-
Mistral AI
· Mistral AI Usage Policy
The policy explicitly states that its terms do not apply to Mistral AI models or products deployed on customer or partner infrastructure, or to Mistral AI's open-source models, limiting the policy's scope to platform-hosted products only....
Why it matters: This provision establishes that users who self-host Mistral AI models or access them through partner-deployed infrastructure are not subject to this Usage Policy, meaning separate governance frameworks apply to those deployment contexts. Institutional customers evaluating compliance coverage across their AI deployment stack should identify which governance documents apply to non-platform deployments....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits generating intimate images of any person using Mistral AI products unless all individuals depicted have provided explicit consent....
Why it matters: This provision applies the explicit consent requirement to all individuals depicted, not only the user, creating a compliance obligation that extends beyond the user's own consent. The term 'intimate images' is not defined in the policy, which may introduce interpretive ambiguity about the scope of the restriction....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits generating content that promotes hate or discrimination based on specified characteristics, engages in historical revisionism or genocide denialism, or constitutes harassment or glorification of suffering....
Why it matters: The explicit inclusion of Holocaust denial and genocide revisionism as prohibited content categories reflects obligations under applicable law in multiple EU jurisdictions where denial of certain historical events is criminalized. The broad scope of the prohibition across multiple protected characteristics and the inclusion of 'any target' for harassment language creates an expansive restriction that applies across all platform content....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits using Mistral AI products to create malware, exploit security vulnerabilities in any system, or attempt to bypass Mistral AI's security protections and AI safety filters....
Why it matters: The prohibition on circumventing AI safety filters is operationally significant for security researchers, red-team practitioners, and adversarial AI testing professionals, as the policy does not include an exception for authorized security research or vulnerability disclosure programs. The breadth of the prohibition to include security compromise of 'any third party' extends the restriction beyond Mistral AI's own systems....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits generating deliberately misleading or false content, including health and scientific misinformation, content that undermines civic or political processes, harmful conspiracy theories, and misinformation targeting protected groups....
Why it matters: The prohibition on content that 'undermines the integrity of a civic or political process' is operationally significant given the broad scope of activities that could be characterized as political, including legitimate political commentary, satire, and advocacy. The policy's use of 'for instance' framing indicates these are non-exhaustive examples, meaning the prohibition may extend beyond the enumerated categories....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits generating content that violates others' privacy, including using a person's likeness or voice to generate outputs or impersonate them without their prior consent....
Why it matters: The prohibition on using another person's likeness or voice without prior consent intersects with right-of-publicity law, biometric privacy statutes, and GDPR provisions on special category data including biometric data used for identification purposes. The policy uses 'for instance' framing, indicating the privacy prohibition is not limited to the likeness and voice examples provided....
-
Mistral AI
· Mistral AI Usage Policy
The policy states that violations may result in temporary suspension or permanent termination of accounts, and that certain violations may be reported to law enforcement or other relevant authorities, with the determination of what is 'appropriate' left to Mistral AI's discretion....
Why it matters: The discretionary 'where appropriate' formulation for law enforcement reporting means Mistral AI retains sole discretion over which violations are reported to authorities beyond the mandatory CSAM reporting obligation. The policy does not describe appeal procedures, notice requirements prior to account termination, or a mechanism for users to contest enforcement decisions....
-
Anthropic
· Anthropic Sub-Processors
The document lists Palantir Federal Cloud Service (PFCS) as the sole subprocessor for the Claude for Government product, designated specifically as a FedRAMP Cloud environment located in the United States. All other subprocessors listed are explicitly excluded from the Claude for Government product line....
Why it matters: This provision establishes that Claude for Government operates on a distinct, isolated subprocessor infrastructure from all other Claude products, consistent with FedRAMP authorization requirements applicable to U.S. federal agency data. Compliance teams evaluating Claude for Government for federal procurement must confirm the applicable FedRAMP authorization level (Moderate, High, or tailored) and impact classification applicable to PFCS....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Nutun, located in South Africa, as a subprocessor providing user support functions across all Anthropic Claude products except Claude for Government. South Africa is not the subject of an EU adequacy decision under GDPR....
Why it matters: The use of a South Africa-based subprocessor for user support functions creates international data transfer obligations under GDPR Chapter V for EU and UK personal data, requiring either Standard Contractual Clauses, Binding Corporate Rules, or another recognized transfer mechanism. Enterprise customers with GDPR obligations should verify that Anthropic's DPA addresses this transfer adequately....
-
Anthropic
· Anthropic Sub-Processors
The document identifies two subprocessors, Persona (United States) and Yoti (United Kingdom), as handling fraud and abuse detection and identity verification specifically for Claude Free, Pro, and Max consumer accounts. These functions are not listed for Claude for Work, Claude Developer Platform, or Claude for Government....
Why it matters: Identity verification functions typically involve processing government-issued identity documents and may involve biometric data depending on the verification method, creating potential obligations under GDPR, UK GDPR, and state-level biometric privacy laws such as Illinois BIPA. The product-specific scope, limited to consumer-tier accounts, means enterprise and developer platform users are not subject to this processing under these listed subprocessors....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Google Cloud Platform, Amazon Web Services, and Microsoft Azure as cloud infrastructure subprocessors for all Anthropic products worldwide. All three are designated as operating worldwide....
Why it matters: The use of three major cloud infrastructure providers across all products means that data processed through any Claude product, including user inputs and model outputs, is hosted within the infrastructure of one or more of these providers. Enterprise customers should verify that their DPAs with Anthropic address how workloads are distributed across these three providers and confirm that applicable data residency requirements, if any, are satisfied....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Stripe, located in the United States, as the billing subprocessor for Claude Pro/Max, Claude Developer Platform, and Claude for Work products. Stripe is not listed for Claude Free or Claude for Government....
Why it matters: The designation of Stripe as the billing subprocessor for paid Claude products confirms that payment card and billing data for these products is processed by Stripe in the United States. Enterprise customers and individuals subject to GDPR should confirm that Anthropic's DPA addresses the transfer of billing-related personal data to Stripe....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Sift and Arkose Labs, both located in the United States, as subprocessors providing fraud and abuse detection across all Claude products except Claude for Government....
Why it matters: Fraud and abuse detection systems typically analyze behavioral signals, device fingerprints, IP addresses, and usage patterns to identify anomalous activity. Processing of this data by two separate U.S.-based vendors across all non-government products creates data sharing obligations under GDPR and may be relevant to user transparency and profiling disclosures....
-
Anthropic
· Anthropic Sub-Processors
The document lists three subprocessors providing user support functions across all Claude products except Claude for Government: Intercom in the United States, Nutun in South Africa, and Boldr in Canada. All three are explicitly excluded from Claude for Government....
Why it matters: User support processing typically involves contact information, account details, and the content of support communications, which may include sensitive personal information. The geographic distribution across three jurisdictions, including South Africa (no EU adequacy decision), creates multi-jurisdictional transfer documentation requirements for GDPR-covered data....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Twilio and Iterable, both in the United States, as subprocessors for analytics, email, and SMS communications across all Claude products except Claude for Government. Twilio is designated for analytics and email/SMS communications; Iterable is designated for email communications....
Why it matters: Analytics and communications subprocessors process contact information, behavioral signals, and communication content including email and SMS interactions. Enterprise customers subject to GDPR or CCPA should confirm that communications data flows to these vendors are addressed in their data processing documentation....
-
Anthropic
· Anthropic Sub-Processors
The document lists Brave Search and TurboPuffer, both in the United States, as subprocessors for web search functionality. Brave Search applies to all Claude products including Claude for Government; TurboPuffer applies to all products except Claude for Government....
Why it matters: Web search subprocessors process user queries that may contain personal information or sensitive content. Brave Search's inclusion across all products, including Claude for Government, while TurboPuffer is excluded from Claude for Government, creates a distinction in web search infrastructure between government and non-government product lines....
-
Anthropic
· Anthropic Sub-Processors
The document identifies ElevenLabs, located in the United States, as the text-to-speech subprocessor for Claude for Work. This function is not listed for other Claude product tiers....
Why it matters: Text-to-speech processing involves audio synthesis from text input, which may process document content, user-generated text, or other data submitted through Claude for Work. Enterprise customers deploying Claude for Work in contexts involving confidential business information should confirm what content categories are processed by ElevenLabs....
-
Minecraft
· Minecraft Privacy Statement
The page footer references separate documents titled 'Privacy and Cookies,' 'Consumer Health Privacy,' and 'Terms of use' as the locations where operative privacy and data terms are disclosed, rather than presenting those terms on this page....
Why it matters: The operative privacy terms governing Minecraft user data are not contained on this page but are distributed across multiple externally linked documents, which compliance teams would need to obtain and review separately to assess data collection, sharing, and user rights provisions....
-
Minecraft
· Minecraft Privacy Statement
The page footer includes a distinct 'Consumer Health Privacy' link separate from the general 'Privacy and Cookies' link, indicating the existence of a separate notice addressing consumer health data....
Why it matters: The presence of a separate Consumer Health Privacy notice may indicate that Minecraft or its parent Microsoft collects or processes health-related data subject to jurisdiction-specific statutes such as the Washington My Health MY Data Act or similar state laws, though the content of that notice is not available in the provided text....
-
Minecraft
· Minecraft Privacy Statement
The page footer includes a 'Manage Consent' link, indicating the availability of a consent management mechanism for cookies or tracking technologies....
Why it matters: The presence of a Manage Consent interface indicates that users may be able to adjust cookie or tracking preferences, which is a requirement under GDPR, the ePrivacy Directive, and equivalent frameworks for users in the EU and UK....
-
Minecraft
· Minecraft Privacy Statement
The footer includes a 'Your Privacy Choices' link attributed to Microsoft, indicating the presence of a privacy rights exercise mechanism consistent with U.S. state privacy law requirements....
Why it matters: The 'Your Privacy Choices' link is associated with opt-out rights under CCPA and CPRA, specifically the right to opt out of the sale or sharing of personal information; its placement in the Minecraft footer indicates that these rights are available to applicable users through the Microsoft privacy framework....
-
Minecraft
· Minecraft Privacy Statement
The page footer attributes copyright to Mojang AB and trademark to Microsoft Corporation, indicating a dual-entity governance structure for the Minecraft platform that may affect which entity acts as data controller under applicable privacy frameworks....
Why it matters: The joint attribution of Mojang AB and Microsoft Corporation in the footer is relevant to determining controller identity under GDPR and equivalent frameworks, which affects which entity bears primary data protection obligations and which privacy documentation governs user data....
-
Threads
· Threads Privacy Policy
This provision states that when users interact with or enable content sharing with third-party federated services, Threads transmits user profile information, post content, attachments, and metadata (including server IP address and interaction timestamps) to those external services, which then store and process that data under their own terms. The policy frames this transmission as user-directed, occurring when users enable interoperable capabilities or interact with third-party content....
Why it matters: This provision establishes that data transmitted to third-party federated services exits Meta's data governance perimeter and becomes subject to the terms and policies of those external services. Compliance teams must account for this data flow boundary when conducting data mapping, assessing data subject rights fulfillment, or evaluating cross-border data transfer obligations....
-
Threads
· Threads Privacy Policy
This provision states that Meta's ability to verify and process data deletion requests submitted directly by third-party federated service users is described as limited, and that Meta may be unable to process such requests. The policy states that deletion signals transmitted automatically via the interoperable protocol from third-party services will receive reasonable efforts to honor....
Why it matters: This provision establishes a qualified data deletion pathway for third-party federated service users, conditioning fulfillment on Meta's ability to verify the request and committing only to reasonable efforts for protocol-based deletion signals. This may require evaluation under GDPR's right to erasure and CCPA's deletion rights framework, particularly regarding the adequacy of the deletion mechanism for non-Threads users whose data has been collected by Threads....
-
Threads
· Threads Privacy Policy
This provision states that username, name, profile picture, and bio are always public on Threads regardless of whether the user has set their profile to private or public, and are accessible to anyone on or off Meta Products. Post content visibility is configurable via private or public profile settings, but the four enumerated profile fields are not subject to audience restriction....
Why it matters: This provision establishes that four categories of user data (username, name, profile picture, bio) are permanently public and not subject to the audience controls available for other content. Compliance teams assessing user data minimization or privacy-by-default configurations should note that these fields cannot be restricted regardless of profile setting....
-
Threads
· Threads Privacy Policy
This provision states that Threads uses account information from the Instagram, Facebook, or other linked account used to sign up in order to generate connection recommendations on Threads, and that this use is bidirectional, meaning Threads activity may also inform recommendations on the linked account....
Why it matters: This provision authorizes cross-product data use between Threads and other linked Meta accounts for the purpose of connection recommendations. Compliance teams assessing Meta's cross-product data integration practices should note that this provision explicitly extends the data use relationship bidirectionally between Threads and linked accounts....
-
Threads
· Threads Privacy Policy
This provision states that Threads collects data about users of third-party federated services who interact with Threads content, including their username, profile picture, the name and IP address of their third-party service, content they share with Threads users, and their interaction activity with Threads content. This collection occurs regardless of whether the third-party user has a Threads account....
Why it matters: This provision establishes that Threads collects personal data, including IP address-level metadata of third-party service infrastructure, from individuals who are not Threads users but who interact with Threads content via the fediverse. This data collection may engage privacy regulatory frameworks in jurisdictions where those third-party users are located, and may require evaluation regarding lawful basis and notice obligations under GDPR and similar frameworks....
-
Threads
· Threads Privacy Policy
This provision establishes that the Threads Supplemental Privacy Policy does not stand alone but operates in conjunction with the Meta Privacy Policy, which governs the full scope of information processing for Meta Products including Threads. Users must review both documents to understand the complete data governance framework applicable to their Threads use....
Why it matters: This provision means that the data practices applicable to Threads users are governed by a two-document framework, and that the Threads Supplemental Privacy Policy provides additional detail rather than a complete standalone disclosure. Compliance and legal teams conducting data governance assessments must account for the full Meta Privacy Policy in addition to this supplemental document....
-
Threads
· Threads Privacy Policy
This provision describes the audience control mechanisms available to Threads users: a binary private or public profile setting, and the ability to block individual accounts. A private profile limits content visibility to approved followers, while a public profile makes content visible to anyone including third-party federated services and other Meta products. Blocking individual accounts provides an additional restriction layer....
Why it matters: This provision establishes the operational scope of Threads' audience control tools, which determine the reach of user content to third-party federated services and other Meta products. The provision conditions fediverse content sharing on whether the user has enabled interoperable capabilities, providing a discrete control point for federated distribution....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
When a supplemental term such as the AI Terms of Use, Data Processing Agreement, or Security Exhibit conflicts with the base Terms of Service, the supplemental term governs on that subject matter. Each supplemental term activates only when its stated condition is met....
Why it matters: This provision establishes the contractual priority structure across all Sourcegraph legal documents, which determines which obligations and limitations apply to a given customer in cases of conflict. Legal teams must assess which supplemental terms are triggered by their specific agreement conditions to understand the complete applicable framework....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
Customers with agreements predating February 15, 2024, or whose order forms explicitly reference the AI Terms of Use, are governed by separate AI-specific terms. All other customers have their AI tool usage governed by the base Terms of Service....
Why it matters: This provision creates two distinct legal frameworks governing AI tool usage depending on agreement execution date, which means enterprise customers may be operating under materially different AI-related obligations, rights, and limitations depending solely on when their agreement was signed....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Security Exhibit applies to all users of generally available Sourcegraph products and governs how Sourcegraph handles User Content, source code, and Confidential Information submitted through the platform....
Why it matters: This provision identifies that source code and Confidential Information processed through Sourcegraph are subject to a dedicated Security Exhibit, which is a material consideration for enterprise customers whose proprietary codebases are processed by the Cody AI assistant....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Data Processing Agreement activates when Sourcegraph processes Customer Personal Data on behalf of a customer, establishing a controller-processor relationship for the purposes of applicable data protection law....
Why it matters: This provision triggers the activation of the Data Processing Agreement when Sourcegraph processes personal data on a customer's behalf, which is a required contractual mechanism under GDPR Article 28 and analogous data protection frameworks for controller-processor relationships....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Privacy Policy applies to all users of any Sourcegraph product or service and governs personal data that Sourcegraph collects and uses in its capacity as a Data Controller....
Why it matters: This provision establishes that Sourcegraph acts as a Data Controller for personal data collected through its products, which under GDPR imposes direct legal obligations on Sourcegraph regarding lawful basis for processing, data subject rights, and accountability independent of the agreement's own terms....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
A dedicated set of supplemental terms applies to employees and contractors of the U.S. Government who use Sourcegraph products and services....
Why it matters: This provision identifies a distinct legal framework applicable to U.S. Government users, which is operationally relevant for federal procurement compliance and may address Federal Acquisition Regulation requirements, data handling restrictions applicable to federal systems, and government-specific use limitations....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Acceptable Use Policy applies to all users of any Sourcegraph product or service without exception....
Why it matters: This provision establishes that the Acceptable Use Policy is a universally applicable supplemental term, meaning its restrictions and requirements govern all user interactions with Sourcegraph products regardless of account type, agreement date, or order form contents....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Professional Services Terms apply when a customer's order form includes Professional Services, supplementing the base Terms of Service for those specific engagements....
Why it matters: This provision establishes that customers who procure Professional Services through Sourcegraph are subject to an additional set of terms that control over the base Terms of Service on Professional Services subject matter, which may include delivery obligations, acceptance criteria, IP ownership, and liability terms specific to services engagements....
-
Character.AI
· Character.AI Safety Center
The Parental Insights tool allows teen users to invite parents or guardians to receive a weekly activity report disclosing time spent on the platform and the top Characters interacted with. Both the initiation of sharing and the removal of parental access are controlled by the teen user, with parents receiving a confirmation email before removal takes effect....
Why it matters: This provision establishes a teen-controlled parental visibility mechanism, in which the minor user determines whether, with whom, and when activity data is shared with a parent or guardian. The design, in which the teen initiates and terminates parental access, may warrant evaluation under COPPA and analogous minor-protection frameworks that address the adequacy of parental consent and oversight mechanisms....
-
Character.AI
· Character.AI Safety Center
The document references community guidelines governing platform conduct and describes the platform's safety-by-design approach as anchored by a goal of creating a safe and engaging experience....
Why it matters: This provision references community guidelines as the operative framework for content moderation on the platform, but the Safety Center page does not reproduce or summarize the specific moderation rules, enforcement mechanisms, or account action procedures....
-
Character.AI
· Character.AI Safety Center
The document references a support and reporting function accessible through a linked resource, but does not describe the mechanism, scope, or response timelines on this page....
Why it matters: The provision references a reporting and support pathway but does not disclose what categories of conduct can be reported, what response procedures apply, or what timelines govern the company's review of reports....
-
Character.AI
· Character.AI Safety Center
The Safety Center page references but does not reproduce Character.AI's Privacy Policy, Regional Privacy Disclosures, Cookie Policy, Terms of Service, and Privacy Choices mechanism, which govern the operative legal relationship with users....
Why it matters: The operative contractual and data processing terms applicable to users are located in the referenced documents, not in this Safety Center page; any compliance assessment of Character.AI's user data practices, arbitration provisions, or consumer rights requires review of those documents....
-
Character.AI
· Character.AI Safety Center
The document states that Character.AI's safety approach is anchored by a goal of creating a safe and engaging experience, and describes safety topics including parental insights, content moderation, teen safety, and reporting....
Why it matters: This provision articulates a general safety commitment but does not establish specific operational standards, metrics, timelines, or enforcement mechanisms that would allow compliance teams to assess implementation....
-
Runway
· Runway Usage Policy
The policy states that Runway may suspend a user's account for any violation of the usage policy, with an appeal process available via email to suspension@runwayml.com....
Why it matters: This provision reserves broad discretionary suspension authority without specifying a graduated enforcement process, notice period, or defined timeline for appeal resolution, which creates operational continuity exposure for enterprise and business users relying on platform access....
-
Runway
· Runway Usage Policy
The policy prohibits any content depicting, facilitating, or promoting child sexual abuse or sexualization of minors, requires reporting of CSAM to NCMEC, and states that all accounts associated with CSAM are indefinitely suspended....
Why it matters: This provision reflects mandatory federal reporting obligations under U.S. law for online platforms that become aware of CSAM, and the indefinite suspension of associated accounts represents the most severe enforcement action described in this policy....
-
Runway
· Runway Usage Policy
The policy prohibits using Runway's tools to create or modify non-consensual intimate imagery of real individuals....
Why it matters: This provision addresses a category of AI-generated content that engages a growing body of federal and state legislation specifically targeting AI-generated NCII, including the DEFIANCE Act and numerous state statutes, making this prohibition legally material for both users and the platform....
-
Runway
· Runway Usage Policy
The policy prohibits generating content that may violate intellectual property rights and separately prohibits attempting to create content in the style of a known living artist....
Why it matters: The prohibition on content in the style of a known living artist represents a notable policy position in the generative AI context, engaging unsettled questions under copyright law and personality rights doctrines that are the subject of active litigation and regulatory attention as of the document's publication date....
-
Runway
· Runway Usage Policy
The policy prohibits using Runway's tools to impersonate individuals or entities, misrepresent affiliation, defraud, scam, or deliberately mislead others....
Why it matters: This provision addresses AI-generated deepfake and synthetic media use cases that engage FTC Act Section 5 prohibitions on deceptive practices and, for election-related contexts, emerging federal and state AI transparency and disclosure requirements....
-
Runway
· Runway Usage Policy
The policy establishes additional prohibitions specific to Runway's Characters and Game Worlds products, including prohibitions on characters modeled on minors' likeness or voice, content targeting users under 18, and AI characters designed to simulate professional medical, legal, financial, or therapeutic advice....
Why it matters: The prohibition on characters targeting users under 18 engages COPPA obligations and platform-level duty-of-care frameworks applicable to AI products used by or designed to attract minors. The prohibition on AI characters simulating professional advice engages FTC guidance on AI-generated professional recommendations and state-level professional licensing frameworks....
-
Runway
· Runway Usage Policy
The policy states that the listed prohibitions are not exhaustive and that the policy will be updated over time as Runway's products and their uses change....
Why it matters: This clause reserves Runway's authority to modify the scope of prohibited conduct without specifying a notice period or user consent mechanism for material changes, which creates ongoing compliance uncertainty for enterprise users who have structured workflows around the current policy terms....
-
Runway
· Runway Usage Policy
The policy prohibits using another person's image, video, or audio without their permission as an input or basis for content generation on Runway's platform....
Why it matters: This provision engages right of publicity law, biometric privacy statutes, and personality rights frameworks across multiple jurisdictions, and is operationally relevant for enterprise users generating synthetic media that incorporates real individuals' likenesses or voices....