-
Runway
· Runway Content Policy
The policy prohibits users from attempting to create or modify non-consensual intimate imagery using Runway's tools....
Why it matters: This provision addresses the use of AI generation tools to produce NCII, an area of active state and federal legislative development in the United States and under the EU AI Act framework; the prohibition applies to both creation and modification of such content....
-
Runway
· Runway Content Policy
The policy prohibits using another person's image, video, or audio in Runway's tools without that person's permission....
Why it matters: This provision engages right-of-publicity law, GDPR Article 9 (where biometric data is implicated), and state biometric privacy statutes (including Illinois BIPA) by prohibiting the input or generation of identifiable real-person media without consent; the requirement for 'permission' is not further defined in the document in terms of form, scope, or documentation standards....
-
OneLogin
· OneLogin Terms of Service
This provision limits OneLogin's total financial liability to fees paid by the user in the preceding 12 months and excludes liability for indirect, consequential, or data-loss damages. It also expressly disclaims responsibility for losses resulting from hacking, unauthorized access, or tampering with the Service or user accounts....
Why it matters: This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational continuity at risk for organizations using OneLogin as identity infrastructure. The express exclusion of liability for hacking and unauthorized access is particularly material given the nature of the Service as an SSO and identity management platform....
-
OneLogin
· OneLogin Terms of Service
This provision states that OneLogin implements commercially reasonable security measures but does not guarantee protection against unauthorized access, and requires users to acknowledge that they provide personal information at their own risk....
Why it matters: This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard....
-
Heap
· Heap Terms of Service
The agreement places an affirmative technical obligation on Customer to prevent the transfer of any visitor Personal Data beyond the defined Permitted Personal Data categories (IP address, cookie ID, behavioral data, technical data) to Contentsquare, using blocking Scripts or other available tools across all relevant areas of Customer Sites and Apps....
Why it matters: This provision places the technical and operational responsibility for data minimization on the Customer rather than Contentsquare, covering keystroke data, prefilled form data, HTML-displayed data, and API error logs. Failure to implement blocking mechanisms creates both contractual liability under Section 9.2 and potential regulatory exposure under applicable data protection laws....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
PlanetScale
· PlanetScale Terms of Service
The agreement requires customers to irrevocably release all claims against PlanetScale related to AI-generated output, including claims for copyright, trademark, and other intellectual property infringement or misappropriation arising from use of AI features within the product....
Why it matters: This provision requires customers to prospectively waive all IP-related claims arising from AI-generated output, including direct and indirect infringement claims. For organizations deploying AI output in commercial or regulated contexts, this clause places the entirety of IP infringement risk associated with AI features on the customer....
-
PlanetScale
· PlanetScale Terms of Service
The agreement authorizes PlanetScale to suspend customer and end user access to the product immediately upon notice based on PlanetScale's sole discretion determination across five enumerated trigger categories, including suspected security risks and potential third-party liability, while requiring customers to continue paying fees during the suspension period....
Why it matters: This provision grants PlanetScale unilateral suspension authority triggered by subjective determinations including 'may subject PlanetScale to third party liability' and 'suspected unauthorized access,' with no stated cure period prior to suspension and no fee relief during the suspension. For organizations dependent on PlanetScale's database platform for production operations, this creates operational continuity risk....
-
PlanetScale
· PlanetScale Terms of Service
The agreement prohibits customers from transmitting, storing, or processing HIPAA-covered health information without an executed BAA, PCI-DSS-covered payment card information, and GDPR special category personal data on the PlanetScale platform....
Why it matters: This provision establishes three distinct data category prohibitions with materially different practical implications: HIPAA data is conditionally permitted via BAA execution; PCI-DSS data is categorically prohibited without a stated exception pathway; and GDPR special category data is categorically prohibited without a stated exception pathway. Organizations processing any of these data categories must verify their compliance posture before deploying workloads on PlanetScale....
-
General Motors
· GM Terms of Use
The terms require that any legal claim related to the Web site be filed within one year of when the claim arises, after which the claim is permanently barred under the agreement....
Why it matters: This provision contractually shortens the limitations period for all causes of action related to the Web site. The default statutory limitations period for many claim types in New York and other states exceeds one year, and courts in certain jurisdictions have scrutinized or declined to enforce contractually shortened limitations periods for consumer claims depending on the nature of the claim....
-
Marqeta
· Marqeta Terms of Use
Customer is required to indemnify Marqeta, the Issuer, and the KYC Service Provider against claims, costs, and damages arising from Customer's breach, its customers' conduct, Retail Partners' legal violations, Card Brand fines imposed on or through the Issuer, and the general operation of Customer's business under the agreement. This indemnification obligation extends to third-party claims arising from conduct by parties downstream of Customer, including cardholders and retail partners....
Why it matters: This provision requires Customer to absorb financial and legal exposure arising not only from its own conduct but also from the acts or omissions of its customers, Retail Partners, and Lending Bank in connection with the agreement. The inclusion of Card Brand fines and Issuer-imposed penalties within the indemnification scope means Customer's liability exposure may be determined by regulatory or network actions outside Customer's direct control....
-
Marqeta
· Marqeta Terms of Use
The agreement caps each party's total liability to the other at the net revenue Marqeta earned under the agreement in the 12 months preceding the triggering event, with enumerated exceptions including indemnification obligations, confidentiality breaches, and Customer misuse of PII or KYC data. All breach claims must be brought within one year of discovery of the breach....
Why it matters: This provision establishes a contractual liability ceiling tied to Marqeta's revenue rather than Customer's potential losses, and imposes a one-year contractual limitations period on all breach claims regardless of form. For customers operating large-scale card programs, the net revenue cap may be substantially lower than the financial exposure created by a service failure or data breach....
-
Marqeta
· Marqeta Terms of Use
The agreement grants Marqeta a continuous right to set off any amounts Customer owes Marqeta against amounts Marqeta owes Customer, including funds held in the Custodial Account, until Customer's liability is fully satisfied. This right operates in addition to all other contractual and legal remedies available to Marqeta....
Why it matters: This provision authorizes Marqeta to apply funds from Customer's Custodial Account against outstanding Customer liabilities on a continuous basis without requiring a separate triggering event or court order. For card programs with active transaction volumes, the Custodial Account may contain operational funds required for cardholder settlements, and the set-off right could affect Customer's ability to maintain required minimum balances....
-
Marqeta
· Marqeta Terms of Use
Customer's use of KYC identity verification services is restricted to GLBA-permitted purposes and explicitly prohibited from FCRA permissible purpose use cases, adverse action decisions, and DPPA-restricted data uses. Customer is also prohibited from using KYC service outputs in violation of any applicable law governing PII use....
Why it matters: This provision establishes that KYC service outputs cannot be used as a basis for FCRA adverse action decisions, which means Customer cannot use identity verification results to deny credit, employment, housing, or other FCRA-covered determinations. Violations of these restrictions would constitute Customer indemnification triggers under Section B(7)(b) and could expose Customer to direct regulatory liability under the FCRA, GLBA, and DPPA....
-
Marqeta
· Marqeta Terms of Use
If the agreement is terminated for any reason other than Marqeta's breach, Customer remains obligated to pay all fees and charges through the end of the applicable Initial or Renewal Term. This includes terminations initiated by Customer, terminations at Issuer or Regulator direction, and terminations triggered by changes in applicable law or Card Brand Rules....
Why it matters: This provision requires Customer to pay remaining term fees even in circumstances where termination is triggered by external regulatory or network events outside Customer's control, such as Issuer withdrawal or Card Brand directive, provided the trigger is not Marqeta's breach. The financial obligation persists through the end of the contracted term regardless of whether services are actually delivered during that period....
-
Zendesk
· Zendesk Terms of Service
The agreement prohibits storage of HIPAA-regulated or HDS-regulated health data in the Services unless a Business Associate Agreement is in place, and places the compliance configuration responsibility for HIPAA, HDS, and other applicable regulations on the Customer....
Why it matters: This provision places affirmative HIPAA compliance configuration obligations on the Customer rather than Zendesk, and creates a contractual prohibition on health data storage absent a BAA. The agreement defines Health Data to include medical, patient, or other identifiable health information regulated under HIPAA or Article L1111-8 of the French Public Health Code, meaning healthcare-adjacent customers using Zendesk for support operations must assess whether their Service Data includes such information....
-
Instacart
· Instacart Terms of Service (Superseded Capture)
U.S. residents are required to resolve most disputes with Instacart through binding individual arbitration administered by the AAA under its Consumer Arbitration Rules, rather than through court proceedings, subject to limited exceptions for small claims and intellectual property injunctive relief....
Why it matters: This provision requires U.S. residents to submit covered claims to binding arbitration on an individual basis, with the arbitrator holding exclusive authority to decide questions of arbitrability under the delegation clause, except for challenges to the class action waiver subsection. The Federal Arbitration Act governs interpretation and enforcement, preempting state arbitration laws to the extent permitted....
-
Instacart
· Instacart Terms of Service (Superseded Capture)
The agreement waives users' rights to participate in class, collective, or representative actions and to jury trials for all covered claims. Disputes may only be brought on an individual basis in arbitration, with the exception that the enforceability of the class action waiver itself is reserved for judicial determination....
Why it matters: This provision establishes that the enforceability of the class action waiver subsection is specifically carved out from the arbitrator's authority and reserved for a court of competent jurisdiction, creating a judicial review point. If a court finds the waiver unenforceable as to a specific claim, that claim may be severed and litigated in court while the remainder of the arbitration agreement continues....
-
Instacart
· Instacart Terms of Service (Superseded Capture)
The agreement caps Instacart's total liability for all claims at $100 or 12 months of payments by the user, whichever is greater, and excludes liability for indirect, consequential, and physical injury damages including bodily injury and death, to the extent permitted by applicable law....
Why it matters: This provision extends the liability exclusion to cover physical injuries, bodily injury, and death arising from Third-Party Provider services, which may interact with state consumer protection and personal injury statutes that restrict limitation-of-liability clauses in consumer contracts. The savings clause acknowledges that applicable law may limit these exclusions, but the default contractual position asserts broad exclusion of damages....
-
Instacart
· Instacart Terms of Service (Superseded Capture)
Users who elect unattended prescription drug delivery waive and release all claims against Instacart, its affiliates, and Third-Party Providers for loss, theft, physical harm, bodily injury, death, and health information privacy disclosure arising from that delivery method, including claims arising from Instacart's own negligence, to the extent permitted by law....
Why it matters: This provision extends the waiver to claims arising from Instacart's own negligence and from sensitive health information disclosure, including information relating to mental health, HIV status, and sexually transmitted infections. The provision also includes an indemnification obligation requiring users who elect unattended delivery to defend Instacart and Third-Party Providers against third-party claims arising from that election....
-
Loom
· Loom Terms of Service
The agreement prohibits uploading or processing HIPAA-regulated protected health information in Cloud Products unless a separate Business Associate Agreement has been executed between the parties....
Why it matters: This provision places a direct compliance obligation on the Customer to ensure that no protected health information is introduced into Atlassian's Cloud Products absent a BAA, and assigns responsibility for this gatekeeping function to the Customer rather than Atlassian....
-
Loom
· Loom Terms of Service
The general liability cap is set at twelve months of fees paid. For claims arising from Atlassian's unauthorized disclosure of Customer Data caused by a breach of its security program obligations, a higher cap applies: two times fees paid during the preceding twelve months or US$5,000,000, whichever is lower....
Why it matters: This provision establishes the financial ceiling on Atlassian's liability for data security failures, with the Special Claims cap creating a specific recovery ceiling for unauthorized Customer Data disclosures that may be substantially lower than actual damages for high-value enterprise data incidents....
-
Linear
· Linear Terms of Service
The agreement incorporates by reference a separately hosted AI Addendum that governs all AI and machine learning features, including usage-based fees calculated on consumption metrics such as tokens, API calls, or compute units. The AI Addendum controls over the base Agreement in the event of any conflict regarding AI Services....
Why it matters: This provision establishes that material billing terms and data processing obligations for AI features are located in a document external to this Agreement, meaning the full contractual scope of AI Services cannot be assessed without reviewing the AI Addendum at linear.app/legal/ai-addendum. The AI Addendum's control over conflict resolution further means its terms may supersede base Agreement provisions in ways not predictable from this document alone....
-
Harvey AI
· Harvey AI Terms of Service
The agreement conditions the use of Protected Health Information with the Service on execution of a Business Associate Addendum. The agreement also states that the Service is not PCI compliant, which the customer acknowledges....
Why it matters: This provision establishes a prerequisite BAA execution for any use of PHI with the Service, consistent with HIPAA requirements for covered entities and business associates. The explicit PCI non-compliance acknowledgment restricts use cases involving payment card data and places contractual notice on customers regarding that limitation....
-
Anthropic
· Anthropic Responsible Scaling Policy
The RSP establishes a capability threshold specifically addressing chemical, biological, radiological, and nuclear development capabilities, triggered when a model could substantially uplift CBRN development for moderately resourced state programs, with corresponding required safeguards....
Why it matters: This provision establishes that CBRN-related AI capabilities are subject to a defined threshold that triggers mandatory safeguard requirements, reflecting a specific operational constraint on model deployment in relation to dual-use technologies....
-
LlamaIndex
· LlamaIndex Privacy Policy
The policy discloses that LlamaIndex deploys third-party session-recording technologies that may capture mouse movements, scrolling, clicks, keystroke activity, and text entered into the platform including chat features and other communication tools....
Why it matters: This provision authorizes deployment of third-party session-recording tools that may capture text inputs in real time, including content entered into LLM-related chat or communication features, which may include sensitive, confidential, or proprietary information depending on how the platform is used....
-
LlamaIndex
· LlamaIndex Terms of Service
The agreement requires all disputes between users and LlamaIndex to be resolved through binding individual arbitration administered by JAMS, rather than through court proceedings. New users have 30 days from acceptance to opt out by emailing dispute@runllama.ai with their full legal name and a statement of intent to opt out....
Why it matters: This provision requires disputes to proceed through individual JAMS arbitration rather than federal or state court, and the agreement assigns to the arbitrator exclusive authority to resolve questions about the scope, enforceability, and formation of the arbitration clause itself. The clause applies retroactively to claims that arose before the user agreed to these Terms....
-
LlamaIndex
· LlamaIndex Terms of Service
The agreement requires users to waive participation in class actions, collective actions, private attorney general actions, and jury trials for all disputes arising from the Service. This waiver applies to both individual consumers and business entities regardless of the purpose for which the Service is used....
Why it matters: This provision requires disputes to proceed on an individual basis only, prohibiting consolidation of claims and precluding class-wide relief through arbitration or court proceedings. The agreement states that if the class action waiver is found unenforceable because it prevents a user from seeking public injunctive relief, that specific claim may be litigated in civil court while all other claims remain subject to arbitration....
-
LlamaIndex
· LlamaIndex Terms of Service
The agreement caps LlamaIndex's total liability for any claims at the greater of amounts paid by the user or $100 USD, and excludes all indirect, consequential, punitive, and exemplary damages including loss of data, profits, or goodwill....
Why it matters: This provision establishes a combined damages exclusion and aggregate liability cap that limits LlamaIndex's financial exposure to $100 or amounts paid, whichever is greater, regardless of the nature or extent of harm alleged. The exclusion of data loss damages is particularly relevant given that the Service processes user documents and data....
-
Baseten
· Baseten Terms of Service
The agreement excludes Baseten's liability for all indirect, incidental, special, consequential, and punitive damages including lost profits, business interruption, and data loss costs, and caps Baseten's total aggregate liability for any claim at fees paid in the twelve months preceding the event giving rise to liability....
Why it matters: This provision establishes a financial ceiling on Customer's recoverable damages against Baseten that is limited to historical fees paid, and categorically excludes recovery for categories of harm that are likely to be most economically significant in a machine learning infrastructure context, such as business interruption and data loss....
-
Baseten
· Baseten Terms of Service
The DPA prohibits Customer from submitting to Baseten any personal data constituting Restricted Data, defined to include government identifiers, HIPAA-protected health information, biometric data, financial account credentials, payment card data, children's personal data under age thirteen, GDPR special category data, and criminal conviction data, unless a separate written agreement with Baseten expressly permits such submission....
Why it matters: This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition....
-
Stash
· Stash Terms of Use (Superseded URL)
The terms establish New York state and federal courts (Southern District) as the exclusive venue for disputes, unless the user has entered into Stash's Advisory Agreement, in which case the arbitration clause within that separate agreement governs and is incorporated by reference into these Terms....
Why it matters: This provision creates a two-tier dispute resolution framework: users who have executed the Advisory Agreement are subject to mandatory arbitration as defined in that separate document, while users who have not are subject to exclusive New York court jurisdiction. The arbitration clause's specific terms, including any class action waiver, are not disclosed in this document and require review of the Advisory Agreement....
-
Coinbase
· Coinbase User Agreement
The agreement requires that virtually all disputes between users and Coinbase be resolved through binding individual arbitration rather than court proceedings, and includes waivers of the right to bring class actions, collective actions, representative actions, and jury trials. Users must also complete a formal complaint process before initiating arbitration....
Why it matters: This provision requires disputes to proceed through individual binding arbitration, eliminating access to class or collective proceedings and jury trials. Users must complete a formal complaint process, including a 45-business-day resolution window, before filing any arbitration or small claims action; failure to complete this step may result in dismissal of the claim....
-
Coinbase
· Coinbase User Agreement
Coinbase may immediately suspend, restrict, or terminate any user account for any reason at its sole discretion, without being required to disclose the reason or the risk criteria that informed the decision. Users retain a 90-day window to transfer assets after account deactivation unless prohibited by law or court order....
Why it matters: This provision authorizes immediate account suspension or termination without prior notice or disclosed justification, based on confidential risk criteria. The operational consequence for users is that access to digital assets and USD wallet funds may be interrupted without advance warning, subject to the 90-day transfer window and any applicable legal restrictions....
-
Coinbase
· Coinbase User Agreement
Coinbase's maximum liability to any user is capped at the value of the digital assets in that user's wallet at the time of the claim, and Coinbase excludes all liability for lost profits, diminution in value, consequential, indirect, and incidental damages, except where a court finally determines that the damages resulted from Coinbase's gross negligence, fraud, willful misconduct, or intentional violation of law....
Why it matters: This provision establishes a damages cap tied to the current wallet value and excludes all consequential, indirect, and incidental damages from the scope of potential recovery. The gross negligence and fraud carve-out preserves some recovery pathway, but applicable law in some jurisdictions may limit the enforceability of certain exclusions....
-
Coinbase
· Coinbase User Agreement
The agreement states that title to digital assets held in user wallets remains with users at all times, that these assets are not Coinbase property, and are not subject to Coinbase creditor claims. Coinbase may hold assets in shared omnibus blockchain addresses across multiple protocols with no obligation to create segregated addresses per user....
Why it matters: This provision establishes the contractual custodial framework, asserting user ownership and creditor-protection status for held assets. However, the omnibus account structure means assets are held on shared blockchain addresses; the practical application of the ownership and creditor-protection assertions in a Coinbase insolvency scenario would depend on applicable bankruptcy law and state property law rather than solely on these contract terms....
-
Coinbase
· Coinbase User Agreement
Users consent to Coinbase collecting and retaining name, address, telephone number, email, date of birth, taxpayer identification number, government identification, bank account details, and in some cases biometric information. Users also authorize their wireless carrier to share device and account information with Coinbase for identity verification and fraud prevention for the duration of the account....
Why it matters: This provision establishes the scope of personal data collection and retention, including biometric data where permitted by law, and extends to a standing authorization for wireless carrier data disclosure to Coinbase for the life of the account. The biometric data collection, where applicable, interacts with state biometric privacy laws including the Illinois Biometric Information Privacy Act....