Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
California residents may submit verifiable requests for Midjourney to disclose categories and specific pieces of personal information collected, sources, business purposes, and third-party sharing within the preceding 12 months, up to two times per year, and may also request deletion of their personal data.
This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the CCPA access, portability, and deletion request process, including a 45-day response window with a possible 90-day extension, a two-request-per-year limit for access and portability requests, and a verification requirement. The policy states that fees may be charged for excessive, repetitive, or manifestly unfounded requests.
Under these terms, California residents can request access to or deletion of their personal data by submitting a verifiable consumer request at www.midjourney.com/account. The agreement establishes a 45-day response period, extendable to 90 days with written notice, and limits access and portability requests to two per 12-month period.
Cross-platform context
See how other platforms handle CCPA Data Access, Deletion, and Portability Rights and similar clauses.
Compare across platforms →Monitoring
Midjourney has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Access to Specific Information and Data Portability Rights You have the right to request that Midjourney disclose certain information to you about our collection and use of your Personal Information over the past twelve (12) months. Once Midjourney receives and confirms your verifiable information access request, Midjourney must disclose to you: (i) the categories of Personal Information we collected about you; (ii) the categories of sources for the Personal Information we collected about you; (iii) our business or commercial purpose for collecting or, if applicable, selling that Personal Information; (iv) the categories of third parties with whom we share that Personal Information; (v) the specific data points or pieces of Personal Information we collected about you.Excerpt from Midjourney's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly implements CCPA requirements enforced by the California Privacy Protection Agency and California Attorney General. The policy's description of verifiable consumer request procedures, response timelines, and fee provisions tracks the CCPA statutory framework. Compliance with CCPA request handling timelines and verification procedures is subject to regulatory scrutiny. 2. GOVERNANCE EXPOSURE: Low. The provision describes a CCPA-compliant process for handling consumer requests, including required disclosures, response timelines, and the deletion request workflow. The fee provision for excessive requests is consistent with CCPA statutory language. 3. JURISDICTION FLAGS: Applicable to California residents and individuals whose personal information was collected in California. Non-California users may have analogous rights under other state privacy laws (Virginia, Colorado, Connecticut, Texas) but the policy does not separately enumerate those frameworks. 4. CONTRACT AND VENDOR IMPLICATIONS: Business accounts submitting requests on behalf of employees or customers should note the requirement for California Secretary of State registration for authorized representatives. The policy permits minor children's requests to be submitted by a parent or guardian. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that Midjourney's verification process for consumer requests does not create unnecessary barriers to rights exercise as assessed under CCPA guidance. The 12-month lookback limitation on access request disclosures should be documented in data subject rights response procedures. Fee notification procedures for excessive requests should be reviewed against CCPA requirements.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes the CCPA access, portability, and deletion request process, including a 45-day response window with a possible 90-day extension, a two-request-per-year limit for access and portability requests, and a verification requirement. The policy states that fees may be charged for excessive, repetitive, or manifestly unfounded requests.
Under these terms, California residents can request access to or deletion of their personal data by submitting a verifiable consumer request at www.midjourney.com/account. The agreement establishes a 45-day response period, extendable to 90 days with written notice, and limits access and portability requests to two per 12-month period.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.