-
Character.AI
· Character.AI Safety Center
The document references community guidelines governing platform conduct and describes the platform's safety-by-design approach as anchored by a goal of creating a safe and engaging experience....
Why it matters: This provision references community guidelines as the operative framework for content moderation on the platform, but the Safety Center page does not reproduce or summarize the specific moderation rules, enforcement mechanisms, or account action procedures....
-
Character.AI
· Character.AI Safety Center
The document references a support and reporting function accessible through a linked resource, but does not describe the mechanism, scope, or response timelines on this page....
Why it matters: The provision references a reporting and support pathway but does not disclose what categories of conduct can be reported, what response procedures apply, or what timelines govern the company's review of reports....
-
Character.AI
· Character.AI Safety Center
The Safety Center page references but does not reproduce Character.AI's Privacy Policy, Regional Privacy Disclosures, Cookie Policy, Terms of Service, and Privacy Choices mechanism, which govern the operative legal relationship with users....
Why it matters: The operative contractual and data processing terms applicable to users are located in the referenced documents, not in this Safety Center page; any compliance assessment of Character.AI's user data practices, arbitration provisions, or consumer rights requires review of those documents....
-
Character.AI
· Character.AI Safety Center
The document states that Character.AI's safety approach is anchored by a goal of creating a safe and engaging experience, and describes safety topics including parental insights, content moderation, teen safety, and reporting....
Why it matters: This provision articulates a general safety commitment but does not establish specific operational standards, metrics, timelines, or enforcement mechanisms that would allow compliance teams to assess implementation....
-
Runway
· Runway Usage Policy
The policy states that the listed prohibitions are not exhaustive and that the policy will be updated over time as Runway's products and their uses change....
Why it matters: This clause reserves Runway's authority to modify the scope of prohibited conduct without specifying a notice period or user consent mechanism for material changes, which creates ongoing compliance uncertainty for enterprise users who have structured workflows around the current policy terms....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a 0.2% processing fee on Lightning Network bitcoin transfers and a 0.01% processing fee capped at 20 USDT on USDT withdrawals, with separate network transaction fees applying in addition to both processing fees....
Why it matters: This provision establishes explicit percentage-based processing fees for Lightning Network and USDT transfers that are charged in addition to separate network transaction fees, creating a dual-fee structure for these transfer types. The 20 USDT cap on USDT processing fees provides a defined maximum cost for large USDT withdrawals....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a 0.10% processing fee on the net USDC conversion volume exceeding $5 million within any rolling 30-day period, with net volume calculated by netting USDC-to-USD and USD-to-USDC conversions within that period....
Why it matters: This provision establishes a fee structure specifically applicable to high-volume USDC conversion users, using a net rather than gross volume calculation methodology for the threshold, which means bidirectional conversion activity within the 30-day window reduces the effective fee basis....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy reserves Google's discretion to grant exceptions to any of the stated prohibitions based on educational, documentary, scientific, or artistic grounds, or where public benefits are assessed to outweigh harms....
Why it matters: This provision grants Google unilateral discretion to determine when exceptions apply, without specifying a procedural mechanism, eligibility criteria, or appeal process for users seeking exception status....
-
Airbnb
· Airbnb Privacy Policy
The document states that Airbnb.org is a separate and independent legal entity from Airbnb, Inc., and maintains its own privacy policy governing data collected through that platform....
Why it matters: This provision clarifies that users who interact with Airbnb.org are subject to a distinct privacy framework under a separate legal entity; data handling practices, rights, and obligations applicable to Airbnb.org are not governed by the Airbnb, Inc. privacy policy or its supplements....
-
Visa
· Visa Privacy Notice
Visa publishes a separate Cookie Notice disclosing its practices regarding cookies, tags, and similar online data collection technologies....
Why it matters: The Cookie Notice governs Visa's use of cookies, tags, and similar tracking technologies, which may collect identifiers, browsing activity, and device information; the applicable consent and opt-out mechanisms for these technologies are addressed in that separate notice rather than in the Global Privacy Notice....
-
Visa
· Visa Privacy Notice
Visa provides three channels for privacy rights requests: an online Privacy Rights Portal, email to [email protected], and postal mail to the Visa Global Privacy Office at 900 Metro Center Blvd., Foster City, CA 94404; users are instructed not to include sensitive information such as account numbers in email submissions....
Why it matters: This provision establishes the operative mechanisms through which users may submit requests to exercise privacy rights under applicable laws, including the specific contact addresses and a caution regarding sensitive information in email communications....
-
Arlo
· Arlo Privacy Policy
The Arlo website footer references a 'Your Privacy Choices' link, indicating the existence of a privacy preference or opt-out mechanism, but the substantive terms of that mechanism are not present in the submitted text....
Why it matters: The presence of a 'Your Privacy Choices' link is consistent with disclosure requirements under the California Consumer Privacy Act and similar state privacy laws, but the scope, categories of data covered, and method of exercising choices cannot be assessed from the navigation text alone....
-
Arlo
· Arlo Privacy Policy
The Arlo website footer includes a 'Manage Cookies' option, indicating the existence of a cookie consent or preference management interface, but the substantive scope of that control is not present in the submitted text....
Why it matters: A cookie management interface is associated with consent requirements under the EU General Data Protection Regulation and ePrivacy Directive for users in the EU and EEA, and with similar requirements in other jurisdictions. The categories of cookies covered, the granularity of consent options, and the technical implementation cannot be assessed from the footer reference alone....
-
StockX
· StockX Privacy Policy
The policy states that StockX does not knowingly collect personal information from users under age 16 and commits to deleting any such data if inadvertently collected....
Why it matters: This provision establishes a minimum age threshold of 16, which exceeds the COPPA threshold of 13, and commits to deletion of data collected from users under 16. The reliance on a 'knowingly' standard means the protection depends on self-reporting and detection rather than active age verification mechanisms....
-
StockX
· StockX Privacy Policy
The policy states that users have jurisdiction-dependent rights including access, portability, correction, deletion, processing restriction, objection, post-death instructions, and targeted advertising opt-out, and that StockX makes efforts to honor access, portability, deletion, and correction requests from all users regardless of jurisdiction....
Why it matters: This provision establishes a unified Personal Data Access Request portal for exercising data rights and commits to honoring access, portability, deletion, and correction requests globally, which extends certain rights beyond jurisdictions where they are legally mandated. The inclusion of post-death data instructions is a disclosure not universally present in comparable platform privacy policies....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy reserves the right to update the Privacy Statement at any time for any reason, with notification provided solely by updating the 'last updated' date on the posted statement; email reminders may be sent periodically but are not guaranteed....
Why it matters: This provision establishes that changes to data handling practices may take effect upon posting without individualized notice to users, placing the responsibility on users to monitor the statement for updates. Under GDPR, material changes to processing purposes or legal bases may require renewed consent or advance notice beyond a date-stamp update, a tension the provision does not address....
-
ClickUp
· ClickUp Privacy Policy
The policy states that ClickUp does not honor Do Not Track browser signals and takes no action in response to such requests....
Why it matters: This provision discloses that browser-level Do Not Track signals are not acted upon by ClickUp, meaning tracking technologies including cookies and similar tools operate regardless of browser-level opt-out signals. California law requires disclosure of Do Not Track response practices, which this provision satisfies....
-
ClickUp
· ClickUp Privacy Policy
The policy states that significant changes to data use or disclosure will be communicated by email, while non-significant changes may be posted without direct notification, with continued platform use constituting acceptance of non-significant changes....
Why it matters: This provision distinguishes between significant and non-significant policy changes, reserving email notification for significant changes while treating continued use as acceptance of non-significant changes. The characterization of whether a change is significant or non-significant is determined by ClickUp under the terms as written....
-
ClickUp
· ClickUp Privacy Policy
The policy enumerates GDPR data subject rights including access, rectification, erasure, restriction, portability, objection, consent withdrawal, and supervisory authority complaint, exercisable by contacting support@clickup.com or the postal address provided....
Why it matters: This provision discloses the GDPR data subject rights available to users and the mechanism for exercising them, which is relevant for EEA and UK users and for enterprise customers assessing ClickUp's compliance with GDPR processor obligations. The provision also notes the right to complain to the UK ICO directly....
-
ClickUp
· ClickUp Privacy Policy
The policy asserts CCPA and CPRA compliance, states that ClickUp does not sell personal information, and provides California consumers with a request mechanism at support@clickup.com for exercising CCPA rights, including identity verification using account information or government identification....
Why it matters: This provision establishes ClickUp's stated position under CCPA and CPRA, including the no-sale assertion and the consumer request mechanism. Whether data shared with advertising and market research partners constitutes sharing under CPRA's cross-context behavioral advertising definition is a separate question from whether it constitutes a sale, and may require further evaluation....
-
ClickUp
· ClickUp Privacy Policy
The policy states that the ClickUp Service is not directed to children under 16 and that ClickUp does not knowingly collect personally identifiable information from individuals it actually knows are under 16....
Why it matters: This provision establishes the age threshold for the service and the scope of the children's data protection commitment, which is framed as applying to individuals ClickUp actually knows are under 16 rather than establishing a verified age-gating mechanism. This framing is relevant to COPPA applicability assessments....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement authorizes transfer of users' personal data to acquirers or counterparties in connection with mergers, acquisitions, divestitures, financing transactions, and insolvency, bankruptcy, or receivership proceedings, including during negotiation phases prior to transaction completion....
Why it matters: This provision permits personal data disclosure during transaction negotiations as well as on transaction completion, and expressly covers insolvency and bankruptcy scenarios where data may transfer to creditors or administrators outside the ordinary commercial relationship....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement states that Mixpanel's services are not intended for users under 13 and provides a contact mechanism for parents or guardians who believe their child's data has been collected, but does not describe an active age verification mechanism....
Why it matters: The provision establishes an age 13 minimum for service use consistent with COPPA thresholds but does not describe technical or procedural controls for preventing collection of data from users under 13. The CCPA section separately confirms no actual knowledge of sale or sharing of under-16 personal information....
-
Segment
· Segment Privacy Policy
The notice states that Twilio's services are not directed to children under 13 in the U.S. and UK or under 16 in the EEA, and that accounts identified as belonging to children will be deactivated and data deleted....
Why it matters: This provision establishes age thresholds aligned with COPPA in the U.S. and GDPR Article 8 in the EEA, and discloses a remediation procedure for inadvertently collected child data. The differentiated age thresholds for U.S./UK versus EEA reflect applicable legal requirements in each jurisdiction....
-
Snowflake
· Snowflake Privacy Notice
Snowflake publishes a separate Cookie Statement and provides a 'Cookie Settings' link in the page footer, indicating that a consent management mechanism for cookies and similar tracking technologies is available to website visitors....
Why it matters: The Cookie Statement and Cookie Settings mechanism establish the operative framework for Snowflake's use of cookies and similar tracking technologies on its website. The availability of a Cookie Settings interface indicates that users may be able to modify consent choices for non-essential cookies....
-
RunPod
· RunPod Privacy Policy
The policy states that profile data and user-generated content (excluding messages) may be visible to other users and the public, and that RunPod is not responsible for how third parties, including search engines, collect, copy, or store that information....
Why it matters: This provision establishes that publicly visible profile and user-generated content may be indexed by search engines and collected by third parties, and that RunPod disclaims responsibility for such downstream uses. Users considering converting to team accounts or making profile information publicly available should account for the persistence of third-party caching....
-
RunPod
· RunPod Privacy Policy
The policy states the Service is not intended for users under 18, and that RunPod will comply with applicable legal requirements to delete personal information collected from minors without parental consent if discovered....
Why it matters: This provision establishes an age threshold of 18 for the Service, which is above the federal COPPA threshold of 13. The policy does not describe technical age verification mechanisms, relying instead on a stated policy position and reactive deletion procedures....
-
RunPod
· RunPod Privacy Policy
The policy discloses that RunPod does not respond to browser-level Do Not Track signals....
Why it matters: This provision establishes that browser-level Do Not Track signals will not alter RunPod's data collection or tracking practices. Users who wish to limit tracking must use the opt-out mechanisms described elsewhere in the policy, such as the Cookie Notice opt-out or DSAR email....
-
AWS Bedrock
· AWS Service Terms
AWS reserves the right to use customer interaction and usage data to improve its services, without specifying the categories of interaction data collected or the scope of improvement activities....
Why it matters: This provision authorizes AWS to use customer usage and interaction data for service improvement, which may engage data minimization and purpose limitation principles under GDPR where the customer is processing personal data through their AWS interactions....
-
AWS Bedrock
· AWS Service Terms
The terms prohibit customers and their end users from using any AWS service for cryptocurrency mining....
Why it matters: This provision establishes a categorical prohibition on cryptocurrency mining across all AWS services, applicable to both direct customer use and use facilitated through customer platforms, which may be an enforceable use restriction under the Acceptable Use Policy and the agreement's content enforcement mechanisms....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that it does not honor Do Not Track signals sent by web browsers, meaning users who enable DNT in their browser settings will not have that preference recognized by Zendesk's tracking technologies....
Why it matters: This provision discloses that browser-level DNT signals are not acted upon by Zendesk, which is relevant to users who rely on browser privacy settings as a primary opt-out mechanism. Whether this practice creates regulatory exposure depends on applicable state or national law requirements regarding DNT signal recognition....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that its digital properties are not directed to children under 16 and that it does not knowingly collect personal data from children, setting its age threshold at 16 rather than the COPPA threshold of 13....
Why it matters: The notice sets its children's privacy threshold at 16, which exceeds the minimum 13-year COPPA threshold and aligns with GDPR Article 8's default age of digital consent in many EU member states. This threshold applies to Zendesk's Controller-capacity data collection on its digital properties....
-
Zendesk
· Zendesk Privacy Policy
Zendesk states that automated decision-making as defined under GDPR Article 22 does not currently apply to personal data processed under this notice, but commits to notifying affected individuals and providing human intervention rights if that practice changes....
Why it matters: This provision constitutes a disclosure about the current absence of Article 22 automated decision-making and a forward-looking commitment to notification and rights provision if such processing is introduced. Given that Zendesk describes itself as an 'AI-first service platform,' this disclosure is operationally significant for monitoring as Zendesk's AI capabilities develop....
-
McDonald's
· McDonald's Privacy Policy
For EU, EEA, UK, and Switzerland-based processing, McDonald's states it transfers personal information only to countries with an adequate level of protection or under Standard Contractual Clauses based on Commission Implementing Decision (EU) 2021/914, with those mechanisms available upon request....
Why it matters: This provision establishes the legal mechanism McDonald's relies upon for international data transfers from the EU, EEA, UK, and Switzerland, referencing SCCs and adequacy decisions as the primary transfer tools and noting that transfer documentation is available upon request....
-
McDonald's
· McDonald's Privacy Policy
The US addendum states that McDonald's does not knowingly collect personal information from children under 13 through its online services, and that any future decision to do so would be conducted in compliance with applicable law including required parental consent mechanisms....
Why it matters: This provision establishes McDonald's stated COPPA compliance posture and the conditional commitment to parental consent if children's data collection is introduced in the future, while acknowledging that certain child-accessible features currently operate without personal information collection....
-
McDonald's
· McDonald's Privacy Policy
Under the Data Privacy Framework, EU, UK, and Swiss individuals whose privacy concerns cannot be resolved by McDonald's or JAMS may invoke binding arbitration as a final recourse mechanism, at no charge to the individual, subject to specified conditions....
Why it matters: This provision establishes a tiered dispute resolution mechanism for DPF-covered personal data disputes: direct contact with McDonald's, then JAMS mediation at no cost, and finally binding arbitration, with the FTC retaining investigatory and enforcement authority over McDonald's DPF compliance....
-
McDonald's
· McDonald's Privacy Policy
McDonald's states it retains personal information for the duration necessary to fulfill stated purposes, comply with legal obligations, resolve disputes, and enforce agreements, without specifying defined retention periods for particular data categories....
Why it matters: This provision establishes a purpose-based retention standard without specifying retention periods for individual data categories, which may present compliance considerations under GDPR's storage limitation principle and US state privacy laws that require defined retention schedules....
-
Ford
· Ford Privacy Policy
The policy states that Ford's digital services are not directed to children under 13, that Ford does not knowingly collect personal information from this group, and that Ford will delete such information if discovered....
Why it matters: This provision establishes COPPA compliance posture for Ford's digital properties. The standard 'not directed to children' and 'do not knowingly collect' formulation is common in US privacy policies and reflects minimum COPPA compliance requirements enforced by the FTC....
-
Duolingo
· Duolingo Privacy Policy
This provision states that IP addresses are retained for a maximum of 30 days under standard circumstances, with an exception permitting extended retention for subscribers who provide a payment method, limited to payment processing and fraud prevention purposes....
Why it matters: This provision establishes a specific IP address retention timeline with a carve-out for payment subscribers that does not define a maximum extended retention period, which may require evaluation under GDPR data minimization and storage limitation principles for EU users....
-
Duolingo
· Duolingo Privacy Policy
This provision enumerates twelve data subject rights including access, deletion, correction, export, opt-out of third-party sharing, objection to processing, and consent withdrawal, and establishes that these rights are not absolute, with refusal permitted on grounds of authentication failure, third-party rights, legal requirements, or service interference. Requests can be submitted through the Duolingo Data Vault or by emailing privacy@duolingo.com....
Why it matters: This provision establishes the operational framework for user data subject rights requests, including the enumerated grounds on which Duolingo may decline to fulfill a request. The breadth of disclosed rights reflects GDPR, CCPA, and other applicable framework requirements, and the refusal grounds align with standard exemptions recognized under those frameworks....
-
Walgreens
· Walgreens Privacy Policy
The policy states that Walgreens does not interpret or respond to browser-level Do Not Track signals, while separately stating that it does recognize opt-out preference signals such as Global Privacy Control for California residents....
Why it matters: This provision discloses that Walgreens does not honor Do Not Track signals, which is a common industry practice but is distinguished from the policy's separate disclosure that it recognizes opt-out preference signals under California law, creating a distinction between general DNT signals and California-specific GPC signals....
-
Roblox
· Roblox Privacy Policy
The policy states that Roblox may transfer user Personal Information as a business asset in mergers, acquisitions, asset sales, insolvency, bankruptcy, or receivership proceedings, with notification and consent required where law mandates it....
Why it matters: This provision reserves the right to transfer Personal Information, including data of users under 13, to a successor entity in corporate transactions, with user notification and consent conditioned on legal requirement rather than as a default practice....
-
Calendly
· Calendly Privacy Notice
The policy states that in the event of a sale, merger, asset transfer, or other corporate reorganization, Calendly may transfer Personal Data to the parties involved, and users are stated to acknowledge that such transfers are permitted....
Why it matters: This provision authorizes transfer of Personal Data to acquiring or successor entities in a corporate reorganization without requiring additional individual consent at the time of transfer. Under GDPR and CCPA, such transfers may require assessment of whether the successor entity's data practices are consistent with the purposes for which data was originally collected....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly may share Personal Data with government entities and in legal proceedings in a range of circumstances including legal process responses, safety protection, fraud prevention, and litigation, subject to Calendly's belief that such disclosure is reasonably necessary....
Why it matters: This provision authorizes disclosure to government entities and in legal proceedings across multiple broadly stated circumstances, including where Calendly 'believes' disclosure is reasonably necessary, without specifying a requirement for formal legal process in all cases. The DPF notice separately states that Calendly may be required to disclose Personal Data in response to lawful requests by public authorities including for national security or law enforcement requirements....
-
Calendly
· Calendly Privacy Notice
The policy states that Calendly does not direct its services to individuals under 18, does not knowingly collect Personal Data from children under 18, and commits to promptly deleting such data if discovered; it also references a separate FERPA and COPPA Privacy Policy and Notice for educational service providers....
Why it matters: This provision establishes an age threshold of 18 for Calendly's stated COPPA compliance, which exceeds the statutory threshold of 13 under COPPA. The reference to a separate FERPA and COPPA policy for educational institutions indicates that Calendly has specific compliance obligations in educational contexts that are addressed outside this notice....
-
Calendly
· Calendly Privacy Notice
The policy states that users may exercise data rights including access, correction, deletion, portability, and opt-out rights by submitting a request through the Calendly Privacy Center, subject to identity verification before processing....
Why it matters: This provision establishes the Privacy Center as the centralized mechanism for exercising data subject rights under CCPA, GDPR, and applicable state privacy laws, and conditions fulfillment on identity verification that may require additional information from non-account holders. The right to appeal denials is acknowledged for applicable jurisdictions....
-
Grammarly
· Grammarly Privacy Policy
The policy states that user content such as emails, documents, and drafts is not used for marketing or advertising purposes, while other data categories including email address, purchase history, usage data, and inferences may be used for marketing and advertising subject to user settings....
Why it matters: This provision establishes a categorical exclusion of user content from advertising data flows, operationally distinguishing between content-level data and account or behavioral data for marketing purposes....
-
HubSpot
· HubSpot Privacy Policy
The policy states that HubSpot has certified under the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. DPF, and that in the event of conflict between the Privacy Policy and DPF Principles, the DPF Principles govern. The U.S. FTC is identified as the enforcement authority for DPF compliance....
Why it matters: This provision establishes HubSpot's primary cross-border transfer mechanism for EEA, UK, and Swiss personal data, identifies the FTC as the enforcement authority for DPF compliance, and commits HubSpot to a 45-day complaint resolution timeline with escalation paths through EU data protection authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner, including binding arbitration as a last resort....
-
HubSpot
· HubSpot Privacy Policy
The policy states that where applicable law does not require consent, HubSpot conducts marketing and advertising activities on the basis of legitimate business interests, and may combine data from third-party providers with other collected information for personalized communications and event promotion....
Why it matters: This provision establishes legitimate interests as the default legal basis for marketing activities targeting individuals who have not provided explicit consent, and authorizes combination of third-party sourced data with HubSpot-collected data for personalized outreach. The provision is conditioned on legal requirements in applicable jurisdictions, acknowledging that consent will be obtained where law requires it....
-
HubSpot
· HubSpot Privacy Policy
The policy states that in the event of a merger, acquisition, or bankruptcy, all personal data collected by HubSpot would transfer to the acquiring entity, with notification provided to users via email or website notice....
Why it matters: This provision authorizes the transfer of all collected personal data to a successor entity in a corporate transaction, and commits to notifying users of any resulting changes in data ownership and use. The provision does not specify a timeline for notification or describe what choices would be available to users following a transfer....