-
Replit
· Replit Terms of Service
Subscriptions automatically renew at current rates, prices may change at renewal, and usage-based billing charges are non-refundable. Full refunds for subscription payments are available within 30 days of purchase only, and accounts may be limited or terminated for non-payment....
Why it matters: This provision establishes automatic renewal at potentially updated rates and designates usage-based billing charges as categorically non-refundable. The combination of automatic billing and non-refundable metered usage creates a financial obligation structure that users should account for when selecting and managing their plan....
-
Replit
· Replit Terms of Service
The agreement reserves Replit's right to suspend or terminate accounts at its sole discretion for a non-exhaustive list of reasons including inactivity or actions deemed detrimental to the platform, and states that paid fees will not be refunded upon termination....
Why it matters: This provision establishes broad discretionary termination authority with a non-refund policy for prepaid fees. The open-ended framing of 'any other actions that Replit deems as detrimental' means that the enumerated grounds are illustrative rather than exhaustive, and paid subscription or usage fees are not recoverable upon termination regardless of the basis....
-
Replit
· Replit Terms of Service
The agreement requires users to indemnify Replit and cover legal costs for any claims or losses Replit incurs arising from the user's use of the Service, with a non-exhaustive scope covering any actions or disputes related to platform use....
Why it matters: This provision establishes a broad user indemnification obligation that covers legal costs and expenses arising from any claims related to the user's platform use. The non-exhaustive framing means the scope is not limited to enumerated scenarios, which may have implications for users whose platform activities generate third-party claims....
-
Replit
· Replit Terms of Service
The agreement requires users to be adults, permits users under 13 to access the Service only with written parental or guardian consent, and holds parents and guardians legally responsible for the platform activity of minors under 18....
Why it matters: This provision establishes a conditional access mechanism for users under 13 based on written parental consent, engaging COPPA compliance obligations for Replit. The provision also extends full Terms of Service obligations to parents and guardians of any user under 18, creating a direct contractual relationship with adults who permit minor access....
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs collects and logs blockchain wallet addresses upon connection and screens them using third-party blockchain analytics providers to detect prior illicit activity....
Why it matters: This provision establishes an automated screening process applied to all connecting wallet addresses using third-party intelligence services, with no opt-out mechanism described in the policy. Compliance teams should assess the contractual and data-sharing terms governing these analytics providers, including data retention, onward transfer, and whether the screening constitutes automated decision-making with significant effects under GDPR....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs is unable to edit or delete transaction data, wallet addresses, or asset information stored on blockchain networks, and characterizes this data as beyond the company's control....
Why it matters: This provision establishes a structural limitation on the company's ability to fulfill GDPR erasure requests and CCPA deletion requests for on-chain data. Compliance teams and supervisory authorities may need to evaluate whether this limitation is consistent with applicable data protection obligations, as the document asserts rights for users that cannot be operationally fulfilled for this category of data....
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs and its third-party service providers collect information via localStorage, device IDs, cookies, and web beacons, including browser type, operating system, referring and exit pages, and device language, to personalize the Services and analyze usage....
Why it matters: This provision authorizes collection of device and session data by both Uniswap Labs and unnamed third-party service providers across user sessions, and the policy separately identifies Google as one such third-party provider. Users have several opt-out mechanisms described in the policy, including browser settings, device advertising ID controls, and Google's opt-out tool....
-
Uniswap
· Uniswap Privacy Policy
The policy states four GDPR lawful bases for processing EU user data: consent, contract performance, legal obligation, and legitimate interests. It also enumerates GDPR rights including access, rectification, erasure, objection, restriction, and portability, exercisable by contacting privacy@uniswap.org....
Why it matters: This provision establishes the GDPR compliance framework for EU data subjects and invokes legitimate interests as one of four processing bases without specifying the particular processing activities to which each basis applies, which may require evaluation under applicable supervisory authority guidance on documentation of legitimate interests assessments....
-
Uniswap
· Uniswap Privacy Policy
The policy states that material changes will be notified via the Services, and that continued use of the Services constitutes consent to the updated policy terms....
Why it matters: This provision conditions consent to policy changes on continued use of the Services following in-app notification, without specifying a minimum notice period before changes take effect or a separate affirmative consent mechanism for material changes....
-
ConvertKit
· ConvertKit Terms of Service
The document footer references a dedicated GDPR page, indicating that Kit maintains separate GDPR-specific documentation addressing EU data protection obligations applicable to users in the EU and EEA....
Why it matters: This provision signals that Kit asserts GDPR compliance and directs EU users to a companion document, which may contain data processing terms, lawful basis disclosures, and data subject rights procedures relevant to institutional compliance assessments....
-
ConvertKit
· ConvertKit Terms of Service
The document footer references a Privacy Policy as a companion document, indicating that data collection, use, and sharing practices are governed by a separate policy document linked from the platform....
Why it matters: Privacy policies incorporated by reference into terms of service form part of the overall contractual framework; the specific data types collected, sharing authorizations, and user rights established by Kit's Privacy Policy govern the data relationship between Kit and its users....
-
ConvertKit
· ConvertKit Terms of Service
The document describes platform features including paid newsletter subscriptions, digital product sales with transaction fees, newsletter sponsorships, and paid recommendations, indicating that Kit's terms govern commercial transactions conducted through the platform....
Why it matters: Platform-mediated commerce features including paid newsletters and digital product sales are subject to terms governing transaction fees, payout eligibility, and seller obligations that have direct financial implications for creator accounts....
-
ConvertKit
· ConvertKit Terms of Service
The platform describes advertiser participation and newsletter sponsorship features, indicating that terms governing advertiser relationships, sponsored content placements, and sponsorship payment structures are part of the platform's operative terms....
Why it matters: Advertiser and sponsorship terms establish the conditions under which sponsored content is placed within creator newsletters, including advertiser eligibility, content restrictions, payment terms, and disclosure obligations that may engage FTC endorsement guidelines....
-
23andMe
· 23andMe Privacy Statement
The agreement states that users may elect whether their biological DNA sample is stored after laboratory processing, and that a choice to discard the sample is irreversible....
Why it matters: This provision establishes that the storage or destruction of biological genetic material is a one-time irreversible election, which affects users' ability to request future sample-based testing or retrieval of physical genetic material....
-
23andMe
· 23andMe Privacy Statement
The agreement states that participation in sharing features, including DNA Relatives and Your Connections, is a voluntary user election rather than a default setting....
Why it matters: This provision establishes that genetic relationship data disclosed through features such as DNA Relatives is shared only upon affirmative user participation, which has implications for the genetic privacy of both the opting-in user and any biological relatives whose identities may be inferred from shared genetic data....
-
23andMe
· 23andMe Privacy Statement
The document references separate regional privacy notices for EEA, UK, and Switzerland users, indicating that the full privacy framework for these user populations is governed by documents beyond this Privacy Statement....
Why it matters: This provision indicates that the privacy terms applicable to EU, UK, and Swiss users are contained in separate regional notices, which means this Privacy Statement alone does not constitute the complete disclosure for those populations. Compliance assessment for these regions requires review of the referenced regional notices....
-
Windsurf
· Windsurf Security & Data Handling
The document states that user data is used for model training by default, with a self-service opt-out available to paid plan users through the Data Controls settings page; on the Teams plan, only administrators may exercise this opt-out....
Why it matters: This provision establishes a default opt-in structure for model training across non-enterprise paid tiers, requiring affirmative action by the user or administrator to disable. The tiered access to the opt-out mechanism (individual paid users versus Teams administrators) creates a differentiated data governance structure that organizations must account for in their internal access and consent workflows....
-
Windsurf
· Windsurf Security & Data Handling
The document states that enterprise customers are subject to a stricter standard under which Cognition will not use their data for model training without express prior written consent, with specific terms deferred to the individual enterprise agreement....
Why it matters: This provision establishes a higher consent threshold for enterprise customers relative to other paid tiers, requiring affirmative written authorization before any training use. The deferral to individual enterprise agreements means the specific scope and enforceability of this commitment may vary by contract....
-
Windsurf
· Windsurf Security & Data Handling
The document states that while general customer data is retained for the duration of the customer relationship, Feedback Data and User Interaction Data are retained for an unspecified period determined solely by Cognition....
Why it matters: This provision creates a carve-out for two categories of data (Feedback Data and User Interaction Data) from the general customer relationship-duration retention standard, with no defined maximum retention period. The retention duration for these categories is governed entirely by Cognition's internal determination....
-
Windsurf
· Windsurf Security & Data Handling
The document states that output produced by Devin is treated as the user's intellectual property for commercial purposes, subject to a restriction prohibiting use of that output to train models that reverse engineer or compete with Devin....
Why it matters: This provision asserts a use restriction on output that would otherwise be characterized as user-owned intellectual property. The restriction on training competing models using Devin output may require legal evaluation in open-source deployment contexts or where users intend to develop adjacent AI tooling....
-
Windsurf
· Windsurf Security & Data Handling
The document advises users to store credentials such as passwords, API keys, and cookies through the Secrets feature in Settings rather than sharing them directly in prompts or sessions....
Why it matters: This provision places responsibility on users to manage credential security by directing them to a specific product feature. The document frames this as advisory guidance rather than a platform-enforced restriction, meaning users who share credentials outside the Secrets feature do so outside the recommended security perimeter....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document states, in response to the FAQ question, that GitHub does not use Copilot Business or Enterprise customer data to train AI models....
Why it matters: This provision is the most operationally significant data use commitment on the Trust Center page for enterprise customers, as it defines the boundary of how prompt and engagement data submitted through Business and Enterprise tiers may be used by GitHub....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document identifies four categories of data processed by Copilot: AI-generated suggestions, user feedback including reactions and support ticket feedback, user prompts and associated context, and pseudonymous engagement data including accepted/dismissed completions, error messages, system logs, and product usage metrics....
Why it matters: This provision establishes the disclosed scope of data processing by Copilot, which is the foundational disclosure required for privacy compliance assessments and data mapping exercises across the organizations using Copilot....
-
DraftKings
· DraftKings Terms of Use
The agreement states that player deposits and winnings are held in a segregated bank account controlled by DK Player Reserve LLC, a separate DraftKings subsidiary, and asserts that these funds are not available to DraftKings Inc. creditors. The terms prohibit commingling of DraftKings Inc. funds with the segregated player funds....
Why it matters: This provision establishes the structural mechanism for player fund protection, asserting that user deposits and winnings are held in a legally distinct entity and are insulated from DraftKings Inc. creditor claims. The operational and legal effectiveness of this structure depends on applicable state regulatory requirements and the corporate separateness of DK Player Reserve LLC....
-
DraftKings
· DraftKings Terms of Use
The agreement authorizes DraftKings and its affiliates to transfer, allocate, or apply user account funds across affiliated platforms and services subject to applicable law and location-based restrictions. The terms note that deposited funds may not always be transferable depending on the user's physical location....
Why it matters: This provision grants DraftKings and its affiliates authorization to move user account funds across multiple platforms and services, with restrictions that vary by location. The operational scope of this authorization depends on which affiliated platforms and services are in scope at any given time....
-
DraftKings
· DraftKings Terms of Use
By entering a contest or accepting a prize, users agree to indemnify DraftKings and its affiliates from all liability, claims, and actions arising from contest participation, prize use or misuse, travel to prize-related activities, and claims based on publicity rights, defamation, or invasion of privacy....
Why it matters: This provision requires users to hold DraftKings harmless from a broad range of claims arising from contest participation and prize activities, including personal injury, property damage, and privacy-related claims. The indemnification obligation is triggered by contest entry or prize acceptance....
-
DraftKings
· DraftKings Terms of Use
The agreement requires users to certify under penalty of perjury the accuracy of their taxpayer identification number, backup withholding status, U.S. person status, and any FATCA exemption codes provided. Users consent to receive tax documents including Forms 1099 and W-2G electronically through the player account page....
Why it matters: This provision imposes a perjury-certified tax certification obligation on users as part of account registration and prize participation, engaging IRS reporting requirements for fantasy sports winnings. The electronic tax document consent governs delivery of Forms 1099 and W-2G, which are required for user income tax reporting....
-
DraftKings
· DraftKings Terms of Use
The agreement states that all payments are final and no refunds will be issued. If a deposit is charged back, all winnings generated from that deposit are invalidated and forfeited, the original deposit amount is deducted from the account balance, and DraftKings may close the account without notice....
Why it matters: This provision establishes a no-refund policy for all deposits and authorizes DraftKings to forfeit winnings, deduct the original deposit, and close the account without notice if a chargeback is processed on any deposit....
-
DraftKings
· DraftKings Terms of Use
The agreement restricts contest participation to users physically located outside specified excluded states and Louisiana parishes, and prohibits use of virtual private networks or any means of disguising physical location while using the platform. Use of a VPN constitutes a terms violation....
Why it matters: This provision establishes physical location verification as an eligibility condition and prohibits VPN use as a mechanism to circumvent geographic restrictions. Violation of the VPN prohibition constitutes a terms breach that may trigger account enforcement actions....
-
Ticketmaster
· Ticketmaster Terms of Use
Before commencing arbitration or filing in small claims court, users must send a written notice to disputes@ticketmaster.com with specified account and claim information, then participate in a teleconference or videoconference within 60 days; only after completing this process may arbitration be initiated....
Why it matters: This provision establishes a mandatory procedural prerequisite to arbitration that requires personal participation in a teleconference or videoconference meet-and-confer, with a 60-day window, before any formal claim may be filed. The statute of limitations tolling provision during this period is operationally significant for users managing time-sensitive claims....
-
Ticketmaster
· Ticketmaster Terms of Use
When 75 or more similar arbitration demands are filed by claimants represented by the same or coordinating law firms, the claims are processed under JAMS Mass Arbitration Procedures, with aggregate consumer filing fees capped at $2,500 and a JAMS Process Administrator overseeing preliminary matters....
Why it matters: This provision establishes a distinct procedural track for coordinated consumer claims that meet the 75-demand threshold, which may affect the pace and structure of resolution for large-scale consumer disputes. The aggregate $2,500 consumer fee cap in mass arbitration contexts is operationally distinct from the $250 per-claimant filing fee applicable to individual arbitrations....
-
Ticketmaster
· Ticketmaster Terms of Use
Users must defend and indemnify Ticketmaster, its officers, directors, agents, event organizers, suppliers, advertisers, and sponsors against all claims, damages, and legal fees arising from the user's misuse of the Marketplace, third-party rights violations, negligence, or terms violations....
Why it matters: This provision extends the user's indemnification obligation to cover event organizers, suppliers, advertisers, and sponsors in addition to Ticketmaster itself, and grants Ticketmaster the right to assume exclusive control of any covered claim and require user cooperation in mounting defenses. The breadth of covered parties and Ticketmaster's right to control defense strategy are operationally significant for users who may face third-party claims....
-
Ticketmaster
· Ticketmaster Terms of Use
Users who opt into mobile messaging authorize Ticketmaster to send recurring automated marketing messages to their mobile number, and separately authorize their wireless carrier to disclose account and device information to Ticketmaster for identity verification and fraud investigation purposes....
Why it matters: The provision includes an authorization for wireless carriers to disclose user account and device information to Ticketmaster, which is a disclosure mechanism distinct from Ticketmaster's own data collection and may not be prominently visible to users who enroll in mobile messaging primarily for event alerts. The opt-out process specifies up to 10 days for removal from the messaging database....
-
Ticketmaster
· Ticketmaster Terms of Use
Account eligibility requires users to be at least 18 years old, or at least 13 years old with parental authorization and parental acceptance of the Terms; users under 13 are not permitted to use the Marketplace....
Why it matters: This provision permits users as young as 13 to hold accounts with parental authorization, and places responsibility for minors' conduct and use of the Marketplace on parents or legal guardians who accept the Terms on their behalf. The liability waiver and indemnification provisions elsewhere in the Terms would apply to minor users under this framework....
-
Nextdoor
· Nextdoor Privacy Policy
The policy discloses that members may voluntarily provide race or ethnicity information, either as part of their profile or via a welcoming platform survey, and states that survey-collected race or ethnicity data will be used only to understand and address potential bias in Nextdoor's services....
Why it matters: Race and ethnicity constitute special category data under GDPR Article 9 and sensitive personal information under CCPA, requiring explicit consent and heightened processing justifications; the policy's limitation on survey-collected race or ethnicity data to bias assessment purposes is a narrowing condition, but the scope of profile-level demographic data use is not equivalently restricted in the document....
-
Nextdoor
· Nextdoor Privacy Policy
The policy discloses that personal information about individuals who have not registered for Nextdoor, including name, email address, and phone number, may be collected through contact lists or address books uploaded by existing members, or through manual entry by members....
Why it matters: This provision establishes a data collection pathway for individuals who have not consented to Nextdoor's terms of service, raising transparency and lawful basis obligations under GDPR and equivalent frameworks; the policy states non-members may contact privacy@nextdoor.com to inquire about their data, but does not describe proactive notice mechanisms for affected individuals....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that continued use of Nextdoor constitutes consent to the transfer and processing of personal information outside the user's home country, including to the United States, which may have less protective data protection rules....
Why it matters: The use of behavioral consent (continued use) as the stated mechanism for authorizing international transfers may require evaluation against GDPR and UK GDPR requirements, which recognize Standard Contractual Clauses, adequacy decisions, and other specific mechanisms as lawful transfer bases rather than general consent obtained through continued service use....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that Nextdoor may collect precise geolocation data from device GPS with user permission, and separately derives general location from IP address or other data without requiring separate device permission, using both for content personalization and advertising....
Why it matters: The distinction between permission-gated precise geolocation and passively derived general location is operationally significant because the latter does not require a separate device-level permission grant, meaning location-based content and ad personalization may occur regardless of whether a user grants location access to the app....
-
Nextdoor
· Nextdoor Privacy Policy
The policy discloses that Nextdoor shares member personal information with service providers including generative AI vendors, who are described as contractually restricted to using the data only to provide services to Nextdoor and prohibited from using it for their own purposes....
Why it matters: The inclusion of generative AI as a named service provider category is a specific disclosure that member personal information may be processed by generative AI systems; the contractual restriction described does not specify which data categories are processed by which vendor types, leaving the scope of AI-involved data processing unspecified beyond the general contractual limitation....
-
Nextdoor
· Nextdoor Privacy Policy
The policy authorizes disclosure of member content and personal information to law enforcement, government authorities, and private parties under a good-faith necessity standard covering legal process responses, fraud investigation, safety protection, terms enforcement, and harm prevention....
Why it matters: The provision authorizes disclosure to private parties (in addition to law enforcement) under a good-faith necessity standard, and includes terms enforcement and unethical (not solely illegal) activity as enumerated disclosure grounds, which extends the scope of permissible disclosure beyond legally compelled responses....
-
Nextdoor
· Nextdoor Privacy Policy
The policy prohibits use of Nextdoor's services by children under 13 or under the applicable consent age in their jurisdiction, and provides a contact mechanism at privacy@nextdoor.com for reporting and requesting deletion of any inadvertently collected child data....
Why it matters: The provision establishes a dual threshold (under 13 or under the applicable local consent age) that references jurisdiction-specific standards without detailing verification mechanisms, which is relevant to COPPA compliance in the US and GDPR Article 8 age consent requirements in the EU (16 or lower national variation) and UK (13)....
-
MetaMask
· MetaMask Terms of Use
Consensys asserts ownership over all improvements and derivative works created using de-identified metadata, usage patterns, and aggregated performance data derived from user activity, to the extent permitted by data protection law....
Why it matters: This provision establishes Consensys's ownership claim over algorithmic improvements and derivative works generated from aggregated user activity data, which may interact with GDPR purpose limitation and data minimization obligations for EU/EEA users and warrants review as part of any data mapping or IP rights assessment....
-
MetaMask
· MetaMask Terms of Use
Consensys may immediately suspend user access to any or all Offerings without prior notice if it determines the user's activity poses security risks, legal exposure, regulatory risk, or constitutes a payment default of 30 days or more....
Why it matters: This provision authorizes Consensys to suspend access immediately and without advance notice across a broad range of subjective determinations, including potential legal liability to third parties or potential unlawfulness, which may affect users relying on MetaMask or Infura for operational continuity....
-
MetaMask
· MetaMask Terms of Use
Users are required to defend, indemnify, and hold Consensys and its affiliates harmless from losses arising from the user's breach of the Agreement, violation of law, or disputes between the user and their own customers or end users, including attorneys' fees....
Why it matters: This provision establishes a broad user indemnification obligation that extends to third-party claims arising from the user's Agreement violations, legal violations, or disputes with their own downstream users, which is operationally significant for business accounts and developers deploying Consensys-powered products to their own user bases....
-
MetaMask
· MetaMask Terms of Use
Consensys discloses that MetaMask Agent Wallet features are AI-driven systems under the EU AI Act, and requires users to acknowledge they are interacting with an automated system rather than a human when using those features....
Why it matters: This provision constitutes a transparency disclosure required under the EU AI Act for AI systems interacting with users, and establishes the contractual acknowledgment that users are on notice of the automated nature of Agent Wallet features at the point of use....
-
MetaMask
· MetaMask Terms of Use
Consensys disclaims all responsibility for third-party content and services accessible through MetaMask and related Offerings, including MetaMask Swaps, Bridging, Staking, and Snaps, and states that users access such services at their own risk....
Why it matters: This provision establishes that users bear all risk associated with third-party decentralized applications, tokens, and services accessed through MetaMask, and that Consensys has no liability for losses arising from misleading, erroneous, or harmful third-party content, which is operationally significant given MetaMask's role as a primary access point to decentralized finance applications....
-
MetaMask
· MetaMask Terms of Use
Consensys may modify any part of the Agreement at any time at its sole discretion; continued use of the Offerings following posted changes constitutes acceptance of the modified terms, regardless of whether the user has reviewed the changes....
Why it matters: This provision establishes that Agreement modifications take effect through continued use, without requiring affirmative re-consent from users, which may interact with consumer protection requirements in EU/EEA and UK jurisdictions that require meaningful consent to material contract changes....
-
Stripe
· Stripe Restricted Businesses List
The policy prohibits using Stripe Issuing to create cards for consumer personal, family, or household use, or to disburse payroll, payouts, or any consumer funds through issued cards....
Why it matters: This provision restricts Stripe Issuing to business-purpose use cases only and prohibits program structures that would load, access, or disburse consumer funds through issued cards, which directly affects fintech and payroll platforms evaluating Stripe Issuing as a distribution mechanism....
-
Stripe
· Stripe Restricted Businesses List
Stripe Issuing requires that the business's physical location, jurisdiction of registration, and at least one beneficial owner's physical address all match, and that Issuing cards be used primarily within that jurisdiction....
Why it matters: This provision imposes a geographic consistency requirement for Stripe Issuing that limits cross-border use of the product and requires beneficial owner address documentation to align with business registration jurisdiction, creating onboarding and ongoing compliance obligations....
-
Stripe
· Stripe Restricted Businesses List
The policy prohibits providing false or misleading information to Stripe about identity or business nature, requires immediate notification of any changes to personal or business information, and prohibits processing transactions on behalf of undisclosed third-party merchants....
Why it matters: This provision establishes affirmative ongoing disclosure obligations for all Stripe merchants, including an immediate notification requirement for any information changes, and prohibits transaction facilitation for undisclosed parties, which are standard anti-payment-facilitation controls....