The policy states that hashed email addresses may be shared with advertising platform partners for programmatic advertising and paid acquisition campaigns, with legitimate business interest asserted as the legal basis and consent obtained where required.
This analysis describes what Poe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes disclosure of a derived personal identifier (hashed email) to third-party advertising platforms, a practice that may engage GDPR consent requirements under ePrivacy Directive frameworks and CCPA opt-out of sharing obligations depending on jurisdiction and the specific processing purpose.
Interpretive note: The policy does not specify which jurisdictions or circumstances trigger the consent requirement for advertising processing, leaving the scope of the consent obligation ambiguous.
Under this provision, Poe may share a hashed version of a user's email address with third-party advertising platforms for programmatic ad targeting and acquisition campaigns. The policy states that consent will be obtained where legally required but does not specify the jurisdictions or mechanisms in which consent is sought.
Cross-platform context
See how other platforms handle Hashed Email Sharing with Advertising Partners and similar clauses.
Compare across platforms →"We may share your hashed email with our ad platform partners for our advertising activities, such as for programmatic ads and paid acquisition campaigns. It is in our legitimate business interest to advertise our platform. Where necessary, we will obtain your consent before engaging in this processing.Excerpt from Poe's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision engages GDPR lawful basis requirements, particularly the tension between legitimate interests and consent as bases for advertising-related processing under the ePrivacy Directive; the relevant enforcement authorities are EU member state …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes disclosure of a derived personal identifier (hashed email) to third-party advertising platforms, a practice that may engage GDPR consent requirements under ePrivacy Directive frameworks and CCPA opt-out of sharing obligations depending on jurisdiction and the specific processing purpose.
Under this provision, Poe may share a hashed version of a user's email address with third-party advertising platforms for programmatic ad targeting and acquisition campaigns. The policy states that consent will be obtained where legally required but does not specify the jurisdictions or mechanisms in which consent is sought.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Poe.