Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Ideogram's website is not designed to respond to browser Do Not Track signals or opt-out preference signals, and that the company does not process information in a manner that would legally require recognition of such signals.
This analysis describes what Ideogram's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that browser-level privacy signals, including Do Not Track and Global Privacy Control (GPC) signals, are not honored by the platform. The assertion that no legal obligation to recognize opt-out preference signals applies may require evaluation under California's CCPA, which mandates recognition of opt-out preference signals for businesses that sell or share personal information.
Interpretive note: The legal sufficiency of Ideogram's non-recognition of opt-out preference signals depends on whether its data sharing practices are accurately characterized as not constituting sale or sharing under CCPA; this determination may be subject to regulatory or judicial interpretation.
The updated policy now provides explicit disclosure of which categories of personal information are collected and which parties receive each category. Previously, the policy required readers to consult other sections to identify this information. The updated table format discloses that identifiers such as name and email address, visual information including uploaded images, and geolocation data may be shared with other users, vendors, service providers, login integration partners, social media widgets, and affiliates. This change provides clearer visibility into data sharing practices without altering what data is collected or shared, but rather how that information is disclosed.
View change record →The updated policy no longer provides a single consolidated view of which specific categories of recipients receive which types of personal data. Previously, users could see in one table that identifiers, commercial information, geolocation data, images, account credentials, and precise location were shared with specific recipient categories such as vendors, service providers, other users, login partners, social media widgets, and tracking technology providers. The revised policy instead directs users to review other sections of the document to find this information. The specificity and accessibility of this disclosure has been reduced, though the underlying data-sharing practices may remain unchanged.
View change record →Under this provision, browser-based Do Not Track and opt-out preference signals transmitted by users will not be recognized or acted upon by Ideogram's platform. The policy asserts that no legal obligation to recognize such signals applies, though this assertion may require evaluation under applicable state privacy law.
Cross-platform context
See how other platforms handle Do Not Track Signal Non-Response and similar clauses.
Compare across platforms →Monitoring
Ideogram has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Your browser settings may also allow you to transmit a 'Do Not Track', 'opt-out preference' signal or other mechanism for exercising your choices regarding the collection of your information when you visit various websites. Like many websites, our website is not designed to respond to such signals and we do not use or disclose your information in any way that would legally require us to recognize opt-out preference signals.Excerpt from Ideogram's Privacy Policy
1) REGULATORY LANDSCAPE: California's CCPA, as amended by CPRA, requires businesses that sell or share personal information to recognize opt-out preference signals including the Global Privacy Control (GPC). Ideogram's policy states it does not sell or share personal information as defined under CCPA, which is the basis on which it asserts no legal obligation to recognize these signals. The California Privacy Protection Agency (CPPA) and California Attorney General are the relevant enforcement authorities. This provision may require re-evaluation if Ideogram's data practices are ever determined to constitute sharing under the CCPA. 2) GOVERNANCE EXPOSURE: Medium. The non-recognition of opt-out preference signals is permissible if the business does not sell or share personal information as defined under CCPA. However, if the characterization of Ideogram's data sharing practices were to change or be challenged, this provision would create heightened exposure to CPPA enforcement. Other U.S. state privacy laws, including Colorado, Connecticut, and Virginia, may also impose opt-out signal recognition requirements. 3) JURISDICTION FLAGS: California users face the most direct exposure given the CPPA's active enforcement posture on GPC signal recognition. Colorado and other states with similar opt-out signal requirements should also be evaluated. 4) CONTRACT AND VENDOR IMPLICATIONS: This provision does not directly create vendor or B2B contract implications, but institutional customers operating in California should verify that their own privacy compliance posture accounts for Ideogram's non-recognition of GPC signals in any consumer-facing deployments. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that Ideogram's characterization of its data practices as not constituting sale or sharing under CCPA is accurate and documented, and should monitor regulatory developments regarding opt-out signal recognition obligations in jurisdictions where Ideogram operates.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that browser-level privacy signals, including Do Not Track and Global Privacy Control (GPC) signals, are not honored by the platform. The assertion that no legal obligation to recognize opt-out preference signals applies may require evaluation under California's CCPA, which mandates recognition of opt-out preference signals for businesses that sell or share personal information.
Under this provision, browser-based Do Not Track and opt-out preference signals transmitted by users will not be recognized or acted upon by Ideogram's platform. The policy asserts that no legal obligation to recognize such signals applies, though this assertion may require evaluation under applicable state privacy law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ideogram.