-
Duolingo
· Duolingo Privacy Policy
This provision authorizes teachers in Duolingo for Schools to access student names, email addresses, learning progress data, and to log in as the student to manage their account. Students can remove teacher access by leaving the classroom in app Settings....
Why it matters: This provision establishes a delegated account access model in which teachers can authenticate as students and access account management functions, which creates data access and identity management considerations under FERPA and applicable state student privacy statutes where school-affiliated accounts involve minors....
-
Duolingo
· Duolingo Privacy Policy
This provision states that Duolingo may anonymize personal information and use the resulting de-identified data for any purpose, including AI model training, asserting that such data falls outside the definition of personal information because it cannot identify individuals....
Why it matters: This provision reserves broad secondary use rights over de-identified data derived from user activity. The practical scope of this authorization depends on the robustness of the anonymization method applied, which the policy does not describe in technical detail; applicable law in some jurisdictions may impose standards for what constitutes adequate de-identification....
-
Duolingo
· Duolingo Privacy Policy
This provision discloses that FullStory and a Session Replay service log user activity including clicks, mouse movements, scrolling, typing, browser and device information, IP address, pages visited, and learning activity. Users can disable these services using the Tracking toggle in app Settings; both are disabled by default for Child Users....
Why it matters: This provision discloses that detailed behavioral session recording, including keystroke-level typing activity and video replay of user sessions, is conducted by third-party services. Users must actively opt out via the Tracking toggle rather than being enrolled on an opt-in basis, except for Child Users who are excluded by default....
-
Duolingo
· Duolingo Privacy Policy
This provision establishes that Child Users under 13 (or applicable local age of digital consent) are registered without name, email, or phone number, using only a non-identifying username. The policy asserts COPPA compliance by limiting collection to what is necessary for internal service operations and committing to delete inadvertently collected additional data....
Why it matters: This provision establishes the operational framework for COPPA compliance, including the categories of data excluded from collection for Child Users and the parental notification mechanism triggered at first logout. The policy separately states that all users under 16 receive additional protections including non-personalized advertising and disabled third-party behavioral tracking....
-
Duolingo
· Duolingo Privacy Policy
This provision states that Duolingo relies on the EU-U.S. DPF, UK Extension to the DPF, and Swiss-U.S. DPF as the legal mechanism for transferring personal data from the EU, UK, and Switzerland to the United States, and that Duolingo retains liability under DPF Principles for data transferred to third-party agents that process it inconsistently with those Principles....
Why it matters: This provision establishes the international data transfer legal basis for EU, UK, and Swiss user data processed in the United States, and affirms FTC jurisdiction over DPF compliance. Duolingo's ongoing DPF certification requires annual renewal and is subject to FTC enforcement action for material misrepresentation of compliance....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Duolingo
· Duolingo Privacy Policy
This provision states that IP addresses are retained for a maximum of 30 days under standard circumstances, with an exception permitting extended retention for subscribers who provide a payment method, limited to payment processing and fraud prevention purposes....
Why it matters: This provision establishes a specific IP address retention timeline with a carve-out for payment subscribers that does not define a maximum extended retention period, which may require evaluation under GDPR data minimization and storage limitation principles for EU users....
-
Duolingo
· Duolingo Privacy Policy
This provision authorizes Duolingo to share personal information with named advertising networks including Unity, Meta, LiftOff, Pangle, Moloco, and Google for personalized advertising purposes. EU and UK users are opted out by default; all other users may opt out through app Settings....
Why it matters: This provision discloses that personal information is shared with six named advertising network vendors and unspecified additional marketing analytics and website analysis providers for cross-site advertising and market research purposes. The default opt-out for EU and UK users reflects applicable regulatory requirements in those jurisdictions....
-
Duolingo
· Duolingo Privacy Policy
This provision enumerates twelve data subject rights including access, deletion, correction, export, opt-out of third-party sharing, objection to processing, and consent withdrawal, and establishes that these rights are not absolute, with refusal permitted on grounds of authentication failure, third-party rights, legal requirements, or service interference. Requests can be submitted through the Duolingo Data Vault or by emailing privacy@duolingo.com....
Why it matters: This provision establishes the operational framework for user data subject rights requests, including the enumerated grounds on which Duolingo may decline to fulfill a request. The breadth of disclosed rights reflects GDPR, CCPA, and other applicable framework requirements, and the refusal grounds align with standard exemptions recognized under those frameworks....
-
Walgreens
· Walgreens Privacy Policy
The policy states that Walgreens collects biometric information including facial scans for safety, security, and product feature purposes, and commits to permanently destroying that information either when the original collection purpose is satisfied or within three years of the consumer's last interaction with Walgreens, whichever comes first....
Why it matters: This provision establishes a specific biometric data retention and destruction schedule consistent with requirements under statutes such as the Illinois Biometric Information Privacy Act, which mandates destruction within a specified period. The collection of facial scans for product feature purposes alongside security purposes broadens the stated collection scope beyond traditional loss prevention use cases....
-
Walgreens
· Walgreens Privacy Policy
The policy discloses that health-related retail product purchase data, categorized as Sensitive Personal Information under California law, has been and may continue to be shared with online advertising networks, marketing companies, financial services partners, and social media companies in transactions that may constitute a sale or sharing under the California Consumer Privacy Act....
Why it matters: This provision discloses that health-related retail purchase data is among the categories of Sensitive Personal Information shared with advertising and marketing third parties for secondary purposes, which triggers CPRA opt-out rights for California residents and may require evaluation under CPRA's purpose limitation and sensitive data handling requirements....
-
Walgreens
· Walgreens Privacy Policy
The policy states that information submitted through a pharmacy account login, including prescription order data, is governed by HIPAA's Notice of Privacy Practices rather than this privacy policy, creating a distinct legal framework for pharmacy interactions separate from general retail data practices....
Why it matters: This provision establishes a structural data governance boundary between HIPAA-covered pharmacy data and general retail personal information, which determines which consumer rights framework and which notice and consent mechanisms apply depending on the nature of the customer interaction....
-
Walgreens
· Walgreens Privacy Policy
The policy states that Walgreens collects precise location information through satellite, cell phone tower, WiFi, beacons, Bluetooth, and near field communication protocols when location services are enabled on a user's device, and may use Bluetooth signals from the mobile application to determine a user's location within a Walgreens store....
Why it matters: This provision authorizes collection of precise geolocation data through multiple technical mechanisms including in-store Bluetooth positioning, which the policy separately categorizes as Sensitive Personal Information under California law subject to opt-out and heightened handling requirements....
-
Walgreens
· Walgreens Privacy Policy
The policy states that personal information collected from customers may be disclosed to potential buyers or transferred to acquiring entities in connection with mergers, acquisitions, or the sale of Walgreens stores or assets, and that customer information is treated as a transferred business asset in such transactions....
Why it matters: This provision establishes that customer personal information, including all categories described in the policy, may be disclosed during the evaluation phase of a potential transaction and transferred to a new entity following an acquisition, without requiring separate individual consent at the time of transfer....
-
Walgreens
· Walgreens Privacy Policy
The policy states that by using chatbot or managed chat features on the Walgreens website, users consent to Walgreens recording and retaining transcripts of all communications and recording or recreating website activity, with that data potentially shared with third-party service providers for analysis and storage....
Why it matters: This provision establishes that chatbot interactions and website activity may be recorded, retained, and shared with service providers, and that use of the interactive features constitutes consent to these practices. Users who discuss health or pharmacy-adjacent topics through chatbot channels should note that this data may be subject to the general retail privacy policy rather than HIPAA depending on whether the interaction occurs outside of a pharmacy account login....
-
Walgreens
· Walgreens Privacy Policy
The policy states that third-party advertising networks place cookies on users' devices to collect data and build behavioral profiles for targeted advertising on Walgreens' website and third-party websites, and that some of these networks participate in opt-out programs operated by the Digital Advertising Alliance and Network Advertising Initiative....
Why it matters: This provision authorizes third-party advertising networks to build behavioral profiles from user data collected across Walgreens and unaffiliated websites, and discloses that opting out of interest-based advertising does not stop data collection for analytics and fraud prevention purposes....
-
Walgreens
· Walgreens Privacy Policy
The policy states that Walgreens does not interpret or respond to browser-level Do Not Track signals, while separately stating that it does recognize opt-out preference signals such as Global Privacy Control for California residents....
Why it matters: This provision discloses that Walgreens does not honor Do Not Track signals, which is a common industry practice but is distinguished from the policy's separate disclosure that it recognizes opt-out preference signals under California law, creating a distinction between general DNT signals and California-specific GPC signals....
-
Walgreens
· Walgreens Privacy Policy
The policy discloses that Walgreens' myWalgreens loyalty program provides price discounts and perks in exchange for consumer participation that may generate personal information across all categories described in the policy, and includes a California-required Notice of Financial Incentive describing the basis for the data-for-benefit exchange including a qualitative description of data valuation methodology....
Why it matters: CPRA requires that businesses offering financial incentives in exchange for personal information provide a Notice of Financial Incentive including a good faith estimate of the value of the consumer's data and the material terms of the program, and this provision constitutes Walgreens' attempt to satisfy that requirement, including the statement that data value is not calculated in accounting statements....
-
Verizon
· Verizon Privacy Policy
The policy discloses that Verizon collects biometric identifiers including voice recordings and voiceprints, along with Social Security Numbers, driver's license numbers, and payment information from customers....
Why it matters: This provision establishes that Verizon's data collection scope includes categories of sensitive personal information, specifically biometric identifiers and government-issued identification numbers, that are subject to heightened protection requirements under multiple state laws including Illinois BIPA, Texas CUBI, and California CPRA....
-
Verizon
· Verizon Privacy Policy
The policy discloses that Verizon installs system software on wireless devices that can automatically install or update applications, collect device and location conditions, and operate on Wi-Fi even when the device is deactivated from the wireless network; some installed apps do not display visible icons....
Why it matters: This provision establishes that Verizon reserves the right to install and maintain software on customer devices that operates independently of active wireless service, including the automatic installation of applications and collection of location and device data, with opt-out limited to disabling notifications from specific management applications....
-
Verizon
· Verizon Privacy Policy
The policy discloses that named Verizon Value brands (Total Wireless, Straight Talk, Tracfone, Simple Mobile, Walmart Family Mobile, Net10 Wireless, Go Smart Mobile, and SafeLink Wireless) share customer-identifying information with Prove, which uses it to assist banks and other third parties in making credit application decisions....
Why it matters: This provision establishes that customer-identifying data from prepaid wireless brands is shared with a third-party partner that uses it in connection with credit application decisioning at financial institutions, creating potential obligations and exposure under the Fair Credit Reporting Act depending on whether these data flows constitute consumer report transactions....
-
Verizon
· Verizon Privacy Policy
The Custom Experience program uses browsing and app usage data to personalize communications and product recommendations. Customers are enrolled by default and must actively opt out to be excluded from the program....
Why it matters: This provision establishes an opt-out default for a program that uses mobile device browsing and app usage data for behavioral profiling and targeted marketing, meaning customers are included unless they take affirmative action to opt out....
-
Verizon
· Verizon Privacy Policy
The policy authorizes disclosure of email addresses, purchase history, and site and app activity to third-party advertising and analytics companies, which may use this data to create persistent cross-platform identifiers associated with customers, their households, or their devices, and may combine it with data from other sources for targeted advertising and audience matching....
Why it matters: This provision authorizes disclosure of personally identifying information including email addresses to third-party advertising companies for cross-platform identifier creation and audience matching, a practice that extends data use beyond Verizon's own platforms and involves third parties combining Verizon customer data with independently collected data....
-
Verizon
· Verizon Privacy Policy
The policy discloses that CPNI (telecommunications usage data including call records, location, and billing information) is governed by federal law and that Verizon may seek consent to use CPNI to market services beyond those a customer already has, with an opt-out available....
Why it matters: This provision establishes that CPNI is subject to federal Communications Act requirements and that customers can limit its use for marketing beyond existing services, an operationally significant right for telecommunications customers that is governed by FCC rules rather than general consumer privacy law....
-
Verizon
· Verizon Privacy Policy
The Business and Marketing Insights program uses postpaid and small business customer data including web browsing, device location, app usage, demographic information, and third-party data to generate aggregate insights that are disclosed to third parties; the policy states the disclosed insights do not individually identify customers....
Why it matters: This provision establishes that Verizon uses individual-level behavioral and location data from postpaid and small business customers as inputs to create aggregate insights that are then commercially disclosed to third parties, with the policy asserting individual identifiability is removed at the output stage....
-
Verizon
· Verizon Privacy Policy
The policy discloses that Fios TV apps and the Fios TV website include Comscore and Nielsen software that collects TV viewership data, advertising identifiers, IP addresses, and device information and transmits this data to Comscore and Nielsen for market research and audience measurement purposes....
Why it matters: This provision establishes that Fios TV viewing data, advertising identifiers, and device information are disclosed to Comscore and Nielsen through embedded software, creating a third-party data collection arrangement within a video service subject to the Cable Communications Policy Act's subscriber data protection requirements....
-
Verizon
· Verizon Privacy Policy
The policy authorizes Verizon to use automated processing including artificial intelligence and machine learning to train algorithmic models using customer data for network management, marketing personalization, and service prediction. The policy includes a specific statement that customer personal information is not collected, used, or sold to train large language models....
Why it matters: This provision establishes that customer data is used to train machine learning models for marketing and service prediction purposes, and includes an explicit carve-out stating that personal information is not used for large language model training, a disclosure that addresses a specific area of consumer and regulatory concern regarding generative AI....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states that personal data collected across all categories described in the notice may be used to train artificial intelligence models, with examples including network improvement and customer service enhancement....
Why it matters: This provision establishes AI model training as a stated purpose for personal data use across all collected data categories, without specifying which categories are excluded from AI training or what separate consent conditions, if any, apply to this use beyond those governing the underlying collection purpose....
-
T-Mobile
· T-Mobile Privacy Policy
Upon opt-in, T-Mobile and its partners analyze app usage, purchase history, browsing activity, precise location, and CPNI to create audience segments and insights, which may be shared with third-party brands for targeted advertising and campaign measurement....
Why it matters: This provision establishes that CPNI, which is subject to FCC regulatory protections under the Communications Act, is combined with precise location, browsing activity, and purchase data for advertising purposes upon opt-in, and that resulting audience segments and ad IDs may be shared with external brand partners....
-
T-Mobile
· T-Mobile Privacy Policy
T-Mobile's Relevant Ads program operates as a default, collecting app usage data, mobile advertising IDs, and purchased demographic data to build interest models and deliver targeted third-party advertising through advertising partners....
Why it matters: This provision establishes that targeted advertising using app usage data, mobile advertising IDs, and purchased demographic data operates by default, requiring consumers to actively opt out through the Privacy Dashboard rather than opt in to participate....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement discloses a broad list of sensitive personal data categories collected, including Social Security numbers, biometric data, precise location, text message content, and children's data, and states that without consent these categories are not used for characteristic inference or sold or shared for cross-context behavioral advertising....
Why it matters: This provision establishes the categories of sensitive data T-Mobile collects and the consent conditions limiting their use for advertising purposes, explicitly anchoring the default use restrictions to CCPA regulatory section 7027(m) and defining the boundary between permissible operational use and consent-required advertising use....
-
T-Mobile
· T-Mobile Privacy Policy
T-Mobile compiles fraud indicators from account status, SIM change history, call and text history, URL interaction data, and risk scores, and shares these indicators with third-party companies where a consumer holds accounts, with an opt-out available through the Privacy Dashboard....
Why it matters: This provision establishes that SIM change history, call and text history, and risk scores derived from network behavior may be shared with external companies outside T-Mobile for fraud prevention purposes, creating a third-party data sharing relationship that consumers can opt out of through the Privacy Dashboard....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states that T-Mobile collects personal data from social media companies, financial institutions, credit reporting agencies, and data resellers, supplementing data collected directly from consumers and automatically through network interactions....
Why it matters: This provision establishes that consumer profiles at T-Mobile are built in part from externally purchased or obtained data sourced from data resellers, social media companies, and credit reporting agencies, which are then combined with internally collected network, usage, and account data for uses described throughout the notice....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states T-Mobile collects location data from all devices and home internet gateways on its network for service delivery, fraud detection, and emergency response purposes, and may use precise location for advertising with consent, while committing not to share or sell precise location for targeted advertising without consent....
Why it matters: This provision establishes that location data collection is continuous for all network-connected devices and home gateways, with an explicit consent requirement imposed before precise location is used for advertising or shared with advertising partners, creating a consent-gated boundary for advertising use of this sensitive data category....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement provides a data sale and sharing opt-out mechanism through the Privacy Dashboard and a site-level link, recognizes the Global Privacy Control signal as a valid opt-out, and states that separate consent withdrawal through the Privacy Dashboard may be required for consumers enrolled in specific advertising programs....
Why it matters: This provision establishes that T-Mobile engages in the sale and sharing of personal data for targeted advertising as defined under applicable state privacy law, that opt-out is available but requires multiple steps for consumers enrolled in program-specific advertising, and that GPC signal recognition satisfies California's CCPA opt-out signal requirement....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement provides an opt-out mechanism through the Privacy Dashboard for profiling activities that produce legal or similarly significant effects, defining profiling as automated processing to evaluate or predict aspects including economic situation, health, reliability, behavior, and location....
Why it matters: This provision establishes a consumer opt-out right for profiling that produces legal or similarly significant effects, consistent with emerging state privacy law requirements for automated decision-making, and signals that T-Mobile engages in or anticipates engaging in such profiling activities....
-
T-Mobile
· T-Mobile Privacy Policy
The agreement states that device usage, app behavior, demographic, and ad interaction data is aggregated and that resulting aggregate reports may be sold to third-party companies, with an opt-out available through the Privacy Dashboard....
Why it matters: This provision establishes that aggregate behavioral and demographic reports derived from consumer device and network usage data may be commercially sold to external companies, representing an outbound commercial data product derived from subscriber activity....
-
Roblox
· Roblox Privacy Policy
The policy states that audio captured through a user's device during voice feature use is monitored, collected, stored, and used for voice chat, safety enforcement, AI model training, and product improvement. This provision applies to users 13 and older....
Why it matters: This provision establishes that audio data collected through voice features is retained and used for AI training and product improvement purposes in addition to the primary safety and communications functions, which may require evaluation under GDPR lawful basis requirements, state-level biometric and wiretapping consent laws, and emerging AI training data regulations depending on user jurisdiction....
-
Roblox
· Roblox Privacy Policy
The policy states that Roblox may collect facial images, including selfies, to estimate a user's age, and that such images are deleted after the age assurance process is completed. Additional detail is provided in a separate Roblox Facial Media Capture Policy....
Why it matters: This provision establishes a biometric data collection practice for age estimation purposes, which may require evaluation under state biometric privacy laws including Illinois BIPA, Texas CUBI, and Washington's My Health My Data Act, as well as GDPR's requirements for processing biometric data as a special category under Article 9....
-
Roblox
· Roblox Privacy Policy
The policy states that third-party experience creators automatically receive users' usernames, display names, user IDs, game metrics, UGC transaction details, and regional location derived from IP addresses, without any opt-out mechanism described for this sharing....
Why it matters: This provision establishes automatic data sharing with third-party creators as an inherent condition of using any Roblox experience, creating downstream data controller or processor relationships that may require contractual documentation under GDPR Article 28 and equivalent frameworks in other jurisdictions....
-
Roblox
· Roblox Privacy Policy
The policy states that user-posted content, including chat and audio, may be used for AI training and content filtering improvement purposes where law permits. This applies to content posted in chats, forums, group walls, personal posts, and other features....
Why it matters: This provision reserves the right to use user-generated content, including communications content, for AI training purposes subject to applicable law, which may require evaluation under GDPR's lawful basis and purpose limitation principles, as well as emerging AI training data regulations in the EU and other jurisdictions....
-
Roblox
· Roblox Privacy Policy
The policy states that for users under 13, persistent identifiers such as IP addresses and device identifiers are collected and used only for the six enumerated internal operations purposes, and that Roblox implements technical and contractual measures to enforce this restriction....
Why it matters: This provision establishes COPPA-compliant limitations on persistent identifier use for users under 13, with the policy asserting that technical and contractual safeguards are in place to prevent use beyond the enumerated purposes, including a restriction to contextual advertising only (no personalized advertising) for this age group....
-
Roblox
· Roblox Privacy Policy
The policy establishes that users under 18 receive only non-personalized advertisements, while users 18 and older may receive personalized advertisements, with consent required where applicable law mandates it. Users 18 and older can manage personalized ad preferences through account settings....
Why it matters: This provision establishes a platform-wide age gate for personalized advertising set at 18 rather than the COPPA threshold of 13, which represents a more restrictive advertising policy for the 13-17 age cohort and may interact with GDPR consent requirements for users in the EEA who are minors under applicable national law....
-
Roblox
· Roblox Privacy Policy
The policy states that users who opt into the Contact Importer feature share their mobile address book contents, including first and last names and phone numbers of all contacts, with Roblox, and that Roblox automatically accesses and syncs this data periodically. Data from non-matching contacts is not retained....
Why it matters: This provision establishes ongoing, automatic collection of third-party contact data (individuals who are not Roblox users and have not consented to data collection) from the address books of users who activate the feature, which may require evaluation under GDPR, CCPA, and other privacy frameworks with respect to the rights of non-user data subjects....
-
Roblox
· Roblox Privacy Policy
The policy states that Roblox may share Personal Information and the contents of user communications with law enforcement, regulators, courts, schools, children's services, and other public agencies under several conditions including legal process, crime prevention belief, safety threats, and legal rights protection. The policy also specifically references obligations under the EU Digital Services Act Article 18, UK Online Safety Act, and Australian Online Safety Act as bases for disclosing communication contents....
Why it matters: This provision establishes the conditions under which Roblox discloses user data and communications to governmental and public authorities, including discretionary disclosures based on Roblox's belief that disclosure may prevent a crime or protect legal rights, in addition to compelled disclosures under legal process. The explicit reference to DSA Article 18, UK Online Safety Act, and Australian Online Safety Act reflects jurisdiction-specific statutory obligations....
-
Roblox
· Roblox Privacy Policy
The policy states that Roblox may transfer user Personal Information as a business asset in mergers, acquisitions, asset sales, insolvency, bankruptcy, or receivership proceedings, with notification and consent required where law mandates it....
Why it matters: This provision reserves the right to transfer Personal Information, including data of users under 13, to a successor entity in corporate transactions, with user notification and consent conditioned on legal requirement rather than as a default practice....
-
Roblox
· Roblox Privacy Policy
The policy states that participation in the Roblox Developer Exchange Program requires submission of IRS W-9 or W-8 tax forms and may require identity verification through a government-issued photo ID processed by a third-party vendor. This program is limited to users 13 and older....
Why it matters: This provision establishes that developers seeking to monetize through the Developer Exchange Program must provide tax identification information and may be required to submit government-issued identity documents to a third-party vendor, creating distinct data collection and processing obligations for this user segment including identity document handling by a named or unnamed third party....
-
Samsung
· Samsung Privacy Policy
The US Supplement states that Samsung may use personal information about US residents to develop and train its artificial intelligence algorithms and models, in addition to the purposes described in the main policy. The document does not specify which categories of personal information are eligible for AI training use or whether separate consent is required....
Why it matters: This provision appears only in the US Supplement rather than the main policy body, and the document does not limit the categories of personal information that may be applied to AI training. Compliance teams should evaluate whether this disclosure satisfies notice and secondary-use consent requirements under applicable state privacy laws, particularly in states that require explicit consent or opt-out mechanisms for secondary processing....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung shares identifiers and online activity data with advertising services via automated technologies and server-to-server connections, and acknowledges this may constitute a sale of personal information or use for targeted advertising under applicable state privacy laws. Users who have consented may have their personal information shared for personalized ad delivery....
Why it matters: This provision establishes that Samsung's ad data sharing practices may trigger sale or targeted advertising definitions under state privacy laws such as the CCPA and CPRA, requiring Samsung to honor opt-out requests submitted through the designated mechanisms. The use of server-to-server connections alongside automated technologies broadens the scope of third-party data access beyond cookie-based collection....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung's services may automatically generate biometric data including face-clustering data that groups images of the same face across photos stored on the device, and that this data remains on-device and is not accessed, transferred to, or shared by Samsung. Deletion of this data is the user's responsibility through device settings, factory reset, or photo deletion....
Why it matters: The automatic generation of face-clustering data from stored photos may implicate state biometric privacy laws such as the Illinois Biometric Information Privacy Act (BIPA), which imposes specific notice, consent, and retention requirements for biometric identifiers generated from facial geometry. The policy's assertion that Samsung does not access this data limits Samsung's ability to fulfill deletion requests on behalf of users....
-
Samsung
· Samsung Privacy Policy
The policy states that Samsung collects and stores voice recordings on its servers when users enable voice commands or contact customer service, and that third-party speech-to-text or call center providers may also receive and store voice commands. The policy also states that keyboard input typed when predictive text is enabled is collected and may be synchronized across Samsung mobile devices via a Samsung account....
Why it matters: Voice recordings and keyboard input represent categories of personal information with heightened sensitivity; collection of keyboard input through predictive text and synchronization across devices via Samsung account extends the scope of data collection beyond single-device interactions. Third-party receipt of voice commands via speech-to-text providers introduces additional data controllers outside Samsung's direct control....