contains the words HIPAA, business associate, or protected health information anywhere. That is a checked absence in those two documents, and we are not claiming anything about what HubSpot may publish elsewhere. If PHI has to live in a CRM, put the question to HubSpot directly and get the answer in writing. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.
Comparing vendors on this specifically? See BAA status for all 26 tools →
HubSpot’s DPA states its hosting sub-processors maintain independently validated security programmes including SOC 2 and ISO 27001, and that HubSpot’s systems are audited annually as part of SOC 2 compliance. Treat that as the vendor’s own statement and ask for the current report under NDA — a SOC 2 report has a defined scope and a fixed audit window, and neither is visible from a badge on a trust page. A certification is also not a contract: it describes how HubSpot AI (Breeze) runs its controls, not what your agreement with them permits.
HIPAA is the gate: Neither of the two documents we read end to end — the Data Processing Agreement and the Product Specific Terms, section 7 on HubSpot AI included — contains the words HIPAA, business associate, or protected health information anywhere. That is a checked absence in those two documents, and we are not claiming anything about what HubSpot may publish elsewhere. If PHI has to live in a CRM, put the question to HubSpot directly and get the answer in writing. Until a BAA is confirmed in writing, treat HubSpot AI (Breeze) as off-limits for anything containing PHI — patient names, appointment details, clinical notes, even "anonymized" summaries that could be re-identified.
For SEC/FINRA-regulated firms the questions are recordkeeping and confidentiality: can communications through HubSpot AI (Breeze) be captured for books-and-records requirements, and do the data terms hold up in vendor due diligence? Managed through existing HubSpot seat and user administration — the Product Specific Terms govern how you add, remove and audit Users and point to HubSpot’s user-permissions documentation for the per-user controls. For the AI features specifically, section 7.1 states that some HubSpot AI settings may be on by default and that you can manage them at any time in your account, pointing to HubSpot’s "Manage your AI settings" knowledge-base article. Treat "on by default" as the operative phrase: someone has to go and look.
The privilege question comes first: entering client-confidential facts into any third-party AI service must be evaluated as a potential disclosure. Because the vendor’s published documents do not answer whether HubSpot AI (Breeze) trains on what you put in, a firm cannot represent to a client that it does not. Keep matter data out until you hold that answer in writing.
Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. All of them were read on 29 July 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.
Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.
Why the tier verdict is "generic": Limited is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies HubSpot AI (Breeze) and 25 other tools specifically for your industry, company size, and the data your team handles.
And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.
HubSpot AI (Breeze) can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. It operates inside a CRM you already govern under a signed DPA, and HubSpot’s Product Specific Terms carry a dedicated HubSpot AI section — but that section governs inputs, outputs, credits and third-party AI providers without committing either way on model training, so a training exclusion has to come from your contract rather than from the published terms. The approval should name the surface: HubSpot AI on CRM data inside the portal — not "any AI tool that touches customer data."
Unsettled by the terms — but not because HubSpot is silent on AI. Its Product Specific Terms contain section 7, "HUBSPOT AI", which defines your AI Input and AI Output, states that "Some HubSpot AI settings may be on by default; you can manage these settings at any time in your account", and provides at 7.5 that "your AI Input and AI Output, including Customer Data, will be shared with and processed by our AI service providers". What none of section 7’s subsections says is whether that data is used to train models, in either direction. Section 7.5 points to the DPA for "additional information about HubSpot AI and related data handling"; the DPA we read contains no AI-specific section at all. So: sharing with AI providers is documented, training is not addressed. Ask HubSpot for the model-training commitment in writing before you classify this as "no".
Neither of the two documents we read end to end — the Data Processing Agreement and the Product Specific Terms, section 7 on HubSpot AI included — contains the words HIPAA, business associate, or protected health information anywhere. That is a checked absence in those two documents, and we are not claiming anything about what HubSpot may publish elsewhere. If PHI has to live in a CRM, put the question to HubSpot directly and get the answer in writing. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.
HubSpot’s DPA states its hosting sub-processors maintain independently validated security programmes including SOC 2 and ISO 27001, and that HubSpot’s systems are audited annually as part of SOC 2 compliance. Treat that as the vendor’s own statement and ask for the current report under NDA — a SOC 2 report has a defined scope and a fixed audit window, and neither is visible from a badge on a trust page. A certification is also not a contract: it describes how HubSpot AI (Breeze) runs its controls, not what your agreement with them permits.
We classify HubSpot AI (Breeze) as Limited for a typical 50–500 person company, assessed 29 July 2026. It operates inside a CRM you already govern under a signed DPA, and HubSpot’s Product Specific Terms carry a dedicated HubSpot AI section — but that section governs inputs, outputs, credits and third-party AI providers without committing either way on model training, so a training exclusion has to come from your contract rather than from the published terms. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.
New to the topic? Start with what shadow AI is — definition, examples and risks, then measure your own exposure with the shadow AI scorer.
Your team is using HubSpot AI (Breeze). Does your AI policy cover it?
Most policies name a handful of tools and go stale the month after they are written. Two ways to find out where yours stands: check an existing policy for gaps in 30 seconds, or generate a policy that classifies HubSpot AI (Breeze) by name — free preview, no account. Starting from scratch? The free 14-section AI acceptable use policy template is the document itself, ungated.
A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies HubSpot AI (Breeze) and 25 other tools for your company, industry, and data. Generated in about 10 minutes.
Generate my policy kit →We re-check vendor terms monthly and alert you when HubSpot AI (Breeze)’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.
See Monitor plan →Already have an AI policy? Check it for gaps in 30 seconds →