Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes Writer to aggregate or de-identify collected user data and share that de-identified data with any third party, including advertisers, partners, and sponsors, for any purpose including research and marketing.
This analysis describes what Writer's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that once data is de-identified as defined by Writer, it may be disclosed to an unrestricted set of third parties for unrestricted purposes. The policy does not specify the technical standard used to achieve de-identification, and the definition relies on data no longer being linkable to a user or device rather than a codified regulatory standard.
Interpretive note: The policy does not specify the technical standard applied to de-identification, creating ambiguity about whether disclosed data would qualify as genuinely anonymous under GDPR or CCPA definitions in practice.
Under this clause, information derived from user activity may be aggregated or de-identified by Writer and subsequently disclosed to advertisers, partners, and sponsors for any purpose, including marketing and research, without further restriction or user consent.
Cross-platform context
See how other platforms handle De-Identified Data Third-Party Disclosure and similar clauses.
Compare across platforms →Monitoring
Writer has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may aggregate and/or de-identify any information we collect through our Services so this information can no longer be linked to you or your device ('De-Identified Information'). We may use De-Identified Information for any purpose, including without limitation for research and marketing purposes, and may also disclose such data to any third parties, including advertisers, partners, and sponsors.Excerpt from Writer's Privacy Policy
REGULATORY LANDSCAPE: This provision may require evaluation under GDPR recital 26 and Article 4, which establish that truly anonymized data falls outside GDPR scope but set a high bar for anonymization; de-identification that does not meet the GDPR anonymization standard may remain subject to data protection obligations. Under CCPA, de-identified data is defined with specific technical and contractual requirements. The FTC has issued guidance on the limits of de-identification. Relevant enforcement authority includes the FTC and EU data protection authorities. GOVERNANCE EXPOSURE: Medium. The provision's lack of specification regarding the technical de-identification standard creates ambiguity about whether disclosed data would qualify as genuinely anonymous under GDPR or CCPA definitions. If re-identification is technically feasible, the unrestricted third-party disclosure could create compliance exposure under applicable data protection frameworks. JURISDICTION FLAGS: EEA and UK users face the highest exposure given GDPR's stringent anonymization standard. California residents should note that CCPA's de-identification definition includes contractual prohibitions on re-identification that the policy does not explicitly require of third-party recipients. Illinois and other states with emerging data privacy statutes may impose additional requirements. CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should assess whether contracts with downstream recipients of de-identified data include prohibitions on re-identification and technical safeguard requirements, as the policy does not describe such contractual controls. COMPLIANCE CONSIDERATIONS: Compliance teams should review the technical standard applied to de-identification processes, assess whether that standard meets GDPR anonymization or CCPA de-identification requirements, and confirm that third-party disclosure agreements include re-identification prohibitions consistent with applicable law.
This provision establishes that once data is de-identified as defined by Writer, it may be disclosed to an unrestricted set of third parties for unrestricted purposes. The policy does not specify the technical standard used to achieve de-identification, and the definition relies on data no longer being linkable to a user or device rather than a codified regulatory standard.
Under this clause, information derived from user activity may be aggregated or de-identified by Writer and subsequently disclosed to advertisers, partners, and sponsors for any purpose, including marketing and research, without further restriction or user consent.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Writer.