Key Facts
What does Segment train AI/ML models to recognize?
Segment trains AI/ML models to recognize evolving security vulnerabilities and fraud signatures.
What does Segment treat as permanent?
Segment treats account closure or deletion as permanent, resulting in immediate loss of access to some or all data.
What results from account closure or deletion?
Segment treats account closure or deletion as permanent, resulting in immediate loss of access to some or all data.
What does Segment use signals to do?
Segment uses signals to make real-time automated security decisions, such as approving account applications or suspending fraudulent accounts, and notifies affected individuals with an opportunity to object.
What does Segment automatically collect?
Segment automatically collects electronic communications metadata including sender/recipient information, routing details, timestamps, communication type, duration, message status and activity, error data, and traffic records.
When does Segment make binding arbitration available to individuals?
Segment makes binding arbitration available to individuals under certain circumstances pursuant to Annex I of the EU-U.S. Data Privacy Framework Principles.
What does Segment use identity resolution to create?
Segment uses identity resolution to create unified profiles that ensure a consistent experience across different devices and touchpoints.
Does Segment sell personal data to third parties?
Segment does not sell personal data to third parties.
What does Segment endeavor not to do with personal data?
Segment endeavors not to retain personal data in a form that permits identification of individuals for longer than is necessary for the purposes for which that data is processed.
What right does Segment give individuals regarding decisions Twilio makes based solely on automated processing?
Segment gives individuals the right to object to and request human review of decisions Twilio makes based solely on automated processing, which currently includes account approvals and account suspensions related to abusive or fraudulent activity.
Summary
Segment's privacy policy describes how it collects your data, uses it to build a unified profile across your devices, and applies it to automated security decisions about your account. Segment does not sell your personal data. If an automated system makes a decision about your account—such as approving or suspending it—Segment must notify you and give you the right to request a human review.
Analysis
This privacy policy establishes Segment's obligations and rights with respect to the collection, use, retention, sharing, and automated processing of personal data. Segment automatically collects extensive electronic communications metadata and uses identity resolution to build unified cross-device profiles, while committing not to sell personal data to third parties. Personal data is used as training input for AI/ML models for security and fraud detection, and Segment makes real-time automated decisions—such as account approvals and suspensions—with an affirmative obligation to notify affected individuals and provide an opportunity to object, including a right to request human review. Data retention is a best-effort obligation tied to processing necessity, account deletion is permanent with no recovery window, and Segment retains liability under the DPF Principles for third-party misuse of transferred data unless it proves non-responsibility.
What this means for you
As a user, Segment collects detailed metadata about your electronic communications and links your activity across devices into a single profile. Automated systems can affect your account access in real time, but Segment is required to notify you of such decisions and you have the right to object and request human review of any decision based solely on automated processing. Account deletion is permanent with no recovery window, so once you close your account you immediately lose access to your data. If you are subject to an automated decision, you can contact Segment to request human review of that decision.
3 important changes detected
4 versions captured · Last updated: July 2026
What changed
Segment's privacy policy navigation menu was updated on July 3, 2026 to remove the reference to 'GDPR Customer Data Protection Addendum' as a standalone linked item. The menu previously listed this addendum separately; the updated menu consolidates references under broader data protection categories. This appears to be a structural reorganization of legal document navigation rather than a substantive change to privacy protections or data handling practices.
Why this matters
The updated privacy policy removes the standalone navigation link to the GDPR Customer Data Protection Addendum. The addendum itself remains available within Segment's legal documentation suite; the change affects only how users navigate to find it. This is a structural reorganization of the menu interface rather than a modification of data protection terms or practices.
View full change record →
What changed
Segment updated its privacy policy on May 22, 2026 to add two new provisions and clarify one existing process. The company added explicit notice that Twilio Inc. (Segment's parent company) is subject to FTC investigatory and enforcement powers, and introduced a new opt-out right allowing users to decline disclosure of their data to third parties or use for materially different purposes than originally authorized. The policy also revised its dispute resolution language to refer to 'Data Privacy Frameworks' instead of 'Data Protection Frameworks' in the context of JAMS arbitration. These changes establish new user controls and regulatory transparency without removing existing protections.
Why this matters
The updated policy establishes a new opt-out mechanism allowing users to decline having their data disclosed to third parties (other than service providers) or used for purposes materially different from the original collection purpose. The policy also explicitly discloses that Twilio Inc. is subject to FTC investigatory and enforcement powers, providing users with notice of the regulatory authority overseeing the company's privacy practices. You can exercise this opt-out right by contacting Segment through the mechanism specified in their privacy policy.
View full change record →
May 19, 2026
medium
Segment updated its privacy policy on May 19, 2026 to provide more detailed disclosure of its Data Privacy Framework (DPF) compliance certifications and mechanisms. The policy now explicitly states that …
View change record →
Archival ProvenanceSource & Archival Record
Last Captured
July 3, 2026 01:14 UTC
Capture Method
Automated scheduled archival capture
Document ID
CA-D-000700
Version ID
CA-V-004456
SHA-256
e37e6bb1abdf882cdf3d4b9a7ddcbcb1b521744fd46b9d3d4d5f19d611714b48
✓ Snapshot stored
✓ Text extracted
✓ Change verified
✓ Hash verified