Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that Twilio uses personal data including customer content, communications usage data, and customer support and feedback data to train AI and machine learning models for purposes including security, fraud detection, network optimization, and research and innovation.
This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that AI and ML training is conducted across multiple stated processing purposes and draws on data categories including customer content such as email bodies, text bodies, media files, and transcripts. Enterprise customers whose contracts govern Twilio's use of customer content as a data processor should evaluate whether the Data Protection Addendum limits or addresses this training use.
Interpretive note: The notice lists AI and ML training across multiple processing purpose categories with multiple legal bases; the specific data categories subject to training for each purpose are not individually delineated, creating some ambiguity about the full scope of data used.
The updated policy establishes a new opt-out mechanism allowing users to decline having their data disclosed to third parties (other than service providers) or used for purposes materially different from the original collection purpose. The policy also explicitly discloses that Twilio Inc. is subject to FTC investigatory and enforcement powers, providing users with notice of the regulatory authority overseeing the company's privacy practices. You can exercise this opt-out right by contacting Segment through the mechanism specified in their privacy policy.
View change record →The updated terms establish clearer disclosure of how Segment transfers personal data internationally. Segment now explicitly certifies its compliance with the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework, and states that these DPF Principles take precedence if they conflict with other policy terms. The updated policy also adds specific rights allowing you to opt out of: (i) disclosure of your personal data to third parties other than service providers acting under Segment's instructions, or (ii) use of your personal data for purposes materially different from the original purpose or your subsequent authorization. You can exercise these rights by contacting privacy@twilio.com.
View change record →The agreement authorizes use of communications content, support feedback, and usage data for AI and ML model training across security, service improvement, and research purposes. Under these terms, data uploaded to Twilio's services, including call recordings and message content, may inform model development subject to the data use categories and legal bases described in the notice.
Cross-platform context
See how other platforms handle AI and ML Model Training on Customer Data and similar clauses.
Compare across platforms →Monitoring
Segment has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Training AI/ML models to recognize evolving security vulnerabilities and fraud signatures; and, utilizing signals to make real-time automated security decisions, such as approving account applications or suspending fraudulent accounts (of which you will be notified and given an opportunity to object). ... training AI/ML models with performance metrics to optimize network reliability; providing dedicated customer support; and, refining our Service suite through usage insights. ... Developing new features or products to continuously improve our Services.Excerpt from Segment's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Articles governing purpose limitation and the requirement that further processing for new purposes be compatible with the original collection purpose. The UK GDPR imposes analogous requirements. CCPA and CPRA address use of personal information for training AI systems in certain commercial contexts. The EU AI Act may also be relevant depending on the classification of AI systems trained using this data. The FTC, as named enforcement authority over Twilio's DPF certification, has general jurisdiction over unfair or deceptive data practices. 2) GOVERNANCE EXPOSURE: Medium. The notice lists AI and ML training as a stated purpose under legitimate interest and consent legal bases across multiple processing categories. However, the breadth of data categories implicated, including customer content and support recordings, may warrant review against enterprise customer contracts to assess whether the DPA scope adequately covers or restricts this use. 3) JURISDICTION FLAGS: EU and UK organizations face heightened exposure given GDPR and UK GDPR purpose limitation requirements. California organizations should evaluate CPRA provisions governing use of sensitive personal information and automated decision-making. Organizations in regulated sectors such as healthcare or financial services should assess whether communications content processed for AI training is subject to sectoral data restrictions. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers relying on Twilio's DPA to define the scope of data processor obligations should verify whether the DPA expressly addresses or limits AI and ML training uses. Where Twilio acts as an independent controller for certain processing, liability for AI training use may not be governed by the customer's DPA. Procurement teams should flag this for contract review. 5) COMPLIANCE CONSIDERATIONS: Legal teams should map which data categories flowing through Twilio's platform are subject to AI training under the notice's stated purposes and compare this against existing DPA terms. Where gaps exist, contract amendments or supplemental data processing terms may be warranted. Consent mechanism audits may be relevant where consent is a listed legal basis for this processing.
This provision establishes that AI and ML training is conducted across multiple stated processing purposes and draws on data categories including customer content such as email bodies, text bodies, media files, and transcripts. Enterprise customers whose contracts govern Twilio's use of customer content as a data processor should evaluate whether the Data Protection Addendum limits or addresses this training use.
The agreement authorizes use of communications content, support feedback, and usage data for AI and ML model training across security, service improvement, and research purposes. Under these terms, data uploaded to Twilio's services, including call recordings and message content, may inform model development subject to the data use categories and legal bases described in the notice.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.