Live feed · updated daily

Recent policy changes

359 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
844 Documents tracked
359 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
September 2, 2026
Rumble
Rumble Terms of Service
medium
Expanded Premium subscription ad disclosures to include host-read sponsorships, original broadcast ads, and native placement advertisements.
Why it matters: The updated terms clarify what advertising formats Premium subscribers may encounter, expanding beyond live read ads to include host-read sponsorships, original broadcast advertisements, and native placements such as boosted content and homepage ads. This change materially affects the scope of advertising disclosure in the Premium subscription offering and may influence consumer expectations about the premium experience.
AWS Bedrock
AWS Service Terms
medium
Removed Data Processing Addendum reference and explicit consent language for Anthropic content transfers; expanded Kiro abuse detection disclosure to include human review.
Why it matters: The removal of explicit Data Processing Addendum language may affect how organizations document Anthropic as a subprocessor and authorize international data transfers under their own compliance frameworks. The expanded disclosure for Kiro clarifies the scope of human review in abuse detection, which may be material for organizations processing sensitive content or operating under privacy regulation requiring transparency on data handling practices.
Midjourney
Midjourney Data Retention & Privacy FAQ
high
Removed privacy policy sections covering data sharing, children's privacy, and security from Data Retention & Privacy FAQ.
Why it matters: The removal of published privacy disclosures from Midjourney's FAQ affects transparency about data handling practices. Previously, users and organizations could review documented explanations of data collection, sharing, security, and children's privacy protections. The removal of these sections means this FAQ no longer serves as a reference for those disclosures, and it is unclear whether equivalent documentation remains available elsewhere or whether privacy protections for children and regional compliance have been modified.
Amazon
Amazon Conditions of Use
high
Replaced court dispute resolution with mandatory binding arbitration; added class action waiver and 60-day pre-arbitration resolution requirement
Why it matters: This change fundamentally restructures how disputes are resolved. The updated terms establish binding arbitration as the sole mechanism for resolving nearly all disputes, removing court access and jury trial rights that previously applied. The mandatory pre-arbitration procedure and class action waiver substantially alter the practical options available to customers seeking to resolve grievances with Amazon.
September 1, 2026
Hims & Hers
Hims & Hers Terms and Conditions
medium
Revised medication plan cancellation timing; cancellations no longer take effect immediately after the next billing date but instead at end of medication supply period.
Why it matters: The updated terms establish a clearer but more restrictive cancellation timeline for pre-paid medication plans. Users who request cancellation after a billing date will now have their subscription continue through the end of their current medication supply period, which may result in additional medication shipments and charges after cancellation is requested. This affects the practical timing and cost control available to subscribers managing their medication subscriptions.
OpenRouter
OpenRouter Privacy Policy
medium
Raised minimum age requirement from 13 to 18 and added comprehensive Files API handling procedures including encryption and prohibited uses.
Why it matters: The age restriction change eliminates access for users under 18, which affects platform eligibility and downstream vendor representations. The Files API procedures establish concrete commitments about encryption, access control, and deletion that affect data processing agreements, vendor compliance certifications, and privacy notice accuracy for any organization relying on OpenRouter for file handling or inference processing.
OpenRouter
OpenRouter Terms of Service
high
Raises minimum age from 13 to 18; removes parental permission option; adds file upload feature with automated CSAM/malware screening and formal DMCA takedown procedures.
Why it matters: This change establishes a material barrier to service access for minors and introduces mandatory content safeguards with federal reporting obligations. The elimination of the parental permission pathway creates immediate compliance implications for any organization that previously relied on that mechanism to serve younger users, while the automated file scanning and NCMEC reporting obligations formalize OpenRouter's independent legal duties under federal CSAM law.
Stability AI
Stability AI Terms of Service
medium
Lowers audio service age minimum to 13 with parental consent; restricts arbitration to US users; expands content licensing grants.
Why it matters: The updated terms create new compliance obligations for organizations serving minors 13-17 via audio services (parental consent and supervision verification), expand Stability's authority to process and adapt all submitted content, and narrow the arbitration clause to US users only, shifting dispute resolution frameworks for Canadian users. These changes materially alter the legal and operational terms governing use of the platform, particularly for organizations and products targeting younger audiences.
August 29, 2026
Cursor
Cursor Data Use & Privacy Overview
medium
Removed detailed disclosure language regarding plaintext code and metadata retention during codebase indexing processes.
Why it matters: The updated policy removes explicit disclosures about how Cursor processes and retains codebase data during indexing. Users and organizations can no longer rely on the stated data handling practices for plaintext code deletion and metadata storage, creating ambiguity about retention practices for sensitive source code and metadata.
Verizon
Verizon Privacy Policy
medium
Removed opt-out instructions for Verizon Community users from privacy policy
Why it matters: The updated policy removes a disclosed opt-out mechanism for Verizon Community users. Under state privacy laws, removal of a previously published privacy control or instruction may raise compliance concerns unless the functionality remains accessible and is disclosed elsewhere. Verizon Community users will no longer locate this opt-out guidance in the policy as written.
Gusto
Gusto Privacy Policy
medium
Adds disclosure that personal data is sold or shared with advertising and business partners; opt-out mechanism available.
Why it matters: The updated language formalizes Gusto's disclosure of personal information sales and sharing practices under U.S. state privacy laws, clarifying what data is shared, with whom, and how users can opt out. This affects how Gusto consumers understand their data privacy rights and responsibilities under CCPA, CPRA, and similar state regimes, and may require employers and vendors using Gusto to align their own privacy practices and agreements with these disclosures.
August 28, 2026
Mercury
Mercury Privacy Policy
medium
Expanded data collection practices for business accounts to include contractors, payment beneficiaries, and employees; clarified SMS consent structure separating transactional from marketing messages.
Why it matters: The updated policy expands the category of personal information Mercury collects and processes on behalf of businesses, now explicitly including employees, contractors, payment beneficiaries, and dependents collected directly from those individuals rather than just the business. This affects data flow and disclosure obligations for any business using Mercury's payroll, contractor payment, or benefits services, and may require those businesses to update their own privacy disclosures and data processing agreements to reflect this expanded third-party collection. The SMS consent change also clarifies the distinction between transactional and marketing message consent, which affects how marketing communications are permissioned and personalized.
Verizon
Verizon Privacy Policy
medium
Expanded stated purposes for data use to include discount eligibility, employment offers, and third-party partner marketing; clarified creditworthiness assessment and contact practices.
Why it matters: The updated policy expands Verizon's stated authority to use customer data for new purposes: determining eligibility for employment-related discounts and rewards programs, and contacting you with partner marketing offers based on third-party data. This narrows the scope of what constitutes 'unexpected' data use and may increase the volume or frequency of eligibility assessments and marketing contact tied to your personal data. In jurisdictions with privacy laws requiring explicit notice of all data uses (GDPR, CCPA, state privacy acts), this expansion of stated uses affects the adequacy of privacy disclosures.
Google Maps
Google Maps Platform Terms of Service
medium
Expanded liability carve-out to include customer breaches of usage and license restrictions in Google Maps Platform Terms
Why it matters: This change clarifies the liability allocation in Google's Platform Terms by confirming that Google cannot contractually cap its liability if customers violate the agreement's usage or license restrictions. The revision affects the contractual risk framework for organizations that depend on Google Maps Platform for production services.
August 26, 2026
Canva
Canva Terms of Use
medium
Restructured print fulfillment model to separate Canva-sold products from third-party marketplace seller transactions; added order rejection authority; clarified refund policy limited to rejected orde
Why it matters: The restructured print fulfillment model introduces a separate contractual framework for marketplace seller transactions, which affects the governing terms and remedies available to customers. The explicit order rejection authority and refund limitation clarify what remedies are not available to consumers, which may narrow dispute resolution options compared to the prior model where all print services were attributed to Canva's third-party partners. Organizations relying on Canva's print services should confirm which contractual tier applies and adjust customer expectations accordingly.
August 25, 2026
Venmo
Venmo User Agreement
high
Added class action and jury trial waivers to mandatory arbitration clause; introduced tiered cash back program with $250 and $1,500 monthly spending thresholds
Why it matters: The explicit addition of class action and jury trial waivers to the arbitration clause materially restricts users' legal remedy options and creates regulatory exposure for Venmo under CFPB and FTC standards. The restructuring of the cash back program with specific spending thresholds and transaction exclusions changes how rewards are calculated and may reduce the rewards available to users who do not meet the higher spending tiers, affecting the practical value proposition of the program.
August 22, 2026
Ramp
Ramp Privacy Policy
medium
Added Automated Decision-Making and Artificial Intelligence disclosure section; revised scope to include banking and accounts receivable; shifted terminology from Personal Information to Personal Data
Why it matters: The updated policy introduces formal disclosure of Automated Decision-Making and AI systems (section 10), expanding regulatory transparency expectations under GDPR and emerging AI frameworks. The policy scope now explicitly covers banking and accounts receivable services, creating new data-handling obligations beyond the original corporate card and expense management focus. Organizations using Ramp should confirm whether these changes require updates to vendor assessments, Data Processing Agreements, or customer privacy notices.
August 21, 2026
Eventbrite
Eventbrite Privacy Policy
medium
Expands organizer email access to include opt-in marketing subscribers, not just event registrants
Why it matters: The updated terms broaden the circumstances under which your email address is shared with event organizers. Previously, sharing occurred only when you registered for their events; now it also occurs when you affirmatively opt into marketing communications through the platform. The policy clarifies that organizers own the relationship with you for these marketing subscriptions and can use email tools to reach you.
August 20, 2026
Faire
Faire Privacy Policy
medium
Expands retailer data collection to include inferred business attributes and automated credit limit decisions; introduces Faire Pay with SSN collection and banking partner sharing.
Why it matters: The updated terms establish new automated decision-making systems affecting retailer payment terms and credit limits, expand what business data Faire collects and infers about retailers, and broaden how that information is shared within the marketplace and with external partners. These changes affect how retailers' accounts are managed, what information other marketplace participants can access about their business, and what sensitive information they may need to provide to access Faire's credit product. Retailers should understand that payment terms may be set by algorithm based on credit assessment and that business profile information is now actively shared to facilitate marketplace discovery and transactions.
Cash App
Cash App Terms of Service
medium
Restructured Cash App Tag pricing from $25 flat fee to variable up to $250; expanded eligibility to include Children in Sponsored Accounts.
Why it matters: The restructured Cash App Tag pricing introduces variable fees up to $250 (vs. a prior fixed $25) and shifts the point of price certainty to checkout disclosure rather than upfront terms. This affects customer cost predictability and purchase decisions. Simultaneously, extending Tag eligibility to Children broadens transaction capabilities for minors previously restricted, requiring parents managing Sponsored Accounts to understand that children can now conduct Tag transactions within sponsor-set limits.
August 19, 2026
Gumroad
Gumroad Terms of Service
medium
Added automatic forfeiture of unpaid earnings if creators change payout country or method without advance notice and confirmation.
Why it matters: This change establishes a financial consequence for creators who change their payout country or method without withdrawing unpaid balances first. The forfeiture mechanism introduces operational risk for creators managing earnings across multiple jurisdictions, and the notice-and-confirmation requirement creates a friction point in account modifications that creators need to understand to avoid unintended losses.
SoFi
SoFi Terms of Service (Superseded URL)
medium
Restructured SoFi Plus investment match: removes 1-year subscription requirement, imposes 5-year holding period instead, expands eligible account types, enables stacking with limited-time offer.
Why it matters: The revised terms materially change the cost of exiting SoFi Plus and the liquidity constraints on investment deposits. Prior terms imposed a one-year membership lock with a cancellation fee for early exit; the revised terms eliminate the fee but impose a five-year holding requirement on deposits themselves. Members can now cancel SoFi Plus without penalty, but deposits cannot be withdrawn for five years without forfeiting the 1% match. This shifts the friction from membership continuity to account liquidity and may affect portfolio rebalancing, tax-loss harvesting, and withdrawal planning.
SoFi
SoFi Terms of Service
medium
Restructured SoFi Plus 1% investment match: replaced 1-year membership holding requirement with 5-year deposit holding; removed early cancellation fees; restarted promotion August 18, 2026.
Why it matters: The updated terms establish a five-year asset retention requirement as the new condition for receiving and retaining the SoFi Plus 1% investment match benefit, replacing the prior one-year membership requirement. This structural shift materially extends the period during which members cannot withdraw deposits without forfeiting match proceeds, fundamentally altering the liquidity profile and financial planning implications of the benefit. The change also restarts the promotional period and introduces a secondary limited-time offer window, creating distinct eligibility cohorts and enforcement dates that SoFi members must track separately.
August 18, 2026
AWS Bedrock
AWS Service Terms
high
Adds spend limit suspension authority, project-based service structure, and team member content ownership rules.
Why it matters: The updated terms establish AWS's authority to suspend and permanently close accounts based on spend limit violations, and introduce new team member content ownership and liability rules that affect how data and intellectual property are governed within shared projects. Organizations using AWS Bedrock should understand that enabling spend limits creates exposure to account suspension and permanent content deletion without a specified reactivation grace period. Project owners become liable for team member conduct and content contributions, which affects internal governance and contract allocation of risk.
Cohere
Cohere Enterprise Data Commitments
medium
Adds explicit data retention and control procedures for SaaS users: 30-day auto-deletion, opt-out from training data use, and logging disclosures.
Why it matters: The updated terms establish explicit data retention, logging, and opt-out procedures that organizations subject to data protection regulations (GDPR, CCPA) need to evaluate against their own data governance obligations. The 30-day automatic deletion with stated exceptions, training data opt-out mechanism, and disclosure of safety monitoring provide operational clarity that was previously implicit, enabling organizations to confirm alignment with their vendor contracts and regulatory obligations.
August 16, 2026
Perplexity AI
Perplexity Data Processing Addendum
medium
Revised subprocessor disclosure mechanism to live Trust Center list; introduced product-specific data postures for Embeddings API and Search.
Why it matters: The updated DPA restructures how subprocessor disclosures are communicated and managed, shifting from static document amendments to a live online registry that customers must actively monitor. The introduction of product-specific data postures for Embeddings API and Perplexity Search creates a more complex compliance model where different services operate under different rules, which organizations subject to GDPR or UK GDPR must carefully track to ensure their own data controller obligations are met.
August 15, 2026
Mistral AI
Mistral Medium 3.5 Model Card
medium
Mistral AI adjusted mistral-medium-3-5 pricing from €1.25/$6.4 to $1.5/$7.5 per million tokens and shifted primary currency to USD.
Why it matters: The updated pricing reflects a material increase in per-token costs for mistral-medium-3-5 API consumption and a shift in the primary pricing currency to USD. Organizations that budget for Mistral API expenses, embed the model in production systems, or operate on margins sensitive to inference costs should evaluate the impact on their cost structure and contract terms.
Perplexity AI
Perplexity Privacy Policy
medium
Removed transparency statement about data sales and advertiser sharing; restructured privacy policy header with updated navigation.
Why it matters: The updated policy removes an explicit, prominent reassurance that personal data is not sold and user conversations are not shared with advertisers. While the document may retain substantive privacy protections elsewhere, the removal of this upfront commitment changes what assurances are immediately visible to users and may affect how privacy commitments are represented in third-party vendor assessments or customer-facing disclosures.
August 14, 2026
Cursor
Cursor Terms of Service
high
Replaced binding arbitration with mandatory litigation in Texas courts; added statutory limitation periods (1 year federal, 2 years state) for dispute initiation.
Why it matters: The updated terms fundamentally restructure dispute resolution from a private, streamlined arbitration process to mandatory public litigation in Texas courts with strict filing deadlines. Users in other states or countries face significantly increased friction and cost to pursue claims, and claims not filed within 1-2 years are permanently barred. This change affects access to justice and the practical enforceability of user rights under the agreement.
Perplexity AI
Perplexity Enterprise Terms
high
Expands scope to multiple enterprise products; adds marketing data sharing with third parties; introduces usage-based billing and automatic acceptance of term changes upon continued use.
Why it matters: The updated terms substantially expand Perplexity's unilateral authority to modify which services are covered, introduce marketing data sharing outside the data processing agreement, and establish automatic acceptance of changes through continued use. For organizations with vendor governance frameworks, data processing agreements, or privacy representations tied to specific product scope and processor-only data handling, these changes create new compliance review obligations and potential gaps between what the organization has represented to customers or regulators and what Perplexity's terms now permit.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

Page 1 of 12 Older →