-
YouTube Ads
· Google Privacy Policy
The policy states that for users on organizational Google accounts, domain administrators and resellers have access to account data including email content, usage statistics, and account credentials, and can modify, suspend, or restrict the account and its privacy settings....
Why it matters: This provision establishes that organizational administrators have broad access and control over employee or student Google accounts, including the ability to restrict users' own privacy controls. This has particular significance for educational settings covered by FERPA and COPPA, and for employment contexts governed by applicable data protection laws....
-
YouTube Ads
· Google Privacy Policy
The policy establishes a tiered data retention framework under which some data is deleted at user request, some is automatically deleted or anonymized after set periods, and some is retained until account deletion or for extended periods for legitimate business or legal purposes, with acknowledged delays between user deletion requests and removal from backup systems....
Why it matters: This provision establishes that user-initiated deletion does not result in immediate removal from all systems, and that certain categories of data are retained beyond user control for business or legal purposes. The acknowledgment of backup system delays is relevant to the operationalization of deletion rights under GDPR and U.S. state privacy laws....
-
YouTube Ads
· Google Privacy Policy
The policy states that Google does not use sensitive categories (race, religion, sexual orientation, health) or content from Drive, Gmail, or Photos for personalized ad targeting, and does not share personally identifying information such as name or email with advertisers without user request....
Why it matters: This provision establishes specific categorical exclusions from Google's advertising personalization system. The exclusion of Drive, Gmail, and Photos content from ad targeting is a material limitation on the scope of data used for advertising, and the prohibition on sharing personally identifying information with advertisers addresses a frequently cited consumer concern....
-
YouTube Ads
· Google Privacy Policy
The policy states that Google does not sell personal information and does not share it as defined under the CCPA, and discloses that U.S. state privacy laws provide users rights to access, correct, delete, and port their data, as well as opt out of profiling and targeted advertising....
Why it matters: This provision makes a material legal representation that Google's data practices do not constitute a sale or CCPA-defined share of personal information, which is significant given the breadth of Google's advertising and data partnerships. The enumeration of state privacy rights establishes the operative framework for user rights requests across approximately twenty U.S. jurisdictions....
-
YouTube Ads
· Google Privacy Policy
The policy states that Google collects and stores data from users who are not signed in to a Google Account, linking this data to unique identifiers tied to the user's browser, application, or device, and uses this data for preference maintenance and ad relevance....
Why it matters: This provision establishes that Google's data collection applies to signed-out and unregistered users through device and browser-level identifiers, not only to users with Google Accounts. This collection is relevant to cookie consent frameworks, ePrivacy obligations in the EU, and the scope of U.S. state privacy law coverage for non-account holders....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
OnlyFans
· OnlyFans Privacy Policy
The policy states that biometric face recognition data is collected and retained exclusively by third-party verification providers during onboarding, that Fenix does not access this data, and that users may withdraw consent to its retention for authentication by contacting privacy@onlyfans.com....
Why it matters: This provision structures biometric processing as occurring entirely within third-party data processors, with Fenix asserting no direct access, while simultaneously identifying consent as the lawful basis and establishing a consent withdrawal mechanism. Under GDPR Article 28 and state biometric privacy statutes including Illinois BIPA, the practical enforceability of this structural framing as a full insulation from controller-level accountability may require jurisdiction-specific legal evaluation....
-
OnlyFans
· OnlyFans Privacy Policy
The policy states that OnlyFans may use background screening providers to check US-based users against sex offender registries and for serious criminal convictions, using the user's full name and date of birth, as part of Terms of Service enforcement....
Why it matters: This provision establishes that background screening, including sex offender registry checks, is a reserved enforcement mechanism applicable to all US-based users, conducted using name and date of birth data already collected during onboarding. The policy does not specify the frequency, trigger criteria beyond 'serious criminal offence,' notification procedures, or user appeal mechanisms for background screening determinations....
-
OnlyFans
· OnlyFans Privacy Policy
The policy states that personal data may be retained indefinitely where OnlyFans reasonably suspects a Terms of Service violation, for the duration of investigations by law enforcement or organizations such as NCMEC, and for up to 7 years for financial and identity record-keeping obligations....
Why it matters: The Trust and Safety retention basis is triggered by reasonable suspicion of a Terms of Service violation, not a confirmed violation, and does not specify a maximum retention period. This provision may create tension with GDPR storage limitation principles under Article 5(1)(e) and UK GDPR equivalents, where indefinite retention on suspicion grounds may require proportionality justification....
-
OnlyFans
· OnlyFans Privacy Policy
The policy states that personal data may be transferred outside the UK, EEA, and Switzerland to group companies and third parties, using adequacy decisions, appropriate safeguards (such as standard contractual clauses), or other legal authorizations, depending on the destination country....
Why it matters: This provision discloses that international transfers occur but does not specify the destination countries, the specific transfer mechanisms used for each category of recipient, or the third-party providers involved in cross-border processing. Users seeking this information are directed to contact the company using the details in Section 19....
-
OnlyFans
· OnlyFans Privacy Policy
The policy states that OnlyFans does not sell personal data, does not share personal data for targeted or cross-context behavioural advertising, and does not use cross-site tracking technologies, while disclosing that sensitive information including partial payment card data, government identifiers, usernames and passwords, and biometric data may be disclosed to service providers for business purposes....
Why it matters: This provision makes explicit data practice representations that engage CCPA opt-out rights and Nevada law requirements. The policy simultaneously confirms no data sale or targeted advertising while disclosing that sensitive information categories are shared with service providers for operational purposes, which the policy characterizes as business purpose disclosures rather than sales....
-
OnlyFans
· OnlyFans Privacy Policy
The policy discloses that Creators must provide bank account information, VAT numbers, tax identification numbers, and US tax forms (W-9, 1099-MISC, 1099-NEC) as part of the onboarding and payment process, with Financial Data also collected as a verification and anti-fraud measure....
Why it matters: This provision establishes that Creator onboarding requires submission of tax identification data and IRS-reportable income forms, indicating that OnlyFans operates as a reporting entity for US tax purposes with respect to Creator earnings. The collection of W-9, 1099-MISC, and 1099-NEC forms indicates compliance with IRS reporting obligations for independent contractor payments....
-
OnlyFans
· OnlyFans Privacy Policy
The policy enumerates data subject rights including access, correction, deletion, restriction, portability, and consent withdrawal, and establishes an appeals process for US state residents whose privacy rights requests are denied, with a final escalation path to the relevant state Attorney General....
Why it matters: This provision establishes a multi-tier rights request and appeals process consistent with GDPR, UK GDPR, and US state privacy law requirements, including identity verification procedures for request submissions and authorization requirements for third-party representatives. The appeals escalation to state Attorneys General reflects compliance with Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and other state laws requiring internal appeals before regulatory escalation....
-
OnlyFans
· OnlyFans Privacy Policy
The policy states that OnlyFans moderates text and content uploaded to the platform, livestreams, and chat messages, and maintains records of banned users to prevent re-access, with legal bases including performance of a contract, compliance with legal obligations, and legitimate interests....
Why it matters: This provision establishes that chat messages and livestream content are subject to monitoring and moderation in addition to uploaded content, and that a permanent ban record is maintained under the legitimate interests legal basis. The filtration of direct messages is listed as a separate processing activity from general content moderation....
-
Google
· Google Terms of Service
When users upload or share content through Google services, they grant Google a worldwide, non-exclusive, royalty-free license to host, reproduce, distribute, modify, create derivative works from, publicly display, and sublicense that content for purposes including service operation, automated analysis, ad personalization, product promotion, and new technology development. This license persists for as long as the content retains intellectual property protection....
Why it matters: This provision establishes the contractual basis on which Google processes, analyzes, and uses user-generated content across its services, including through automated systems for ad targeting and machine learning model development. Organizations and users submitting content to Google services should assess whether the scope of this license, including sublicensing to contractors and use for new technology development, is compatible with their own data governance, confidentiality, or IP obligations....
-
Google
· Google Terms of Service
Google's maximum financial liability to users under these terms is capped at the greater of $200 or fees paid to Google in the 12 months preceding the dispute. The cap does not apply to liability arising from gross negligence or willful misconduct, and the document states the cap applies only to the extent permitted by applicable law....
Why it matters: This provision establishes the outer bound of Google's financial exposure to individual users in disputes arising under these terms, which is particularly significant for users who rely on Google services for business operations or data storage, where actual damages could substantially exceed $200 or prior fees paid. The carve-outs for gross negligence, willful misconduct, and applicable law limits introduce conditions under which the cap may not apply, which requires jurisdiction-specific legal analysis....
-
Google
· Google Terms of Service
The terms designate California law as governing all disputes and require that disputes be resolved exclusively in federal or state courts in Santa Clara County, California. Users consent to personal jurisdiction in those courts by accepting these terms. These terms do not include a mandatory arbitration clause or class action waiver....
Why it matters: This provision establishes the forum and applicable law for all disputes arising under these terms, requiring users located outside California to litigate in Santa Clara County courts. The absence of a mandatory arbitration clause or class action waiver is operationally notable relative to many large platform terms of service, as it preserves access to federal and state court litigation including potential class actions....
-
Google
· Google Terms of Service
Google reserves the right to suspend or terminate user access to services or delete Google Accounts for material or repeated terms violations, legal compliance requirements, court orders, or conduct causing harm or liability. The terms state that Google will provide advance notice and an opportunity to address the issue when reasonably possible, with specified exceptions....
Why it matters: This provision establishes the conditions and procedural framework under which Google may restrict or terminate access to its full suite of services, including email, cloud storage, and integrated third-party applications. Because a Google Account serves as authentication infrastructure for many third-party services, account termination may have operational consequences beyond Google's own products....
-
Google
· Google Terms of Service
Business users and organizations agree to indemnify Google and its personnel against third-party legal proceedings, including government enforcement actions, arising from unlawful service use or terms violations. The indemnification covers claims, losses, damages, fines, and legal fees....
Why it matters: This provision places financial indemnification obligations on business users and organizations for a broad range of third-party legal proceedings, including government authority actions, arising from their use of Google services in violation of the terms. The inclusion of government authority actions within the scope of indemnified proceedings is operationally significant for organizations in regulated industries....
-
Google
· Google Terms of Service
Google disclaims all express and implied warranties for its services, including warranties of merchantability, fitness for a particular purpose, and non-infringement, to the extent permitted by applicable law. The terms explicitly state that service content on medical, legal, and financial topics is informational only and not professional advice....
Why it matters: This provision disclaims warranty liability for service accuracy, reliability, and availability, which is operationally relevant for users or organizations that incorporate Google services into workflows dependent on service uptime or content accuracy. The explicit disclaimer regarding medical, legal, and financial content is particularly relevant given Google's AI-powered search and Gemini services....
-
Google
· Google Terms of Service
Google reserves the right to update these terms for reasons including service changes, legal or regulatory requirements, security, or abuse prevention, with reasonable advance notice for material changes. The terms state that continued use of services after a material update constitutes acceptance of the updated terms....
Why it matters: This provision establishes the conditions under which Google may modify the contractual terms governing user access to its services, with advance notice required for material changes except in specified urgent circumstances. Users who do not agree to updated terms are directed to remove their content and close their Google Account....
-
Google
· Google Terms of Service
Users below the minimum account management age must obtain parental or guardian consent to use a Google Account, and parents or guardians who permit their child's use accept these terms and bear responsibility for the child's activity on Google services....
Why it matters: This provision places parental responsibility for minor users' Google service activity on parents or guardians who permit that use, which has implications for content licensing, data processing, and terms compliance obligations where a minor submits content or engages in conduct that would otherwise be attributable to an adult user....
-
Google
· Google Terms of Service
The terms prohibit a defined list of abusive, harmful, and deceptive service uses, including malware, hacking, jailbreaking, adversarial prompting, prompt injection, creating fake accounts or reviews, misrepresenting AI-generated content as human-created, and using Google's AI-generated content to train third-party machine learning models....
Why it matters: This provision explicitly prohibits using AI-generated content from Google services to develop third-party machine learning models, which is operationally significant for AI developers, researchers, and organizations building products that incorporate outputs from Google's generative AI services. The prohibition on jailbreaking and adversarial prompting, except in authorized safety and bug testing programs, also has implications for security researchers....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The agreement permits use of user Inputs and Outputs for AI model training by default, with an opt-out available in account settings, but specifies two conditions under which training use continues regardless of opt-out status: when conversations are flagged for safety review, and when users have explicitly submitted content as feedback....
Why it matters: This provision establishes a conditional opt-out structure in which the training data opt-out right is subject to two categorical exceptions that may encompass a meaningful subset of user conversations. Compliance teams should evaluate whether this carve-out structure satisfies the opt-out right requirements under CCPA and the purpose limitation and legal basis requirements under GDPR and UK GDPR....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy discloses that identity or age verification processes may collect government-issued identity document images, photographic or video images of the user, and facial geometry templates, and acknowledges that facial geometry templates may qualify as biometric data under applicable law in certain jurisdictions....
Why it matters: This provision establishes that facial geometry template collection is within scope of Anthropic's data collection practices, and the policy's acknowledgment that such data may be classified as biometric data in some jurisdictions triggers compliance review obligations under state biometric privacy statutes that impose specific consent, retention, and destruction requirements....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy establishes that agentic sessions, in which Claude performs multi-step tasks including sending communications, modifying files, or interacting with third-party services on the user's behalf, generate Inputs and Outputs that Anthropic collects, and that personal data included in Inputs may be reproduced in Outputs....
Why it matters: This provision establishes that data generated during agentic sessions, including instructions that result in actions in external systems, is collected as part of the Services and may be used for the purposes described in the policy including model training. The scope of data collection extends to any personal data included in instructions or retrieved from connected third-party services....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy discloses that de-identified Inputs and Outputs, including those disassociated from user IDs for safety classification purposes, may be re-identified and linked back to specific users when necessary to enforce the Terms of Service or Usage Policy....
Why it matters: This provision establishes that de-identification of Inputs and Outputs for training purposes is conditional rather than permanent, and that Anthropic reserves the right to re-link de-identified content to specific user accounts for enforcement purposes. Compliance teams should evaluate whether this re-identification carve-out is consistent with de-identification representations made elsewhere in the policy and with applicable privacy law requirements....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy discloses that consumer accounts using an employer-owned or organization-owned email address may be linked to that organization's enterprise account, with implications for how personal data from that account is received or disclosed....
Why it matters: This provision establishes that consumer account data may be associated with an enterprise account controlled by a user's employer or organization when an organizational email address is used, which affects the confidentiality of user activity and the governance framework applicable to that data....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy states that EEA and UK personal data transferred outside those regions is covered by either European Commission adequacy decisions under Article 45 GDPR or Standard Contractual Clauses under Article 46 GDPR, with equivalent mechanisms for UK and Switzerland transfers, and that Brazil transfers rely on ANPD-approved SCCs....
Why it matters: This provision establishes the legal transfer mechanisms supporting Anthropic's global data flows for EEA, UK, Swiss, and Brazilian personal data, and specifies reliance on GDPR Articles 45 and 46 mechanisms. Compliance teams should verify that SCCs are executed with all relevant processors and that the subprocessor list referenced in the Trust Center is current....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy states that Anthropic's services are not directed at users under 18, that Anthropic does not knowingly collect personal data from minors under 18, and that measures are in place to detect and remove minors from the services....
Why it matters: This provision establishes a minimum age threshold of 18, which is higher than the 13-year COPPA threshold applicable in the US, and discloses that technical detection measures are in place to identify and remove underage users. The policy does not detail the specific detection methodology or its accuracy....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy states that Anthropic does not sell personal data as defined by applicable law, and that users may opt out of sharing personal data for targeted advertising of Anthropic's own products and services, including through global privacy controls such as browser-level signals....
Why it matters: This provision establishes that while Anthropic does not characterize its data practices as a sale of personal data, it does share personal data for targeted advertising of its own services, from which users may opt out. The policy states that Global Privacy Control signals will be honored, which is relevant to California and other state privacy compliance....
-
Anthropic
· Anthropic Privacy Policy (Superseded Capture)
The policy establishes a rights request submission process requiring identity verification, sets a one-month response timeline for GDPR and UK GDPR requests with a possible two-month extension for complex or multiple requests, and requires authorization evidence for third-party representative requests....
Why it matters: This provision establishes the procedural framework for exercising data subject rights including access, deletion, correction, portability, objection, and restriction, and specifies the verification and timeline requirements that govern request processing under GDPR, UK GDPR, and other applicable laws....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement authorizes Microsoft to use personal data, including data generated through product use, to develop, train, and fine-tune AI models including large language models. In some markets, users can opt out of their conversation data being used to train AI models in Microsoft Copilot....
Why it matters: This provision establishes that personal data collected through Microsoft products may be used for AI model development and training, including LLMs. The opt-out mechanism is described as market-dependent, meaning it may not be available to all users, and the statement does not specify which markets have access to the opt-out....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement authorizes Microsoft to use Copilot prompts, location, and related settings to deliver relevant advertising as part of the Copilot service. This applies to the consumer Microsoft Copilot website and app....
Why it matters: This provision establishes that conversational input submitted to Microsoft Copilot, including user prompts, may be used to deliver advertising. The statement separately notes that Microsoft does not use email content, human-to-human chat, video calls, or personal files to target ads, but Copilot prompt data is disclosed as an advertising input....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement authorizes Microsoft to retain, access, transfer, and disclose user content, including emails and files stored in Outlook and OneDrive, based on a good faith belief that such access is necessary for legal compliance, safety, security, or protection of Microsoft's rights. This standard is self-assessed by Microsoft rather than requiring a judicial or regulatory determination prior to access....
Why it matters: This provision establishes that Microsoft may access and disclose the substantive content of user communications and stored files under a self-assessed good faith standard. The breadth of the triggering conditions, which includes protecting Microsoft's rights and property as well as responding to legal process, means this provision may be invoked across a wide range of circumstances....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement authorizes Microsoft to share collected personal data with named third-party advertising partners including Facebook, Yahoo, The Trade Desk, Taboola, Outbrain, and Media.net for purposes of delivering personalized advertising across Microsoft and third-party properties. The list is described as non-exhaustive....
Why it matters: This provision discloses data flows to a named but non-exhaustive list of third-party advertising companies, with data used for cross-site behavioral advertising. The non-exhaustive characterization means additional advertising partners beyond those named may receive personal data under these terms....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
Microsoft certifies compliance with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, subjecting it to FTC enforcement and onward transfer liability for agent processing. Residual complaints not resolved through other mechanisms may proceed to binding arbitration under DPF Principles....
Why it matters: This provision establishes Microsoft's legal mechanism for cross-border personal data transfers from the EU, UK, and Switzerland to the United States. It also establishes that Microsoft retains liability for onward transfers to third-party agents, and that binding arbitration is the final dispute resolution mechanism for DPF-related complaints that cannot be resolved through other channels....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement requires parental consent for account creation by children under 13 (or a higher age where required by local law), prohibits personalized advertising to users identified as under 18, and limits data collection from children to what is necessary for the product. Parents can revoke consent and access or delete child data through the privacy dashboard....
Why it matters: This provision establishes the conditions under which children's accounts may be created and the data protections applied to users under 18, including a blanket prohibition on personalized advertising to users identified as minors based on their Microsoft account birthdate. Parent and guardian controls are available through the Microsoft Family Safety tools and privacy dashboard....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
Windows collects required diagnostic data covering device configuration, performance, and update status, and optional diagnostic data that includes app activity, browser history, search terms in Microsoft Edge, and enhanced error reports that may contain fragments of user content. Users can choose between required and optional diagnostic data levels in Windows settings....
Why it matters: This provision establishes that optional diagnostic data in Windows may include browsing history and search terms from Microsoft Edge, as well as error reports that may unintentionally contain user content such as file fragments. The statement acknowledges this risk explicitly for enhanced error reporting....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement does not specify fixed retention periods for most data categories, instead providing criteria-based standards that include business operations, legal obligations, product improvement, and dispute resolution. Retention periods are described as varying significantly by data type and context....
Why it matters: This provision establishes that retention periods are determined by Microsoft based on a multi-factor criteria framework rather than fixed schedules, meaning users and compliance teams cannot determine specific data retention timelines from this statement alone. Product-specific documentation is referenced for additional detail....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement asserts that Microsoft provides data protection rights to all users regardless of location, including rights to access, erasure, correction, portability, withdrawal of consent, and objection to processing. These rights are exercisable via the Microsoft Privacy Dashboard and the privacy support and requests page....
Why it matters: This provision establishes that Microsoft asserts GDPR-equivalent data protection rights as a baseline for all users globally, not only those in jurisdictions where such rights are legally mandated. The practical availability and fulfillment of these rights depends on the specific product and data type involved....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
For enterprise and developer products, the applicable customer agreement supersedes this privacy statement in the event of conflict. Organizations using Microsoft products with work or school accounts have administrative access to and control over employee or student data, including communications, files, and diagnostic data....
Why it matters: This provision establishes that employees and students using Microsoft products through organizational accounts are subject to their organization's data governance policies and that the organization, not Microsoft, is the primary data controller for those interactions. The provision directs end users to their organization's administrator for privacy inquiries rather than to Microsoft....
-
Cursor
· Cursor Data Use & Privacy Overview
Privacy Mode activates zero data retention agreements with all model providers, preventing training use of Customer Data, but the document states that prompts or conversations triggering abuse detection classifiers may be stored by model providers including Cursor for investigation under their own retention policies....
Why it matters: This provision establishes that Privacy Mode does not constitute an absolute data retention barrier; a carve-out permits storage of user data triggered by abuse detectors, with retention duration and deletion governed by the individual model provider's policies rather than Cursor's own terms....
-
Cursor
· Cursor Data Use & Privacy Overview
With Privacy Mode disabled, the document authorizes Cursor to use and store codebase data, prompts, editor actions, and code snippets for AI model training and feature improvement, and to share prompts and limited telemetry with model providers selected by the user....
Why it matters: This provision authorizes broad use of source code and prompt data for AI training purposes when Privacy Mode is off, including data categories that may contain proprietary code, personal data of third parties, or trade secret information depending on the nature of the user's codebase....
-
Cursor
· Cursor Data Use & Privacy Overview
The document discloses that named third-party inference providers Baseten, Together AI, and Fireworks may temporarily access and store model inputs and outputs, with deletion occurring after use, when Privacy Mode is disabled....
Why it matters: This provision identifies specific third-party subprocessors by name and authorizes temporary storage of model inputs and outputs by those providers, with retention duration determined by the phrase 'deleted after use' rather than a defined timeframe....
-
Cursor
· Cursor Data Use & Privacy Overview
The document states that requests made using a user's own API key are routed through Cursor's backend for final prompt construction, rather than being sent directly to the model provider....
Why it matters: This provision establishes that API key users do not bypass Cursor's data processing infrastructure, meaning the data handling terms described in this document apply to API key-based requests including any applicable training use or logging provisions....
-
Cursor
· Cursor Data Use & Privacy Overview
The document states that codebase indexing uploads code in chunks to Cursor's servers, with plaintext code deleted after each request, but embeddings and metadata including file hashes and file names may be retained in Cursor's database....
Why it matters: This provision establishes that while plaintext code is not persistently stored during indexing, derived artifacts including vector embeddings and file metadata such as hashes and file names may be retained in Cursor's database, which may carry data governance implications for users with sensitive or proprietary codebases....
-
Cursor
· Cursor Data Use & Privacy Overview
A footnote in the document states that prompts and limited telemetry will not be shared with model providers when Privacy Mode is off if the user's account was created before October 15, 2025....
Why it matters: This provision creates a data sharing exemption that is account-creation-date-dependent, meaning the applicable data handling terms differ between users based on when they registered, without a mechanism described in this document for users to verify or confirm their account creation date eligibility....
-
Mistral AI
· Mistral AI Usage Policy
The policy states that any generation or attempted generation of child sexual abuse material on Mistral AI platform products is strictly prohibited and will result in immediate account termination and reporting to law enforcement authorities....
Why it matters: This provision establishes a non-discretionary enforcement and reporting mechanism for CSAM violations, combining account termination with a stated obligation to report to law enforcement. The clause covers both actual and suspected CSAM, which may interact with applicable reporting obligations under national child protection laws and EU Digital Services Act provisions....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits users from using Mistral AI platform products to provide investment, financial, legal, or medical advice or guidance, except where the user holds 'proper qualification,' a term the policy does not define....
Why it matters: This provision introduces an undefined qualification exception ('without proper qualification') that creates interpretive ambiguity for enterprise users in regulated sectors such as financial services, legal services, and healthcare who may use the platform to support qualified professionals. The operational boundary between prohibited unqualified advice and permitted qualified professional use is not specified in the policy....
-
Mistral AI
· Mistral AI Usage Policy
The policy reserves the right to modify its terms at any time without specifying advance notice to users, directing users to check the policy website frequently for updates....
Why it matters: This provision establishes that changes to the Usage Policy may take effect upon publication without prior user notification, placing the obligation to monitor for changes on the user. For enterprise customers who have integrated Mistral AI platform capabilities into regulated workflows, this creates a dependency on proactive monitoring of policy changes to maintain compliance with applicable commercial and regulatory obligations....