Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data collected during the process of training Midjourney's machine learning algorithms is within the scope of this privacy policy, in addition to data collected through the platform services and websites.
This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that machine learning training data collection is an explicitly disclosed data processing activity governed by this policy. The policy does not separately articulate purpose limitations, retention terms, or opt-out mechanisms specific to the use of user data in ML training, which may require evaluation under applicable data minimization and purpose limitation principles in GDPR-governed jurisdictions.
Interpretive note: The policy discloses ML training data collection within its scope but does not separately specify the lawful basis, retention terms, or opt-out mechanism for this processing activity, creating interpretive ambiguity about whether existing general bases are sufficient under applicable law.
The agreement establishes that data collected during Midjourney's machine learning algorithm training is subject to this policy, indicating that user-submitted content including prompts and images may be within scope of this training data category. The policy does not provide a separate opt-out mechanism specifically for the use of personal data in machine learning training.
Cross-platform context
See how other platforms handle Machine Learning Training Data Collection and similar clauses.
Compare across platforms →Monitoring
Midjourney has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Applicability: This Policy applies to personal data that Midjourney collects, uses, and discloses and which may include: (i) data collected through the Services, (ii) data collected through the process of training Midjourney machine learning algorithms, (iii) data collected through Midjourney websites, and (iv) data collected from third party sources.Excerpt from Midjourney's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Articles on purpose limitation, data minimization, and lawful basis for processing, enforced by EU supervisory authorities and the UK Information Commissioner's Office. The disclosure that ML training data collection is within policy scope may require evaluation against whether a valid lawful basis (consent, legitimate interests, or contract) has been separately identified and documented for this specific processing purpose. The FTC Act is also relevant at the federal level in the United States regarding unfair or deceptive data practices. 2. GOVERNANCE EXPOSURE: Medium. The provision discloses ML training data collection but does not separately enumerate the legal basis, retention period, or opt-out mechanism for this specific use. For GDPR-governed users, this gap may present a compliance exposure depending on whether the policy's general legitimate interests or consent bases are considered adequate for ML training use of personal data by applicable supervisory authorities. 3. JURISDICTION FLAGS: EEA, UK, and Switzerland users face heightened exposure due to GDPR and UK GDPR purpose limitation and lawful basis requirements. California users may have rights regarding inferences generated from ML training under the CCPA. The policy's treatment of ML training data may also engage emerging AI-specific regulatory frameworks in the EU. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations submitting employee or business-account data as prompts should assess whether this policy's ML training data disclosure is compatible with their own privacy obligations to employees or customers. Vendor assessments should include whether Midjourney's ML training data practices align with applicable data processing agreement requirements. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether a separate data processing agreement or addendum is required for business use of Midjourney that addresses ML training data specifically. For GDPR-governed deployments, a legitimate interests assessment or explicit consent mechanism for ML training data may be warranted. Data mapping should include ML training as a processing activity with Midjourney identified as a processor or controller as applicable.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that machine learning training data collection is an explicitly disclosed data processing activity governed by this policy. The policy does not separately articulate purpose limitations, retention terms, or opt-out mechanisms specific to the use of user data in ML training, which may require evaluation under applicable data minimization and purpose limitation principles in GDPR-governed jurisdictions.
The agreement establishes that data collected during Midjourney's machine learning algorithm training is subject to this policy, indicating that user-submitted content including prompts and images may be within scope of this training data category. The policy does not provide a separate opt-out mechanism specifically for the use of personal data in machine learning training.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.