Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy asks users not to submit sensitive personal information such as government identification numbers, health information, or financial information through the Service, while also acknowledging that sensitive personal information may be incidentally collected and stating that users may request limitation of its processing to specified purposes.
This analysis describes what RunPod's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a contractual restriction on user submission of sensitive data, while simultaneously acknowledging the possibility of incidental collection and providing a statutory limitation right under applicable state privacy laws. The coexistence of a user-facing prohibition and a processing limitation right indicates that the policy contemplates the possibility of sensitive data entering the system despite the restriction.
Interpretive note: The operational effectiveness of the contractual prohibition on sensitive data submission depends on whether technical controls are in place; the policy does not disclose such controls.
Under this clause, users agree not to submit government identification numbers, health information, or financial information through the Service. If sensitive personal information is nonetheless collected, users covered by applicable state privacy laws may submit requests to limit its processing to specified purposes by emailing DSAR@runpod.io.
Cross-platform context
See how other platforms handle Sensitive Personal Information Processing Limitation and similar clauses.
Compare across platforms →Monitoring
RunPod has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"You agree that no sensitive personal information shall be provided to us or via the Services as part of your usage of the Services, such as government identification numbers, medical or health information, or financial information. Limit processing of Sensitive Personal Information. You can ask us to limit the processing of any Sensitive Personal Information we collect as necessary for our (1) Service delivery and operations, (2) Compliance and protection, (3) research and development, or (4) Service improvement and analytics purposes.Excerpt from RunPod's Privacy Policy
REGULATORY LANDSCAPE: This provision implicates CCPA as amended by CPRA, which defines and grants rights with respect to sensitive personal information, including the right to limit processing. GDPR also addresses special categories of personal data with heightened protections. The contractual prohibition on user submission of sensitive data does not eliminate RunPod's legal obligations if such data is incidentally received. GOVERNANCE EXPOSURE: Medium. The contractual prohibition on sensitive data submission attempts to shift responsibility to users but does not eliminate RunPod's obligations as a data controller or processor if sensitive information is incidentally collected. The CCPA sensitive personal information limitation right must be operationally honored regardless of the contractual prohibition. JURISDICTION FLAGS: California (CPRA sensitive personal information rights), Virginia (CDPA sensitive data provisions), and comparable state frameworks. EU and UK GDPR Article 9 governs special categories of personal data with stricter requirements than the general data protection framework. CONTRACT AND VENDOR IMPLICATIONS: Business customers using RunPod's platform to process any data that may include sensitive personal information should evaluate whether their data processing agreements adequately address sensitive data handling obligations and whether RunPod's contractual prohibition on sensitive data provides sufficient operational protections. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether RunPod's data ingestion systems have technical controls to detect or prevent sensitive data submission, and whether the CCPA sensitive personal information limitation right is operationally implemented with documented response procedures.
This provision creates a contractual restriction on user submission of sensitive data, while simultaneously acknowledging the possibility of incidental collection and providing a statutory limitation right under applicable state privacy laws. The coexistence of a user-facing prohibition and a processing limitation right indicates that the policy contemplates the possibility of sensitive data entering the system despite the restriction.
Under this clause, users agree not to submit government identification numbers, health information, or financial information through the Service. If sensitive personal information is nonetheless collected, users covered by applicable state privacy laws may submit requests to limit its processing to specified purposes by emailing DSAR@runpod.io.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by RunPod.