Live feed · updated daily

Recent policy changes

221 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
838 Documents tracked
221 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
October 6, 2026
Google Play Store
Google Play Terms
medium
Google added a notice to the Google Play Terms of Service saying it is updating the terms on November 5, 2026, and that the current terms continue to apply until then. The notice links to a preview of the upcoming terms but does not itself say what will change, and the terms on the page are unchanged.
October 3, 2026
Meta
Llama API Terms of Service
medium
Meta added Exhibit C, “Hosted Platform Access”, to its Meta Model API Terms of Service, last updated October 2, 2026. It applies when the Meta Materials are used through a third-party cloud platform authorized by Meta. The platform provider may disclose “Platform Account Data” to Meta, which can include the customer's organization name and domain, account and billing identifiers, location, subscription details, usage volumes, and revenue, fee and billing metrics; Meta may use it to operate and secure the service and to administer its arrangements with platform providers. Meta states that it does not receive or process customer content, including inputs and outputs, accessed through a hosted platform, and does not use that content to train or improve its models. The terms' sections on accounts and API keys, discounted services, and fees and taxes do not apply to hosted-platform access, where the platform provider bills fees under its own agreement.
Google
Google Privacy Policy
medium
Google's Privacy Policy now gives an effective date of October 1, 2026, replacing May 26, 2026. One passage changed. It covers information Google collects when you are not signed in, which it stores with identifiers tied to your browser, app or device. The policy previously said this lets Google show more relevant search results or ads “based on your activity”; it now says “based on your activity across devices.”
September 25, 2026
Mercury
Mercury Terms of Service
medium
Clarifies that third-party promotional partners may change or discontinue perks anytime and Mercury won't be responsible for honoring discontinued offers.
Why it matters: The updated terms establish that Mercury will not guarantee or be responsible for promotional offers provided by third-party partners, even if you have already met the perk's eligibility requirements. This means a qualified offer could be withdrawn or modified by the partner without recourse through Mercury, and you would need to contact the partner directly to resolve disputes.
Google Gemini
Gemini Apps Privacy Notice
medium
Added agentic calling feature with user-controlled data sharing and server-side transcript storage.
Why it matters: The updated privacy notice discloses a new data collection practice involving call transcripts and audio recordings on Pixel devices. This represents a material expansion of the types of personal data Gemini collects and processes, with specific retention and use practices that users should understand before using the calling feature.
TikTok
TikTok Community Guidelines
medium
Expanded prohibited conduct on regulated goods to include 'providing access'; narrowed seller exception from registered to verified business accounts.
Why it matters: The updated Community Guidelines restrict commerce in regulated goods more broadly and limit which sellers may qualify for exceptions. The expansion of prohibited conduct to include 'providing access to' regulated goods affects not just direct sales but also any facilitation of access, which may impact affiliate programs, reseller networks, or user-generated content involving regulated items. The narrowing of the seller exception to 'verified' accounts only means that merchants with registered but unverified accounts may no longer qualify to sell regulated items, potentially disrupting existing commerce operations.
September 24, 2026
Baseten
Baseten Privacy Policy
medium
Restructured privacy policy to clarify processor vs. controller roles and expand disclosure of collected personal data categories.
Why it matters: The updated policy establishes explicit processor-controller distinctions that clarify legal responsibility for data processing under GDPR and similar frameworks. Organizations using Baseten now have clear guidance that Baseten acts as a processor of customer content under separate agreements, while Baseten controls other personal data it collects directly, which affects how organizations must structure their own privacy notices and data processing agreements.
ZipRecruiter
ZipRecruiter Privacy Policy
medium
Adds voice or audio recording collection to Identity Data category; expands AI definition to include large language models.
Why it matters: The updated policy introduces explicit disclosure of voice or audio recording collection, a sensitive personal data category that may trigger heightened regulatory scrutiny under GDPR, CCPA, and similar privacy laws. The expanded AI definition to include large language models signals a material change in how candidate data is processed and matched, which may affect both individual privacy expectations and organizational compliance obligations for employers using the platform.
September 23, 2026
Ramp
Ramp Terms of Service
medium
Restricts no-cause termination to non-subscription accounts; adds data collection limits for integrations; expands warranty disclaimers.
Why it matters: The termination restriction provides subscription customers with greater account stability by removing Ramp's unilateral right to end service on 30 days' notice. The data minimization commitment for integrations aligns Ramp's practices with privacy principles requiring collection limitation, which may reduce data exposure for customers using third-party connections. The Canadian entity designation ensures Canadian customers have a local contracting party, which may affect jurisdiction, dispute resolution, and regulatory compliance.
September 22, 2026
Delta Airlines
Delta Terms of Use
medium
Expanded acceptable-use restrictions to prohibit automated access, content scraping, and commercial use; added mandatory Georgia jurisdiction for unauthorized-use disputes.
Why it matters: The updated terms establish new operational restrictions on how Delta's website may be accessed and used. Organizations operating automated tools, scrapers, or content aggregation services now require express written permission to access the site, and any reproduction or commercial use of site content is prohibited. The mandatory Georgia jurisdiction clause also changes how disputes over unauthorized use will be resolved, potentially affecting litigation strategy and vendor contract terms for organizations with Delta in their supply chain.
September 19, 2026
Cash App
Cash App Terms of Service
medium
Adds Lightning Network feature enabling automatic Bitcoin-to-USD conversion with automatic crediting to Cash App Balance
Why it matters: The updated terms establish a new service allowing automatic Bitcoin-to-USD conversion, which introduces market-dependent pricing, irreversibility once initiated, and geographic limitations. This affects how users who receive bitcoin payments will experience currency conversion and may have implications for tax reporting, payment processing workflows, and regulatory compliance depending on the user's jurisdiction and business model.
September 18, 2026
Pika
Pika Terms of Service
high
Raises minimum age to 18, adds API access and organizational accounts, restructures payment model to include prepaid credits with 365-day expiration
Why it matters: The updated terms establish new governance structures for organizational use, introduce prepaid credit expiration and nonrefundability provisions that affect payment obligations, and raise the minimum age requirement to 18, which restricts access for users aged 13-17. The new API management provisions authorize Pika to establish rate limits, throttle usage, and revoke API keys, which affects developers' operational continuity. Organizations using Pika now bear explicit liability for all authorized user acts and omissions, which may require changes to internal compliance procedures and vendor contracts.
September 16, 2026
DeepL
DeepL Privacy Policy
medium
Expanded privacy disclosures for DeepL Voice services, including audio retention periods, speaker matching, and voice processing details.
Why it matters: The updated policy establishes clear data handling practices for Voice services, including retention periods and speaker matching mechanics. This transparency allows users and organizations to understand how audio data is processed during real-time translation and how long transcripts are retained, which is operationally significant for organizations managing sensitive conversations or compliance obligations around audio data.
Square
Square Privacy Notice
medium
Adds explicit data-sharing authorization for multi-location merchant groups; clarifies text message phone number protections
Why it matters: The updated terms establish explicit authorization for data sharing within merchant groups, which may affect how customer and employee data flows across locations. Organizations operating multiple Square merchant accounts should confirm whether this data-sharing practice aligns with their own privacy policies and customer commitments, particularly if they have represented data isolation across locations.
Eventbrite
Eventbrite Privacy Policy
medium
Expanded disclosure of phone number collection, consent record retention, and organizer text messaging practices for event attendees.
Why it matters: The updated policy establishes explicit disclosure of phone number collection and consent record retention practices, which clarifies Eventbrite's data handling obligations and may affect how organizers and Eventbrite comply with TCPA and state telemarketing laws. The policy also clarifies that Eventbrite does not sell mobile opt-in data to third parties, which may reduce downstream data sharing risks for users who opt into organizer marketing texts.
September 15, 2026
Apple Pay
Apple Media Services Terms
medium
Prohibits using Apple Pay services or content to train AI models; clarifies subscription commitment refund terms.
Why it matters: The updated terms establish a new substantive restriction on AI model training using Apple's services and content, which may affect organizations and individuals using Apple services in AI development workflows. The clarification of subscription commitment refund terms narrows refund eligibility and may affect subscriber expectations around cancellation rights. The expansion of Apple Bundle restrictions to all bundles (not just Apple One) affects how free trial stacking rules apply across Apple's subscription ecosystem.
Cohere
Cohere Enterprise Data Commitments
medium
Expanded Enterprise Data Commitments with explicit opt-out controls, 30-day retention, logging disclosures, and compliance certifications for SaaS Platform customers.
Why it matters: The updated terms establish explicit, documented procedures for how Cohere handles enterprise customer data on its SaaS Platform, including opt-out controls, automatic retention limits, and monitoring practices. This expanded disclosure allows enterprise customers to understand and control their data use, and provides compliance teams with specific procedures to reference in vendor assessments and privacy documentation.
PayPal
PayPal User Agreement
high
Expanded arbitration to cover pre-existing and post-termination disputes; added explicit class action and jury trial waivers; introduced mandatory 60-day informal resolution process
Why it matters: The updated terms establish mandatory arbitration for substantially all disputes, including those arising before or after the agreement, and eliminate access to class actions and jury trials. This change materially restricts the remedies available to users and shifts dispute resolution from courts to arbitration, which typically offers less discovery, limited appeal rights, and individual-only relief.
September 13, 2026
Meta
Llama API Terms of Service
medium
Expanded API key restrictions to prohibit resale through aggregators; introduced Coding Harness Subscription model with separate governance.
Why it matters: The updated terms establish new contractual restrictions that directly affect how developers can distribute, resell, or integrate Llama API access. The explicit prohibition on providing access through model aggregators, gateways, or proxies without written authorization narrows the permissible business models for API integration and may require organizations to renegotiate terms or restructure their technical architecture to remain compliant.
September 12, 2026
BeReal
BeReal Terms of Service
medium
Replaced three-strike suspension rule with graduated enforcement; added EU users formal appeal rights and decision transparency.
Why it matters: The updated terms establish formal procedural protections for EU users that align with Digital Services Act requirements, including mandatory transparency about enforcement decisions and internal appeal rights. For all users, the shift from a fixed three-strike rule to graduated enforcement means account actions will now depend on violation severity and context rather than a predetermined penalty schedule, potentially allowing more proportionate responses but also permitting immediate permanent termination for severe violations.
Anthropic
Anthropic Privacy Policy
medium
Restructured Korea-specific privacy disclosures to detail identity verification data collection, fraud detection practices, and overseas transfer to US vendors with opt-out mechanism.
Why it matters: The updated terms establish explicit disclosures of personal data collection and overseas transfer practices for Korean residents, which may affect how individuals understand Anthropic's data handling and whether they choose to use the service. The addition of an opt-out mechanism for overseas transfer provides a procedural right, though the stated consequence of service limitations creates a practical constraint on exercising that right.
September 11, 2026
Anyscale
Anyscale Privacy Policy
medium
Restructured privacy policy with new CCPA supplemental notice; removed sections on privacy rights, data retention, and international transfers.
Why it matters: The restructuring establishes separate supplemental notices for different jurisdictions, which may affect how users understand their rights and how organizations assess vendor compliance. The explicit disclosure that marketing activities may constitute a 'sale' or 'targeted advertising' under privacy laws clarifies Anyscale's data practices, while the removal of retention and international transfer language from the main policy relocates (rather than eliminates) those obligations to supplemental notices. Organizations using Anyscale should verify that their data processing agreements and vendor assessments account for the new policy structure.
Square
Square Terms of Service
high
Adds non-compete restriction on platform use; expands content licensing to include AI training; revises payment collection procedures.
Why it matters: The updated terms establish a contractual non-compete restriction that may limit sellers' ability to develop competing services using Square's platform, and they expand Square's rights to collect and use seller business branding for AI training and product development without per-use consent. The revised payment procedures establish a primary payment method framework with fallback authorization to collect from transaction proceeds or account balance, which affects how fees are collected and may impact cash flow management for sellers.
OpenAI
OpenAI Privacy Policy
medium
Clarified ad-related data collection for Free and Go users; removed Sora and Atlas browser references.
Why it matters: The updated policy adds explicit disclosure of behavioral data collection (ads history and interests) for Free and Go users, clarifying a data category that was previously referenced only generically. This change affects how users understand what data OpenAI collects about their ad engagement and how that data is used to improve ad targeting and measurement.
September 10, 2026
Cash App
Cash App Terms of Service
medium
Revised identity verification procedures to permit third-party services and made account conversion conditional on verification outcomes.
Why it matters: The updated terms establish that Cash App may use third-party verification services to confirm identity and that successful identity verification does not automatically grant access to all account types or services. This shifts account access from an automatic conversion model to a discretionary one where Cash App retains authority to require additional verification or information before granting access to certain account types or services. This affects onboarding timelines and service access predictability for new users.
Microsoft
Microsoft Privacy Statement (Legacy)
medium
Expands device data collection to include website and app interactions; restructures Copilot personalization to permit cross-product data usage from Bing, Edge, and MSN.
Why it matters: The updated statement materially expands what personal data Microsoft collects and authorizes it to use data from other products to personalize Copilot experiences. The removal of explicit opt-out language for AI model training and replacement with a reference to an external Transparency Note shifts transparency responsibility from the privacy statement itself to a separate document, requiring users to consult multiple sources to understand data usage practices.
September 5, 2026
DeepL
DeepL Privacy Policy
medium
Adds three new account-based storage features (Translation Memories, Translation Memory Generation, Adaptive Translation) with explicit language stating data is used only within user accounts and not
Why it matters: The updated policy establishes explicit data handling commitments for three new account-level storage features, stating that all stored content, embeddings, and derived data remain within individual user accounts and are never used for model training or shared with other customers. This clarifies the scope of data use and provides procedural transparency for organizations and users concerned about how customization features handle their language assets and translation data.
Midjourney
Midjourney Data Retention & Privacy FAQ
medium
Expanded personal data collection categories and clarified data use purposes including purchase processing, marketing, and event-related activities.
Why it matters: The updated policy materially expands the transparency of what personal data Midjourney collects and how it uses that data, moving from a more general disclosure framework to explicit enumeration of data categories and use purposes. This expanded scope affects how personal data flows through Midjourney's systems and may require corresponding updates to privacy notices, vendor contracts, and compliance frameworks maintained by organizations that rely on Midjourney services.
September 4, 2026
Ro
Ro Privacy Policy
medium
Adds contractual restrictions on advertising partners' data use and expands state protections for sensitive personal information.
Why it matters: The updated policy establishes contractual restrictions on how advertising partners can use Ro consumer data, limiting those partners to service provision and reducing the scope of permissible downstream data use. The expansion of states where Ro does not sell sensitive data for advertising and the clarification of default partner settings provide additional operational transparency around how state privacy laws affect data handling, which matters for consumers in covered states and for organizations subject to similar data protection regimes.
Suno
Suno Terms of Service
high
Added age restrictions requiring parental consent for ages 13-17; expanded account termination window; simplified arbitration language with explicit class action and jury trial waivers.
Why it matters: The updated terms establish a hard age cutoff (under 13 prohibited) and a new parental consent requirement (ages 13-17) that materially changes who may legally access Suno and under what conditions. The 30-day account closure deadline creates immediate operational friction: users who do not accept the new terms must affirmatively delete their accounts, and Suno must communicate this deadline clearly to avoid unintended acceptance through continued use. The removal of free tier language eliminates explicit protection against platform discontinuation of free access, narrowing the operational guarantees available to users. Together, these changes significantly alter the user eligibility landscape and impose time-sensitive compliance obligations on both Suno and organizations that serve minors through Suno integration.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

Page 1 of 8 Older →