When you upload data to Replicate to train AI models, that data is collected and may contain sensitive personal information about individuals.
This analysis describes what Replicate's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Training data uploaded to build AI models could contain highly sensitive information about real people, and the policy does not specify special handling, access controls, or retention limits for this category of data.
Users who upload training datasets to Replicate should be aware that this data, including any sensitive personal information it may contain, is collected under this policy without specific protections or retention boundaries articulated for that data type.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
To stop us collecting your location information, you can update your device settings, stop using the Service, or uninstall our mobile apps.
"Any training data you upload to our Services to train models (collectively, "Training Data"). Note, Training Data may include any type of information, some of which could be deemed 'sensitive' under various privacy laws.Excerpt from Replicate's Privacy Policy
REGULATORY LANDSCAPE: The collection of training data that may include sensitive personal information implicates CCPA/CPRA sensitive personal information provisions, GDPR special categories of data under Article 9, and potentially HIPAA if health-related data is included.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Training data uploaded to build AI models could contain highly sensitive information about real people, and the policy does not specify special handling, access controls, or retention limits for this category of data.
Users who upload training datasets to Replicate should be aware that this data, including any sensitive personal information it may contain, is collected under this policy without specific protections or retention boundaries articulated for that data type.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Replicate.