Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document discloses that Apple collects metadata about Private Cloud Compute requests including approximate request and response size, feature type, and processing duration, and states that this metadata does not include request content and is not linked to an Apple Account or other Apple service data.
This analysis describes what Apple Intelligence's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision defines the scope of data Apple asserts it collects in connection with server-side AI processing, establishing the boundary between content data (not collected) and operational metadata (collected). The assertion that metadata is not identifiable or linked to an Apple Account is a material privacy representation that compliance teams in regulated industries should evaluate in the context of applicable data minimization and de-identification standards.
Interpretive note: The document does not specify a retention period for request metadata, and whether the metadata qualifies as personal data under GDPR depends on context-specific identifiability analysis.
Under this clause, Apple states it collects metadata about each Private Cloud Compute request including approximate size, feature used, and processing duration, but asserts this metadata does not include the content of requests and is not linked to an Apple Account or other Apple service data. The document does not specify the retention period for this metadata.
Cross-platform context
See how other platforms handle Request Metadata Collection and similar clauses.
Compare across platforms →Monitoring
Apple Intelligence has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When your device sends a request to Private Cloud Compute, Apple only collects limited information about the request, such as the approximate size of the request and response, which features are used for the request, and how long the request takes to complete. This data does not include any information about the content of your request or the returned result. It is not identifiable or linked to your Apple Account or other data Apple may have from your use of other Apple services.Excerpt from Apple Intelligence's Privacy Report
(1) REGULATORY LANDSCAPE: This provision engages GDPR data minimization principles and CCPA disclosure requirements for categories of personal information collected. The assertion that metadata is not identifiable or linked to an Apple Account relates to GDPR anonymization standards; whether operational request metadata constitutes personal data under GDPR depends on whether it can be combined with other data to identify an individual, which is a context-specific analysis. (2) GOVERNANCE EXPOSURE: Low. The metadata categories described are operationally standard for server infrastructure monitoring, and the document's assertion of non-identifiability limits the primary privacy exposure. However, compliance teams in regulated sectors should confirm that the metadata described does not inadvertently capture information subject to sector-specific obligations. (3) JURISDICTION FLAGS: EU and EEA organizations should evaluate whether the metadata described qualifies as personal data under GDPR given the broad definition of identifiability under that framework. California residents may consider whether this metadata falls within CCPA's definition of personal information depending on how it is retained and combined with other data. (4) CONTRACT AND VENDOR IMPLICATIONS: The absence of a stated retention period for this metadata is a due diligence consideration for organizations with data retention governance policies. Procurement teams should assess whether Apple's enterprise documentation specifies retention limits for this category of operational data. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should review data mapping documentation to determine whether Apple Intelligence request metadata requires inclusion in records of processing activities under GDPR Article 30, and should assess whether the non-identifiability assertion is sufficient to exclude this data from CCPA's personal information definition under their specific operational context.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision defines the scope of data Apple asserts it collects in connection with server-side AI processing, establishing the boundary between content data (not collected) and operational metadata (collected). The assertion that metadata is not identifiable or linked to an Apple Account is a material privacy representation that compliance teams in regulated industries should evaluate in the context of applicable …
Under this clause, Apple states it collects metadata about each Private Cloud Compute request including approximate size, feature used, and processing duration, but asserts this metadata does not include the content of requests and is not linked to an Apple Account or other Apple service data. The document does not specify the retention period for this metadata.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Apple Intelligence.