Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice discloses that Twilio uses customer content, communications usage data, and customer support and feedback data to train AI and ML models for purposes including security, fraud detection, network optimization, and research and development of new features.
This analysis describes what Twilio's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes the use of customer content, which the notice defines as including email subject and body, text body, media files, transcripts, recordings, and communications logs, as training data for AI and ML models across multiple stated purposes. The notice does not specify which legal basis applies specifically to AI training on customer content, which may require evaluation under GDPR Article 6 and applicable U.S. state privacy frameworks.
Interpretive note: The notice does not specify which legal basis applies specifically to AI and ML model training on customer content, creating ambiguity regarding whether consent or legitimate interest governs each training use.
The updated Privacy Notice now explicitly discloses that Twilio is subject to FTC investigatory and enforcement powers, clarifying the regulatory oversight applying to the company. The policy also establishes an opt-out right allowing users to prevent disclosure of their data to third parties (other than service providers) or use of data for purposes materially different from the original collection purpose. You can exercise this opt-out by contacting Twilio through the mechanisms described in the privacy notice.
View change record →The updated notice establishes more explicit disclosures of Twilio's Data Privacy Framework certifications and specifies the legal hierarchy governing data processing. Under the revised policy, the DPF Principles now take precedence if they conflict with other terms in the privacy notice. The updated language also clarifies your right to opt out of third-party disclosures (except to service providers acting on Twilio's behalf) and to opt out of uses that materially differ from original collection purposes. You can exercise these choices by contacting privacy@twilio.com.
View change record →The updated Privacy Notice now provides more detailed explanations of how Twilio collects and processes personal data, including explicit definitions of what constitutes personal data and descriptions of direct relationships (when you create an account or opt into communications) versus indirect relationships (when you are a customer of one of Twilio's customers). The revised language establishes that Twilio acts as a data controller and determines how and why personal data is processed, subject to applicable law. The notice states it aims to be transparent about data use and to explain how you can exercise your rights, but the change itself does not modify what data is collected, how it is used, or what rights or controls are available to you.
View change record →Under these terms, personal data including communications content and call recordings may be processed to train AI and ML models under the purposes of platform security, service improvement, and research and innovation. The notice cites consent and legitimate interest as potential legal bases but does not specify which basis applies to AI training on customer content.
Cross-platform context
See how other platforms handle AI and ML Model Training Using Customer Content and similar clauses.
Compare across platforms →Monitoring
Twilio has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Training AI/ML models to recognize evolving security vulnerabilities and fraud signatures; and, utilizing signals to make real-time automated security decisions, such as approving account applications or suspending fraudulent accounts (of which you will be notified and given an opportunity to object). [...] Troubleshooting technical issues; training AI/ML models with performance metrics to optimize network reliability; providing dedicated customer support; and, refining our Service suite through usage insights. [...] Developing new features or products to continuously improve our Services.Excerpt from Twilio's Privacy Notice
1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 6 (lawful basis for processing), Article 22 (automated decision-making), and the EU AI Act where AI systems trained on personal data may be subject to transparency and data governance obligations. The FTC Act and CCPA may also apply to the extent AI training on consumer data constitutes a use that is materially different from the original collection purpose. The Irish Data Protection Commission and FTC are the primary enforcement authorities. 2) GOVERNANCE EXPOSURE: High. The notice discloses AI and ML model training across customer content, communications usage data, and customer support and feedback data without specifying the precise legal basis for each training use. Under GDPR, legitimate interest as a basis for processing customer communications content for AI training may require a documented legitimate interest assessment, and the notice does not confirm one is in place. 3) JURISDICTION FLAGS: Heightened exposure in the EEA and UK, where GDPR and the UK GDPR impose specific requirements for processing based on legitimate interest, and where the EU AI Act may impose additional obligations on AI systems trained on personal communications data. California CPRA creates exposure where AI training constitutes a use of sensitive or previously collected data beyond the original purpose. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose communications content is used for AI model training should evaluate whether their Data Protection Addenda with Twilio adequately address AI training uses, particularly where Twilio acts as a data processor and the customer is the controller of underlying content. The provision's breadth may create a mismatch between the DPA's processor obligations and the controller-level AI training activities described here. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether legitimate interest assessments have been documented for AI training on customer content, evaluate whether data subject rights including the right to object apply to this processing, review DPA terms for AI training carve-outs or limitations, and determine whether the EU AI Act requires additional transparency disclosures for AI systems trained on communications data.
This provision authorizes the use of customer content, which the notice defines as including email subject and body, text body, media files, transcripts, recordings, and communications logs, as training data for AI and ML models across multiple stated purposes. The notice does not specify which legal basis applies specifically to AI training on customer content, which may require evaluation under …
Under these terms, personal data including communications content and call recordings may be processed to train AI and ML models under the purposes of platform security, service improvement, and research and innovation. The notice cites consent and legitimate interest as potential legal bases but does not specify which basis applies to AI training on customer content.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Twilio.