Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy's CCPA data category table states that Midjourney both collects and discloses inferences, defined as conclusions used to create profiles reflecting an individual's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitude.
This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that inferences derived from user activity are both collected and disclosed to third parties. The policy does not separately identify which third-party categories receive inferences, under what constraints, or on what legal basis inferences are shared, which may require evaluation under GDPR and CCPA data minimization and disclosure requirements.
Interpretive note: The policy confirms inference collection and disclosure in the CCPA table but does not describe which third-party categories receive inferences or the legal basis for inference-specific sharing, creating ambiguity about the scope of this disclosure.
Under these terms, conclusions about a user's preferences, psychological trends, predispositions, and aptitude may be collected and disclosed to third parties. The policy does not specify which third-party categories receive inferences or describe limitations on how inferences may be used by recipients.
Cross-platform context
See how other platforms handle Inference Collection and Disclosure and similar clauses.
Compare across platforms →Monitoring
Midjourney has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Inferences Conclusions that could be used to create a profile reflecting an individual's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, aptitude. YES. YESExcerpt from Midjourney's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates the CCPA's disclosure requirements for inferences as a defined personal information category, enforced by the California Attorney General and California Privacy Protection Agency. Under GDPR, profiling and automated decision-making provisions may engage depending on how inferences are derived and used. The FTC Act is relevant at the federal level regarding disclosure adequacy. 2. GOVERNANCE EXPOSURE: Medium. The policy discloses inference collection and disclosure in the CCPA table but does not separately describe the inference generation process, the third-party categories receiving inferences, or applicable retention limits. This gap may present exposure under CCPA transparency requirements and GDPR profiling provisions. 3. JURISDICTION FLAGS: California residents have the most direct statutory rights regarding inferences under the CCPA, including the right to access the specific inferences collected. EEA and UK users may have rights under GDPR provisions on profiling, depending on whether inferences are used in automated decision-making. Illinois users should note that the policy confirms biometric information is not collected, limiting BIPA exposure. 4. CONTRACT AND VENDOR IMPLICATIONS: Business users should assess whether inferences derived from their employees' or customers' prompts and activity on Midjourney are shared with third parties in ways that may conflict with their own privacy obligations. Vendor agreements with Midjourney should address inference generation and sharing as a processing activity. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should request from Midjourney a more granular description of the third-party categories receiving inferences and the legal basis for disclosure. Data subject access request processes should be evaluated to confirm that inferences can be identified and provided in response to CCPA access requests. For GDPR-governed deployments, a review of whether inference generation constitutes profiling requiring a lawful basis under applicable provisions is warranted.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that inferences derived from user activity are both collected and disclosed to third parties. The policy does not separately identify which third-party categories receive inferences, under what constraints, or on what legal basis inferences are shared, which may require evaluation under GDPR and CCPA data minimization and disclosure requirements.
Under these terms, conclusions about a user's preferences, psychological trends, predispositions, and aptitude may be collected and disclosed to third parties. The policy does not specify which third-party categories receive inferences or describe limitations on how inferences may be used by recipients.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.