Medium updated its Privacy Policy on May 18, 2026 to add detailed disclosure about its address book contact feature. The new language explains that when users opt in to this feature, Medium converts contact names and email addresses into encrypted, non-reversible identifiers to match against its member database. Medium does not store names or emails in plain text, deletes identifiers for non-members immediately, and deletes all encrypted identifiers within 30 days. The policy also reorganized its personal information collection disclosure, though the categories themselves (identifiers, commercial information, internet activity, inferences) remain unchanged.
The updated policy adds transparency about Medium's address book feature by explaining the technical process: contact names and emails are converted into encrypted identifiers, matched against Medium's member database, and then deleted. For contacts who are not Medium members, these encrypted identifiers are deleted immediately; all encrypted identifiers are deleted within 30 days regardless. The policy states Medium relies on legitimate interests to offer this feature, specifically its interest in helping users connect with people they know. You can review the specific disclosure in the 'Helping You Connect With People You Know' section of the updated policy.
Added new section explaining that contact names and emails are converted to encrypted identifiers, matched against Medium's database, and deleted within 30 days (immediately for non-members).
Stated that Medium relies on legitimate interests under Article 6(1)(f) to offer this feature, citing the interest in helping users connect and supporting freedom of expression.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Medium added explicit disclosure of its address book contact matching feature and the technical safeguards it employs. The change operationalizes consent and technical documentation that may be relevant to GDPR Article 6(1)(f) (legitimate interests), Article …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002165.
A minor editorial change was detected in Medium's Privacy Policy on August 5, 2026. The phrase 'Privacy Media' was removed …
In an update detected on August 4, 2026, Medium modified a single sentence in its Privacy Policy header. The document …
In an update detected on August 4, 2026, Medium's Terms of Service underwent minor structural and editorial modifications. The document's …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.