The policy states that Medium retains personal information for as long as necessary to provide services and for legal, dispute, and enforcement purposes, without specifying defined retention periods for individual data categories.
This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The absence of defined retention periods for specific data categories may present a compliance consideration under GDPR's storage limitation principle, which requires that personal data be kept no longer than necessary for the specified processing purpose.
Interpretive note: The policy does not specify retention periods by data category, creating ambiguity about the practical duration of retention for specific data types such as reading history or payment information.
The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.
View change record →Provision now specifies a 14-day deletion timeline for closed account data and distinguishes between account data and other personal data retention, providing more granular detail.
View full change record →Replaced vague 'legitimate business purposes' with specific enumerated purposes (legal compliance, dispute resolution, agreement enforcement), providing greater clarity.
View full change record →The agreement establishes an open-ended retention standard tied to service provision and legal purposes, meaning personal data including reading history, identifiers, and payment information may be retained for indeterminate periods absent a specific user deletion request.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"We retain personal information for as long as necessary to provide you with our Services, and for other essential purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements.Excerpt from Medium's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The absence of defined retention periods for specific data categories may present a compliance consideration under GDPR's storage limitation principle, which requires that personal data be kept no longer than necessary for the specified processing purpose.
The agreement establishes an open-ended retention standard tied to service provision and legal purposes, meaning personal data including reading history, identifiers, and payment information may be retained for indeterminate periods absent a specific user deletion request.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.