“If you intend to upload personal information about your own end users to the Cohere SaaS Platform, you are responsible for complying with applicable privacy laws.”
This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause shifts legal compliance responsibility for end-user personal data to the customer, meaning Cohere does not assume that obligation for data customers choose to upload.
The updated terms establish specific data handling practices for Cohere's SaaS Platform: customer prompts and generations are automatically deleted after 30 days unless flagged for potential policy violations or required by law or contract; Cohere logs and monitors usage for compliance and security; and safety teams may review flagged content to enforce policies. The terms state that data intended for training purposes may be retained separately according to your agreement, and that you can opt out of training data use by toggling 'Data Controls' off in your dashboard settings. You can verify and adjust these settings at any time under Settings > Data Controls in the Cohere Platform.
View change record →Customers who upload end-user personal information to the platform bear the legal compliance burden for that data under applicable privacy laws — Cohere does not absorb that responsibility.
How other platforms handle this
We follow the Payment Card Industry Data Security Standard (PCI DSS) when handling credit card data.
if you do not allow us to collect personal information from you, we may not be able to deliver certain experiences, products, and services to you, and some of our services may not be able to take account of your interests and preferences.
GDPR...requires organizations to maintain appropriate security of personal data.
"If you intend to upload personal information about your own end users to the Cohere SaaS Platform, you are responsible for complying with applicable privacy laws.Excerpt from Cohere's Enterprise Data Commitments
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause shifts legal compliance responsibility for end-user personal data to the customer, meaning Cohere does not assume that obligation for data customers choose to upload.
Customers who upload end-user personal information to the platform bear the legal compliance burden for that data under applicable privacy laws — Cohere does not absorb that responsibility.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.