-
Ideogram
· Ideogram Privacy Policy
The policy states that when a user signs up through a referral link, the referring user may receive information confirming the new user's subscription and subscription tier....
Why it matters: This provision establishes that subscription status and tier information is shared with referring users as part of the referral program, which constitutes disclosure of commercial information about a user's account to another private individual....
-
Tabnine
· Tabnine Privacy Policy
The policy provides CCPA/CPRA notice to California residents, stating that Tabnine does not sell personal information and does not share sensitive personal information for cross-context behavioral advertising. California residents retain rights of access, correction, deletion, and non-retaliation....
Why it matters: This provision satisfies CCPA/CPRA notice-at-collection requirements for California residents and asserts that no sale of personal information occurs, which is a material representation under California Privacy Laws. The policy states that identity verification, including possible government identification, may be required before honoring consumer rights requests, and that responses are provided within 45 days with a possible 90-day extension....
-
Tabnine
· Tabnine Privacy Policy
The policy commits to erasing personal information from its systems upon consent withdrawal, subject to exceptions for legal claims and continued service performance. Retention is otherwise described as limited to what is necessary for service provision and lawful business needs....
Why it matters: This provision establishes a consent-withdrawal-triggered erasure obligation with carve-outs for legal defense and ongoing service necessity, which aligns with GDPR erasure right conditions but depends on consent being the stated lawful basis for the relevant processing. Where Tabnine processes data on the basis of legitimate interest or contract rather than consent, this withdrawal mechanism may not apply....
-
Tabnine
· Tabnine Privacy Policy
Tabnine has appointed Prighter Group as its EU/EEA privacy representative under GDPR Article 27, providing EU and EEA data subjects a local point of contact for exercising data subject rights including access and erasure requests....
Why it matters: This provision reflects Tabnine's compliance with GDPR Article 27, which requires non-EU controllers that offer goods or services to EU data subjects to appoint an EU representative. The appointment provides EU users with a procedural channel to exercise GDPR rights without routing requests through Israeli-jurisdiction channels....
-
Inflection AI
· Inflection AI Privacy Policy
The Cookie Policy discloses that Inflection AI does not respond to Do Not Track browser signals or similar signals from users....
Why it matters: California law requires that online services disclose whether they respond to Do Not Track signals. This disclosure satisfies that requirement by explicitly stating non-response. The practical effect is that browser-level Do Not Track settings do not alter the data collection practices described in the Cookie Policy....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Windsurf
· Windsurf Privacy Policy
The policy states that privacy rights including access, deletion, correction, objection, and portability are available to users where legally required by jurisdiction, and that the company retains absolute discretion to grant or deny those rights where not legally mandated....
Why it matters: This provision establishes that the availability of privacy rights outside legally mandated jurisdictions is at the company's sole discretion. Users in jurisdictions without comprehensive privacy statutes have no contractual entitlement to exercise the listed rights and may be denied requests at the company's discretion....
-
Windsurf
· Windsurf Privacy Policy
The policy states that the services are not intended for children and that the minimum age for access is 18 years old, with a stated practice of not knowingly collecting personal information from children....
Why it matters: This provision establishes a minimum age of 18, which exceeds the COPPA threshold of 13 and the GDPR Article 8 digital consent ages applicable in most EU member states. The policy does not describe a technical age verification mechanism for enforcement of this restriction....
-
Windsurf
· Windsurf Privacy Policy
The policy states that commercially reasonable security measures are implemented but are not a guarantee of absolute security, and that users acknowledge and accept that their use of the services is at their own risk....
Why it matters: This provision asserts a risk acceptance by users regarding data security incidents, framed as an acknowledgment embedded in the privacy policy. The 'commercially reasonable' standard is the commonly stated benchmark in the industry, and the practical enforceability of the risk acceptance language may vary by jurisdiction and applicable law....
-
Hims & Hers
· Hims & Hers Terms and Conditions
The agreement asserts that users grant legal agency authority to any third party who clicks the acceptance button or otherwise indicates agreement on the user's behalf, binding the user to the terms through that third party's action....
Why it matters: This provision asserts that acceptance of the agreement by a third party acting on the user's behalf is binding, creating a contractual mechanism that extends the agreement's obligations to users who did not personally click acceptance. The enforceability of this provision depends on whether applicable contract law recognizes such advance agency grants in the context of electronic consumer agreements....
-
Hims & Hers
· Hims & Hers Privacy Policy
The policy states that the company's websites do not respond to browser Do Not Track signals, distinguishing DNT from the Global Privacy Control which the company states it will honor....
Why it matters: This provision establishes that users who rely on Do Not Track browser signals will not have those preferences recognized by the Hims & Hers platform; users must instead use the Global Privacy Control, cookie controls, or advertising opt-out tools described in the policy to limit data collection....
-
Replit
· Replit Privacy Policy
The policy authorizes disclosure and transfer of user information to potential acquirers, merger partners, advisors, and other third parties during the consideration, negotiation, or completion of a corporate transaction, including partial asset sales or liquidation....
Why it matters: This provision permits disclosure of user data to third parties at the due diligence and negotiation stage of a corporate transaction, not only upon completion, which means user data may be accessed by potential but ultimately unsuccessful acquirers. The provision covers partial asset transfers as well as full acquisitions....
-
Replit
· Replit Privacy Policy
The policy states that Replit retains data based on service type, relationship length, legal requirements, and applicable statutes of limitations, and commits to deleting account data within 30 days of an account deletion request, with the option to maintain data in de-identified form....
Why it matters: This provision establishes a 30-day deletion timeline for account data, which is a concrete operational commitment, while also preserving Replit's right to retain data for fraud prevention, backups, legal obligations, archiving, and analytics, and to maintain data in de-identified form under the separate de-identification provision....
-
Replit
· Replit Privacy Policy
The policy provides jurisdiction-specific rights sections for California, Colorado, Connecticut, Iowa, Utah, and Virginia residents, with rights including access, deletion, correction, profiling opt-out, and appeals varying by state. Replit states it does not sell personal information as defined under any of the applicable state laws....
Why it matters: This provision documents Replit's stated compliance with six US state privacy frameworks and establishes the specific procedural mechanisms, including email to privacy@replit.com and account settings, through which users in each state may exercise their rights. The profiling opt-out right, available to California, Colorado, Connecticut, Virginia, and Iowa residents, is operationally significant for users concerned about automated processing of their behavioral data....
-
Poshmark
· Poshmark Privacy Policy
Any feedback, suggestions, or ideas submitted by users to Poshmark are treated as non-confidential and non-proprietary, and Poshmark may use this information for any commercial or other purpose without compensating or crediting the user....
Why it matters: This provision establishes that user-submitted feedback is not treated as confidential or proprietary, and authorizes Poshmark to use, disseminate, and commercialize such feedback without restriction, acknowledgment, or compensation. Users retain no proprietary claim to feedback submitted through the service....
-
Twilio
· Twilio Privacy Notice
The notice states that Twilio's services are not directed to children under 13 in the U.S. and UK or under 16 in the EEA, and that accounts found to belong to children will be deactivated and data deleted....
Why it matters: This provision sets age thresholds consistent with COPPA in the U.S. and GDPR Article 8 in the EEA, and provides a reporting mechanism for inadvertent collection at privacy@twilio.com. The notice applies a higher threshold of 16 for EEA users, which aligns with the maximum age of digital consent available to EU member states under GDPR....
-
Teachable
· Teachable Terms of Use
Teachable reserves the right to determine account ownership disputes in its sole judgment and to transfer accounts to the party it determines to be the rightful owner, with Teachable having final authority subject only to legal prohibition....
Why it matters: This provision establishes Teachable as the sole arbiter of account ownership disputes with unilateral transfer authority, which may affect Creator businesses where multiple stakeholders claim account rights. The sole judgment standard does not specify an appeal mechanism or independent review process....
-
Poshmark
· Poshmark Terms of Service
Any feedback, suggestions, or ideas submitted to Poshmark are treated as non-confidential, and Poshmark may use such submissions for any commercial or other purpose without compensating or crediting the submitting user....
Why it matters: This provision establishes that user-submitted feedback of any kind is not proprietary to the user and may be used by Poshmark without restriction, including for commercial product development, without payment or attribution. Users who submit specific product ideas or suggestions have no intellectual property claim over those submissions under this clause....
-
Poshmark
· Poshmark Terms of Service
Users are solely responsible for maintaining current payment information to access earned funds. After a state-mandated dormancy period, unclaimed funds are turned over to government authorities, and Poshmark may charge a dormancy fee where permitted by applicable law....
Why it matters: This provision establishes that Poshmark will escheat dormant account balances to government authorities following the applicable statutory period, and may deduct a dormancy fee before doing so. Sellers who do not actively maintain their accounts or update payment information risk forfeiture of accrued earnings to the escheatment process....
-
Google Maps
· Google Maps Platform Terms of Service
The agreement grants Google an unrestricted, royalty-free right to use any feedback or suggestions provided by the customer regarding the Services, with no compensation or obligation to the customer....
Why it matters: This provision establishes that any technical, product, or operational feedback submitted by a customer to Google becomes available for Google's unrestricted use, including for product development purposes, without creating any intellectual property claim or compensation right for the customer....
-
Cohere
· Cohere Usage Policy
The policy permits limited exceptions to its prohibited use categories for research purposes, but only when specifically authorized by Cohere or when the research falls within Cohere's published Responsible Disclosure Policy. Safety-related research outside that scope requires contact with safety@cohere.com....
Why it matters: This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities....
-
TurboTax
· TurboTax Privacy Statement
Intuit states that users can download, update, and delete their data directly through the Intuit Account portal without requiring support contact....
Why it matters: This provision describes a self-service data rights mechanism that may operationally correspond to CCPA right-to-delete and right-to-access obligations and GDPR data subject rights. The document does not specify response timelines, exceptions to deletion, or the categories of data covered by these controls....
-
TurboTax
· TurboTax Privacy Statement
The document references a cookie management mechanism allowing users to adjust cookie-related preferences, though the scope, categories of cookies, and opt-out effects are not detailed in this landing page text....
Why it matters: The presence of a cookie management tool is relevant to CCPA opt-out rights for sale or sharing of personal information and GDPR consent requirements for non-essential cookies. The operative terms of the cookie consent mechanism are not reproduced in this document....
-
TurboTax
· TurboTax Privacy Statement
Intuit Payments Inc. is identified as the entity providing money movement services, licensed as a Money Transmitter by the New York State Department of Financial Services, with a specific complaint reference for Texas customers....
Why it matters: This disclosure identifies Intuit Payments Inc. as a regulated money transmitter subject to New York State Department of Financial Services oversight, which has implications for how payment and money movement data is governed and what regulatory recourse is available to users of payment-related features....
-
TurboTax
· TurboTax Privacy Statement
Intuit references a Do Not Call Policy applicable to consumers, though the operative terms of that policy are not reproduced in this document text....
Why it matters: A Do Not Call Policy references Intuit's telemarketing contact practices and consumer opt-out rights under the Telephone Consumer Protection Act (TCPA) and FTC Telemarketing Sales Rule, but the specific mechanisms and scope are not assessable from the landing page reference alone....
-
Replit
· Replit Terms of Service
The agreement states that any feedback or suggestions submitted to Replit about the Service become Replit's sole and exclusive property, with no compensation or credit owed to the submitting user....
Why it matters: This provision assigns full intellectual property ownership of submitted suggestions to Replit and explicitly excludes any obligation for credit or compensation. The breadth of this assignment covers ideas and improvements, which may include operationally significant product concepts submitted by developers or business users....
-
Replit
· Replit Terms of Service
The agreement designates California law as governing and requires all disputes to be resolved in courts located in San Francisco, California, to which users expressly consent by accepting the terms....
Why it matters: This provision requires users to litigate disputes in San Francisco, California courts regardless of where they are located. There is no mandatory arbitration clause or class action waiver in this document; disputes proceed through courts, but the exclusive jurisdiction designation may present practical access limitations for users located outside California or outside the United States....
-
Replit
· Replit Terms of Service
The agreement requires users to grant Replit a license to copy, display, distribute, perform, reformat, and modify submitted content, along with the right to sublicense these permissions to third-party service providers used to operate the platform....
Why it matters: This provision establishes the operational license Replit requires to host and deliver the Service. The sublicense right extends these permissions to third-party providers, meaning that content may be processed by Replit's infrastructure and service partners as part of normal platform operation....
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs does not collect or store personal identifiers including names, IP addresses, street addresses, or dates of birth in connection with use of the Services....
Why it matters: This provision establishes the foundational data minimization claim of the policy, limiting the categories of personal data Uniswap Labs asserts it retains. Compliance teams should note that the policy separately discloses collection of wallet addresses, device data, and correspondence, and should assess whether any of these categories constitute personal data under applicable law including GDPR....
-
Uniswap
· Uniswap Privacy Policy
The policy discloses CCPA rights for California residents including data access, copy, and deletion requests submitted to privacy@uniswap.org, and states that Uniswap Labs will verify the identity of requesters before responding and will only fulfill requests where it can associate submitted identifying details with held information using reasonable effort....
Why it matters: This provision establishes the CCPA rights framework applicable to California residents and conditions fulfillment of data requests on identity verification and the company's ability to associate provided identifiers with held data. Given the policy's stated practice of not collecting names or IP addresses, the practical scope of fulfillable CCPA requests may be limited....
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs may transfer or share collected data to another entity in connection with a merger, acquisition, bankruptcy, dissolution, reorganization, asset or stock sale, or other business transaction....
Why it matters: This provision reserves the right to transfer user data, including wallet addresses, device data, and any other collected information, to a successor or acquiring entity in a broad range of corporate transactions, without specifying user notification procedures or consent requirements for such transfers....
-
Uniswap
· Uniswap Privacy Policy
The policy states that the Services are not directed at children, that Uniswap Labs does not knowingly collect personal information from children as defined by COPPA, and provides a contact address for reporting potential child data collection....
Why it matters: This provision establishes a COPPA compliance representation and sets the reporting mechanism for child data concerns, though the policy applies the under-18 threshold rather than COPPA's statutory under-13 threshold, which may reflect a broader internal policy choice....
-
Uniswap
· Uniswap Privacy Policy
The policy states that Uniswap Labs does not share user information with any third parties for marketing purposes....
Why it matters: This provision establishes an explicit prohibition on sharing user data for third-party marketing, which is a specific and unqualified representation that may be assessed against actual data flows to advertising and analytics providers described elsewhere in the policy....
-
ConvertKit
· ConvertKit Terms of Service
The document states that the platform formerly operated as ConvertKit and is now branded as Kit, indicating a corporate rebranding that may affect how existing contractual relationships, data processing agreements, and service terms are referenced by prior account holders....
Why it matters: A platform rebranding can affect the legal entity name under which terms are entered, the continuity of existing Data Processing Agreements referencing the prior entity name, and the enforceability of terms accepted under the prior brand identity....
-
23andMe
· 23andMe Privacy Statement
The agreement states that 23andMe accounts are protected with two-factor authentication as a standard security measure....
Why it matters: This provision establishes two-factor authentication as a baseline account security control for a platform holding sensitive genetic and health-related data, which is relevant to regulatory expectations under GDPR Article 32 and FTC data security guidelines....
-
Windsurf
· Windsurf Security & Data Handling
The document states that users may configure and limit which GitHub repositories Devin can access, with permissions manageable through GitHub's App Settings before and after installation....
Why it matters: This provision establishes that source code repository access is configurable by the user, placing responsibility for access scope management with the customer. The document references a GitHub Integration Guide for detailed permission and security information but does not enumerate specific permissions granted by default....
-
Windsurf
· Windsurf Security & Data Handling
The document states that the Slack integration is limited to processing only data explicitly provided in Slack threads where Devin is tagged, with no access to broader Slack instance data....
Why it matters: This provision defines the data minimization scope of the Slack integration, limiting Devin's data access to thread-specific interactions. This disclosure is operationally relevant for organizations concerned about Devin accessing broader Slack workspace data....
-
Windsurf
· Windsurf Security & Data Handling
The document discloses that Cognition obtained SOC 2 Type II certification in March 2024, covering security policies, procedures, and controls related to data security, privacy, processing integrity, confidentiality, and availability....
Why it matters: The SOC 2 Type II certification provides a third-party audit attestation of Cognition's security controls across the five trust service criteria, which is a commonly required vendor security credential for enterprise procurement. The document references a Trust Center for additional detail but does not provide the certification report or audit period directly....
-
GitHub
· GitHub Copilot Business Privacy Statement
GitHub states it has achieved ISO/IEC 42001:2023 certification, an international standard for AI management systems, and is extending this certification across the GitHub Copilot portfolio, applying consistent governance controls across developer productivity, enterprise workflow, and custom agent use cases....
Why it matters: This provision documents GitHub's stated compliance with ISO/IEC 42001:2023, which is the primary international standard for AI management systems and a certification increasingly referenced in enterprise procurement requirements and EU AI Act readiness assessments....
-
GitHub
· GitHub Copilot Business Privacy Statement
GitHub displays a warning on GitHub.com when a file contains hidden Unicode text, which the document states can cause code to appear differently in a user interface than it is interpreted or compiled, including by AI systems....
Why it matters: This provision discloses a platform-level security control implemented on GitHub.com that is operationally relevant to organizations using Copilot, as hidden Unicode characters in code files can alter AI-generated suggestions or code interpretation in ways not visible in standard views....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document discloses that GitHub Copilot holds SOC 1 Type 2, SOC 2 Type 2, SOC 3, ISO 27001:2013, CSA STAR Level 2, TISAX, and ISO/IEC 42001:2023 certifications, and makes audit reports and bridge letters available through the Trust Center....
Why it matters: The availability of SOC 2 Type 2 and SOC 1 Type 2 reports, including bridge letters covering December 2025, provides enterprise procurement and compliance teams with independently audited evidence of Copilot's operational security and availability controls....
-
GitHub
· GitHub Copilot Business Privacy Statement
The document states that GitHub Copilot includes an AI-based vulnerability prevention system that blocks insecure coding patterns in real time, operating on Azure infrastructure with encryption....
Why it matters: This provision discloses a real-time AI content moderation mechanism within Copilot that filters code suggestions, which is operationally relevant to security teams assessing the reliability and scope of Copilot's security controls in development workflows....
-
Arlo
· Arlo Terms of Service
The Arlo website uses Google's reCAPTCHA service on at least its email sign-up form, and the agreement states that Google's Privacy Policy and Terms of Service apply in connection with that feature....
Why it matters: This disclosure establishes that users interacting with the reCAPTCHA-protected form are subject to Google's Privacy Policy and Terms of Service in addition to Arlo's own terms, creating a third-party data processing relationship that compliance teams may need to account for in data mapping and consent frameworks....
-
Ticketmaster
· Ticketmaster Terms of Use
Ticketmaster may update the Terms at any time for stated or unstated reasons; updated Terms become binding only upon the user's agreement to the updated version, and the prior version continues to govern until the user agrees to the updated Terms....
Why it matters: The provision states that updated Terms bind users only upon their affirmative agreement, which is a consumer-favorable mechanism relative to terms that take effect automatically upon continued use; however, the practical mechanism by which agreement is solicited and recorded is not described in this provision. The prior version is accessible via a download link, which provides a transparency mechanism for tracking changes....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that personal information is retained for as long as necessary to provide services or fulfill stated purposes, with extended retention authorized for legal and regulatory obligations, dispute resolution, and enforcement of platform terms....
Why it matters: The retention standard is defined by necessity and purpose rather than fixed maximum durations; the absence of stated retention periods for specific data categories may require evaluation against GDPR storage limitation principles and equivalent state law requirements....
-
Nextdoor
· Nextdoor Privacy Policy
The policy states that material changes will be communicated in advance as required by applicable law, and that continued use of Nextdoor after such notice constitutes acknowledgment that the updated policy governs data collection, use, and sharing....
Why it matters: The continued-use consent mechanism for policy updates is standard in platform privacy policies but may require evaluation against GDPR requirements in EU and UK contexts, where material changes to data processing may require renewed consent rather than constructive acceptance through continued use....
-
Stripe
· Stripe Restricted Businesses List
Stripe automatically closes a Stripe Issuing account if all associated cards have been inactive for 12 consecutive months....
Why it matters: This provision establishes an automatic account closure trigger based solely on card inactivity, without requiring any notice or cure period, which may affect businesses with seasonal or project-based card usage patterns....
-
Stripe
· Stripe Restricted Businesses List
The policy states that Stripe Capital lending products are unavailable to nonprofit organizations, businesses in speculation-based industries, gambling businesses, and religious institutions, with potential additional restrictions for government and utility businesses....
Why it matters: This provision establishes eligibility restrictions for Stripe Capital that exclude specific organizational types and industries from access to Stripe's lending and capital products, which may affect financial planning for businesses in the named categories that rely on Stripe for payment processing....
-
TikTok Ads
· TikTok Branded Content Policy
The updated Smart+ feature allows SMB advertisers to select among three levels of campaign automation including full automation, partial automation, and manual control across audience targeting, budget allocation, ad placements, and product catalog management....
Why it matters: This provision describes a tiered automation framework that governs how audience targeting, budget, and placement decisions are made for SMB campaigns, with the degree of algorithmic versus human control variable depending on the advertiser's configuration selection....
-
TikTok Ads
· TikTok Branded Content Policy
TikTok Ads Manager's split testing feature divides the advertiser's audience into two equal groups, each receiving one ad variant, to enable performance comparison across targeting, placement, bidding, budget, creative, and catalog variables....
Why it matters: This provision describes an audience segmentation mechanism that assigns users to test groups for ad performance measurement. The audience division methodology and data use for optimization purposes may have implications for consent and data processing disclosures depending on the jurisdiction....
-
TikTok Ads
· TikTok Branded Content Policy
Product Shopping Ads pull product images and information from the advertiser's Product Details Page and display them across TikTok feed, Shop Tab, and Search placements, with clicks directing users to the Product Details Page for purchase consideration....
Why it matters: This provision describes the data source and display mechanism for product ads, establishing that product listing data from the advertiser's Product Details Page is used directly in ad creative across multiple TikTok surfaces. Accuracy of product data at the source directly affects ad content and may have implications for consumer protection and advertising accuracy obligations....