-
Asana
· Asana Privacy Statement
Asana's privacy team reviews each law enforcement or government access request for legal validity and proportionality before responding, and the company publishes an annual Law Enforcement Transparency Report disclosing the number of requests received and responded to....
Why it matters: This provision describes the procedural framework Asana applies to government data access requests, including a proportionality review and commitment to adhere to established legal process, with transparency reporting available annually....
-
Monday.com
· Monday.com Privacy Policy
The policy asserts that continued use of the Services after publication of an amended policy constitutes acceptance of the amended terms, with material changes accompanied by notice via prominent in-service display or email....
Why it matters: This provision establishes that policy amendments take effect upon publication and that continued use of the platform constitutes acceptance, with the adequacy of notice (prominent in-service display or email) varying depending on circumstances as determined by monday.com....
-
Monday.com
· Monday.com Privacy Policy
The policy states that personal data may be retained for as long as reasonably needed for service delivery, legal and contractual compliance, and dispute protection, with retention periods determined at monday.com's reasonable discretion and in accordance with an internal data retention policy....
Why it matters: This provision does not specify fixed retention periods for any category of personal data, instead reserving retention duration determinations to monday.com's reasonable discretion and an internal policy document not reproduced in the Privacy Policy....
-
Monday.com
· Monday.com Privacy Policy
The policy authorizes disclosure of contact, business, and usage details to business partners, resellers, and distributors for purposes including sales engagement and local market development, and states that engagements with those partners beyond the scope of monday.com-directed activities are governed by the partner's own terms....
Why it matters: This provision establishes that contact, business, and usage data may be shared with an unspecified set of business partners and resellers, and that once a user engages with a partner independently, that engagement is governed by the partner's own privacy terms rather than monday.com's....
-
Monday.com
· Monday.com Privacy Policy
The policy states that monday.com Inc. is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, and relies primarily on this certification for EEA, UK, and Switzerland to US data transfers, with Standard Contractual Clauses used for transfers to other non-adequate countries. DPF Principles govern in case of conflict with policy terms....
Why it matters: This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability to Service Providers under that framework. The DPF is subject to ongoing legal and political scrutiny, and its continued validity as a transfer mechanism depends on factors external to monday.com's own policy....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Figma
· Figma Privacy Policy (Superseded URL)
Figma certifies compliance with the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, providing EU, UK, and Swiss users with an independent dispute resolution pathway through JAMS at no cost, with binding arbitration available as a final escalation mechanism under DPF rules....
Why it matters: This provision establishes a structured complaint resolution pathway for EU, UK, and Swiss users, including a 45-day initial response commitment, free referral to JAMS for unresolved complaints, and access to binding arbitration under DPF conditions, with the FTC holding enforcement jurisdiction over Figma's DPF obligations....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that personal data transferred outside the EEA, Switzerland, and UK to non-adequate countries is safeguarded through Module 2 Standard Contractual Clauses under GDPR Article 46(2), with Swiss-law amendments and a UK Addendum for UK-originating transfers....
Why it matters: This provision documents the legal transfer mechanisms Figma relies upon for international data flows, specifying Module 2 SCCs (controller-to-processor) as the primary safeguard, which is operationally significant for enterprise customers conducting transfer impact assessments under GDPR....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that when a user acquires resources from third-party creators on Figma Community, the user's name and transaction-related personal information are disclosed to those creators, with any further information sharing governed by the individual creator's privacy policy....
Why it matters: This provision establishes that Community marketplace transactions trigger disclosure of user personal information to individual third-party creators who operate under their own independent privacy policies, creating a data governance gap that Figma does not contractually bridge for users....
-
Figma
· Figma Privacy Policy (Superseded URL)
The policy states that Figma recognizes GPC signals from supported browsers and treats them as CCPA opt-out requests for sale and sharing of personal information for targeted advertising, when the signal can be associated with an identifiable consumer. DNT signals are not recognized....
Why it matters: This provision operationalizes CCPA's GPC signal recognition requirement, establishing that GPC-enabled browsers trigger an opt-out of sale and sharing for targeted advertising, while also providing a manual opt-out mechanism through the Manage Cookies footer link. The policy's qualification that recognition depends on the ability to associate the signal with an identifiable consumer introduces a practical limitation on GPC effectiveness....
-
Airtable
· Airtable Privacy Policy
The policy states that linking third-party services (such as Google Drive) to Airtable authorizes Airtable to collect information from those services, and that users also become subject to the privacy policies of the third-party services they connect....
Why it matters: This provision establishes that activating third-party integrations creates a data flow from the third-party service to Airtable and subjects users to the third party's own privacy terms, creating a layered privacy governance structure that may not be fully visible to users at the point of integration....
-
Airtable
· Airtable Privacy Policy
The policy states that Airtable's services are not intended for users under 18 (or applicable local age threshold) and that Airtable will take reasonable steps to delete personal information discovered to have been collected from a child....
Why it matters: This provision establishes Airtable's age restriction at 18 rather than the 13-year threshold applicable under U.S. federal COPPA, which may create a higher age floor than legally required but also may not include the verifiable parental consent mechanisms required by COPPA if children under 13 do access the service....
-
Airtable
· Airtable Privacy Policy
The policy states that Airtable may revise the Privacy Policy at any time and will notify users via email of material revisions, with materiality determined solely by Airtable....
Why it matters: This provision reserves to Airtable the unilateral authority to determine which revisions constitute material changes requiring email notification, meaning that revisions Airtable determines to be non-material will not trigger direct user notification and will apply to previously collected information under the new terms....
-
Airtable
· Airtable Privacy Policy
The policy discloses that EEA, UK, and Swiss residents have the right to access, portability, rectification, erasure, restriction, consent withdrawal, and objection regarding their personal data, and may submit requests by email or online form....
Why it matters: This provision establishes the operational mechanism for EEA, UK, and Swiss data subject rights requests, including the specific contact method and subject line required, and confirms Airtable's recognition of its controller obligations under GDPR for these user groups....
-
Klarna
· Klarna Privacy Policy
The document directs California residents to a dedicated California Privacy Page for information on their privacy rights, and provides a US regional privacy notice page for general US privacy rights information, without reproducing the specific rights or mechanisms on this page....
Why it matters: This provision acknowledges CCPA applicability for California residents and directs them to a separate page, meaning the operative CCPA disclosures and opt-out mechanisms are not contained in this document and require review of the linked California Privacy Page....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel's terms authorize the transfer of personal information to third parties as part of corporate transactions including mergers, acquisitions, asset sales, and bankruptcy proceedings, with post-transfer notification to users described as possible rather than guaranteed....
Why it matters: This provision authorizes personal information to constitute a transferred asset in corporate transactions, including during pre-transaction due diligence; notification is described as occurring 'thereafter' and 'as applicable,' meaning users may not receive prior notice before their data is disclosed to prospective acquirers....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel states that it uses AI and automated decision-making to analyze personal information but asserts that it does not apply these technologies to decisions with legal or similarly significant effects on users....
Why it matters: This provision addresses GDPR Article 22 automated decision-making requirements by asserting that Vercel's automated processing does not produce legally significant decisions; this assertion limits the applicability of data subject rights to object to automated decisions, though the practical scope of 'similarly significant effects' involves interpretive uncertainty....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel uses cookies and similar tracking technologies on its sites and services, states that it obtains consent where required by applicable law, and directs users to its Cookie Notice for management options....
Why it matters: This provision conditions consent for cookie and tracking technology use on applicable law requirements, meaning the consent mechanism applied may vary by jurisdiction; users are directed to a separate Cookie Notice for specific opt-out and preference management options....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel retains personal information for the minimum necessary period to fulfill legal, contractual, and legitimate business purposes, after which it commits to deletion or anonymization; backup copies that cannot be immediately deleted will be retained securely....
Why it matters: This provision establishes Vercel's stated retention standard as the minimum necessary period, which aligns with GDPR storage limitation principles; the provision does not specify concrete retention timelines for specific data categories, leaving the practical duration of retention determined by Vercel's internal assessments of legal and business necessity....
-
Vercel AI
· Vercel AI SDK Privacy
Vercel restricts its Sites and Services to users age 16 and older, states it does not knowingly collect personal information from individuals under 16, and commits to removing such information if discovered....
Why it matters: The stated minimum age of 16 aligns with GDPR's default age of digital consent in many EU member states and exceeds COPPA's US minimum of 13; this provision creates a compliance boundary relevant to any Customer deploying Vercel-hosted services accessible to minors....
-
Mercury
· Mercury Privacy Policy
The policy states that SMS opt-in consent data and mobile phone numbers will not be sold, rented, or shared for marketing purposes, and will only be passed to telecommunications carriers under confidentiality agreements solely to deliver SMS messages....
Why it matters: This provision establishes an express contractual restriction on SMS opt-in data use and third-party disclosure, which is operationally distinct from the broader data sharing permissions described elsewhere in the policy and may engage TCPA and carrier-level messaging compliance requirements....
-
Mercury
· Mercury Privacy Policy
The policy states that Mercury's services are not directed at children under 13 and that Mercury does not knowingly collect Personal Information from users under 13, with a parental contact mechanism provided....
Why it matters: This provision establishes COPPA compliance positioning; because Mercury also states it does not knowingly sell or share Personal Information of minors under 16 elsewhere in the policy, the age threshold for data sale and sharing restrictions extends to a broader group than the under-13 service exclusion....
-
Synthesia
· Synthesia Privacy Policy
The policy enumerates GDPR-aligned data subject rights including access, portability, restriction, withdrawal of consent, rectification, erasure, objection, and the right not to be subject to solely automated decision-making. Users may exercise these rights by emailing support@synthesia.io, and may lodge complaints with the UK ICO or local EU supervisory authority....
Why it matters: This provision establishes the procedural mechanism for users to exercise GDPR and UK GDPR data subject rights directly with Synthesia, and identifies the UK ICO as the primary supervisory authority for complaint escalation. The policy notes that erasure or processing restriction may result in loss of access to some services....
-
Synthesia
· Synthesia Privacy Policy
The policy states that Synthesia's services are not directed at users under age 16, and that Synthesia does not knowingly collect information from or permit use by minors. The age threshold of 16 exceeds the US COPPA threshold of 13 and aligns with GDPR Article 8's default age of digital consent in many EU member states....
Why it matters: The policy sets a minimum age of 16, which aligns with GDPR Article 8 digital consent thresholds applicable in several EU member states and exceeds the US COPPA threshold of 13. Given that the platform collects biometric data, the application of this age restriction to biometric processing workflows is particularly material....
-
Writer
· Writer Privacy Policy
The policy states that Writer will not use data provided by users during service use, including AI prompt inputs and generated outputs, to train its models under any circumstances....
Why it matters: This provision directly addresses a primary data use concern for AI platform users by establishing an explicit contractual prohibition on using user-provided content for model training. The scope covers all inputs and outputs provided during service use in the controller context governed by this policy....
-
Writer
· Writer Privacy Policy
The policy establishes a CCPA opt-out right for California residents to opt out of the disclosure of personal information for cross-context behavioral advertising, exercisable via a 'Your privacy choices' link or Global Privacy Control signal....
Why it matters: This provision establishes the operative opt-out mechanism for California residents under the CCPA and confirms that Writer honors Global Privacy Control browser signals, which satisfies a specific California regulatory requirement under the CCPA regulations....
-
Writer
· Writer Privacy Policy
The policy states that Writer's services are not directed to users under 16, that the company does not knowingly collect personal information from persons under 16, and that it will delete such information if discovered....
Why it matters: The policy sets a minimum age of 16 rather than 13, which exceeds the minimum threshold under the U.S. Children's Online Privacy Protection Act (COPPA) and aligns with the minimum age threshold established under GDPR Article 8 for information society services in jurisdictions that have not lowered the default age....
-
Writer
· Writer Privacy Policy
The policy authorizes disclosure of user personal information to third parties during or in contemplation of corporate transactions including mergers, asset sales, reorganizations, financing events, or changes of control....
Why it matters: This provision establishes that personal data may be shared with potential acquirers or transaction counterparties during due diligence, prior to any completed transaction, and without a separate user notification mechanism described in this clause....
-
Writer
· Writer Privacy Policy
The policy states that Writer may update the Privacy Policy at any time by posting a revised version on its website, and that continued use of the services constitutes confirmation that the user has read and understood the updated policy....
Why it matters: This provision treats continued service use as affirmative acknowledgment of any updated policy terms. Users are not guaranteed active notification of changes beyond the posting of an updated version on the website, except where applicable law requires another form of notice....
-
OpenAI
· OpenAI GPT-5.5 System Card
The document asserts that GPT-5.5 is being released with OpenAI's most robust safeguard set across its model releases to date, characterized as designed to reduce misuse while maintaining access for legitimate use cases....
Why it matters: This provision constitutes a comparative safety claim that may be assessed against prior OpenAI model releases and evaluated under consumer protection and advertising standards frameworks. The document does not define the specific safeguards or metrics underlying this assertion....
-
Palantir
· Palantir Privacy Statement
The statement designates Stripe as an independent data controller for payment and contact data collected during transactions on Palantir websites, and directs users to Stripe's own privacy policy for information on how that data is processed....
Why it matters: This provision establishes that Palantir does not control the processing of payment data once it is submitted via Stripe's payment interface on Palantir platforms. Individuals seeking to exercise data rights over payment data or understand how it is used must engage directly with Stripe under Stripe's own terms and privacy policy....
-
Palantir
· Palantir Privacy Statement
The statement discloses that personal data transferred out of the EEA, UK, or Switzerland to non-adequate countries is protected using Standard Contractual Clauses approved by the European Commission, UK Secretary of State, or UK ICO....
Why it matters: This provision establishes the legal mechanism Palantir relies upon for cross-border data transfers from the EEA, UK, and Switzerland to the United States and other third countries. Individuals may request additional information about applicable transfer safeguards by exercising their data access rights....
-
Palantir
· Palantir Privacy Statement
The statement enumerates data subject rights available to individuals in the UK, EEA, and Switzerland, including access, correction, erasure, restriction, objection, portability, consent withdrawal, and the right to lodge a supervisory authority complaint....
Why it matters: This provision establishes the specific rights Palantir acknowledges for EEA, UK, and Swiss residents and the mechanism for exercising them, including direct contact with Palantir's Data Protection Officer. The statement notes these rights are not absolute and may be balanced against other considerations....
-
Palantir
· Palantir Privacy Statement
The statement discloses that Palantir's websites are not intended for children under 16 and that Palantir does not knowingly collect personal information from children under 16 as defined by COPPA....
Why it matters: This provision establishes Palantir's stated age threshold of 16 years for website use, which exceeds COPPA's 13-year statutory threshold, and provides a deletion mechanism for parental notification of inadvertent collection....
-
Meta
· Meta Frontier AI Framework
The document states that the Frontier AI Framework is published in fulfillment of a commitment Meta made at the 2024 Seoul AI Summit, a multilateral governmental AI governance forum....
Why it matters: This provision contextualizes the framework as a voluntary commitment made in a multilateral governmental forum rather than a regulatory obligation, which is relevant to assessing the enforceability and scope of the framework's stated practices....
-
Meta
· Meta Frontier AI Framework
The document asserts that open-source AI development is essential to U.S. technological leadership, economic growth, and national security, framing open-source release as a policy imperative rather than solely a commercial or technical decision....
Why it matters: This provision articulates a public policy position on open-source AI that may be relevant to regulatory and legislative discussions about AI release modalities, export controls, and national security review processes for AI technologies....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave may apply AI and ML technologies to user data for service operation, maintenance, improvement, security, and customer experience purposes, with the policy stating that notice or consent will be obtained where required by applicable law....
Why it matters: This provision authorizes AI and ML processing of user data under a conditional consent framework tied to applicable law requirements, which means the level of notice or consent provided may vary by jurisdiction. The policy separately states that CoreWeave does not perform automated decision-making or profiling producing legal or similarly significant effects, which limits the scope of this provision's most significant potential impacts....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy states that CoreWeave recognizes and honors GPC signals as opt-out requests for sale or sharing of personal information where applicable law requires, processes the GPC signal as a restriction on non-essential tracking technologies on the specific device and browser, and does not respond to Do Not Track browser signals....
Why it matters: This provision operationalizes CPRA's requirement that businesses recognize GPC signals as opt-out requests, while clarifying that the effect of the GPC signal is limited to the specific device and browser from which it is sent and is processed through CoreWeave's consent management platform. The explicit non-response to DNT signals is a standard disclosure under California's Online Privacy Protection Act....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy states that personal data is retained only as long as necessary for the described purposes or as required by law, and that upon expiration of that necessity, data will be deleted, anonymized, or securely isolated, with a carve-out for data that cannot be immediately deleted from backup systems....
Why it matters: This provision does not specify fixed retention periods for any category of personal data, instead applying a purpose-necessity standard with a backup system carve-out. The absence of specific retention schedules may complicate enterprise customers' data mapping and audit obligations under GDPR and CPRA, which encourage or require specific retention period documentation....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy discloses that CoreWeave may transfer personal data internationally, including to countries without equivalent data protection standards, and states that Standard Contractual Clauses are used as a transfer mechanism where required....
Why it matters: This provision discloses cross-border data transfer practices and identifies Standard Contractual Clauses as the primary safeguard mechanism, consistent with GDPR Chapter V requirements. The policy does not specify which country-to-country transfer routes are covered or identify whether transfer impact assessments have been conducted, which are additional requirements under GDPR for SCCs....
-
Weights & Biases
· Weights & Biases Privacy Policy
The policy authorizes disclosure or transfer of personal data to potential or actual acquirers, successors, or assignees in connection with mergers, acquisitions, debt financing, asset sales, or insolvency proceedings, where personal data is treated as a business asset....
Why it matters: This provision is a standard business transfer clause that authorizes sharing personal data with potential acquirers during due diligence and transferring it to successors upon completion of a transaction. Users have no advance notice or opt-out mechanism specified for this transfer scenario under the policy's terms....
-
Weights & Biases
· Weights & Biases Terms of Service
The agreement establishes that W&B retains full ownership of its platform, AI features, and any improvements or derivatives, and that any feedback provided by Customer may be used by W&B without restriction or compensation....
Why it matters: The Feedback provision establishes an unrestricted, royalty-free license for W&B to use any customer-provided suggestions or recommendations regarding the platform, including for product development, without any obligation to the Customer providing the feedback....
-
Ideogram
· Ideogram Terms of Service
Any feedback, comments, or suggestions submitted to Ideogram become the sole and exclusive property of the company, which may use or disclose them for any purpose without notice or compensation to the submitting user....
Why it matters: This provision assigns all rights in submitted feedback to Ideogram without compensation or retention of any proprietary interest by the submitting user, covering any purpose including commercial product development....
-
Glean
· Glean Privacy Policy
Glean's websites collect browser type, IP address, and clickstream behavior through cookies, web beacons, and similar technologies, and the statement discloses that Do Not Track signals from browsers are not currently honored....
Why it matters: The explicit non-response to Do Not Track signals is a disclosed operational practice; compliance teams in California should evaluate this against CPRA's requirements regarding user preference signals, noting that CPRA requires honoring opt-out preference signals under regulations that may apply to this context....
-
Glean
· Glean Privacy Policy
Glean retains Personal Information for the duration necessary to fulfill the business purposes of collection and to meet legal, accounting, and dispute resolution obligations, with retention periods determined by sensitivity, risk, and applicable legal requirements....
Why it matters: The retention policy does not specify fixed retention periods for any data category, relying instead on purpose-based and obligation-based standards, which may require supplemental documentation to satisfy GDPR's storage limitation principle and CCPA's reasonable retention requirements....
-
Glean
· Glean Privacy Policy
Brazil-based users hold LGPD rights including review of decisions made solely through automated processing that affect their personal, professional, consumption, or credit profile, with Glean obligated to provide information about the criteria and procedures used, subject to commercial and industrial secret limitations....
Why it matters: The automated decision review right under LGPD is operationally significant for any Glean website interaction involving automated personalization or profiling, and the commercial secrets limitation on disclosure of criteria may require case-by-case assessment of what information must be provided....
-
Glean
· Glean Privacy Policy
Glean reserves the right to update this Privacy Statement at any time, treating continued website use after posting as acceptance of revised terms....
Why it matters: The continued use acceptance mechanism does not include a notice requirement, meaning users may not receive direct notification before updated terms take effect, which has compliance implications under GDPR and CCPA where material changes to processing may require renewed consent or proactive notice....
-
Ideogram
· Ideogram Privacy Policy
The policy states that Ideogram's website is not designed to respond to browser Do Not Track signals or opt-out preference signals, and that the company does not process information in a manner that would legally require recognition of such signals....
Why it matters: This provision establishes that browser-level privacy signals, including Do Not Track and Global Privacy Control (GPC) signals, are not honored by the platform. The assertion that no legal obligation to recognize opt-out preference signals applies may require evaluation under California's CCPA, which mandates recognition of opt-out preference signals for businesses that sell or share personal information....
-
Ideogram
· Ideogram Privacy Policy
The policy explicitly states that Ideogram does not sell or share personal information as those terms are defined under the CCPA, and has not done so in the preceding 12 months, including with respect to residents under 16 years of age....
Why it matters: This provision establishes Ideogram's CCPA compliance posture with respect to data sale and sharing, which has direct implications for California residents' rights and for the company's obligations regarding opt-out mechanisms and consent requirements under that statute....
-
Ideogram
· Ideogram Privacy Policy
The policy establishes that users may submit access, deletion, correction, portability, restriction, objection, and consent withdrawal requests by emailing privacy@ideogram.ai, with identity verification potentially required, and authorizes the use of authorized agents acting under written authorization or power of attorney....
Why it matters: This provision establishes the operational mechanism for exercising data subject rights, including the identity verification requirement and the authorized agent framework, which are relevant to GDPR and CCPA compliance posture....
-
Ideogram
· Ideogram Privacy Policy
The policy authorizes disclosure of user personal information to third parties in connection with or in anticipation of an asset sale, merger, bankruptcy, or other business transaction, under a legitimate interest basis....
Why it matters: This provision establishes that personal data may be transferred to third parties in the context of corporate transactions, including in anticipation of such transactions, which may occur prior to any formal change in ownership or control....