Vercel AI · Vercel AI SDK Privacy · View original document ↗

AI Product Data Sharing for Model Training

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Vercel AI changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Vercel AI Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Vercel may share de-identified AI product information, including chat prompts, uploaded images, and design or text generations, from Hobby and Pro plan users with external AI business partners for model training and product development purposes, subject to opt-out through team settings.

This analysis describes what Vercel AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes disclosure of de-identified AI product inputs to third-party AI business partners, creating a data flow that extends beyond Vercel's internal operations; compliance teams should evaluate whether the de-identification standard applied satisfies applicable law thresholds, particularly under GDPR and US state privacy laws where re-identification risk standards vary.

Interpretive note: The operational scope of this provision depends on whether user-generated AI inputs are classified as Customer Content subject to the data processor carve-out or as information collected directly by Vercel under this Notice; this distinction is not fully resolved in the document.

Recent Activity

This document changed recently

Medium Jun 2, 2026

The updated policy establishes a new mechanism for resolving privacy disputes related to Data Privacy Framework transfers. Users in the EU, UK, and EEA who have unresolved privacy complaints can now submit them to VeraSafe for independent review, which will be conducted free of charge. Additionally, the policy introduces an explicit Right to Restriction, permitting users to request that Vercel limit processing of their personal information or restrict further disclosures in certain instances, particularly for sensitive information. You can file a complaint with VeraSafe by submitting required information at https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.

View change record →

Consumer impact (what this means for users)

Under this clause, Vercel may share de-identified versions of AI product inputs such as chat prompts and uploaded images from Hobby and Pro accounts with AI business partners for training purposes, unless the user opts out through Team Preferences settings in the Vercel dashboard.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Log in to your Vercel account, navigate to Team Preferences, and locate the model training opt-out option as described in Section 3 of the Terms of Service.

Cross-platform context

See how other platforms handle AI Product Data Sharing for Model Training and similar clauses.

Compare across platforms →

Monitoring

Vercel AI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
For Hobby and Pro plan users, subject to your data preferences in your team settings, we may disclose de-identified information (including de-identified AI Product Information) to AI business partners for their product improvement and development, including training and improving AI and machine learning models, with the ultimate purpose of improving the Vercel Services you use.

Excerpt from Vercel AI's SDK Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 4 definitions of anonymization and pseudonymization, as European data protection authorities including the EDPB have issued guidance requiring high standards for data to be treated as truly anonymized and outside GDPR scope. Under CCPA and CPRA, de-identified data is subject to specific maintenance obligations including prohibitions on re-identification; the California Privacy Protection Agency oversees enforcement. EU AI Act obligations for AI system training data governance may also be relevant depending on how Vercel classifies its AI products. (2) GOVERNANCE EXPOSURE: Medium. The provision's reliance on de-identification as the basis for third-party AI model training disclosure creates compliance exposure contingent on whether the de-identification methodology meets applicable legal standards in relevant jurisdictions; if re-identification risk is not adequately addressed, this disclosure may constitute personal data processing subject to additional legal bases under GDPR or a 'sale' or 'sharing' under CCPA. (3) JURISDICTION FLAGS: EU and EEA users face the greatest exposure given GDPR's strict anonymization threshold; UK users are similarly affected under UK GDPR. California users should evaluate whether disclosed AI product information overlaps with categories subject to sensitive data restrictions under CPRA. The provision is limited by plan type to Hobby and Pro users, which narrows but does not eliminate enterprise exposure where accounts use these tiers. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should confirm through the Data Processing Addendum whether AI product inputs processed under their Customer account are covered by this provision or excluded as Customer Content subject to the data processor carve-out; the Notice's scope exclusion for processor activities creates ambiguity about whether end-user-generated AI inputs fall under this provision or the DPA. Vendor assessments should request Vercel's de-identification methodology documentation. (5) COMPLIANCE CONSIDERATIONS: Legal teams should audit whether existing consent mechanisms and privacy notices for end users of Customer-deployed applications adequately disclose potential downstream de-identified AI data sharing by Vercel; where GDPR applies, a legitimate interest or consent assessment may be required. Teams should confirm the Team Preferences opt-out mechanism is implemented and tested for all relevant accounts.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data practices and over Vercel's DPF compliance, including data sharing practices that may engage consumer protection standards.
    File a complaint →

Provision details

Document information
Document
Vercel AI SDK Privacy
Entity
Vercel AI
Document last updated
May 12, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015770
Document ID
CA-D-00548
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2aa1fc8d3fb3e809780dfbadb1415e7d8a6e06ada97e231c9f7c5dffbc2f611c
Analysis generated
July 9, 2026 08:47 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Vercel AI
Document: Vercel AI SDK Privacy
Record ID: CA-P-015770
Captured: 2026-07-09 08:47:06 UTC
SHA-256: 2aa1fc8d3fb3e809…
URL: https://conductatlas.com/platform/vercel-ai/vercel-ai-sdk-privacy/provision/CA-P-015770/ai-product-data-sharing-for-model-training/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Vercel AI's AI Product Data Sharing for Model Training clause do?

This provision authorizes disclosure of de-identified AI product inputs to third-party AI business partners, creating a data flow that extends beyond Vercel's internal operations; compliance teams should evaluate whether the de-identification standard applied satisfies applicable law thresholds, particularly under GDPR and US state privacy laws where re-identification risk standards vary.

How does this clause affect you?

Under this clause, Vercel may share de-identified versions of AI product inputs such as chat prompts and uploaded images from Hobby and Pro accounts with AI business partners for training purposes, unless the user opts out through Team Preferences settings in the Vercel dashboard.

Is ConductAtlas affiliated with Vercel AI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Vercel AI.