Live feed · updated daily

Recent policy changes

208 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
838 Documents tracked
208 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
October 6, 2026
Google Play Store
Google Play Terms
medium
Google added a notice to the Google Play Terms of Service saying it is updating the terms on November 5, 2026, and that the current terms continue to apply until then. The notice links to a preview of the upcoming terms but does not itself say what will change, and the terms on the page are unchanged.
October 3, 2026
Meta
Llama API Terms of Service
medium
Meta added Exhibit C, “Hosted Platform Access”, to its Meta Model API Terms of Service, last updated October 2, 2026. It applies when the Meta Materials are used through a third-party cloud platform authorized by Meta. The platform provider may disclose “Platform Account Data” to Meta, which can include the customer's organization name and domain, account and billing identifiers, location, subscription details, usage volumes, and revenue, fee and billing metrics; Meta may use it to operate and secure the service and to administer its arrangements with platform providers. Meta states that it does not receive or process customer content, including inputs and outputs, accessed through a hosted platform, and does not use that content to train or improve its models. The terms' sections on accounts and API keys, discounted services, and fees and taxes do not apply to hosted-platform access, where the platform provider bills fees under its own agreement.
Google
Google Privacy Policy
medium
Google's Privacy Policy now gives an effective date of October 1, 2026, replacing May 26, 2026. One passage changed. It covers information Google collects when you are not signed in, which it stores with identifiers tied to your browser, app or device. The policy previously said this lets Google show more relevant search results or ads “based on your activity”; it now says “based on your activity across devices.”
September 12, 2026
BeReal
BeReal Terms of Service
medium
Replaced three-strike suspension rule with graduated enforcement; added EU users formal appeal rights and decision transparency.
Why it matters: The updated terms establish formal procedural protections for EU users that align with Digital Services Act requirements, including mandatory transparency about enforcement decisions and internal appeal rights. For all users, the shift from a fixed three-strike rule to graduated enforcement means account actions will now depend on violation severity and context rather than a predetermined penalty schedule, potentially allowing more proportionate responses but also permitting immediate permanent termination for severe violations.
Anthropic
Anthropic Privacy Policy
medium
Restructured Korea-specific privacy disclosures to detail identity verification data collection, fraud detection practices, and overseas transfer to US vendors with opt-out mechanism.
Why it matters: The updated terms establish explicit disclosures of personal data collection and overseas transfer practices for Korean residents, which may affect how individuals understand Anthropic's data handling and whether they choose to use the service. The addition of an opt-out mechanism for overseas transfer provides a procedural right, though the stated consequence of service limitations creates a practical constraint on exercising that right.
September 11, 2026
Anyscale
Anyscale Privacy Policy
medium
Restructured privacy policy with new CCPA supplemental notice; removed sections on privacy rights, data retention, and international transfers.
Why it matters: The restructuring establishes separate supplemental notices for different jurisdictions, which may affect how users understand their rights and how organizations assess vendor compliance. The explicit disclosure that marketing activities may constitute a 'sale' or 'targeted advertising' under privacy laws clarifies Anyscale's data practices, while the removal of retention and international transfer language from the main policy relocates (rather than eliminates) those obligations to supplemental notices. Organizations using Anyscale should verify that their data processing agreements and vendor assessments account for the new policy structure.
Square
Square Terms of Service
high
Adds non-compete restriction on platform use; expands content licensing to include AI training; revises payment collection procedures.
Why it matters: The updated terms establish a contractual non-compete restriction that may limit sellers' ability to develop competing services using Square's platform, and they expand Square's rights to collect and use seller business branding for AI training and product development without per-use consent. The revised payment procedures establish a primary payment method framework with fallback authorization to collect from transaction proceeds or account balance, which affects how fees are collected and may impact cash flow management for sellers.
OpenAI
OpenAI Privacy Policy
medium
Clarified ad-related data collection for Free and Go users; removed Sora and Atlas browser references.
Why it matters: The updated policy adds explicit disclosure of behavioral data collection (ads history and interests) for Free and Go users, clarifying a data category that was previously referenced only generically. This change affects how users understand what data OpenAI collects about their ad engagement and how that data is used to improve ad targeting and measurement.
September 10, 2026
Cash App
Cash App Terms of Service
medium
Revised identity verification procedures to permit third-party services and made account conversion conditional on verification outcomes.
Why it matters: The updated terms establish that Cash App may use third-party verification services to confirm identity and that successful identity verification does not automatically grant access to all account types or services. This shifts account access from an automatic conversion model to a discretionary one where Cash App retains authority to require additional verification or information before granting access to certain account types or services. This affects onboarding timelines and service access predictability for new users.
Microsoft
Microsoft Privacy Statement (Legacy)
medium
Expands device data collection to include website and app interactions; restructures Copilot personalization to permit cross-product data usage from Bing, Edge, and MSN.
Why it matters: The updated statement materially expands what personal data Microsoft collects and authorizes it to use data from other products to personalize Copilot experiences. The removal of explicit opt-out language for AI model training and replacement with a reference to an external Transparency Note shifts transparency responsibility from the privacy statement itself to a separate document, requiring users to consult multiple sources to understand data usage practices.
September 5, 2026
DeepL
DeepL Privacy Policy
medium
Adds three new account-based storage features (Translation Memories, Translation Memory Generation, Adaptive Translation) with explicit language stating data is used only within user accounts and not
Why it matters: The updated policy establishes explicit data handling commitments for three new account-level storage features, stating that all stored content, embeddings, and derived data remain within individual user accounts and are never used for model training or shared with other customers. This clarifies the scope of data use and provides procedural transparency for organizations and users concerned about how customization features handle their language assets and translation data.
Midjourney
Midjourney Data Retention & Privacy FAQ
medium
Expanded personal data collection categories and clarified data use purposes including purchase processing, marketing, and event-related activities.
Why it matters: The updated policy materially expands the transparency of what personal data Midjourney collects and how it uses that data, moving from a more general disclosure framework to explicit enumeration of data categories and use purposes. This expanded scope affects how personal data flows through Midjourney's systems and may require corresponding updates to privacy notices, vendor contracts, and compliance frameworks maintained by organizations that rely on Midjourney services.
September 4, 2026
Ro
Ro Privacy Policy
medium
Adds contractual restrictions on advertising partners' data use and expands state protections for sensitive personal information.
Why it matters: The updated policy establishes contractual restrictions on how advertising partners can use Ro consumer data, limiting those partners to service provision and reducing the scope of permissible downstream data use. The expansion of states where Ro does not sell sensitive data for advertising and the clarification of default partner settings provide additional operational transparency around how state privacy laws affect data handling, which matters for consumers in covered states and for organizations subject to similar data protection regimes.
Suno
Suno Terms of Service
high
Added age restrictions requiring parental consent for ages 13-17; expanded account termination window; simplified arbitration language with explicit class action and jury trial waivers.
Why it matters: The updated terms establish a hard age cutoff (under 13 prohibited) and a new parental consent requirement (ages 13-17) that materially changes who may legally access Suno and under what conditions. The 30-day account closure deadline creates immediate operational friction: users who do not accept the new terms must affirmatively delete their accounts, and Suno must communicate this deadline clearly to avoid unintended acceptance through continued use. The removal of free tier language eliminates explicit protection against platform discontinuation of free access, narrowing the operational guarantees available to users. Together, these changes significantly alter the user eligibility landscape and impose time-sensitive compliance obligations on both Suno and organizations that serve minors through Suno integration.
September 3, 2026
Coinbase
Coinbase User Agreement
medium
Expanded liquidation authority to cover failed or reversed securities transfers into customer accounts
Why it matters: The updated terms establish a broader trigger for Coinbase to automatically liquidate customer assets without advance notice. Previously liquidation was limited to scenarios where the customer failed to settle their own trades; the change now includes incoming transfer failures or reversals, which may be outside customer control. This expands the platform's unilateral authority over customer assets and may affect how customers structure incoming securities transfers or maintain asset buffers.
September 2, 2026
Rumble
Rumble Terms of Service
medium
Expanded Premium subscription ad disclosures to include host-read sponsorships, original broadcast ads, and native placement advertisements.
Why it matters: The updated terms clarify what advertising formats Premium subscribers may encounter, expanding beyond live read ads to include host-read sponsorships, original broadcast advertisements, and native placements such as boosted content and homepage ads. This change materially affects the scope of advertising disclosure in the Premium subscription offering and may influence consumer expectations about the premium experience.
Amazon
Amazon Conditions of Use
high
Replaced court dispute resolution with mandatory binding arbitration; added class action waiver and 60-day pre-arbitration resolution requirement
Why it matters: This change fundamentally restructures how disputes are resolved. The updated terms establish binding arbitration as the sole mechanism for resolving nearly all disputes, removing court access and jury trial rights that previously applied. The mandatory pre-arbitration procedure and class action waiver substantially alter the practical options available to customers seeking to resolve grievances with Amazon.
September 1, 2026
Hims & Hers
Hims & Hers Terms and Conditions
medium
Revised medication plan cancellation timing; cancellations no longer take effect immediately after the next billing date but instead at end of medication supply period.
Why it matters: The updated terms establish a clearer but more restrictive cancellation timeline for pre-paid medication plans. Users who request cancellation after a billing date will now have their subscription continue through the end of their current medication supply period, which may result in additional medication shipments and charges after cancellation is requested. This affects the practical timing and cost control available to subscribers managing their medication subscriptions.
OpenRouter
OpenRouter Privacy Policy
medium
Raised minimum age requirement from 13 to 18 and added comprehensive Files API handling procedures including encryption and prohibited uses.
Why it matters: The age restriction change eliminates access for users under 18, which affects platform eligibility and downstream vendor representations. The Files API procedures establish concrete commitments about encryption, access control, and deletion that affect data processing agreements, vendor compliance certifications, and privacy notice accuracy for any organization relying on OpenRouter for file handling or inference processing.
OpenRouter
OpenRouter Terms of Service
high
Raises minimum age from 13 to 18; removes parental permission option; adds file upload feature with automated CSAM/malware screening and formal DMCA takedown procedures.
Why it matters: This change establishes a material barrier to service access for minors and introduces mandatory content safeguards with federal reporting obligations. The elimination of the parental permission pathway creates immediate compliance implications for any organization that previously relied on that mechanism to serve younger users, while the automated file scanning and NCMEC reporting obligations formalize OpenRouter's independent legal duties under federal CSAM law.
Stability AI
Stability AI Terms of Service
medium
Lowers audio service age minimum to 13 with parental consent; restricts arbitration to US users; expands content licensing grants.
Why it matters: The updated terms create new compliance obligations for organizations serving minors 13-17 via audio services (parental consent and supervision verification), expand Stability's authority to process and adapt all submitted content, and narrow the arbitration clause to US users only, shifting dispute resolution frameworks for Canadian users. These changes materially alter the legal and operational terms governing use of the platform, particularly for organizations and products targeting younger audiences.
August 29, 2026
Gusto
Gusto Privacy Policy
medium
Adds disclosure that personal data is sold or shared with advertising and business partners; opt-out mechanism available.
Why it matters: The updated language formalizes Gusto's disclosure of personal information sales and sharing practices under U.S. state privacy laws, clarifying what data is shared, with whom, and how users can opt out. This affects how Gusto consumers understand their data privacy rights and responsibilities under CCPA, CPRA, and similar state regimes, and may require employers and vendors using Gusto to align their own privacy practices and agreements with these disclosures.
August 28, 2026
Mercury
Mercury Privacy Policy
medium
Expanded data collection practices for business accounts to include contractors, payment beneficiaries, and employees; clarified SMS consent structure separating transactional from marketing messages.
Why it matters: The updated policy expands the category of personal information Mercury collects and processes on behalf of businesses, now explicitly including employees, contractors, payment beneficiaries, and dependents collected directly from those individuals rather than just the business. This affects data flow and disclosure obligations for any business using Mercury's payroll, contractor payment, or benefits services, and may require those businesses to update their own privacy disclosures and data processing agreements to reflect this expanded third-party collection. The SMS consent change also clarifies the distinction between transactional and marketing message consent, which affects how marketing communications are permissioned and personalized.
Verizon
Verizon Privacy Policy
medium
Expanded stated purposes for data use to include discount eligibility, employment offers, and third-party partner marketing; clarified creditworthiness assessment and contact practices.
Why it matters: The updated policy expands Verizon's stated authority to use customer data for new purposes: determining eligibility for employment-related discounts and rewards programs, and contacting you with partner marketing offers based on third-party data. This narrows the scope of what constitutes 'unexpected' data use and may increase the volume or frequency of eligibility assessments and marketing contact tied to your personal data. In jurisdictions with privacy laws requiring explicit notice of all data uses (GDPR, CCPA, state privacy acts), this expansion of stated uses affects the adequacy of privacy disclosures.
Google Maps
Google Maps Platform Terms of Service
medium
Expanded liability carve-out to include customer breaches of usage and license restrictions in Google Maps Platform Terms
Why it matters: This change clarifies the liability allocation in Google's Platform Terms by confirming that Google cannot contractually cap its liability if customers violate the agreement's usage or license restrictions. The revision affects the contractual risk framework for organizations that depend on Google Maps Platform for production services.
August 25, 2026
Venmo
Venmo User Agreement
high
Added class action and jury trial waivers to mandatory arbitration clause; introduced tiered cash back program with $250 and $1,500 monthly spending thresholds
Why it matters: The explicit addition of class action and jury trial waivers to the arbitration clause materially restricts users' legal remedy options and creates regulatory exposure for Venmo under CFPB and FTC standards. The restructuring of the cash back program with specific spending thresholds and transaction exclusions changes how rewards are calculated and may reduce the rewards available to users who do not meet the higher spending tiers, affecting the practical value proposition of the program.
August 22, 2026
Ramp
Ramp Privacy Policy
medium
Added Automated Decision-Making and Artificial Intelligence disclosure section; revised scope to include banking and accounts receivable; shifted terminology from Personal Information to Personal Data
Why it matters: The updated policy introduces formal disclosure of Automated Decision-Making and AI systems (section 10), expanding regulatory transparency expectations under GDPR and emerging AI frameworks. The policy scope now explicitly covers banking and accounts receivable services, creating new data-handling obligations beyond the original corporate card and expense management focus. Organizations using Ramp should confirm whether these changes require updates to vendor assessments, Data Processing Agreements, or customer privacy notices.
August 21, 2026
Eventbrite
Eventbrite Privacy Policy
medium
Expands organizer email access to include opt-in marketing subscribers, not just event registrants
Why it matters: The updated terms broaden the circumstances under which your email address is shared with event organizers. Previously, sharing occurred only when you registered for their events; now it also occurs when you affirmatively opt into marketing communications through the platform. The policy clarifies that organizers own the relationship with you for these marketing subscriptions and can use email tools to reach you.
August 20, 2026
Faire
Faire Privacy Policy
medium
Expands retailer data collection to include inferred business attributes and automated credit limit decisions; introduces Faire Pay with SSN collection and banking partner sharing.
Why it matters: The updated terms establish new automated decision-making systems affecting retailer payment terms and credit limits, expand what business data Faire collects and infers about retailers, and broaden how that information is shared within the marketplace and with external partners. These changes affect how retailers' accounts are managed, what information other marketplace participants can access about their business, and what sensitive information they may need to provide to access Faire's credit product. Retailers should understand that payment terms may be set by algorithm based on credit assessment and that business profile information is now actively shared to facilitate marketplace discovery and transactions.
Cash App
Cash App Terms of Service
medium
Restructured Cash App Tag pricing from $25 flat fee to variable up to $250; expanded eligibility to include Children in Sponsored Accounts.
Why it matters: The restructured Cash App Tag pricing introduces variable fees up to $250 (vs. a prior fixed $25) and shifts the point of price certainty to checkout disclosure rather than upfront terms. This affects customer cost predictability and purchase decisions. Simultaneously, extending Tag eligibility to Children broadens transaction capabilities for minors previously restricted, requiring parents managing Sponsored Accounts to understand that children can now conduct Tag transactions within sponsor-set limits.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

Page 1 of 7 Older →