10 Total
0 High severity
8 Medium severity
2 Low severity
Summary

Medium's privacy policy establishes the categories of personal information collected from users, including email address, reading and writing history, payment details, device identifiers, and location data, along with the purposes for collection and processing. The policy authorizes Medium to share collected data with third-party advertising partners, analytics providers, and potential acquirers, and permits international data transfers including to the United States. The policy establishes differential data rights for users in the EU and California, who may request access to, correction of, deletion of, or restriction on processing of their personal data by contacting Medium at privacy@medium.com.

Technical / Legal Breakdown

This document is Medium's Privacy Policy (effective March 24, 2022), governing the collection, use, and sharing of personal data by A Medium Corporation across its publishing platform, and operates on a consent and legitimate interest basis depending on jurisdiction. The policy states that Medium collects account registration data, usage data, payment information, location data, and third-party linked account data, and the terms authorize sharing this information with service providers, business partners, affiliated entities, and in connection with mergers or acquisitions. Notably, the policy asserts broad data retention and third-party sharing rights, including the use of third-party analytics and advertising partners, and permits transfer of personal data to the United States and other jurisdictions that may lack equivalent data protection laws, which is a standard but practically significant disclosure for international users. The policy engages GDPR for EU/EEA users (including specific rights to access, erasure, and objection), CCPA for California residents (including rights to know, delete, and opt out of certain data sharing), and COPPA in the context of age restrictions; enforcement oversight would fall primarily under the FTC at the federal level and applicable state attorneys general. Material compliance considerations include the adequacy of consent mechanisms for EU transfers, the sufficiency of the CCPA opt-out infrastructure, and whether third-party advertising and analytics integrations are disclosed with sufficient specificity to satisfy applicable transparency requirements.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

3 important changes detected

3 versions captured · Last updated: May 2026

What changed Medium updated its Privacy Policy on May 18, 2026 to add detailed disclosure about its address book contact feature. The new language explains that when users opt in to this feature, Medium converts contact names and email addresses into encrypted, non-reversible identifiers to match against its member database. Medium does not store names or emails in plain text, deletes identifiers for non-members immediately, and deletes all encrypted identifiers within 30 days. The policy also reorganized its personal information collection disclosure, though the categories themselves (identifiers, commercial information, internet activity, inferences) remain unchanged.
Why this matters The updated policy adds transparency about Medium's address book feature by explaining the technical process: contact names and emails are converted into encrypted identifiers, matched against Medium's member database, and then deleted. For contacts who are not Medium members, these encrypted identifiers are deleted immediately; all encrypted identifiers are deleted within 30 days regardless. The policy states Medium relies on legitimate interests to offer this feature, specifically its interest in helping users connect with people they know. You can review the specific disclosure in the 'Helping You Connect With People You Know' section of the updated policy.
View full change record →
What changed Medium's privacy policy was updated on April 26, 2026, but the changes appear to be primarily formatting and structural rather than substantive. The document added a sentence reiterating the categories of personal information Medium collects (identifiers, commercial information, internet activity, and inferences) and made minor edits to navigation text. The effective date of the policy remains March 24, 2022, and no new data collection practices or rights changes were introduced.
Why this matters This change appears to be a formatting and structural update with minimal consumer impact. Medium reaffirmed existing categories of personal information it collects (identifiers, commercial information, internet activity, and inferences) but did not introduce new data collection practices or modify consumer rights. The policy's effective date remains unchanged at March 24, 2022.
View full change record →

April 22, 2026 low

Medium removed a call-to-action encouraging newsletter sign-up and replaced it with a disclosure statement listing the categories of personal information collected in the preceding 12 months, identifiers, commercial information, internet …

View change record →
Medium — 8 provisions
Low — 2 provisions

Monitoring

Medium has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Reading History and Behavioral Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 18, 2026 00:26 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000246
Version ID CA-V-002703
SHA-256 311b83ba6da0980f518b95cc57466bfc704e527da40a9471e2fde7c772eae6ef
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans