-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta will honor Global Privacy Control opt-out signals but specifies three scenarios in which the association between a device and a prior opt-out signal may be lost: use of a different browser, browser reinstallation or certain upgrades, and clearing of cookies or browsing data. In those scenarios, the opt-out preference may not be applied....
Why it matters: This provision describes the technical scope and limitations of Marqeta's GPC signal recognition mechanism, which is the primary opt-out pathway for CCPA sale and sharing disclosed in Section 3 of the California supplemental notice. The stated limitations on signal persistence may warrant evaluation against California Privacy Protection Agency guidance on the durability and accessibility of opt-out mechanisms....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta participates in the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks as certified by the U.S. Department of Commerce, and that the Data Privacy Framework Notice takes precedence over this Website Privacy Notice in the event of a conflict regarding transatlantic transfers....
Why it matters: Marqeta's DPF certification establishes a recognized adequacy mechanism for transfers of personal data from the EEA, UK, and Switzerland to the U.S., and makes the FTC the relevant enforcement authority for DPF compliance under U.S. law. The document's statement that the DPF Notice governs in the event of a conflict means that the full scope of data subject rights for international transfers requires review of both this notice and the separately published DPF Notice....
-
Marqeta
· Marqeta Privacy Policy
The document states that personal data is retained for variable periods determined by service necessity, legal and regulatory obligations, dispute resolution, and contractual requirements, with retention schedules specified in an internal records retention policy. At the end of the applicable retention period, data will be deleted or de-identified....
Why it matters: The policy does not publish specific retention periods for individual data categories in this notice, instead referencing an internal records retention policy and schedule that is not reproduced here. This means data subjects cannot determine the applicable retention period for their data from this document alone....
-
Marqeta
· Marqeta Privacy Policy
The document states that Marqeta's website services are not directed at individuals under 16, that Marqeta does not intentionally collect personal data from this age group, and that any such data discovered will be promptly deleted. The age threshold of 16 is higher than the COPPA threshold of 13....
Why it matters: The document sets the age threshold for children's data protection at 16, which aligns with GDPR Article 8's default age of digital consent in the absence of member state modification, and exceeds the COPPA threshold of 13 applicable in the United States. The CCPA supplemental notice separately confirms that Marqeta does not disclose personal information of individuals under 16 for monetary or other valuable consideration....
-
Marqeta
· Marqeta Privacy Policy
The document states that material changes to the notice will be communicated via prior notice and, where required by applicable law, consent will be obtained before those changes take effect; non-material changes will be implemented by posting an updated version on the website without prior notification....
Why it matters: The distinction between material and non-material changes determines whether users receive advance notice or consent requests before new data practices take effect. The document does not define the criteria for determining whether a change is material, which means the classification of any given change is determined by Marqeta....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Modal
· Modal Privacy Policy
The policy states that the service is not directed at users under 13, that Modal Labs does not knowingly collect personal information from children under 13, and that upon discovery such information will be immediately deleted; parents or guardians may contact the company to request action....
Why it matters: This provision reflects a standard COPPA-aligned disclosure for services not directed at children. The policy does not provide a specific contact address for parental requests, which may create a practical barrier to exercising the stated deletion right....
-
Modal
· Modal Terms of Service
The agreement states that California law governs all disputes, and that exclusive jurisdiction is vested in the federal courts of the Northern District of California and the state courts of California. Both parties consent to this jurisdiction and waive forum non conveniens challenges....
Why it matters: This provision establishes that all disputes must be litigated in California courts under California law, regardless of where the Customer is located or incorporated. The forum non conveniens waiver means Customers cannot seek to transfer proceedings to a more convenient or locally accessible court....
-
UnitedHealthcare
· UnitedHealthcare Privacy Policy
The Policy states that UnitedHealthcare will not intentionally collect personal information from children under 13 without parental consent, consistent with COPPA requirements, and provides a mechanism for reporting suspected under-13 data collection....
Why it matters: This provision establishes COPPA compliance intent for Online Services that may be accessed by minors in the context of family health plan management or dependent benefit access. The qualifier 'intentionally' in the collection restriction, rather than an absolute prohibition, reflects standard COPPA framing but leaves open the question of how unintentional under-13 data collection would be identified and addressed operationally....
-
Experian
· Experian Privacy Policy
The notice discloses that three named Experian subsidiaries are registered data brokers under Texas law and have registered with the Texas Secretary of State as required to conduct business in Texas. This disclosure is stated in both capitalized and standard text formats....
Why it matters: This provision reflects a mandatory disclosure obligation under the Texas Data Privacy and Security Act and Texas data broker registration requirements. The registration creates a public compliance record with the Texas Secretary of State that is accessible to consumers and regulators....
-
Experian
· Experian Privacy Policy
The notice discloses CCPA-required annual metrics for the 2025 calendar year, showing that Experian received and fully complied with 1,127 deletion requests, 274 correction requests, 704 access requests, 4,700 opt-out of sale/sharing requests, and 4,660 requests to limit sensitive personal information use, with average response times ranging from approximately 2.1 to 2.3 days and zero requests denied due to inability to verify consumer identity....
Why it matters: This provision constitutes a mandatory CCPA compliance disclosure and provides a quantitative record of Experian's rights request processing performance for the 2025 calendar year. The disclosure of full compliance with all received requests and sub-three-day average response times establishes a documented performance baseline that may be referenced in regulatory reviews or compliance audits....
-
Experian
· Experian Privacy Policy
The notice states that Experian does not collect, sell, share, or disclose personal information of individuals under 16 years of age....
Why it matters: This provision establishes a categorical prohibition on data collection and sale for minors under 16, which aligns with the CCPA's prohibition on selling personal information of minors under 16 without affirmative authorization. No mechanism is described for age verification or for addressing cases where a minor's data may have been collected without Experian's knowledge....
-
Harvey AI
· Harvey AI Privacy Policy
The policy discloses that individuals may access, correct, update, delete, object to, restrict, or request portability of their Personal Data, subject to legal exceptions. Users may also opt out of marketing emails and complain to a supervisory authority. These rights are exercised by contacting privacy@harvey.ai....
Why it matters: This provision establishes the available data subject rights mechanisms and confirms access to regulatory complaint channels including EU DPAs and the UK ICO. The rights are subject to exceptions and exemptions, and the scope of available rights varies by jurisdiction as described in the Jurisdiction Specific Provisions section....
-
Harvey AI
· Harvey AI Privacy Policy
Harvey retains Personal Data for as long as necessary for the described purposes, including legal obligations, dispute resolution, agreement enforcement, and tax and audit requirements. Data held in backup archives that cannot be immediately deleted is stored securely and isolated from further processing until deletion is possible....
Why it matters: The retention period for end users whose employers hold a Customer Agreement is governed by that agreement rather than solely by this policy, creating a dependency on enterprise contract terms for determining how long individual user data is held. The backup archive carve-out for data that cannot be immediately deleted is a standard but operationally relevant provision for deletion request management....
-
Together AI
· Together AI Privacy Policy
The policy states that Together AI will notify users and provide a copy of any law enforcement request for their Personal Data, unless legally prohibited from doing so, such as by a court-imposed gag order or applicable legal restriction....
Why it matters: This provision establishes a transparency commitment regarding government data requests that is operationally distinct from policies that provide no such notification; the practical scope of this commitment depends on the frequency and legal constraints applicable to law enforcement requests received....
-
Together AI
· Together AI Privacy Policy
The policy states that Together AI's services are not directed to users under age 13, that the company does not knowingly collect Personal Data from that age group, and that discovered data collected from under-13 users without verified parental consent will be removed from servers....
Why it matters: This provision establishes COPPA-aligned age restriction and data removal commitments; the absence of a defined response timeline for parental notification or removal requests may warrant operational clarification....
-
Together AI
· Together AI Privacy Policy
The policy states that updates may be made at any time and will be effective when posted; direct notification to users is conditioned on a legal requirement to do so, and the policy advises users who find changes unacceptable to cease using the service....
Why it matters: The notification mechanism is conditional on legal obligation rather than a proactive commitment to direct user notice, meaning users bear responsibility for monitoring the policy page for changes absent a legal notification trigger. Under GDPR, material changes to processing purposes or legal bases may require active notification and, in consent-based processing, fresh consent....
-
ActiveCampaign
· ActiveCampaign Acceptable Use Policy
The policy explicitly prohibits use of ActiveCampaign's SMS and messaging services for emergency alerts, disaster notifications, or health and safety threat communications including terrorism, natural disasters, or emergency response....
Why it matters: This clause establishes a specific operational limitation on the permitted use of ActiveCampaign's messaging infrastructure, which is operationally significant for any organization that manages emergency communications or public safety notification workflows alongside marketing operations....
-
ConvertKit
· ConvertKit Acceptable Use Policy
The policy establishes that abusive, threatening, or demeaning communications directed at Kit staff constitute grounds for account termination....
Why it matters: This provision extends account termination authority to conduct in customer communications, not only to content or list management practices, and applies the same no-refund and discretionary data export consequences as other termination grounds....
-
Oscar Health
· Oscar Health Privacy Policy
The policy states that personal information is retained for as long as Oscar determines is reasonably necessary for the purposes described in the notice, legal compliance, dispute resolution, and protection of rights, without specifying fixed retention periods for any data category....
Why it matters: The absence of defined retention periods for specific data categories means the policy does not establish a maximum retention timeline, and the stated standard of 'as long as we believe it is necessary' is discretionary in application, which may be evaluated against state and federal data minimization requirements....
-
Oscar Health
· Oscar Health Privacy Policy
The policy states Oscar's services are not directed to children under 13, that it does not knowingly collect personal information from this age group, and that it endeavors to delete such information if discovered. For individuals aged 13 to 16, the policy states Oscar does not sell or share their information without affirmative authorization, conditioned on Oscar having actual knowledge of the individual's age....
Why it matters: The age 13 to 16 protection is conditioned on Oscar having 'actual knowledge' of the individual's age, which is a standard limitation that means the protection may not apply where age is not verified or disclosed; this is a common limitation in online privacy policies that may be evaluated against COPPA and applicable state minor privacy requirements....
-
Oscar Health
· Oscar Health Privacy Policy
The policy states that Oscar's Sites are operated from the United States and that personal information may be stored, processed, and accessed in the United States and other countries. The policy explicitly states it is not intended to subject Oscar to the laws or jurisdiction of countries other than the United States....
Why it matters: The provision's statement that the Sites are not intended to subject Oscar to the jurisdiction of countries other than the United States, combined with acknowledgment of transfers to countries that may not guarantee equivalent data protection, is relevant for non-U.S. users whose data may be transferred internationally without the safeguards required under frameworks such as the GDPR....
-
Oscar Health
· Oscar Health Privacy Policy
The policy states that Oscar may update the privacy policy at any time, with the only notification being an updated version date. Continued use of the services is stated to constitute acknowledgment of revisions....
Why it matters: This provision establishes that privacy policy changes take effect through continued use without requiring affirmative consent or direct notice to users, which may be evaluated against state law requirements for notice of material changes to privacy practices under CCPA and analogous statutes....
-
Salesforce Einstein
· Salesforce Trusted AI Principles
This provision describes an automated real-time content moderation system that scans AI-generated outputs for hate speech, bias, harassment, and policy violations, and automatically filters, blocks, or flags harmful content before it reaches the end user....
Why it matters: This provision establishes an automated content moderation mechanism within the Einstein Trust Layer that operates on all AI-generated outputs, with direct implications for enterprise customers in regulated industries who must ensure AI outputs comply with anti-discrimination, consumer protection, and professional conduct requirements. The specific categories scanned (hate speech, bias, harassment) and the automated blocking mechanism are relevant to customers' own AI governance and incident response frameworks....
-
Salesforce Einstein
· Salesforce Trusted AI Principles
This provision states that Salesforce publishes model cards for its AI models covering creation methodology, intended and unintended use cases, known ethical or societal implications, and performance scores, and provides explainability information when AI predictions or recommendations are generated....
Why it matters: This provision establishes a transparency mechanism directly relevant to enterprise customers' AI governance obligations, including requirements under the EU AI Act for documentation of high-risk AI systems and emerging US state AI transparency laws. The publication of model cards covering unintended use cases and known ethical or societal implications is a materially significant disclosure for customers conducting AI risk assessments....
-
Salesforce Einstein
· Salesforce Trusted AI Principles
This provision describes a technical architecture that connects the LLM to customer enterprise data sources, restricting model outputs to customer-approved sources to reduce hallucinations while preserving existing data access permissions and controls....
Why it matters: This provision establishes that AI outputs within the Salesforce platform are grounded in customer-approved data sources and that existing data access controls are maintained during AI processing, which has direct implications for data segregation, access control compliance, and the accuracy of AI-generated outputs used in business decisions. The maintenance of permissions during AI data retrieval is relevant to compliance with data access governance frameworks and insider threat controls....
-
Apple Intelligence
· Apple Intelligence Privacy Report
The document discloses that Apple collects metadata about Private Cloud Compute requests including approximate request and response size, feature type, and processing duration, and states that this metadata does not include request content and is not linked to an Apple Account or other Apple service data....
Why it matters: This provision defines the scope of data Apple asserts it collects in connection with server-side AI processing, establishing the boundary between content data (not collected) and operational metadata (collected). The assertion that metadata is not identifiable or linked to an Apple Account is a material privacy representation that compliance teams in regulated industries should evaluate in the context of applicable data minimization and de-identification standards....
-
Apple Intelligence
· Apple Intelligence Privacy Report
The document discloses that users who have opted into Device Analytics allow Apple to collect aggregated, privacy-preserving data about Apple Intelligence content for product improvement purposes, with an opt-out mechanism available at any time through device settings....
Why it matters: This provision establishes the consent basis and opt-out mechanism for Apple's use of Apple Intelligence content data for product improvement, applying only to users who have previously opted into Device Analytics. The opt-out is presented as available at any time without stated consequence to Apple Intelligence functionality, which is operationally significant for users and for enterprise device administrators managing analytics consent at scale....
-
Apple Intelligence
· Apple Intelligence Privacy Report
The document discloses a transparency logging feature called Apple Intelligence Report that allows users to view and export a file showing which requests were sent off-device to Private Cloud Compute and, if the ChatGPT extension is enabled, to ChatGPT, including requests originating from watchOS....
Why it matters: This provision establishes a user-accessible transparency mechanism that documents server-side data routing for Apple Intelligence requests, providing an auditable log of off-device processing. The availability of an exportable report covering Private Cloud Compute and ChatGPT extension requests has operational relevance for users and enterprise administrators seeking to verify data flow practices....
-
Apple Intelligence
· Apple Intelligence Privacy Report
The document states that Apple Intelligence processes tasks using on-device models wherever possible, citing email, message, and notification summaries as examples of features that run entirely on the user's device without data being transmitted externally....
Why it matters: This provision establishes that on-device processing is the default architectural approach for Apple Intelligence, with server-side routing to Private Cloud Compute occurring only when the task requires computational capacity beyond what the device can provide. The distinction between on-device and server-side processing is operationally significant for data flow mapping and regulatory classification of personal data processing....
-
Replicate
· Replicate Acceptable Use Policy
Any suggestions, comments, or ideas about the service provided by the customer, its affiliates, or authorized users are automatically assigned to Replicate upon submission, with no compensation, attribution, or other obligation to the contributor. Replicate may commercialize and distribute feedback without restriction....
Why it matters: This provision operates as an automatic IP assignment clause, transferring ownership of any service-related suggestions or ideas to Replicate without requiring a separate signed agreement or compensation. Organizations that submit technical suggestions, feature requests, or product feedback should be aware that this constitutes an IP transfer....
-
Groq
· Groq Acceptable Use Policy
The policy provides a mechanism for Customers who have implemented adequate safeguards to request exceptions to the AUP's restrictions for lawful business or research purposes, while reserving to Groq sole discretion over whether to grant exceptions without creating any precedent obligation....
Why it matters: This provision establishes that policy flexibility is available only through individual exception requests approved at Groq's discretion, and that approved exceptions create no binding precedent for similar or related cases....
-
Groq
· Groq Acceptable Use Policy
The policy prohibits Customers from exceeding published usage parameters or rate limits, and specifically prohibits circumventing those limits through multiple account registration or coordinated usage across multiple organizations....
Why it matters: This provision establishes that rate limit and parameter compliance is a contractual obligation enforced across the account and organizational level, not just at the individual API request level, and that multi-account or multi-organization orchestration to circumvent limits constitutes a policy violation....
-
Oura
· Oura Terms of Service
Any feedback, suggestions, or recommendations submitted to Oura by users may be used by Oura for any purpose without attribution or compensation, regardless of any other agreement between the parties....
Why it matters: This provision assigns to Oura the right to use any user-submitted feedback, including ideas and concepts, for any purpose without compensation or attribution. This is a standard clause in consumer technology agreements, and its practical scope is limited to the feedback and suggestions users choose to submit....
-
Synthesia
· Synthesia Acceptable Use Policy
The AUP prohibits users from accessing Synthesia's Services for the purpose of building a competing product or service....
Why it matters: This provision establishes a contractual restriction on competitive use of platform access, a common clause in SaaS agreements that may interact with competition law principles in certain jurisdictions....
-
Databricks
· Databricks Security Practices
The document states that Databricks conducts 8-10 external and 15-20 internal penetration tests annually, requires all material findings to be resolved before a test is passed, and makes the platform-wide third-party test report available in a due diligence package....
Why it matters: This provision establishes a specific, measurable penetration testing cadence with a mandatory remediation gate for material findings, and discloses that the third-party test report is available to customers through the due diligence package, providing a basis for customer-initiated security review....