Poe · Poe Privacy Policy · View original document ↗

Message Content Shared with Third-Party AI Providers

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Poe Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When you chat with a bot on Poe, the text of your messages may be sent to the company that built the underlying AI model powering that bot, and that company has its own separate privacy rules.

This analysis describes what Poe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision means your conversation content is not solely governed by Poe's privacy policy; it may also be processed by external AI companies whose data practices and retention policies differ and are not fully disclosed within Poe's own policy.

Interpretive note: The exact scope of data transmitted to third-party AI providers and whether those providers act as processors or independent controllers is not fully specified in the accessible document text.

Consumer impact (what this means for users)

Users' message content, which may include personal or sensitive information shared in conversation, can be transmitted to third-party AI model operators whose privacy policies and data retention practices are independent of Poe's commitments.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@poe.com to request deletion of your personal data held by Poe. Note that Poe may not be able to fulfil deletion requests for data already transmitted to and held by third-party AI model operators.

Cross-platform context

See how other platforms handle Message Content Shared with Third-Party AI Providers and similar clauses.

Compare across platforms →

Monitoring

Poe has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
When you interact with a bot on Poe, the messages you send to that bot may be transmitted to the third-party operator of that bot's underlying AI model. These third-party operators have their own privacy policies and terms of service that govern how they handle your information.

— Excerpt from Poe's Poe Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: This provision implicates GDPR Articles 26 (joint controllers) and 28 (processor contracts), as well as CCPA requirements regarding disclosure of third parties to whom personal information is disclosed. The FTC Act's prohibition on unfair or deceptive practices is also relevant. The legal characterization of the third-party AI provider as a processor or independent controller is not specified, creating regulatory ambiguity. If third-party providers act as independent controllers, separate lawful bases under GDPR Article 6 may be required for each transfer. 2) GOVERNANCE EXPOSURE: High. The transmission of user-generated message content, which may include personal, sensitive, or confidential information, to multiple external entities whose individual privacy practices are not enumerated creates material compliance exposure. The policy does not identify which AI providers receive data, making user consent and data mapping difficult to operationalize. 3) JURISDICTION FLAGS: EU and UK users face heightened exposure under GDPR and UK GDPR, particularly if third-party AI providers are located outside the EEA or UK without adequate transfer mechanisms. California users may have CCPA rights to know the specific third parties receiving their data. Jurisdictions with sector-specific protections (healthcare, legal) could be implicated if users share such information in conversations. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should audit whether data processing agreements or joint controller agreements exist with each third-party AI model provider. The policy's reference to each provider's own terms suggests these may be independent controller relationships, which would require users to separately consent under GDPR and may limit Poe's ability to fulfill data subject access or erasure requests for data held by those providers. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should develop a registry of all third-party AI model providers receiving user data, assess the legal basis for each transfer, and evaluate whether privacy notices adequately inform users. Data subject request workflows should account for data held by third-party providers. GDPR data protection impact assessments may be warranted given the volume and sensitivity of conversational data transmitted.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data practices affecting consumers, including inadequate disclosure of data sharing with third parties.
    File a complaint →

Provision details

Document information
Document
Poe Privacy Policy
Entity
Poe
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011827
Document ID
CA-D-00797
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
69208c7821fb6588265b1c668a07ba65984adf3878bf765983f54ca46eb4acf1
Analysis generated
May 12, 2026 15:27 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Poe
Document: Poe Privacy Policy
Record ID: CA-P-011827
Captured: 2026-05-12 15:27:12 UTC
SHA-256: 69208c7821fb6588…
URL: https://conductatlas.com/platform/poe/poe-privacy-policy/message-content-shared-with-third-party-ai-providers/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Poe's Message Content Shared with Third-Party AI Providers clause do?

This provision means your conversation content is not solely governed by Poe's privacy policy; it may also be processed by external AI companies whose data practices and retention policies differ and are not fully disclosed within Poe's own policy.

How does this clause affect you?

Users' message content, which may include personal or sensitive information shared in conversation, can be transmitted to third-party AI model operators whose privacy policies and data retention practices are independent of Poe's commitments.

Is ConductAtlas affiliated with Poe?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Poe.