-
Medium
· Medium Privacy Policy
The policy authorizes sharing of personal information with third-party vendors and service providers for purposes including payment processing, data analysis, email delivery, hosting, customer service, and marketing, without specifying a complete list of named providers or requiring user notification prior to each sharing event....
Why it matters: This provision establishes the contractual basis under which Medium transfers personal data to external parties for operational purposes, which implicates GDPR Article 28 data processor agreement requirements and CCPA business-purpose sharing disclosure obligations....
-
Medium
· Medium Privacy Policy
The policy states that personal information may be shared or transferred in connection with a merger, asset sale, financing, or acquisition of Medium, including during the negotiation phase of such transactions, with user notification described as prominent notice or direct communication....
Why it matters: This provision establishes that personal data may be disclosed to prospective acquirers or transaction counterparties prior to deal completion, which creates data exposure outside Medium's direct operational relationships and may engage GDPR requirements for lawful transfer basis during pre-transaction due diligence....
-
Medium
· Medium Privacy Policy
The policy states that for EEA users, Medium processes personal data on the legal bases of consent, contract performance, legitimate interests, or legal obligation under GDPR, without specifying in the policy text which legal basis applies to each individual processing activity....
Why it matters: This provision establishes the claimed legal bases for EEA data processing, but the absence of a processing activity-level mapping to specific legal bases may present a compliance gap relative to GDPR accountability and transparency requirements enforced by EU supervisory authorities....
-
Medium
· Medium Privacy Policy
The policy states that California residents hold rights under CCPA to know about, delete, and opt out of the sale of their personal information, and have a right to non-discrimination for exercising these rights, with opt-out available via a designated link....
Why it matters: This provision establishes the operational mechanisms through which California residents can exercise CCPA and CPRA rights, including the opt-out of data sale or sharing, which is a concrete and time-sensitive entitlement available to a defined user population....
-
Medium
· Medium Privacy Policy
The policy authorizes Medium and third-party partners to use cookies, web beacons, and similar technologies to collect usage information and deliver targeted advertising, and permits third parties to independently collect information about user online activities through these technologies on Medium's platform....
Why it matters: This provision establishes that third-party tracking for targeted advertising is permitted on Medium's platform, which engages GDPR consent requirements under the ePrivacy Directive and CCPA opt-out obligations for cross-context behavioral advertising under CPRA....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Medium
· Medium Privacy Policy
The policy states that Medium retains personal information for as long as necessary to provide services and for legal, dispute, and enforcement purposes, without specifying defined retention periods for individual data categories....
Why it matters: The absence of defined retention periods for specific data categories may present a compliance consideration under GDPR's storage limitation principle, which requires that personal data be kept no longer than necessary for the specified processing purpose....
-
Medium
· Medium Privacy Policy
The policy states that personal information may be transferred to and stored on computers outside a user's home jurisdiction, including to jurisdictions with less protective privacy laws, without specifying the transfer mechanisms used to safeguard EEA personal data....
Why it matters: The policy's disclosure of cross-border data transfers without specifying the legal mechanism used for EEA transfers, such as Standard Contractual Clauses or an adequacy decision, creates a compliance documentation gap relevant to GDPR Chapter V requirements enforced by EU supervisory authorities....
-
Medium
· Medium Privacy Policy
The policy states that Medium's services are not directed to children under 13 and that Medium does not knowingly collect personal information from this age group, committing to delete such information if discovered, consistent with COPPA requirements....
Why it matters: This provision establishes Medium's COPPA compliance posture, but the policy does not describe the verification mechanisms used to prevent collection of under-13 data, which is an operational detail relevant to COPPA enforcement by the FTC....
-
Medium
· Medium Privacy Policy
The policy states that Medium may update the Privacy Policy at any time, with notification limited to updating the effective date at the top of the document; additional notice through homepage statements or direct notifications is described as discretionary rather than required....
Why it matters: This provision establishes that material changes to data practices may be implemented with only a date revision as mandatory notice, which may be insufficient to satisfy GDPR requirements for transparent communication of material changes to processing activities or CCPA requirements for material updates to privacy notices....
-
Wise
· Wise Terms of Use
The agreement requires users and Wise to resolve all disputes through individual binding arbitration rather than court proceedings, with limited exceptions for small claims and intellectual property injunctions....
Why it matters: This provision requires disputes to proceed through JAMS individual arbitration, which forecloses court litigation as the default dispute resolution mechanism for claims arising from account use, transactions, or agreement interpretation....
-
Wise
· Wise Terms of Use
The agreement prohibits users from participating in class action lawsuits or representative proceedings against Wise, requiring all claims to be brought individually....
Why it matters: This provision requires that any claim against Wise be brought on an individual basis, which means users cannot join or initiate class or representative actions arising from common grievances related to the service....
-
Wise
· Wise Terms of Use
The agreement caps Wise's total financial liability to any individual user at the greater of fees paid to Wise in the prior 12 months or $100, regardless of the type or scale of the claim....
Why it matters: This provision establishes a ceiling on Wise's monetary exposure to individual users that, for users who paid minimal fees, could be as low as $100, regardless of the amount of any disputed transaction or loss....
-
Wise
· Wise Terms of Use
The agreement authorizes Wise to suspend or terminate user accounts at any time, including without prior notice, for a range of specified reasons including regulatory requirements, fraud risk, identity verification failures, and law enforcement requests....
Why it matters: This provision grants Wise broad discretion to restrict or terminate account access without advance notice, which may interrupt users' ability to access funds held in multi-currency balances or complete pending transfers....
-
Wise
· Wise Terms of Use
The agreement authorizes Wise to hold funds in a user's account or reverse transactions where Wise determines there is an elevated risk of fraud or financial crime, or where required by law or regulation....
Why it matters: This provision authorizes Wise to restrict access to account funds held in multi-currency balances without specifying the maximum duration of a hold or the procedural steps required before funds are released, which creates operational uncertainty for users depending on those funds....
-
Wise
· Wise Terms of Use
The agreement states that the exchange rate applied to transfers is determined at the time of execution, that fees and rates are disclosed before confirmation, and that Wise reserves the right to change fees and rates at any time....
Why it matters: This provision establishes that exchange rates are locked at execution rather than at initiation, and that Wise may change its fee schedule at any time, which affects users' ability to predict the cost of transactions initiated in the future....
-
Wise
· Wise Terms of Use
The agreement prohibits use of Wise services for illegal activities, transactions involving sanctioned parties, and categories of restricted activities listed in the Acceptable Use Policy, with violations potentially resulting in immediate account suspension....
Why it matters: This provision establishes the acceptable use framework that governs account eligibility and may trigger immediate suspension or termination if Wise determines a user has violated the stated restrictions....
-
Wise
· Wise Terms of Use
The agreement requires users to be at least 18 years old and a US resident, with use of the service constituting a representation that these requirements are met....
Why it matters: This provision establishes the eligibility conditions for account access, and use of the service constitutes a warranty by the user that they meet both the age and residency requirements....
-
Wise
· Wise Terms of Use
The agreement designates Delaware law as governing and Delaware courts as the exclusive forum for any disputes that are not subject to the arbitration clause....
Why it matters: This provision establishes that Delaware law governs the agreement and that any non-arbitrated disputes must be litigated in Delaware courts, which may create practical barriers for users located in other states....
-
Wise
· Wise Terms of Use
The agreement states that Wise may amend its terms at any time by posting updated terms on its website, with notice of material changes provided by email or website posting, and continued service use constituting acceptance of amended terms....
Why it matters: This provision establishes that continued use of the service after an amendment's effective date constitutes acceptance of updated terms, which means users who do not review amendment notices and discontinue use may be bound by materially changed terms....
-
Kindle
· Kindle Store Terms of Use
The agreement states that purchasing Kindle Content grants only a limited, personal, non-transferable license to access the content, and that the user does not acquire ownership. The license is restricted to authorized Kindle devices and personal non-commercial use....
Why it matters: This provision establishes that consumers who pay for Kindle Content hold a revocable license rather than a transferable ownership interest, meaning rights associated with ownership such as resale, transfer, or permanent retention are not granted under these terms. The enforceability of the license-not-sale characterization for digital goods is subject to evolving legislative and regulatory scrutiny in multiple U.S. states and the EU....
-
Kindle
· Kindle Store Terms of Use
The agreement reserves Amazon's right to modify, suspend, or discontinue the Kindle Service or any Kindle Content delivered to a user's device at any time without prior notice. Amazon states it will not be liable to users for such changes....
Why it matters: This provision authorizes Amazon to alter or remove content from user devices after purchase without advance notice and without incurring liability under the terms, which operationally affects the reliability of access to paid digital content. The scope of this reservation interacts with consumer protection frameworks that may limit disclaimer of liability for failure to deliver paid-for services....
-
Kindle
· Kindle Store Terms of Use
The agreement states that any content users submit in connection with Kindle services, including reviews, lists, and discussion posts, is subject to a perpetual, irrevocable, royalty-free, and sublicensable license granted to Amazon for global use across any media. Users receive no compensation for this license....
Why it matters: This provision grants Amazon a perpetual and irrevocable right to use, modify, and sublicense user-submitted content including customer reviews and annotations without compensation or defined scope limitation. The breadth and irrevocability of this license may warrant review by users who submit substantial original content through Kindle services....
-
Kindle
· Kindle Store Terms of Use
The agreement states that violation of any term results in immediate termination of service access without notice, and that account closure or termination may result in permanent loss of licenses to all Kindle Content previously accessed or purchased. Amazon retains discretion to determine what constitutes a violation....
Why it matters: This provision establishes that termination of an account, whether initiated by Amazon or the user, may result in loss of access to all Kindle Content licenses, including content for which payment was made. The scope of triggering conditions and the absence of a mandatory notice period before access revocation are operationally significant for users with large Kindle libraries....
-
Kindle
· Kindle Store Terms of Use
The agreement states that users consent to Amazon automatically delivering and applying software updates to Kindle devices, and that such updates may affect access to the service or device features. Users do not have the option to decline automatic updates under these terms....
Why it matters: This provision authorizes Amazon to remotely modify Kindle device software without user approval of individual updates, and acknowledges that updates may alter or restrict access to features users currently rely on. The absence of an opt-out mechanism for automatic updates is operationally relevant for users who depend on specific device functionality....
-
Kindle
· Kindle Store Terms of Use
The agreement limits Amazon's liability to exclude indirect, incidental, special, consequential, or punitive damages arising from use of or inability to access the Kindle service or content, to the extent permitted by applicable law. This limitation applies to loss of data, profits, and other intangible losses....
Why it matters: This provision limits the categories of damages recoverable by users against Amazon, excluding consequential and punitive damages for service disruption or content access failures. The clause includes a statutory carve-out acknowledging that applicable law may limit the scope of this disclaimer in certain jurisdictions....
-
Kindle
· Kindle Store Terms of Use
The agreement requires that disputes related to the Kindle service or Kindle Content be resolved through binding individual arbitration rather than court proceedings, with a limited exception for qualifying small claims court actions. The Federal Arbitration Act governs the arbitration clause....
Why it matters: This provision requires users to resolve disputes with Amazon through individual binding arbitration rather than litigation, which precludes class action proceedings except as otherwise stated. The application of the Federal Arbitration Act is asserted as the governing framework for the arbitration clause....
-
Luma AI
· Luma AI Terms of Service
Users on free-tier plans grant Luma a perpetual, irrevocable license to publicly display, reproduce, distribute, create derivative works of, and publicly perform their uploaded content across any media formats and channels, including for AI model training and product development. This license is permanent and irrevocable with respect to Input already incorporated into Luma's systems....
Why it matters: This provision establishes that free-tier users grant rights substantially broader than the paid-tier license, including public display and distribution rights over user-submitted content in any media format. The perpetual and irrevocable nature of the license as applied to already-incorporated Input means these rights persist regardless of subsequent account deletion or plan changes....
-
Luma AI
· Luma AI Terms of Service
Paid-tier users grant Luma a worldwide, irrevocable, royalty-free license with sublicensing rights to use and store their uploaded content for AI model training, product development, and aggregated data compilation during an active subscription. The license is perpetual and irrevocable with respect to Input already incorporated into outputs, usage data, or aggregated data....
Why it matters: This provision establishes that even paid subscribers' Input is licensed for AI model training purposes on a perpetual and irrevocable basis once incorporated into Luma's systems. The sublicensing right through multiple tiers means third parties may receive derivative rights to this Input....
-
Luma AI
· Luma AI Terms of Service
The agreement states that deleting a Luma account does not terminate the licenses granted over Input or Output that Luma has already incorporated into its systems, AI models, or aggregated data before the deletion request was made....
Why it matters: This provision establishes that the account deletion right does not function as a complete data rights mechanism where Input has already been used in model training or aggregated data. The operational scope of this carve-out depends on Luma's internal data pipeline timelines, which are not disclosed in the document....
-
Luma AI
· Luma AI Terms of Service
The agreement requires that most disputes between users and Luma be resolved through binding individual arbitration rather than court proceedings, and states that both parties waive the right to a jury trial and to participate in class action or representative proceedings....
Why it matters: This provision requires disputes to proceed through individual arbitration rather than court litigation, and prohibits class action participation. The agreement references certain exceptions in Section 16.2, though the full text of those exceptions was not available in the provided document excerpt....
-
Luma AI
· Luma AI Terms of Service
The agreement prohibits using the Services or generated Output for commercial purposes unless the user holds a subscription that specifically permits commercial use as described in Section 4.9. Competing with Luma using the Output is also prohibited....
Why it matters: This provision establishes that commercial use of Output is gated behind a specific subscription tier. Users on free-tier plans who use Output commercially without an appropriate subscription may be in breach of the agreement, which could trigger suspension or termination of access....
-
Luma AI
· Luma AI Terms of Service
The agreement disclaims all warranties and liability for third-party AI tools integrated into the Services, including actions taken by those tools on behalf of users when acting as virtual agents interacting with the internet or other systems....
Why it matters: This provision establishes that when Luma's virtual agents or third-party AI tools take actions on behalf of users (such as interacting with external systems or the internet), all risk and liability for those actions rests entirely with the user. The scope of potential actions is defined broadly to include any activity enabled through settings or prompts....
-
Luma AI
· Luma AI Terms of Service
The agreement asserts that Luma owns all rights to aggregated and usage data derived from users' interactions with the Services, including all analytical results, know-how, and any new products or improvements developed from that data....
Why it matters: This provision establishes Luma's ownership over aggregated and usage data, including all products and services developed from that data. The scope includes improvements to Services made using aggregated or usage data derived from customer activity....
-
Luma AI
· Luma AI Terms of Service
The agreement prohibits users under 13 from accessing the Services and requires users between 13 and 18 to have parental or guardian consent. Luma states it does not knowingly collect personal information from children under 13 and will delete such information if discovered....
Why it matters: This provision establishes age-based access controls and a COPPA compliance commitment. The mechanism for enforcement relies on user self-representation at account creation rather than independent age verification, which is typical but creates a gap between stated policy and practical enforcement....
-
Luma AI
· Luma AI Terms of Service
The agreement authorizes Luma to immediately suspend account access if a user breaches acceptable use or content restrictions, has an account 30 days overdue, if legal changes require suspension, or if user actions risk harm to other customers or the Services. Prior notice will be provided where practicable....
Why it matters: This provision establishes that suspension may occur immediately and without prior notice in the enumerated circumstances, including for reasons related to changes in law or potential liability to Luma. The 'risk harm' standard in subsection (d) introduces a subjective threshold for suspension....
-
Luma AI
· Luma AI Terms of Service
The agreement states that Luma's Services are not HIPAA-compliant, that Luma does not function as a HIPAA Business Associate, and that Luma accepts no liability for use of the Services with prohibited data categories or for high-risk activities....
Why it matters: This provision explicitly excludes healthcare-related data use cases from the scope of the Services and disclaims all liability for prohibited data or high-risk activity use, which may affect healthcare-adjacent organizations that consider using the platform for clinical, administrative, or research purposes....
-
Oura
· Oura Privacy Policy
When a user consents to share their Oura health and biometric data with a Data Recipient (employer, researcher, coach, doctor, or other entity) via the Oura Platform, that recipient becomes an independent data controller, and Oura's direct privacy obligations do not govern the recipient's subsequent processing of that data....
Why it matters: This provision establishes that Oura's privacy obligations cease to directly govern user health data once it is shared with a Data Recipient, shifting data controller responsibility to the receiving entity. Compliance teams evaluating employer wellness deployments or research partnerships should assess whether the consent mechanism presented to users meets applicable standards for valid, freely given consent, particularly under GDPR Article 9 in employment contexts....
-
Oura
· Oura Privacy Policy
The policy states that health data, including physiological measurements and health-related notes and tags, is classified as special-category personal data and is processed only on the basis of user consent; consent may be provided through in-app actions such as adding health tags or notes rather than solely through an explicit consent dialogue....
Why it matters: This provision establishes that behavioral in-app actions (adding notes or health tags) may constitute consent for processing special-category health data. Compliance teams should evaluate whether this mechanism satisfies GDPR Article 9's requirement for explicit consent and whether users are adequately informed that these actions constitute a consent signal....
-
Oura
· Oura Privacy Policy
The policy states that Oura processes personal data for online advertising on behalf of Oura and its partners, using cookies and similar technologies to create advertising audiences, and authorizes direct marketing communications with an opt-out option....
Why it matters: This provision authorizes advertising-related data processing on behalf of third-party partners in addition to Oura itself, with the details of those partner relationships and data flows deferred to a separate Cookie Policy. The scope of partner advertising data sharing may require evaluation under CPRA's opt-out-of-sharing requirements and GDPR's legitimate interest or consent requirements for behavioral advertising....
-
Oura
· Oura Privacy Policy
The policy states that Oura may collect approximate or precise device location via GPS, Wi-Fi, or network ID for location-based features, only with user consent, and that users may withdraw consent at any time through device settings, with the consequence that certain features may no longer be accessible....
Why it matters: This provision establishes that precise location data may be collected via GPS and Wi-Fi triangulation for activity tracking purposes, conditioned on device-level consent. The policy notes that disabling location access may reduce service functionality, which compliance teams should evaluate in the context of whether this creates an effective barrier to consent withdrawal....
-
Oura
· Oura Privacy Policy
The policy states that Oura relies on legitimate interest as the lawful basis for processing personal data for marketing, customer service, and service improvement purposes, asserting that a balancing test has been conducted against user privacy rights....
Why it matters: This provision applies the legitimate interest basis to processing that includes health-adjacent data (service improvement involving sleep and readiness data), which EU supervisory authorities may scrutinize given the sensitivity of the underlying data and the availability of consent as an alternative basis. The policy does not provide a publicly disclosed legitimate interest assessment....
-
Oura
· Oura Privacy Policy
The policy states that users have rights to access, rectify, erase, and port their personal data, and to object to or restrict processing, exercisable by emailing privacy@ouraring.com....
Why it matters: This provision establishes the operational mechanism through which users may exercise GDPR, UK GDPR, and CCPA/CPRA data subject rights, centralizing all requests through a single email address. Compliance teams should verify that response timelines meet applicable statutory deadlines (30 days under GDPR, 45 days under CCPA) and that identity verification procedures do not create unreasonable barriers to access....
-
Oura
· Oura Privacy Policy
The policy states that Oura enables integrations with third-party services including Google Health Connect and Apple HealthKit on a consent basis, and processes data received from these integrations according to the third parties' applicable terms, including the Google Health Connect Permissions policy and Google Limited Use requirements....
Why it matters: This provision establishes that data exchanged through third-party integrations is governed in part by the third parties' own terms and policies, and that Oura's compliance with those terms is conditioned on awareness of policy updates. The qualification 'as we become aware of those policies and agreements' introduces a temporal condition on Oura's adherence to third-party data governance requirements....
-
Oura
· Oura Privacy Policy
The policy states that users may request account closure and personal data deletion, and that Oura will delete or anonymize data unless a legal basis for retention exists, including legal obligations or protection of Oura's legal interests....
Why it matters: This provision establishes that data deletion upon account closure is subject to carve-outs for legal obligation and protection of Oura's legal interests, the latter of which is a broad retention basis that is not further defined in the policy. Compliance teams should assess whether this carve-out is appropriately scoped and disclosed under applicable law....
-
Oura
· Oura Privacy Policy
The policy states that Oura does not sell personal data, which under CCPA/CPRA includes the exchange of personal information for monetary or other valuable consideration....
Why it matters: This provision asserts that Oura does not sell personal data; however, the policy separately discloses advertising-related data processing on behalf of partners using cookies and similar technologies, which may constitute 'sharing' of personal information for cross-context behavioral advertising under CPRA even if it does not meet the definition of 'sale.' Compliance teams should assess whether the advertising practices described elsewhere in the policy require a CPRA 'opt out of sharing' mechanism in addition to the no-sale representation....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that Nextdoor requires users to verify their residential address in order to participate in their neighborhood community, linking the user's platform identity to a specific physical location....
Why it matters: This provision establishes a mandatory association between a user's verified home address and their platform account, which represents a persistent high-sensitivity data linkage that compliance teams should assess against data minimization principles under GDPR and equivalent frameworks....
-
Nextdoor
· Nextdoor Privacy Policy
The policy authorizes Nextdoor to share user data, including identifiers, location data, browsing and usage activity, and inferred interests, with advertising and analytics partners for the purposes of targeted advertising and platform analytics....
Why it matters: This provision authorizes data sharing with third-party advertising and analytics partners, which under CCPA/CPRA may constitute a sale or sharing of personal information and triggers opt-out obligations; under GDPR, it requires a documented lawful basis and, in many cases, user consent....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that users in certain jurisdictions, including EU/EEA member states, the UK, and California, have specific rights regarding their personal data, including rights to access, correct, delete, restrict processing, and opt out of certain data uses....
Why it matters: This provision conditions the availability of privacy rights on the user's jurisdiction, meaning the scope of rights available to a given user depends on their location and the applicable legal framework rather than a uniform global standard....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that Nextdoor collects location data, including data used to verify and assign users to a specific neighborhood, and may use this data for platform functionality, content personalization, and advertising purposes....
Why it matters: This provision authorizes collection of precise location data as both a functional and advertising-related data practice, which implicates heightened sensitivity classifications under CPRA and requires documented lawful basis under GDPR....
-
Nextdoor
· Nextdoor Privacy Policy
The policy indicates that certain user data, potentially including verified address and account activity, may be retained by Nextdoor for a defined or indefinite period following account deactivation or deletion....
Why it matters: This provision establishes that account closure does not necessarily result in immediate deletion of all user data, which is a material consideration for users seeking to exercise deletion rights and for compliance teams assessing storage limitation obligations under GDPR....