101 Total
39 High severity
56 Medium severity
6 Low severity

Key Facts

What does Segment train AI/ML models to recognize?
Segment trains AI/ML models to recognize evolving security vulnerabilities and fraud signatures.
What does Segment treat as permanent?
Segment treats account closure or deletion as permanent, resulting in immediate loss of access to some or all data.
What results from account closure or deletion?
Segment treats account closure or deletion as permanent, resulting in immediate loss of access to some or all data.
What does Segment use signals to do?
Segment uses signals to make real-time automated security decisions, such as approving account applications or suspending fraudulent accounts, and notifies affected individuals with an opportunity to object.
What does Segment automatically collect?
Segment automatically collects electronic communications metadata including sender/recipient information, routing details, timestamps, communication type, duration, message status and activity, error data, and traffic records.
When does Segment make binding arbitration available to individuals?
Segment makes binding arbitration available to individuals under certain circumstances pursuant to Annex I of the EU-U.S. Data Privacy Framework Principles.
What does Segment use identity resolution to create?
Segment uses identity resolution to create unified profiles that ensure a consistent experience across different devices and touchpoints.
Does Segment sell personal data to third parties?
Segment does not sell personal data to third parties.
What does Segment endeavor not to do with personal data?
Segment endeavors not to retain personal data in a form that permits identification of individuals for longer than is necessary for the purposes for which that data is processed.
What right does Segment give individuals regarding decisions Twilio makes based solely on automated processing?
Segment gives individuals the right to object to and request human review of decisions Twilio makes based solely on automated processing, which currently includes account approvals and account suspensions related to abusive or fraudulent activity.
Stay ahead of the changes
Track Segment and get the diff the day its terms change.
Summary

Segment's privacy policy describes how it collects your data, uses it to build a unified profile across your devices, and applies it to automated security decisions about your account. Segment does not sell your personal data. If an automated system makes a decision about your account—such as approving or suspending it—Segment must notify you and give you the right to request a human review.

Analysis

This privacy policy establishes Segment's obligations and rights with respect to the collection, use, retention, sharing, and automated processing of personal data. Segment automatically collects extensive electronic communications metadata and uses identity resolution to build unified cross-device profiles, while committing not to sell personal data to third parties. Personal data is used as training input for AI/ML models for security and fraud detection, and Segment makes real-time automated decisions—such as account approvals and suspensions—with an affirmative obligation to notify affected individuals and provide an opportunity to object, including a right to request human review. Data retention is a best-effort obligation tied to processing necessity, account deletion is permanent with no recovery window, and Segment retains liability under the DPF Principles for third-party misuse of transferred data unless it proves non-responsibility.

What this means for you

As a user, Segment collects detailed metadata about your electronic communications and links your activity across devices into a single profile. Automated systems can affect your account access in real time, but Segment is required to notify you of such decisions and you have the right to object and request human review of any decision based solely on automated processing. Account deletion is permanent with no recovery window, so once you close your account you immediately lose access to your data. If you are subject to an automated decision, you can contact Segment to request human review of that decision.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

3 important changes detected

4 versions captured · Last updated: July 2026

What changed Segment's privacy policy navigation menu was updated on July 3, 2026 to remove the reference to 'GDPR Customer Data Protection Addendum' as a standalone linked item. The menu previously listed this addendum separately; the updated menu consolidates references under broader data protection categories. This appears to be a structural reorganization of legal document navigation rather than a substantive change to privacy protections or data handling practices.
Why this matters The updated privacy policy removes the standalone navigation link to the GDPR Customer Data Protection Addendum. The addendum itself remains available within Segment's legal documentation suite; the change affects only how users navigate to find it. This is a structural reorganization of the menu interface rather than a modification of data protection terms or practices.
View full change record →

May 22, 2026

medium
What changed Segment updated its privacy policy on May 22, 2026 to add two new provisions and clarify one existing process. The company added explicit notice that Twilio Inc. (Segment's parent company) is subject to FTC investigatory and enforcement powers, and introduced a new opt-out right allowing users to decline disclosure of their data to third parties or use for materially different purposes than originally authorized. The policy also revised its dispute resolution language to refer to 'Data Privacy Frameworks' instead of 'Data Protection Frameworks' in the context of JAMS arbitration. These changes establish new user controls and regulatory transparency without removing existing protections.
Why this matters The updated policy establishes a new opt-out mechanism allowing users to decline having their data disclosed to third parties (other than service providers) or used for purposes materially different from the original collection purpose. The policy also explicitly discloses that Twilio Inc. is subject to FTC investigatory and enforcement powers, providing users with notice of the regulatory authority overseeing the company's privacy practices. You can exercise this opt-out right by contacting Segment through the mechanism specified in their privacy policy.
View full change record →

May 19, 2026 medium

Segment updated its privacy policy on May 19, 2026 to provide more detailed disclosure of its Data Privacy Framework (DPF) compliance certifications and mechanisms. The policy now explicitly states that …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

101 provisions
12 featured
16 clause types
39 high severity
Acceptable Use Restrictions 1
Disclosure and Transparency Requirements 1
Stay ahead of the changes

Monitoring

Segment has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Account deletion is permanent with immediate access loss and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 3, 2026 01:14 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000700
Version ID CA-V-004456
SHA-256 e37e6bb1abdf882cdf3d4b9a7ddcbcb1b521744fd46b9d3d4d5f19d611714b48
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans