-
Comcast
· Comcast Terms of Service
The agreement states that Comcast retains ownership and title to all leased equipment at all times, including after a subscriber pays an Unreturned Equipment Fee. Payment of the fee does not transfer ownership, and the equipment may not be resold, used, or operated even after the fee is paid....
Why it matters: This provision establishes that the Unreturned Equipment Fee is a penalty for failure to return equipment rather than a purchase price, and that subscribers who pay it remain prohibited from using or disposing of the equipment while Comcast retains legal title....
-
Comcast
· Comcast Terms of Service
By accepting the agreement, subscribers authorize Comcast to obtain credit information from third parties, record that information in the subscriber's file, and share it with third parties for what the agreement characterizes as reasonable business purposes. The agreement states that risk assessments will comply with applicable law and that credit inquiry practices will not discriminate on specified protected characteristics....
Why it matters: This provision establishes a subscriber authorization for credit-related data collection and third-party disclosure, with the scope of third-party sharing defined broadly as reasonable business purposes, which may warrant evaluation under FCRA and applicable state credit reporting frameworks....
-
Comcast
· Comcast Terms of Service
The agreement establishes broad limitations on Comcast's liability, including exclusion of consequential, indirect, and incidental damages, caps on recovery for customer equipment damage at $500 in cases of gross negligence or willful misconduct, and designation of service credits as the sole and exclusive remedy for service interruptions....
Why it matters: This provision establishes the financial ceiling on Comcast's contractual exposure across multiple categories of harm, with specific dollar caps and exclusive remedy designations that limit subscriber recovery options for service failures and equipment damage....
-
Comcast
· Comcast Terms of Service
The agreement establishes a 120-day window within which subscribers must contact Comcast to dispute bill charges or request billing credits, with failure to contact within that period constituting a waiver of the dispute or credit, subject to applicable law....
Why it matters: This provision establishes a contractual deadline for billing disputes that is shorter than the default statute of limitations for billing-related claims under state law, and characterizes failure to act within 120 days as a waiver of dispute rights....
-
Comcast
· Comcast Terms of Service
The agreement establishes a liquidated damages amount of $500 per device used to receive unauthorized services, in addition to equipment replacement costs, with the characterization that precise damage calculation would be difficult. Comcast also reserves the right to report unauthorized service use to law enforcement....
Why it matters: This provision establishes a specific per-device financial penalty for unauthorized service use and asserts both civil liquidated damages and potential criminal referral as consequences, creating dual enforcement exposure for subscribers in violation of the unauthorized use prohibition....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Glean
· Glean Privacy Policy
The Privacy Statement explicitly excludes Glean's enterprise products and services (Solutions) from its scope, applying only to website interactions and general business operations....
Why it matters: This provision establishes that users and organizations accessing Glean's enterprise AI search products are governed by separate agreements, not this statement, requiring procurement and compliance teams to identify and evaluate those separate data processing agreements to understand applicable data governance obligations....
-
Glean
· Glean Privacy Policy
When a user inquires about Glean Solutions fulfilled through channel partners or resellers, Glean may share that user's Personal Information with those third parties, who may independently communicate third-party product or service information to the user....
Why it matters: This provision creates a downstream disclosure pathway to resellers and channel partners who may operate under their own privacy policies, and who may contact users about third-party offerings beyond Glean's direct control....
-
Glean
· Glean Privacy Policy
Glean holds active DPF certification covering EU, UK, and Swiss data transfers and states that DPF Principles supersede conflicting provisions in this Privacy Statement. For onward transfers to third parties, Glean's liability is conditioned on its ability to demonstrate it was not party to events causing damages....
Why it matters: The onward transfer liability clause conditions Glean's DPF liability on a demonstration defense, which under DPF Annex I and applicable Principles may shift the burden of proof to Glean but has operational implications for how damages claims arising from third-party processor conduct are handled....
-
Glean
· Glean Privacy Policy
California residents are granted rights under CCPA/CPRA to know, delete, correct, and opt out of sharing of Personal Information for cross-context behavioral advertising, with a stated non-discrimination commitment for exercising these rights....
Why it matters: This provision establishes the specific CCPA/CPRA rights framework applicable to California residents interacting with Glean's websites and business operations, with deletion subject to enumerated exemptions and authorized agent submission procedures requiring written permission or power of attorney....
-
Glean
· Glean Privacy Policy
EEA, UK, and Swiss residents hold GDPR and equivalent rights including objection, restriction, data portability, and consent withdrawal, with Glean committing to cooperation with EU DPAs, the UK ICO, and the Swiss FDPIC for unresolved complaints....
Why it matters: This provision establishes the GDPR rights framework and the regulatory escalation pathway for EEA, UK, and Swiss residents, including named supervisory authorities for unresolved complaints, which is operationally relevant for compliance teams managing cross-border data transfers....
-
Glean
· Glean Privacy Policy
The statement authorizes international transfers of Personal Information to the U.S. and other jurisdictions, relying on website use as a consent signal where applicable law permits this mechanism....
Why it matters: Reliance on implicit consent through website use as a transfer mechanism for international data flows may require evaluation under GDPR and LGPD, which impose specific requirements on consent validity and adequacy for cross-border transfers....
-
Ideogram
· Ideogram Privacy Policy
The policy states that text prompts and uploaded images submitted by users are collected and used to improve and develop Ideogram's products and technology, including the AI models that power the Services, under a legitimate interest basis....
Why it matters: This provision establishes that user-generated content, including creative prompts and uploaded images, is used for AI model training and product development. The policy does not describe a specific opt-out mechanism for this processing activity, and the adequacy of legitimate interest as the legal basis for this use is subject to ongoing regulatory scrutiny in EU and UK jurisdictions....
-
Ideogram
· Ideogram Privacy Policy
The policy states that generated images, together with account handles and profile pictures, may be publicly displayed on the Services, and that Ideogram and others may store, reproduce, or publish this content with or without attribution to the user....
Why it matters: This provision establishes that content generated using the platform may be publicly associated with a user's account identifiers unless private content settings are configured. The reservation of rights to publish or display content with or without attribution has implications for user expectations of content ownership and visibility....
-
Ideogram
· Ideogram Privacy Policy
The policy discloses that Amplitude's session replay technology is deployed to record user sessions and collect browsing activity over time and across different websites, with a stated commitment to provide notice and seek consent before recording sessions that may include personal information....
Why it matters: This provision establishes that Ideogram deploys cross-site behavioral tracking and session recording technology. The policy states that consent will be sought before collecting personal information within session recordings, though the scope and mechanism of this consent process are not fully specified in the document....
-
Ideogram
· Ideogram Privacy Policy
The policy discloses that user data may be transferred to and processed in countries other than the user's country of residence, which may have different data protection standards....
Why it matters: This provision establishes that personal data may be transferred internationally, including to jurisdictions with different data protection frameworks. The policy does not specify the transfer mechanisms used to legitimize transfers from the EU or UK, such as Standard Contractual Clauses or adequacy decisions, which is a material disclosure gap for GDPR compliance....
-
Ideogram
· Ideogram Privacy Policy
The policy states the Services are not intended for children and that commercially reasonable deletion efforts will be made if data from children under 13 is identified. It also provides a removal right for California residents under 18 who have posted User Input to the platform....
Why it matters: This provision establishes COPPA-related commitments regarding data collected from children under 13 and a California-specific minor content removal right under California Business and Professions Code Section 22581, while noting that removal may not be comprehensive due to third-party republication....
-
Tabnine
· Tabnine Privacy Policy
The policy authorizes collection of device advertising identifiers (IDFA, Advertising ID) and SSO-linked demographic data including gender and region or country, used to deliver interest-based advertising both within the platform and through third-party websites and applications. This data may be combined with information received from advertising partners....
Why it matters: This provision authorizes use of advertising identifiers and SSO-linked demographic attributes for behavioral targeting delivered across third-party channels, which requires evaluation under GDPR lawful basis requirements and CCPA restrictions on cross-context behavioral advertising for California users. The policy does not specify the legal basis asserted for this processing in the EU context within this clause....
-
Tabnine
· Tabnine Privacy Policy
The policy requires that all claims or actions arising from this Privacy Policy be brought exclusively in Tel Aviv, Israel, under Israeli law, and users expressly agree to this exclusive jurisdiction. No alternative forum is provided....
Why it matters: This clause asserts exclusive Israeli jurisdiction for all privacy-related claims, which may engage tension with GDPR Article 79 (judicial remedy rights before member state courts) and Article 77 (complaint rights before local supervisory authorities) available to EU data subjects, as well as CCPA enforcement mechanisms. Applicable law in EU jurisdictions may limit the enforceability of this forum selection clause against individual data subjects....
-
Tabnine
· Tabnine Privacy Policy
The policy authorizes sharing of personal information with affiliates, subsidiaries, marketing service providers, data management vendors, payment processors, and analytics service providers. Analytics providers are disclosed to set their own cookies and identifiers to collect platform and website usage data directly....
Why it matters: This provision authorizes disclosure of personal data to a range of third parties including analytics providers that independently collect usage data via cookies, which may involve additional data flows beyond Tabnine's direct processing. The policy states that third-party processors are required to comply with obligations similar to those in this privacy policy and to use personal information only for specified purposes....
-
Tabnine
· Tabnine Privacy Policy
The policy prohibits use of the service by children under 16 and states that Tabnine does not knowingly collect personal information from this age group, with an exception where parental consent is provided. No mechanism for obtaining or verifying parental consent is described....
Why it matters: This provision engages GDPR Article 8 requirements for children's consent to digital services (age threshold of 16 in the policy, consistent with GDPR's maximum threshold) and COPPA's restrictions on collecting personal information from children under 13 in the US context. The policy does not describe a parental consent verification mechanism, which creates an operational gap relative to regulatory requirements for the stated parental consent exception....
-
Tabnine
· Tabnine Privacy Policy
The policy reserves the right to revise, amend, or modify terms at any time, with changes effective upon posting. No advance notice period, user notification mechanism, or re-consent requirement is described....
Why it matters: This provision authorizes unilateral modification of privacy terms with no stated advance notice or user notification obligation beyond updating the posted document, which may interact with GDPR requirements for transparent communication of material changes to data processing practices and with CCPA notice-at-collection obligations when processing purposes change materially....
-
Inflection AI
· Inflection AI Privacy Policy
Inflection AI states that it uses information collected from users, including inputs and derived data, to develop and train its AI models. Users can opt out of their data being used for model training by navigating to the account settings page....
Why it matters: This provision authorizes use of user-submitted conversational data for AI model training as a default, with opt-out available through account settings. The scope of data used for training, including inputs that may contain personal information, is relevant for GDPR legitimate interests assessments and U.S. state privacy law compliance....
-
Inflection AI
· Inflection AI Privacy Policy
Inflection AI states it retains Pi user inputs for up to 15 days following account deletion, with exceptions for fraud, security, legal requirements, and financial record-keeping. AI-generated outputs are retained indefinitely for purposes described in Section 4 of the Terms of Service....
Why it matters: This provision establishes an indefinite retention period for AI-generated outputs, cross-referencing Section 4 of the Terms of Service rather than setting out the applicable purposes directly in the privacy policy. The exceptions to the 15-day input deletion window permit extended retention for a range of operational and legal purposes....
-
Inflection AI
· Inflection AI Privacy Policy
For European users, the policy provides a legal basis table mapping processing purposes to GDPR legal bases including contractual necessity, legitimate interests, and consent. AI model training and service improvement are stated to rely on the legitimate interests basis....
Why it matters: This provision discloses the specific GDPR legal bases for each processing purpose, including the reliance on legitimate interests for AI model training. The document also identifies DataRep as the appointed EU and UK representative, and states that international transfers rely on appropriate safeguards such as contractual clauses....
-
Inflection AI
· Inflection AI Privacy Policy
The Terms of Service prohibit a range of uses of the Pi service including biometric categorization to infer protected characteristics, mass public surveillance, emotional recognition in workplace and educational settings, social scoring, and criminal profiling. These prohibitions are stated to apply to users of the service, not to Inflection AI's own processing....
Why it matters: These prohibitions reflect restrictions consistent with EU AI Act prohibited practices and high-risk AI system provisions, applied as user-facing acceptable use constraints. Violations of acceptable use terms are stated as grounds for enforcement action under the Terms of Service....
-
Inflection AI
· Inflection AI Privacy Policy
The Terms of Service prohibit use of Inflection AI services by users under the age of 18 and request that suspected underage use be reported to privacy@inflection.ai....
Why it matters: This provision establishes a categorical age restriction at 18 rather than 13, which exceeds COPPA's minimum age threshold and creates broader restrictions on minor access. The document does not describe a technical age verification mechanism, which is relevant to compliance exposure under COPPA and analogous state and international youth data protection frameworks....
-
Inflection AI
· Inflection AI Privacy Policy
The policy authorizes disclosure of personal information to vendors and service providers performing functions including web hosting, cloud storage, content moderation, marketing and advertising, advertising measurement, and customer support. Personal information may also be disclosed during negotiations or completion of mergers, acquisitions, asset sales, or financing transactions....
Why it matters: This provision authorizes disclosure of personal information to a range of third-party vendors across operational functions, and separately permits disclosure during corporate transaction negotiations before any transaction is completed. The advertising measurement category of vendor is relevant for users who have not opted out of marketing-related data processing....
-
Windsurf
· Windsurf Privacy Policy
The policy states that user content, including personal information provided in inputs, file uploads, feedback, and outputs, may be used to train, fine-tune, and improve the AI models powering the services, subject to the terms applicable to the specific service tier....
Why it matters: This provision asserts a legitimate interests basis for using user-submitted content, including conversational inputs and file uploads, for model training purposes. The practical scope of this use depends on the terms applicable to the user's specific service tier, which may include enterprise or platform-specific agreements that modify or restrict this use....
-
Windsurf
· Windsurf Privacy Policy
The policy states that administrators of enterprise or business accounts may access user content and exercise control over accounts and associated information for users who joined under an employer or organizational account....
Why it matters: This provision establishes that employer-designated administrators have access to employee-generated user content within enterprise accounts, including inputs and outputs from AI interactions. The scope of administrator access and the data categories accessible are defined broadly as 'certain information associated with your account, including your User Content.'...
-
Windsurf
· Windsurf Privacy Policy
The policy states that user personal information may be shared during the evaluation of and entry into asset sales, acquisitions, mergers, or other change of control events, including bankruptcy proceedings, without a requirement for separate user consent....
Why it matters: This provision asserts that personal information across all stated categories may be transferred to third parties in connection with corporate transactions, including during the due diligence evaluation phase. This applies to the full scope of user data described in the policy, including user content, account information, and usage data....
-
Windsurf
· Windsurf Privacy Policy
The policy states that personal information may be transferred to and processed in multiple countries globally, and that Standard Contractual Clauses and the UK International Data Transfer Addendum are used as the legal mechanism for cross-border transfers of EEA, Swiss, and UK personal data....
Why it matters: This provision identifies Standard Contractual Clauses and the UK IDAD as the stated transfer mechanisms for EEA, Swiss, and UK personal data, consistent with GDPR Chapter V requirements. The policy notes that third-party partners and service providers are also included in the scope of cross-border transfers....
-
Windsurf
· Windsurf Privacy Policy
The policy states that audio input collected through voice features is processed to generate transcriptions or commands, and that the underlying audio is deleted after transcription unless the applicable terms state otherwise....
Why it matters: This provision establishes a default deletion practice for raw audio data following transcription, while preserving the right to retain audio where stated in applicable terms. The transcription output is retained as user content and subject to the broader data practices described in the policy....
-
Hims & Hers
· Hims & Hers Terms and Conditions
Subscription products automatically charge the user's payment method at regular intervals until the user cancels at least two days before the renewal date. No refunds are issued for partially used subscription periods, though the company may grant refunds at its sole discretion on a case-by-case basis....
Why it matters: This provision establishes the automatic renewal and billing mechanism for all subscription products and services and limits refund eligibility to the company's sole and absolute discretion, with no defined criteria or process for case-by-case refund determinations. The two-day cancellation window before renewal creates an operationally narrow notice period that may require evaluation under state auto-renewal statutes....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement authorizes Hims & Hers to transfer user prescriptions among any of the named affiliated pharmacies without providing prior notice to the user. Users provide advance consent to this transfer authority through acceptance of the agreement....
Why it matters: This provision establishes a broad transfer authorization that permits prescriptions to be moved among affiliated pharmacies without individual notice or consent at the time of transfer. Pharmacy law in various states imposes specific requirements regarding patient consent and notice for prescription transfers, and the scope of this advance consent may require evaluation against state pharmacy practice regulations....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement establishes that all products and services are provided on a cash-pay basis outside of Medicare, Medicaid, and commercial insurance, and that no claims will be submitted to any payer for reimbursement. Users bear sole financial responsibility for all costs....
Why it matters: This provision explicitly establishes the out-of-network, cash-pay structure of the platform and requires users to acknowledge in advance that no insurance or government program reimbursement will be sought. This affects users who may have assumed coverage eligibility and may have implications under federal healthcare program exclusion and anti-kickback frameworks depending on how affiliated providers are structured....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement discloses that Hims & Hers uses generative AI and machine learning in customer support and clinical care messaging workflows, including drafting responses for licensed healthcare professional review. The agreement states that AI is not used to make clinical decisions and that users will be informed when interacting directly with an AI-supported channel....
Why it matters: This provision establishes the operational parameters of AI use on the platform, drawing a distinction between AI-assisted drafting of clinical communications reviewed by licensed professionals and autonomous clinical decision-making. The disclosure that users will be notified of AI interaction in accordance with applicable law creates a compliance dependency on evolving state AI transparency statutes....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The Weight Loss Membership and associated Medication Plan auto-renew monthly unless cancelled at least two days before the billing date. Refunds on medication are not available after shipment, and refunds on initial Medication Plan orders are available only if cancellation occurs within 48 hours of payment submission....
Why it matters: This provision establishes narrow and time-sensitive refund eligibility windows for the Weight Loss Membership and Medication Plan products, with the 48-hour initial-order refund window and the no-refund-after-shipment rule creating distinct cancellation triggers. The interaction between Medication Plan cancellation and Weight Loss Membership continuation, and the separate Gifthealth billing arrangement, adds operational complexity for users managing multiple subscription components....
-
Hims & Hers
· Hims & Hers Privacy Policy
Users who submit payment and transaction information grant the company an irrevocable, perpetual, and universe-wide license to share that information with third parties for the stated purpose of facilitating the transaction....
Why it matters: This provision establishes a broadly worded license over transaction data that is described as irrevocable and perpetual; while the stated purpose is transaction facilitation, the scope language extends beyond typical payment processing data sharing terms and may warrant review of whether the breadth of the grant is proportionate to the stated purpose....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy authorizes the company to de-identify user information and use, create, or sell de-identified data for any lawful business purpose, with AI model training cited as an explicit example....
Why it matters: This provision establishes that de-identified user data, which may include health-related and other sensitive information, can be used to train AI models and sold to third parties, subject to the adequacy of the de-identification process applied and applicable legal standards....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states the service is not directed to children under 13, establishes a voluntary practice of ceasing use of data if collected from under-13 users, and provides a removal request right for users under 16 via email or certified mail....
Why it matters: This provision establishes the company's stated compliance posture regarding minor data collection, including a voluntary removal mechanism for users under 16 and an express disclaimer that the policy does not constitute an admission of COPPA applicability, which may be relevant to FTC enforcement assessments....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy provides a web-based mechanism at privacy.hims.com/policies for users to submit requests to access, copy, download, correct, or delete personal information, and states that in some states users may additionally request information about third-party sharing....
Why it matters: This provision establishes the operational mechanism through which users exercise data subject rights under applicable state privacy laws, including CCPA and CPRA, and notes that the scope of available rights varies by jurisdiction....
-
Replit
· Replit Privacy Policy
The policy states that Replit may de-identify collected personal information and, once de-identified, may use or share that data for any purpose at its discretion, with no further application of the Privacy Policy to that data....
Why it matters: This provision reserves broad discretion for Replit to repurpose or share data once it is classified as de-identified, without further consent or notice obligations under this policy. The provision does not specify the technical or legal standard applied to determine when data qualifies as de-identified, which creates uncertainty regarding whether the threshold meets requirements under GDPR, CCPA, or other applicable frameworks....
-
Replit
· Replit Privacy Policy
The policy states that user profiles, usernames, profile pictures, code, and forum posts are publicly visible to other users and indexed by search engines by default, with private code visibility requiring a paid upgrade....
Why it matters: This provision establishes that user-generated code is publicly accessible and search-engine indexed by default, which has operational significance for developers who may inadvertently expose proprietary, sensitive, or credential-containing code without upgrading to a paid private tier....
-
Replit
· Replit Privacy Policy
The policy authorizes Replit to share user information, including user-generated code and usage data, with machine learning companies retained as service providers in connection with providing the Services....
Why it matters: This provision authorizes disclosure of user data, including code, to machine learning service providers. This has operational significance for developers whose code may contain proprietary logic, credentials, or sensitive data, and for enterprise customers evaluating the scope of data access granted to Replit's vendor ecosystem....
-
Replit
· Replit Privacy Policy
The policy relies on user consent through acceptance of the policy as the mechanism for authorizing international data transfers to the United States and other hosting locations including India, without specifying alternative transfer mechanisms such as Standard Contractual Clauses....
Why it matters: This provision relies on implicit consent via policy acceptance as the legal basis for cross-border data transfers. For EEA and UK users, this approach may require evaluation under GDPR Chapter V, which imposes specific requirements for international data transfers that may not be satisfied by consent obtained through a broad policy acceptance mechanism alone....
-
Replit
· Replit Privacy Policy
The policy states that Replit may receive demographic and other data about users from third-party data or marketing partners and combine that externally sourced data with information already held about the user....
Why it matters: This provision authorizes the enrichment of user profiles with third-party sourced demographic data, which may include information users did not directly provide to Replit. This affects the scope of the data profile Replit maintains on users beyond what is collected through direct interaction with the platform....
-
Replit
· Replit Privacy Policy
The policy states that the Services are not directed to children under 13 in the US and that Replit will take reasonable steps to obtain parental consent or delete personal information of users found to be underage. Student profiles created in Teams for Education are separately stated to be non-public....
Why it matters: This provision establishes Replit's stated approach to COPPA compliance for the general platform, relying on user self-representation of age eligibility rather than proactive age verification. The separately stated protection for Teams for Education student profiles addresses an education-specific use case with different default visibility settings....
-
Poshmark
· Poshmark Privacy Policy
By posting content on Poshmark, users grant the company a perpetual, irrevocable, worldwide, royalty-free license to use, modify, distribute, and sublicense that content for operating the service and for promotional and marketing purposes across any medium, including third-party platforms such as Facebook, Twitter, and Instagram. This license does not expire upon account closure....
Why it matters: This provision establishes that Poshmark and its affiliates retain ongoing rights to user-posted content for marketing and promotional purposes indefinitely, including after account deletion, across any current or future medium or technology. Compliance and legal teams should evaluate whether this perpetual license interacts with data subject deletion rights asserted under the CCPA or GDPR, as the tension between intellectual property licensing and privacy deletion rights may require jurisdiction-specific legal analysis....
-
Poshmark
· Poshmark Privacy Policy
The agreement caps Poshmark's total liability to any user at the greater of $100 or the fees the user paid as a seller in the six months preceding the claim, with exceptions for gross negligence, fraud, and intentional misconduct....
Why it matters: This provision establishes a ceiling on Poshmark's financial exposure to individual users, limiting recovery to $100 or six months of seller fees paid, whichever is greater. The clause excludes gross negligence, fraud, and intentional misconduct from this cap, and notes that limitations that cannot be excluded by applicable law are preserved....
-
Poshmark
· Poshmark Privacy Policy
The terms limit the period within which users may bring claims against Poshmark to 12 months from the date the cause of action arises, which is shorter than the default statute of limitations applicable to many contract and consumer protection claims under state law....
Why it matters: This provision contractually shortens the window for users to assert claims against Poshmark, which may be shorter than the statutory limitations period under applicable state law. The clause includes a savings provision for jurisdictions where such contractual shortening is prohibited....