-
Tabnine
· Tabnine Privacy Policy
The policy authorizes sharing of personal information with affiliates, subsidiaries, marketing service providers, data management vendors, payment processors, and analytics service providers. Analytics providers are disclosed to set their own cookies and identifiers to collect platform and website usage data directly....
Why it matters: This provision authorizes disclosure of personal data to a range of third parties including analytics providers that independently collect usage data via cookies, which may involve additional data flows beyond Tabnine's direct processing. The policy states that third-party processors are required to comply with obligations similar to those in this privacy policy and to use personal information only for specified purposes....
-
Tabnine
· Tabnine Privacy Policy
The policy provides CCPA/CPRA notice to California residents, stating that Tabnine does not sell personal information and does not share sensitive personal information for cross-context behavioral advertising. California residents retain rights of access, correction, deletion, and non-retaliation....
Why it matters: This provision satisfies CCPA/CPRA notice-at-collection requirements for California residents and asserts that no sale of personal information occurs, which is a material representation under California Privacy Laws. The policy states that identity verification, including possible government identification, may be required before honoring consumer rights requests, and that responses are provided within 45 days with a possible 90-day extension....
-
Tabnine
· Tabnine Privacy Policy
The policy commits to erasing personal information from its systems upon consent withdrawal, subject to exceptions for legal claims and continued service performance. Retention is otherwise described as limited to what is necessary for service provision and lawful business needs....
Why it matters: This provision establishes a consent-withdrawal-triggered erasure obligation with carve-outs for legal defense and ongoing service necessity, which aligns with GDPR erasure right conditions but depends on consent being the stated lawful basis for the relevant processing. Where Tabnine processes data on the basis of legitimate interest or contract rather than consent, this withdrawal mechanism may not apply....
-
Tabnine
· Tabnine Privacy Policy
The policy prohibits use of the service by children under 16 and states that Tabnine does not knowingly collect personal information from this age group, with an exception where parental consent is provided. No mechanism for obtaining or verifying parental consent is described....
Why it matters: This provision engages GDPR Article 8 requirements for children's consent to digital services (age threshold of 16 in the policy, consistent with GDPR's maximum threshold) and COPPA's restrictions on collecting personal information from children under 13 in the US context. The policy does not describe a parental consent verification mechanism, which creates an operational gap relative to regulatory requirements for the stated parental consent exception....
-
Tabnine
· Tabnine Privacy Policy
Tabnine has appointed Prighter Group as its EU/EEA privacy representative under GDPR Article 27, providing EU and EEA data subjects a local point of contact for exercising data subject rights including access and erasure requests....
Why it matters: This provision reflects Tabnine's compliance with GDPR Article 27, which requires non-EU controllers that offer goods or services to EU data subjects to appoint an EU representative. The appointment provides EU users with a procedural channel to exercise GDPR rights without routing requests through Israeli-jurisdiction channels....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
-
Tabnine
· Tabnine Privacy Policy
The policy reserves the right to revise, amend, or modify terms at any time, with changes effective upon posting. No advance notice period, user notification mechanism, or re-consent requirement is described....
Why it matters: This provision authorizes unilateral modification of privacy terms with no stated advance notice or user notification obligation beyond updating the posted document, which may interact with GDPR requirements for transparent communication of material changes to data processing practices and with CCPA notice-at-collection obligations when processing purposes change materially....
-
Inflection AI
· Inflection AI Privacy Policy
Users retain ownership of their inputs and AI-generated outputs, but grant Inflection AI a royalty-free, perpetual, irrevocable, sublicensable worldwide license over that content for service operation and model improvement purposes. The license is described as limited to specified purposes but is perpetual and irrevocable in duration and scope....
Why it matters: This provision establishes a content license that is perpetual and irrevocable in its stated terms, meaning the license persists even after account deletion or service discontinuation. The sublicensable nature of the license through multiple tiers means Inflection AI may authorize third-party service providers to use the licensed content under this grant....
-
Inflection AI
· Inflection AI Privacy Policy
The Terms of Service require most disputes between users and Inflection AI to be resolved through individual arbitration rather than class actions, representative proceedings, or jury trials. Users have the option to opt out of arbitration within 30 days by following the procedure described in Section 13.10....
Why it matters: This provision establishes individual arbitration as the default dispute resolution mechanism and waives class action rights for users who do not opt out within the stated window. The 30-day opt-out period requires affirmative action by users who wish to preserve access to court-based dispute resolution....
-
Inflection AI
· Inflection AI Privacy Policy
Inflection AI states that it uses information collected from users, including inputs and derived data, to develop and train its AI models. Users can opt out of their data being used for model training by navigating to the account settings page....
Why it matters: This provision authorizes use of user-submitted conversational data for AI model training as a default, with opt-out available through account settings. The scope of data used for training, including inputs that may contain personal information, is relevant for GDPR legitimate interests assessments and U.S. state privacy law compliance....
-
Inflection AI
· Inflection AI Privacy Policy
The policy states that Inflection AI may derive inferences about a user's emotional state, tone, and sentiments from their inputs. An opt-out specifically for voice-based emotional inference is available in account settings....
Why it matters: This provision discloses the derivation of emotional and psychological characteristics from user inputs, which may constitute processing of special categories of inferred data under GDPR or sensitive personal information under certain U.S. state privacy laws. The opt-out is limited to voice-based emotional inference, which does not necessarily extend to text-based sentiment inference....
-
Inflection AI
· Inflection AI Privacy Policy
Inflection AI states it retains Pi user inputs for up to 15 days following account deletion, with exceptions for fraud, security, legal requirements, and financial record-keeping. AI-generated outputs are retained indefinitely for purposes described in Section 4 of the Terms of Service....
Why it matters: This provision establishes an indefinite retention period for AI-generated outputs, cross-referencing Section 4 of the Terms of Service rather than setting out the applicable purposes directly in the privacy policy. The exceptions to the 15-day input deletion window permit extended retention for a range of operational and legal purposes....
-
Inflection AI
· Inflection AI Privacy Policy
For European users, the policy provides a legal basis table mapping processing purposes to GDPR legal bases including contractual necessity, legitimate interests, and consent. AI model training and service improvement are stated to rely on the legitimate interests basis....
Why it matters: This provision discloses the specific GDPR legal bases for each processing purpose, including the reliance on legitimate interests for AI model training. The document also identifies DataRep as the appointed EU and UK representative, and states that international transfers rely on appropriate safeguards such as contractual clauses....
-
Inflection AI
· Inflection AI Privacy Policy
The Terms of Service prohibit a range of uses of the Pi service including biometric categorization to infer protected characteristics, mass public surveillance, emotional recognition in workplace and educational settings, social scoring, and criminal profiling. These prohibitions are stated to apply to users of the service, not to Inflection AI's own processing....
Why it matters: These prohibitions reflect restrictions consistent with EU AI Act prohibited practices and high-risk AI system provisions, applied as user-facing acceptable use constraints. Violations of acceptable use terms are stated as grounds for enforcement action under the Terms of Service....
-
Inflection AI
· Inflection AI Privacy Policy
The Terms of Service prohibit use of Inflection AI services by users under the age of 18 and request that suspected underage use be reported to privacy@inflection.ai....
Why it matters: This provision establishes a categorical age restriction at 18 rather than 13, which exceeds COPPA's minimum age threshold and creates broader restrictions on minor access. The document does not describe a technical age verification mechanism, which is relevant to compliance exposure under COPPA and analogous state and international youth data protection frameworks....
-
Inflection AI
· Inflection AI Privacy Policy
The Cookie Policy discloses that Inflection AI does not respond to Do Not Track browser signals or similar signals from users....
Why it matters: California law requires that online services disclose whether they respond to Do Not Track signals. This disclosure satisfies that requirement by explicitly stating non-response. The practical effect is that browser-level Do Not Track settings do not alter the data collection practices described in the Cookie Policy....
-
Inflection AI
· Inflection AI Privacy Policy
The policy authorizes disclosure of personal information to vendors and service providers performing functions including web hosting, cloud storage, content moderation, marketing and advertising, advertising measurement, and customer support. Personal information may also be disclosed during negotiations or completion of mergers, acquisitions, asset sales, or financing transactions....
Why it matters: This provision authorizes disclosure of personal information to a range of third-party vendors across operational functions, and separately permits disclosure during corporate transaction negotiations before any transaction is completed. The advertising measurement category of vendor is relevant for users who have not opted out of marketing-related data processing....
-
Windsurf
· Windsurf Privacy Policy
The policy states that user content, including personal information provided in inputs, file uploads, feedback, and outputs, may be used to train, fine-tune, and improve the AI models powering the services, subject to the terms applicable to the specific service tier....
Why it matters: This provision asserts a legitimate interests basis for using user-submitted content, including conversational inputs and file uploads, for model training purposes. The practical scope of this use depends on the terms applicable to the user's specific service tier, which may include enterprise or platform-specific agreements that modify or restrict this use....
-
Windsurf
· Windsurf Privacy Policy
The policy states that administrators of enterprise or business accounts may access user content and exercise control over accounts and associated information for users who joined under an employer or organizational account....
Why it matters: This provision establishes that employer-designated administrators have access to employee-generated user content within enterprise accounts, including inputs and outputs from AI interactions. The scope of administrator access and the data categories accessible are defined broadly as 'certain information associated with your account, including your User Content.'...
-
Windsurf
· Windsurf Privacy Policy
The policy states that user personal information may be shared during the evaluation of and entry into asset sales, acquisitions, mergers, or other change of control events, including bankruptcy proceedings, without a requirement for separate user consent....
Why it matters: This provision asserts that personal information across all stated categories may be transferred to third parties in connection with corporate transactions, including during the due diligence evaluation phase. This applies to the full scope of user data described in the policy, including user content, account information, and usage data....
-
Windsurf
· Windsurf Privacy Policy
The policy states that privacy rights including access, deletion, correction, objection, and portability are available to users where legally required by jurisdiction, and that the company retains absolute discretion to grant or deny those rights where not legally mandated....
Why it matters: This provision establishes that the availability of privacy rights outside legally mandated jurisdictions is at the company's sole discretion. Users in jurisdictions without comprehensive privacy statutes have no contractual entitlement to exercise the listed rights and may be denied requests at the company's discretion....
-
Windsurf
· Windsurf Privacy Policy
The policy states that personal information may be transferred to and processed in multiple countries globally, and that Standard Contractual Clauses and the UK International Data Transfer Addendum are used as the legal mechanism for cross-border transfers of EEA, Swiss, and UK personal data....
Why it matters: This provision identifies Standard Contractual Clauses and the UK IDAD as the stated transfer mechanisms for EEA, Swiss, and UK personal data, consistent with GDPR Chapter V requirements. The policy notes that third-party partners and service providers are also included in the scope of cross-border transfers....
-
Windsurf
· Windsurf Privacy Policy
The policy states that audio input collected through voice features is processed to generate transcriptions or commands, and that the underlying audio is deleted after transcription unless the applicable terms state otherwise....
Why it matters: This provision establishes a default deletion practice for raw audio data following transcription, while preserving the right to retain audio where stated in applicable terms. The transcription output is retained as user content and subject to the broader data practices described in the policy....
-
Windsurf
· Windsurf Privacy Policy
The policy states that the services are not intended for children and that the minimum age for access is 18 years old, with a stated practice of not knowingly collecting personal information from children....
Why it matters: This provision establishes a minimum age of 18, which exceeds the COPPA threshold of 13 and the GDPR Article 8 digital consent ages applicable in most EU member states. The policy does not describe a technical age verification mechanism for enforcement of this restriction....
-
Windsurf
· Windsurf Privacy Policy
The policy states that commercially reasonable security measures are implemented but are not a guarantee of absolute security, and that users acknowledge and accept that their use of the services is at their own risk....
Why it matters: This provision asserts a risk acceptance by users regarding data security incidents, framed as an acknowledgment embedded in the privacy policy. The 'commercially reasonable' standard is the commonly stated benchmark in the industry, and the practical enforceability of the risk acceptance language may vary by jurisdiction and applicable law....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement requires that most disputes between users and Hims & Hers, Medical Groups, or Providers be resolved through binding individual arbitration rather than court proceedings, and both parties waive the right to a jury trial and class action participation. A 30-day opt-out window is available from the date of first acceptance....
Why it matters: This provision requires disputes to proceed through individual binding arbitration rather than civil litigation or class action, covering not only Hims & Hers but also Medical Groups and Providers as named beneficiaries of the clause. The scope of the waiver and its extension to third-party medical entities may require evaluation under applicable state law, as certain jurisdictions limit the enforceability of consumer arbitration waivers in healthcare contexts....
-
Hims & Hers
· Hims & Hers Terms and Conditions
Subscription products automatically charge the user's payment method at regular intervals until the user cancels at least two days before the renewal date. No refunds are issued for partially used subscription periods, though the company may grant refunds at its sole discretion on a case-by-case basis....
Why it matters: This provision establishes the automatic renewal and billing mechanism for all subscription products and services and limits refund eligibility to the company's sole and absolute discretion, with no defined criteria or process for case-by-case refund determinations. The two-day cancellation window before renewal creates an operationally narrow notice period that may require evaluation under state auto-renewal statutes....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement asserts that Hims & Hers as the direct platform operator is not a HIPAA covered entity, and acknowledges that affiliated Labs, Pharmacies, and Medical Groups may or may not be covered entities or business associates under HIPAA. This means health information provided to Hims & Hers directly may not receive HIPAA protections as applied to the platform operator....
Why it matters: This provision establishes that health and medical information processed by Hims & Hers as the platform operator is not subject to HIPAA protections as applied directly to that entity, while acknowledging uncertainty about the HIPAA status of affiliated clinical partners. Legal and compliance teams should evaluate whether applicable state health data privacy laws and FTC health breach notification rules provide alternative protections for health data processed outside the HIPAA framework....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement authorizes Hims & Hers to transfer user prescriptions among any of the named affiliated pharmacies without providing prior notice to the user. Users provide advance consent to this transfer authority through acceptance of the agreement....
Why it matters: This provision establishes a broad transfer authorization that permits prescriptions to be moved among affiliated pharmacies without individual notice or consent at the time of transfer. Pharmacy law in various states imposes specific requirements regarding patient consent and notice for prescription transfers, and the scope of this advance consent may require evaluation against state pharmacy practice regulations....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement establishes that all products and services are provided on a cash-pay basis outside of Medicare, Medicaid, and commercial insurance, and that no claims will be submitted to any payer for reimbursement. Users bear sole financial responsibility for all costs....
Why it matters: This provision explicitly establishes the out-of-network, cash-pay structure of the platform and requires users to acknowledge in advance that no insurance or government program reimbursement will be sought. This affects users who may have assumed coverage eligibility and may have implications under federal healthcare program exclusion and anti-kickback frameworks depending on how affiliated providers are structured....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement discloses that Hims & Hers uses generative AI and machine learning in customer support and clinical care messaging workflows, including drafting responses for licensed healthcare professional review. The agreement states that AI is not used to make clinical decisions and that users will be informed when interacting directly with an AI-supported channel....
Why it matters: This provision establishes the operational parameters of AI use on the platform, drawing a distinction between AI-assisted drafting of clinical communications reviewed by licensed professionals and autonomous clinical decision-making. The disclosure that users will be notified of AI interaction in accordance with applicable law creates a compliance dependency on evolving state AI transparency statutes....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The Weight Loss Membership and associated Medication Plan auto-renew monthly unless cancelled at least two days before the billing date. Refunds on medication are not available after shipment, and refunds on initial Medication Plan orders are available only if cancellation occurs within 48 hours of payment submission....
Why it matters: This provision establishes narrow and time-sensitive refund eligibility windows for the Weight Loss Membership and Medication Plan products, with the 48-hour initial-order refund window and the no-refund-after-shipment rule creating distinct cancellation triggers. The interaction between Medication Plan cancellation and Weight Loss Membership continuation, and the separate Gifthealth billing arrangement, adds operational complexity for users managing multiple subscription components....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement asserts that users grant legal agency authority to any third party who clicks the acceptance button or otherwise indicates agreement on the user's behalf, binding the user to the terms through that third party's action....
Why it matters: This provision asserts that acceptance of the agreement by a third party acting on the user's behalf is binding, creating a contractual mechanism that extends the agreement's obligations to users who did not personally click acceptance. The enforceability of this provision depends on whether applicable contract law recognizes such advance agency grants in the context of electronic consumer agreements....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement establishes that use of the platform constitutes a request by the user for Hims & Hers and Medical Groups to process sensitive personal information, including health information, as necessary to provide the service, including personalized recommendations delivered by email and on the platform....
Why it matters: This provision frames the processing of sensitive personal information, including health and mental health data, as user-initiated through the act of using the service, which structures consent as implicit in platform use rather than through a separate affirmative consent mechanism. The consent-through-use framing may require evaluation against state privacy laws that impose specific opt-in consent requirements for sensitive data processing....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy explicitly states that Hims & Hers may sell sensitive personal data, including health data and sexual orientation information, as those terms are defined under California and other state privacy laws, through disclosures to advertising and analytics partners....
Why it matters: This provision establishes that data disclosures to third-party advertising and analytics partners may constitute a sale of sensitive personal information under applicable state law definitions, triggering opt-out rights and, in some jurisdictions, opt-in consent requirements for sensitive data categories....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy authorizes sharing of sensitive personal information including health data and sexual orientation or sex life information with advertising partners to enable personalized advertising and lookalike audience targeting, provided that information does not qualify as Protected Information under HIPAA or applicable state health law....
Why it matters: This provision establishes that health-related browsing activity on the Hims & Hers platform, including pages viewed about specific medical conditions or treatments, may be disclosed to external advertising partners for cross-site ad targeting, subject to the company's determination of whether that data constitutes Protected Information....
-
Hims & Hers
· Hims & Hers Privacy Policy
Users who submit payment and transaction information grant the company an irrevocable, perpetual, and universe-wide license to share that information with third parties for the stated purpose of facilitating the transaction....
Why it matters: This provision establishes a broadly worded license over transaction data that is described as irrevocable and perpetual; while the stated purpose is transaction facilitation, the scope language extends beyond typical payment processing data sharing terms and may warrant review of whether the breadth of the grant is proportionate to the stated purpose....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy authorizes the company to de-identify user information and use, create, or sell de-identified data for any lawful business purpose, with AI model training cited as an explicit example....
Why it matters: This provision establishes that de-identified user data, which may include health-related and other sensitive information, can be used to train AI models and sold to third parties, subject to the adequacy of the de-identification process applied and applicable legal standards....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states that Hims & Hers is not a HIPAA covered entity, acknowledges it may in some cases function as a HIPAA business associate, and notes that HIPAA protections may not apply to user transactions depending on the specific service and entity involved....
Why it matters: This provision establishes that the full range of HIPAA protections does not apply to all user interactions with the Hims & Hers platform, and that the applicability of HIPAA depends on the specific transactional context, creating a variable protection landscape across the company's telehealth, pharmacy, and consumer wellness services....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states that the company or its service providers may collect and use biometric information for the purpose of identity verification prior to service access....
Why it matters: This provision authorizes collection of biometric information, a category subject to distinct state biometric privacy statutes including the Illinois Biometric Information Privacy Act, which impose specific consent, retention, and destruction obligations that may apply depending on user location....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states that the company's websites do not respond to browser Do Not Track signals, distinguishing DNT from the Global Privacy Control which the company states it will honor....
Why it matters: This provision establishes that users who rely on Do Not Track browser signals will not have those preferences recognized by the Hims & Hers platform; users must instead use the Global Privacy Control, cookie controls, or advertising opt-out tools described in the policy to limit data collection....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states the service is not directed to children under 13, establishes a voluntary practice of ceasing use of data if collected from under-13 users, and provides a removal request right for users under 16 via email or certified mail....
Why it matters: This provision establishes the company's stated compliance posture regarding minor data collection, including a voluntary removal mechanism for users under 16 and an express disclaimer that the policy does not constitute an admission of COPPA applicability, which may be relevant to FTC enforcement assessments....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy provides a web-based mechanism at privacy.hims.com/policies for users to submit requests to access, copy, download, correct, or delete personal information, and states that in some states users may additionally request information about third-party sharing....
Why it matters: This provision establishes the operational mechanism through which users exercise data subject rights under applicable state privacy laws, including CCPA and CPRA, and notes that the scope of available rights varies by jurisdiction....
-
Replit
· Replit Privacy Policy
The policy states that Replit may de-identify collected personal information and, once de-identified, may use or share that data for any purpose at its discretion, with no further application of the Privacy Policy to that data....
Why it matters: This provision reserves broad discretion for Replit to repurpose or share data once it is classified as de-identified, without further consent or notice obligations under this policy. The provision does not specify the technical or legal standard applied to determine when data qualifies as de-identified, which creates uncertainty regarding whether the threshold meets requirements under GDPR, CCPA, or other applicable frameworks....
-
Replit
· Replit Privacy Policy
The policy states that user profiles, usernames, profile pictures, code, and forum posts are publicly visible to other users and indexed by search engines by default, with private code visibility requiring a paid upgrade....
Why it matters: This provision establishes that user-generated code is publicly accessible and search-engine indexed by default, which has operational significance for developers who may inadvertently expose proprietary, sensitive, or credential-containing code without upgrading to a paid private tier....
-
Replit
· Replit Privacy Policy
The policy authorizes Replit to share user information, including user-generated code and usage data, with machine learning companies retained as service providers in connection with providing the Services....
Why it matters: This provision authorizes disclosure of user data, including code, to machine learning service providers. This has operational significance for developers whose code may contain proprietary logic, credentials, or sensitive data, and for enterprise customers evaluating the scope of data access granted to Replit's vendor ecosystem....
-
Replit
· Replit Privacy Policy
The policy places responsibility on developers who publish content on Replit that collects personal information from users to comply with all applicable privacy laws, including COPPA notice and verifiable parental consent requirements, independently of Replit....
Why it matters: This provision establishes that developers publishing data-collecting content on the Replit platform bear direct legal responsibility for COPPA compliance, parental consent acquisition, and user rights obligations. Compliance teams at organizations deploying Replit-based applications that interact with minors or collect user data should assess this delegation of compliance responsibility....
-
Replit
· Replit Privacy Policy
The policy relies on user consent through acceptance of the policy as the mechanism for authorizing international data transfers to the United States and other hosting locations including India, without specifying alternative transfer mechanisms such as Standard Contractual Clauses....
Why it matters: This provision relies on implicit consent via policy acceptance as the legal basis for cross-border data transfers. For EEA and UK users, this approach may require evaluation under GDPR Chapter V, which imposes specific requirements for international data transfers that may not be satisfied by consent obtained through a broad policy acceptance mechanism alone....
-
Replit
· Replit Privacy Policy
The policy states that Replit may receive demographic and other data about users from third-party data or marketing partners and combine that externally sourced data with information already held about the user....
Why it matters: This provision authorizes the enrichment of user profiles with third-party sourced demographic data, which may include information users did not directly provide to Replit. This affects the scope of the data profile Replit maintains on users beyond what is collected through direct interaction with the platform....
-
Replit
· Replit Privacy Policy
The policy authorizes disclosure and transfer of user information to potential acquirers, merger partners, advisors, and other third parties during the consideration, negotiation, or completion of a corporate transaction, including partial asset sales or liquidation....
Why it matters: This provision permits disclosure of user data to third parties at the due diligence and negotiation stage of a corporate transaction, not only upon completion, which means user data may be accessed by potential but ultimately unsuccessful acquirers. The provision covers partial asset transfers as well as full acquisitions....
-
Replit
· Replit Privacy Policy
The policy states that the Services are not directed to children under 13 in the US and that Replit will take reasonable steps to obtain parental consent or delete personal information of users found to be underage. Student profiles created in Teams for Education are separately stated to be non-public....
Why it matters: This provision establishes Replit's stated approach to COPPA compliance for the general platform, relying on user self-representation of age eligibility rather than proactive age verification. The separately stated protection for Teams for Education student profiles addresses an education-specific use case with different default visibility settings....