8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

This is Midjourney's privacy policy, which explains how the company collects and uses your personal data when you use its AI image generation service. Notably, the policy states that images you create are public by default unless you pay for a plan with Stealth Mode, and Midjourney may use the prompts and content you submit to train its AI models. If you are based in the EU, UK, or California, the policy describes specific rights you can exercise, such as requesting deletion of your personal data by contacting privacy@midjourney.com.

Technical / Legal Breakdown

This document is Midjourney's privacy policy (last updated June 2, 2025), governing the collection, use, and disclosure of personal information by Midjourney, Inc. in connection with its AI image generation services, operating under a consent and legitimate interests framework. The policy states that Midjourney collects identifiers (name, email, username), payment information, device and browser data, IP addresses, usage and interaction data, content users submit (prompts, uploaded images), and inferred preferences; the terms authorize sharing this data with service providers, business partners, payment processors, and third parties in the context of business transfers. A notable provision states that Midjourney may use submitted content and prompts to train and improve its AI models, and the policy discloses that images generated on the platform are generally public by default unless a user subscribes to a plan that includes a Stealth Mode feature, creating an operationally significant disclosure distinction relative to users who assume default privacy for their generated content. The policy engages GDPR and UK GDPR for EU and UK users (citing rights to access, correction, erasure, portability, and objection), CCPA/CPRA for California residents (disclosing categories of personal information and stating Midjourney does not sell personal information in the traditional sense but may share for cross-context behavioral advertising), and COPPA with respect to a stated minimum age of 13. Compliance teams should note that the policy's AI training use of user-submitted content, the default public image setting, and the scope of third-party data sharing each warrant careful evaluation under GDPR lawful basis requirements, CCPA opt-out obligations for sharing, and applicable AI-specific regulatory frameworks.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 6 provisions
Low — 1 provision

Monitoring

Midjourney has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle AI Model Training Use of User Content and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 12, 2026 06:29 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000828
Version ID CA-V-002517
SHA-256 31a78fe46275c58bc78432dcb6f1164a07d9bb61c0ea0f36d50b715fa5c4ffc7
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans