Provision record
Midjourney · Midjourney Privacy Policy · View original document ↗

Prompt and User-Generated Content Collection

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Midjourney changes these terms. Follow Midjourney →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Midjourney Monitor emails you the same day this changes. The archive stays free.
Follow Midjourney →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy categorizes user-submitted prompts, including text, images, spoken-input summaries, photos, videos, documents, and messages, as personally identifiable information subject to collection and the policy's described uses.

This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that prompts and all user-submitted content are treated as personal data, meaning they are subject to the policy's data sharing, retention, and ML training data collection disclosures. The inclusion of spoken-input summaries indicates that voice-derived content processed into text is also within scope.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement establishes that all content submitted to Midjourney's services, including text prompts, images, videos, documents, spoken-input summaries, and messages, is collected as personally identifiable information and is subject to the policy's data use, sharing, and retention terms.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit www.midjourney.com/account and follow the instructions at the bottom of the page to request deletion of your personal data, including submitted content.

Cross-platform context

See how other platforms handle Prompt and User-Generated Content Collection and similar clauses.

Compare across platforms →

Monitoring

Midjourney has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Midjourney → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Personally identifiable information may include, but is not limited to: Your user name for the Services Prompts that you provide (including text, images, and those generated from spoken input and summarized into text), and other content such as photos, videos, documents, and messages that you input into the Services

Excerpt from Midjourney's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: The collection of prompts and user-generated content as personal data implicates GDPR data minimization and purpose limitation principles for EEA and UK users, enforced by relevant supervisory authorities. Under the CCPA, this content falls within the identifiers and sensory data categories disclosed in the policy's data table. The FTC Act is relevant at the federal level regarding adequacy of disclosure. 2. GOVERNANCE EXPOSURE: Medium. The broad scope of content classified as personally identifiable information, including all prompt types and spoken-input summaries, means that any content submitted to the platform is subject to data sharing and ML training disclosures. Organizations using Midjourney for business purposes should assess whether submitted content contains confidential or sensitive information. 3. JURISDICTION FLAGS: EEA and UK users have the strongest protections regarding purpose limitation for personal data collected in this category. California users have CCPA access and deletion rights that extend to this content. Organizations in jurisdictions with sector-specific privacy requirements (healthcare, financial services, legal) should evaluate whether sensitive content submitted as prompts is adequately protected. 4. CONTRACT AND VENDOR IMPLICATIONS: Business users and enterprise accounts should assess the risk of submitting proprietary, confidential, or regulated content as prompts given that this content is classified as personal data subject to sharing with service providers and analytics partners. Vendor agreements should address the treatment of prompt content and whether it is excluded from ML training data. 5. COMPLIANCE CONSIDERATIONS: Compliance teams deploying Midjourney in enterprise contexts should implement policies restricting the submission of personal, confidential, or regulated information as prompts. Data mapping should include prompt content as a personal data category with Midjourney identified as a data controller or processor. For GDPR-governed deployments, a data protection impact assessment may be warranted given the breadth of content categories classified as personal data.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data collection and disclosure practices, including the scope of personal data collected from consumers through AI platform services.
    File a complaint →

Provision details

Document information
Document
Midjourney Privacy Policy
Entity
Midjourney
Document last updated
May 5, 2026
Tracking information
First tracked
May 12, 2026
Last verified
July 9, 2026
Record ID
CA-P-013924
Document ID
CA-D-00094
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
31a78fe46275c58bc78432dcb6f1164a07d9bb61c0ea0f36d50b715fa5c4ffc7
Analysis generated
May 12, 2026 04:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Midjourney
Document: Midjourney Privacy Policy
Record ID: CA-P-013924
Captured: 2026-05-12 04:55:54 UTC
SHA-256: 31a78fe46275c58b…
URL: https://conductatlas.com/platform/midjourney/midjourney-privacy-policy/provision/CA-P-013924/prompt-and-user-generated-content-collection/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Midjourney's Prompt and User-Generated Content Collection clause do?

This provision establishes that prompts and all user-submitted content are treated as personal data, meaning they are subject to the policy's data sharing, retention, and ML training data collection disclosures. The inclusion of spoken-input summaries indicates that voice-derived content processed into text is also within scope.

How does this clause affect you?

The agreement establishes that all content submitted to Midjourney's services, including text prompts, images, videos, documents, spoken-input summaries, and messages, is collected as personally identifiable information and is subject to the policy's data use, sharing, and retention terms.

Is ConductAtlas affiliated with Midjourney?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.