-
Synthesia
· Synthesia Privacy Policy
The policy explicitly states that Synthesia will not sell, lease, trade, or otherwise profit from biometric data, and extends this prohibition to its vendors. This commitment applies to facial geometry, voiceprint, and related biometric identifiers collected during avatar creation....
Why it matters: This provision directly addresses a key requirement of the Illinois Biometric Information Privacy Act and reflects a disclosure that aligns with BIPA's prohibition on selling or profiting from biometric identifiers. The explicit extension of this prohibition to vendors provides an additional layer of contractual commitment beyond Synthesia's own operations....
-
Synthesia
· Synthesia Privacy Policy
The policy states that personal data may be transferred outside the UK and EEA, with transfers protected by European Commission adequacy decisions under GDPR Article 45 or standard contractual clauses under GDPR Article 46. Users may obtain copies of applicable decisions or clauses by contacting support@synthesia.io....
Why it matters: This provision establishes the legal mechanisms Synthesia relies on for cross-border personal data transfers, directly engaging GDPR Chapter V obligations. The disclosure that biometric data may be transferred to third-party vendors including Amazon Web Services EMEA SARL is particularly relevant for compliance assessments given the special category status of biometric data under GDPR Article 9....
-
Synthesia
· Synthesia Privacy Policy
The policy states that personal data including contact information, financial data, usage data, technical data, and potentially biometric data may be transferred to third parties in the event of a merger, acquisition, asset sale, bankruptcy, or insolvency, including during pre-transaction due diligence....
Why it matters: This provision reserves the right to transfer personal data including biometric data to acquiring entities or parties involved in due diligence prior to any transaction closing, which may occur before users are notified of the transfer. The inclusion of biometric data in potentially transferable assets creates heightened compliance considerations under BIPA and GDPR Article 9....
-
Writer
· Writer Privacy Policy
The policy authorizes Writer to aggregate or de-identify collected user data and share that de-identified data with any third party, including advertisers, partners, and sponsors, for any purpose including research and marketing....
Why it matters: This provision establishes that once data is de-identified as defined by Writer, it may be disclosed to an unrestricted set of third parties for unrestricted purposes. The policy does not specify the technical standard used to achieve de-identification, and the definition relies on data no longer being linkable to a user or device rather than a codified regulatory standard....
-
Writer
· Writer Privacy Policy
The policy authorizes third-party advertising partners, including Google, to place cookies and tracking technologies on users' devices to collect behavioral data and serve targeted advertising across other websites and applications....
Why it matters: This provision establishes that third-party advertising networks, operating under their own privacy policies, collect user data through Writer's platform for cross-site behavioral advertising. This creates data flows governed by third-party terms outside Writer's direct control....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Writer
· Writer Privacy Policy
Writer certifies compliance with the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework for personal data transferred from the EEA, UK, and Switzerland, and is subject to FTC enforcement authority for DPF compliance failures....
Why it matters: This provision establishes the legal transfer mechanism Writer relies upon for personal data flows from the EEA, UK, and Switzerland to the United States, and designates JAMS as the dispute resolution provider with binding DPF arbitration available as a final recourse mechanism for unresolved complaints....
-
Writer
· Writer Privacy Policy
The policy states that collected user data may be transferred to and stored in the United States and other countries, and that continued use of the services constitutes acknowledgment that such transfers will occur....
Why it matters: This provision relies on continued use of the services as acknowledgment of international data transfers. Under GDPR, transfer mechanisms must meet specific legal standards, and acknowledgment-by-use may require evaluation as a valid GDPR Chapter V transfer basis depending on the jurisdiction and regulatory interpretation....
-
Jasper AI
· Jasper Privacy Policy
The policy governs data processing associated with user-submitted content inputs across Jasper's AI tools including Jasper Chat, AI Studio, Image Pipelines, and the API layer. The scope of this processing encompasses content generated, submitted, or processed through these systems....
Why it matters: This provision establishes the operational scope of data processing for AI-generated and user-submitted content across Jasper's product surface. Enterprise and API customers should evaluate what data handling obligations apply to content inputs submitted through these systems, particularly where inputs may contain personal or proprietary information....
-
Jasper AI
· Jasper Privacy Policy
The policy addresses sharing of user data with third-party service providers, analytics partners, and integration partners across Jasper's product ecosystem. The specific categories of third parties and the scope of data shared are disclosed within the policy's data sharing provisions....
Why it matters: This provision establishes the conditions under which user data is disclosed to third parties including analytics vendors, infrastructure providers, and integration partners. The breadth of Jasper's product surface including browser extensions, APIs, and third-party integrations means the third-party data sharing perimeter may extend across multiple systems....
-
Jasper AI
· Jasper Privacy Policy
The policy includes provisions addressing the privacy rights of California residents under applicable state law, including rights associated with data access, deletion, and opt-out of certain data sharing practices. These provisions are referenced in the policy's legal information section....
Why it matters: This provision establishes the rights available to California residents under CCPA/CPRA, including access, deletion, correction, and opt-out rights. The operational availability and mechanism for exercising these rights is a material compliance consideration for Jasper's California-based user base....
-
Jasper AI
· Jasper Privacy Policy
The policy addresses data rights and processing obligations for EU, EEA, and UK users under applicable international data protection frameworks. The scope of these provisions and the designated lawful bases for processing are referenced in the policy's international user sections....
Why it matters: This provision establishes the terms under which EU, EEA, and UK user data is processed, including the lawful basis assertions and data subject rights available under GDPR. Enterprise customers with EU-based employees or customers should evaluate whether the policy's international provisions are sufficient for their compliance obligations....
-
Jasper AI
· Jasper Privacy Policy
The policy governs data collected through Jasper's browser extensions and third-party integrations, which extend the platform's data collection scope beyond the core web application. Data collected through these channels is subject to the policy's general data handling terms....
Why it matters: Browser extensions and integrations operate within users' broader browsing and application environments, potentially collecting data beyond the scope of core platform interactions. The policy's application to these channels establishes the data handling terms for an expanded collection surface....
-
Jasper AI
· Jasper Privacy Policy
The policy addresses data processing applicable to enterprise customers and API users of Jasper's platform, covering data submitted through the Jasper APIs, Jasper MCP, and Image APIs. Enterprise customers and developers accessing Jasper via API are subject to the policy's data handling provisions....
Why it matters: API-based data processing creates distinct data flow structures where enterprise customer data and end-user personal data may be transmitted to and processed by Jasper's systems. The policy's application to API users establishes the baseline data handling terms for these technical integrations, though enterprise Data Processing Agreements may supplement or modify these terms....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that GPT-5.5 underwent OpenAI's full pre-deployment safety evaluation suite, including the Preparedness Framework, with targeted red-teaming specifically covering advanced cybersecurity and biology capabilities, supplemented by structured feedback from approximately 200 early-access partners....
Why it matters: This provision establishes the evidentiary basis for OpenAI's safety claims at deployment and identifies cybersecurity and biology as the primary dual-use capability risk domains subjected to structured adversarial testing. Organizations and regulators evaluating compliance with AI safety obligations may reference this disclosure when assessing whether the pre-deployment process meets applicable standards....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that GPT-5.5 Pro safety evaluations are generally based on GPT-5.5 evaluation results used as proxies, with separate evaluation conducted only where OpenAI judges that the parallel test-time compute setting could materially affect risk or safeguard posture....
Why it matters: This provision establishes that GPT-5.5 Pro, a distinct product configuration, relies primarily on safety evaluations conducted for a different operational setting. Compliance teams assessing AI model governance should evaluate whether this proxy methodology meets the independent evaluation expectations of applicable frameworks, particularly for higher-compute configurations that may exhibit different capability profiles....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that the system card was amended after initial publication on April 24, 2026 to add disclosures specific to the deployment of GPT-5.5 and GPT-5.5 Pro through the API....
Why it matters: This provision establishes that material API safeguard information was added to the system card after the model's initial release, which is operationally significant for API users who may have assessed deployment risks based on the original document. Compliance teams should confirm they are reviewing the April 24, 2026 version of the system card....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document describes GPT-5.5 as an agentic model designed to execute multi-step, multi-tool workflows autonomously, including online research, code writing, document creation, and cross-tool task execution, with reduced reliance on user guidance compared to prior models....
Why it matters: The description of GPT-5.5 as an agentic system capable of operating across tools with reduced human guidance is operationally significant for deployers assessing automation risk, human oversight obligations, and accountability frameworks under emerging AI governance requirements. The agentic capability profile described directly informs risk classification under frameworks such as the EU AI Act....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document states that safety evaluation results described across system cards were conducted in an offline setting unless specifically noted otherwise, meaning they do not reflect live or production deployment conditions....
Why it matters: This disclosure establishes that the safety evaluation results described in the system card are based on offline testing rather than production deployment conditions, which is a material methodological limitation for compliance teams assessing the real-world applicability of the stated safety posture....
-
Palantir
· Palantir Privacy Statement
The statement authorizes Palantir to generate inferred data by combining internally collected data with third-party partner and publicly available data, and to use this inferred data along with other collected categories to place targeted advertisements on third-party platforms including LinkedIn and Twitter....
Why it matters: This provision establishes that inferred data, derived from combining multiple internally collected categories with external third-party data, is used as an input for behavioral advertising on external social media and search platforms. The provision relies on legitimate interests as the legal basis for this processing in the EEA, UK, and Switzerland context, which may require evaluation under applicable regulatory guidance on behavioral advertising....
-
Palantir
· Palantir Privacy Statement
The statement authorizes Palantir to disclose an individual's training participation, progress data, quiz results, and certification outcomes to the individual's employer or to the organization that provided the certification exam code....
Why it matters: This provision establishes that training and certification data generated by individual employees using employer-provided exam codes will be disclosed to the employer or issuing organization, creating a data flow from individual to employer that the individual may not separately consent to beyond the initial registration for training....
-
Palantir
· Palantir Privacy Statement
The statement discloses that Palantir collects photographs, images, audio recordings, and video recordings through security and monitoring systems in its offices and during Palantir or Palantir-affiliated events and seminars....
Why it matters: This provision establishes that audiovisual data, including security footage and event recordings, is collected from individuals who visit Palantir offices or attend affiliated events. The legal basis cited for this processing in EEA/UK/Switzerland contexts is Palantir's legitimate interests in safety and security of employees, visitors, and confidential information....
-
Palantir
· Palantir Privacy Statement
The statement authorizes processing and transfer of personal data in connection with a broad range of corporate transactions, including mergers, acquisitions, divestitures, bankruptcy, restructuring, receivership, reorganization, dissolution, and asset sales, where personal data forms part of the assets involved....
Why it matters: This provision establishes that personal data collected under this statement may be transferred to a buyer or other transaction party across a wide range of corporate restructuring scenarios. The provision applies to proposed transactions as well as completed ones, which means personal data may be disclosed during due diligence processes prior to transaction completion....
-
Palantir
· Palantir Privacy Statement
The statement establishes that Palantir may send marketing communications and conduct personalization profiling on the basis of legitimate interests in jurisdictions where consent has not been separately sought, in addition to consent-based marketing where consent is obtained....
Why it matters: This provision establishes a dual legal basis structure for marketing communications and personalization profiling: consent where obtained, and legitimate interests where consent has not been separately sought. This means Palantir may send marketing communications without prior consent in contexts where legitimate interests is asserted as the applicable basis, subject to the right to object....
-
Meta
· Meta Frontier AI Framework
The document states that Meta's Frontier AI Framework is scoped to cybersecurity threats and chemical and biological weapons risks, and that these are designated as the primary areas for risk assessment in frontier AI model development....
Why it matters: This provision defines the operational boundaries of Meta's disclosed risk evaluation framework, establishing that the framework does not purport to address the full range of AI risk categories identified in regulatory frameworks such as the EU AI Act, which encompasses broader harm categories including fundamental rights, discrimination, and societal impact....
-
Meta
· Meta Frontier AI Framework
The document states that Meta conducts threat modeling exercises, including work with external experts, to anticipate misuse scenarios by different actors and to identify catastrophic outcomes related to cyber, chemical, and biological risks associated with frontier AI models....
Why it matters: This provision describes the primary procedural mechanism Meta states it uses to assess model risk before release; however, the document does not disclose the identity of external experts, the frequency or methodology of exercises, or how outcomes of these exercises affect release decisions....
-
Meta
· Meta Frontier AI Framework
The document states that Meta defines risk thresholds based on how much a model facilitates identified threat scenarios, and that the company applies mitigations to keep risks within what it characterizes as acceptable levels....
Why it matters: This provision describes the decision criteria Meta states it applies to model releases, but the specific thresholds, the definition of acceptable levels, and the mitigation mechanisms are not disclosed, limiting external assessment of the framework's operational rigor....
-
Meta
· Meta Frontier AI Framework
The document asserts that Meta's open-source model release approach contributes to risk mitigation by enabling external community assessments of model capabilities, which the document characterizes as improving model efficacy, trustworthiness, and field-level risk evaluation....
Why it matters: This provision frames open-source release as a component of Meta's risk management strategy, a characterization that may be relevant to regulatory discussions about whether open-source AI releases require additional oversight mechanisms compared to closed-model deployments....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave may collect biometric information and video surveillance recordings from individuals who visit its offices or data centers, alongside standard visitor identification data such as name, company affiliation, badge credentials, and access times....
Why it matters: This provision authorizes collection of biometric information at physical locations under a legitimate interests basis (GDPR Article 6(1)(f)), without specifying a separate consent mechanism. State biometric privacy statutes in Illinois, Texas, and other jurisdictions impose independent written consent requirements that may not be satisfied by a legitimate interest basis alone, creating potential compliance exposure for CoreWeave and for enterprise customers whose employees or contractors visit CoreWeave facilities....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy authorizes sharing personal data with current and future CoreWeave parent companies, subsidiaries, and affiliates, including for the purpose of cross-context behavioral advertising, defined as targeted advertising based on user activity across different websites, applications, or services over time....
Why it matters: This provision authorizes cross-context behavioral advertising data sharing with affiliated entities, which under CPRA constitutes 'sharing' subject to opt-out rights. The policy provides opt-out mechanisms via the website footer link, GPC signals, and cookie preference tools, satisfying CPRA's opt-out disclosure requirements, though the operational scope of affiliate sharing across current and future affiliates warrants monitoring as CoreWeave's corporate structure evolves....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy explicitly limits its own scope to personal data processed by CoreWeave as a controller and excludes Customer Data, defined as data processed on behalf of enterprise customers, from coverage; responsibility for Customer Data is attributed to the enterprise customer as data controller....
Why it matters: This provision establishes that enterprise customers bear controller-level obligations for any personal data their end users or employees submit through CoreWeave's Services. The absence of this policy's protections from Customer Data means that end users whose data is processed through enterprise customer deployments on CoreWeave's infrastructure have no direct recourse against CoreWeave under this policy and must direct rights requests to the enterprise customer....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave collects the inputs and outputs of service tools and offerings submitted by customers through the Services, in addition to messages, support communications, and Slack interactions, for purposes including analyzing usage, operating the Services, debugging, evaluation, and product improvement....
Why it matters: This provision authorizes collection and use of the content customers submit to CoreWeave's service tools, including model inputs and outputs, for product improvement and analytics purposes under a legitimate interests basis. Customers using AI or ML tools through CoreWeave's platform should assess whether their submissions may include personal data or confidential information subject to their own data governance obligations....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement grants W&B a right to use Customer Data, including machine learning models, datasets, and generated reports, not only to deliver contracted services but also to develop new products and improve AI features....
Why it matters: This provision establishes a secondary use right over Customer Data that extends beyond service delivery to product development and AI feature improvement, which procurement and legal teams should evaluate against the organization's own data protection obligations and applicable regulatory frameworks including GDPR purpose limitation requirements....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement explicitly authorizes W&B to use Customer Data submitted by free-tier and academic-license users for W&B's internal testing and development purposes, as a condition of free access....
Why it matters: This provision establishes that customers accessing W&B under free or academic licenses, including students and employees of accredited educational institutions, grant W&B rights to use their submitted data for testing and development, which is a condition disclosed in the terms but may not be prominently surfaced at the point of free account creation....
-
Weights & Biases
· Weights & Biases Terms of Service
Based on the document structure and standard MSA provisions referenced, the agreement references arbitration provisions; however, the document text provided was truncated before the full arbitration clause text was reproduced. The agreement is structured to include dispute resolution provisions in Section 14 (Miscellaneous)....
Why it matters: Arbitration clauses in B2B SaaS agreements require disputes to be resolved through private arbitration rather than court proceedings, and commonly include class action waivers that prevent consolidated claims. Legal teams should locate and review the full arbitration provision in the untruncated agreement....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement establishes that all fees paid under Order Forms are non-refundable and all payment obligations are non-cancellable, with the sole exception of pro-rata reimbursement when Customer terminates due to W&B's uncured material breach....
Why it matters: This provision establishes that customers who commit to a subscription term have no contractual right to cancel or receive a refund outside of a W&B material breach scenario, including in cases of service dissatisfaction, organizational change, or underutilization....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement establishes that W&B's maximum financial liability for data privacy and security breaches, including violations of data protection laws, is capped at three times the total fees paid by Customer in the 12 months preceding the event, rather than being uncapped....
Why it matters: This provision establishes a specific financial ceiling on W&B's liability for data breaches and data protection law violations, which is a materially different risk allocation than an uncapped liability structure and may be relevant to procurement teams assessing vendor risk in regulated industries....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement establishes that W&B's Business Associate Agreement, which governs HIPAA-compliant processing of protected health information, applies only to Enterprise-tier customers and only when the BAA is explicitly included in the Customer's Order Form....
Why it matters: This provision establishes that non-Enterprise customers, including those on standard paid plans, do not receive HIPAA-compliant data processing protections under the BAA, which is a material limitation for any organization in healthcare or life sciences that processes PHI through W&B....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement reserves to W&B the right to modify its terms at any time in its sole discretion, with modifications becoming effective 30 days after posting or upon continued use of the platform, whichever occurs first....
Why it matters: This provision establishes that W&B may alter the terms governing Customer Data usage rights, payment obligations, and other material provisions without Customer consent, with continued platform use constituting acceptance of modified terms....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement provides IP indemnification for W&B Assets generally but explicitly excludes from that indemnification any claims arising from content generated through Customer's use of AI Features, meaning Customer bears intellectual property infringement risk for AI-generated outputs....
Why it matters: This provision establishes that W&B's IP indemnification obligation does not extend to outputs generated by AI Features, which means customers using W&B's generative AI functionality bear the risk of third-party IP infringement claims related to AI-generated content....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement establishes that Customer is solely responsible for exporting its data before the agreement ends, that W&B will delete Customer Data upon termination in accordance with its policies, and that post-termination deletion requests submitted to support@wandb.com will be initiated within 30 days....
Why it matters: This provision places the full burden of data export on the Customer before termination, and the deletion timeline of 30 days for post-termination requests should be assessed against applicable data protection law requirements in relevant jurisdictions....
-
Ideogram
· Ideogram Terms of Service
Users grant Ideogram a royalty-free, transferable, sublicensable, worldwide, and irrevocable license to use, store, reproduce, display, and modify all uploaded and generated content for the duration it remains stored on the platform, including the right to pass these permissions to unnamed third-party contractual partners for service provision purposes....
Why it matters: This provision establishes a content license that persists for the full duration of storage on Ideogram's platform and extends sublicensing rights to third parties with whom Ideogram holds contractual relationships, without individually naming those parties. The scope of permitted uses includes improving and promoting the Services, which extends beyond core operational functions....
-
Ideogram
· Ideogram Terms of Service
Subscription payments are non-refundable and no credits are issued for partially used periods; if Ideogram terminates an account for a breach or suspected breach, access ends immediately and no refund is issued regardless of remaining prepaid subscription time....
Why it matters: This provision establishes that account termination for a suspected breach, not only a confirmed breach, results in immediate loss of access to paid Services with no refund entitlement. The use of 'suspected breach' as a termination trigger without a defined review or appeal procedure is an operationally significant condition for paid subscribers....
-
Ideogram
· Ideogram Terms of Service
The agreement authorizes all other users of the Services to use, reproduce, modify, comment on, and create derivative works from any content that is not designated as Private Content, including content originally generated by other users....
Why it matters: This provision establishes a cross-user license permitting reproduction and modification of publicly posted content by any other user of the platform, which is operationally relevant for creators who post content publicly and wish to retain exclusive control over its use or downstream derivatives....
-
Ideogram
· Ideogram Terms of Service
Ideogram reserves the right to suspend, disable, or delete any user account and terminate access to the Services at any time, with or without notice, for any or no reason....
Why it matters: This provision establishes a unilateral account termination right without a notice requirement, stated reason, or appeal mechanism, which applies to both free and paid accounts and takes effect immediately upon the company's determination....
-
Ideogram
· Ideogram Terms of Service
Ideogram's total liability for any claim is capped at the greater of the amount paid by the user in the 12 months preceding the event or USD $100, and excludes indirect, incidental, consequential, special, and punitive damages to the fullest extent permitted by law....
Why it matters: This provision establishes a liability cap that limits the maximum financial exposure of Ideogram and its affiliates across all claim types arising from the Services, which is operationally significant for business users who may sustain losses exceeding this threshold....
-
Ideogram
· Ideogram Terms of Service
Ideogram reserves the right to terminate, withhold, or change affiliate program rewards for any or no reason, and may discontinue the affiliate program entirely at its sole discretion....
Why it matters: This provision establishes that affiliate program rewards, including earned but unpaid rewards, may be withheld or terminated at Ideogram's sole discretion without a stated cause or appeal mechanism, which affects the financial terms for affiliate program participants....
-
Ideogram
· Ideogram Terms of Service
Ideogram reserves absolute discretion to remove, screen, edit, or delete any user content at any time and without notice, including through automated detection software, and this right applies equally to paid and free account holders....
Why it matters: This provision establishes that content removal may occur via automated detection without human review or notice to the affected user, and applies to paid subscribers as well as free users, with no stated appeal mechanism....
-
Ideogram
· Ideogram Terms of Service
Users agree to defend and indemnify Ideogram, its affiliates, and associated personnel against all claims, damages, losses, liabilities, and attorney's fees arising from the user's use of the Services, violation of the terms, violation of third-party rights, or user content....
Why it matters: This provision imposes a broad indemnification obligation on users covering claims arising from their use of the Services, their content, and any third-party rights violations, including attorney's fees, which extends financial exposure to users in the event of third-party claims against Ideogram related to user activity....
-
Comcast
· Comcast Terms of Service
The agreement asserts a one-year limitation period on all claims, which is shorter than the default statutory limitation periods applicable to many consumer claims under state law. The document heading indicates this is Section 12 of the agreement....
Why it matters: This provision establishes a contractually shortened timeframe within which subscribers must initiate any claim against Comcast, which may be shorter than the limitation period that would otherwise apply under applicable state or federal law....
-
Comcast
· Comcast Terms of Service
The agreement prohibits subscribers from using any software or service that takes autonomous, semi-autonomous, or programmatic action to interact with Xfinity services, including account access, scraping, downloading, support interactions, and agreement acceptance, without express written permission from Comcast. The definition of AI Agent is broad and encompasses semi-autonomous and programmatic tools....
Why it matters: This provision establishes an explicit contractual prohibition on the use of AI agents, automation tools, and programmatic software to interact with Comcast services, which may affect subscribers who use third-party account management applications, accessibility tools, or automated monitoring software....