-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement authorizes Microsoft to retain, access, transfer, and disclose user content, including emails and files stored in Outlook and OneDrive, based on a good faith belief that such access is necessary for legal compliance, safety, security, or protection of Microsoft's rights. This standard is self-assessed by Microsoft rather than requiring a judicial or regulatory determination prior to access....
Why it matters: This provision establishes that Microsoft may access and disclose the substantive content of user communications and stored files under a self-assessed good faith standard. The breadth of the triggering conditions, which includes protecting Microsoft's rights and property as well as responding to legal process, means this provision may be invoked across a wide range of circumstances....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement authorizes Microsoft to share collected personal data with named third-party advertising partners including Facebook, Yahoo, The Trade Desk, Taboola, Outbrain, and Media.net for purposes of delivering personalized advertising across Microsoft and third-party properties. The list is described as non-exhaustive....
Why it matters: This provision discloses data flows to a named but non-exhaustive list of third-party advertising companies, with data used for cross-site behavioral advertising. The non-exhaustive characterization means additional advertising partners beyond those named may receive personal data under these terms....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
Microsoft certifies compliance with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, subjecting it to FTC enforcement and onward transfer liability for agent processing. Residual complaints not resolved through other mechanisms may proceed to binding arbitration under DPF Principles....
Why it matters: This provision establishes Microsoft's legal mechanism for cross-border personal data transfers from the EU, UK, and Switzerland to the United States. It also establishes that Microsoft retains liability for onward transfers to third-party agents, and that binding arbitration is the final dispute resolution mechanism for DPF-related complaints that cannot be resolved through other channels....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
The statement requires parental consent for account creation by children under 13 (or a higher age where required by local law), prohibits personalized advertising to users identified as under 18, and limits data collection from children to what is necessary for the product. Parents can revoke consent and access or delete child data through the privacy dashboard....
Why it matters: This provision establishes the conditions under which children's accounts may be created and the data protections applied to users under 18, including a blanket prohibition on personalized advertising to users identified as minors based on their Microsoft account birthdate. Parent and guardian controls are available through the Microsoft Family Safety tools and privacy dashboard....
-
Microsoft
· Microsoft Privacy Statement (Legacy)
Windows collects required diagnostic data covering device configuration, performance, and update status, and optional diagnostic data that includes app activity, browser history, search terms in Microsoft Edge, and enhanced error reports that may contain fragments of user content. Users can choose between required and optional diagnostic data levels in Windows settings....
Why it matters: This provision establishes that optional diagnostic data in Windows may include browsing history and search terms from Microsoft Edge, as well as error reports that may unintentionally contain user content such as file fragments. The statement acknowledges this risk explicitly for enhanced error reporting....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Microsoft
· Microsoft Privacy Statement (Legacy)
For enterprise and developer products, the applicable customer agreement supersedes this privacy statement in the event of conflict. Organizations using Microsoft products with work or school accounts have administrative access to and control over employee or student data, including communications, files, and diagnostic data....
Why it matters: This provision establishes that employees and students using Microsoft products through organizational accounts are subject to their organization's data governance policies and that the organization, not Microsoft, is the primary data controller for those interactions. The provision directs end users to their organization's administrator for privacy inquiries rather than to Microsoft....
-
Cursor
· Cursor Data Use & Privacy Overview
Privacy Mode activates zero data retention agreements with all model providers, preventing training use of Customer Data, but the document states that prompts or conversations triggering abuse detection classifiers may be stored by model providers including Cursor for investigation under their own retention policies....
Why it matters: This provision establishes that Privacy Mode does not constitute an absolute data retention barrier; a carve-out permits storage of user data triggered by abuse detectors, with retention duration and deletion governed by the individual model provider's policies rather than Cursor's own terms....
-
Cursor
· Cursor Data Use & Privacy Overview
The document discloses that named third-party inference providers Baseten, Together AI, and Fireworks may temporarily access and store model inputs and outputs, with deletion occurring after use, when Privacy Mode is disabled....
Why it matters: This provision identifies specific third-party subprocessors by name and authorizes temporary storage of model inputs and outputs by those providers, with retention duration determined by the phrase 'deleted after use' rather than a defined timeframe....
-
Cursor
· Cursor Data Use & Privacy Overview
The document states that requests made using a user's own API key are routed through Cursor's backend for final prompt construction, rather than being sent directly to the model provider....
Why it matters: This provision establishes that API key users do not bypass Cursor's data processing infrastructure, meaning the data handling terms described in this document apply to API key-based requests including any applicable training use or logging provisions....
-
Cursor
· Cursor Data Use & Privacy Overview
The document states that codebase indexing uploads code in chunks to Cursor's servers, with plaintext code deleted after each request, but embeddings and metadata including file hashes and file names may be retained in Cursor's database....
Why it matters: This provision establishes that while plaintext code is not persistently stored during indexing, derived artifacts including vector embeddings and file metadata such as hashes and file names may be retained in Cursor's database, which may carry data governance implications for users with sensitive or proprietary codebases....
-
Cursor
· Cursor Data Use & Privacy Overview
A footnote in the document states that prompts and limited telemetry will not be shared with model providers when Privacy Mode is off if the user's account was created before October 15, 2025....
Why it matters: This provision creates a data sharing exemption that is account-creation-date-dependent, meaning the applicable data handling terms differ between users based on when they registered, without a mechanism described in this document for users to verify or confirm their account creation date eligibility....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits users from using Mistral AI platform products to provide investment, financial, legal, or medical advice or guidance, except where the user holds 'proper qualification,' a term the policy does not define....
Why it matters: This provision introduces an undefined qualification exception ('without proper qualification') that creates interpretive ambiguity for enterprise users in regulated sectors such as financial services, legal services, and healthcare who may use the platform to support qualified professionals. The operational boundary between prohibited unqualified advice and permitted qualified professional use is not specified in the policy....
-
Mistral AI
· Mistral AI Usage Policy
The policy reserves the right to modify its terms at any time without specifying advance notice to users, directing users to check the policy website frequently for updates....
Why it matters: This provision establishes that changes to the Usage Policy may take effect upon publication without prior user notification, placing the obligation to monitor for changes on the user. For enterprise customers who have integrated Mistral AI platform capabilities into regulated workflows, this creates a dependency on proactive monitoring of policy changes to maintain compliance with applicable commercial and regulatory obligations....
-
Mistral AI
· Mistral AI Usage Policy
The policy explicitly states that its terms do not apply to Mistral AI models or products deployed on customer or partner infrastructure, or to Mistral AI's open-source models, limiting the policy's scope to platform-hosted products only....
Why it matters: This provision establishes that users who self-host Mistral AI models or access them through partner-deployed infrastructure are not subject to this Usage Policy, meaning separate governance frameworks apply to those deployment contexts. Institutional customers evaluating compliance coverage across their AI deployment stack should identify which governance documents apply to non-platform deployments....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits generating content that promotes hate or discrimination based on specified characteristics, engages in historical revisionism or genocide denialism, or constitutes harassment or glorification of suffering....
Why it matters: The explicit inclusion of Holocaust denial and genocide revisionism as prohibited content categories reflects obligations under applicable law in multiple EU jurisdictions where denial of certain historical events is criminalized. The broad scope of the prohibition across multiple protected characteristics and the inclusion of 'any target' for harassment language creates an expansive restriction that applies across all platform content....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits using Mistral AI products to create malware, exploit security vulnerabilities in any system, or attempt to bypass Mistral AI's security protections and AI safety filters....
Why it matters: The prohibition on circumventing AI safety filters is operationally significant for security researchers, red-team practitioners, and adversarial AI testing professionals, as the policy does not include an exception for authorized security research or vulnerability disclosure programs. The breadth of the prohibition to include security compromise of 'any third party' extends the restriction beyond Mistral AI's own systems....
-
Mistral AI
· Mistral AI Usage Policy
The policy prohibits generating deliberately misleading or false content, including health and scientific misinformation, content that undermines civic or political processes, harmful conspiracy theories, and misinformation targeting protected groups....
Why it matters: The prohibition on content that 'undermines the integrity of a civic or political process' is operationally significant given the broad scope of activities that could be characterized as political, including legitimate political commentary, satire, and advocacy. The policy's use of 'for instance' framing indicates these are non-exhaustive examples, meaning the prohibition may extend beyond the enumerated categories....
-
Mistral AI
· Mistral AI Usage Policy
The policy states that violations may result in temporary suspension or permanent termination of accounts, and that certain violations may be reported to law enforcement or other relevant authorities, with the determination of what is 'appropriate' left to Mistral AI's discretion....
Why it matters: The discretionary 'where appropriate' formulation for law enforcement reporting means Mistral AI retains sole discretion over which violations are reported to authorities beyond the mandatory CSAM reporting obligation. The policy does not describe appeal procedures, notice requirements prior to account termination, or a mechanism for users to contest enforcement decisions....
-
Anthropic
· Anthropic Sub-Processors
The document lists Palantir Federal Cloud Service (PFCS) as the sole subprocessor for the Claude for Government product, designated specifically as a FedRAMP Cloud environment located in the United States. All other subprocessors listed are explicitly excluded from the Claude for Government product line....
Why it matters: This provision establishes that Claude for Government operates on a distinct, isolated subprocessor infrastructure from all other Claude products, consistent with FedRAMP authorization requirements applicable to U.S. federal agency data. Compliance teams evaluating Claude for Government for federal procurement must confirm the applicable FedRAMP authorization level (Moderate, High, or tailored) and impact classification applicable to PFCS....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Nutun, located in South Africa, as a subprocessor providing user support functions across all Anthropic Claude products except Claude for Government. South Africa is not the subject of an EU adequacy decision under GDPR....
Why it matters: The use of a South Africa-based subprocessor for user support functions creates international data transfer obligations under GDPR Chapter V for EU and UK personal data, requiring either Standard Contractual Clauses, Binding Corporate Rules, or another recognized transfer mechanism. Enterprise customers with GDPR obligations should verify that Anthropic's DPA addresses this transfer adequately....
-
Anthropic
· Anthropic Sub-Processors
The document identifies two subprocessors, Persona (United States) and Yoti (United Kingdom), as handling fraud and abuse detection and identity verification specifically for Claude Free, Pro, and Max consumer accounts. These functions are not listed for Claude for Work, Claude Developer Platform, or Claude for Government....
Why it matters: Identity verification functions typically involve processing government-issued identity documents and may involve biometric data depending on the verification method, creating potential obligations under GDPR, UK GDPR, and state-level biometric privacy laws such as Illinois BIPA. The product-specific scope, limited to consumer-tier accounts, means enterprise and developer platform users are not subject to this processing under these listed subprocessors....
-
Anthropic
· Anthropic Sub-Processors
The document identifies Sift and Arkose Labs, both located in the United States, as subprocessors providing fraud and abuse detection across all Claude products except Claude for Government....
Why it matters: Fraud and abuse detection systems typically analyze behavioral signals, device fingerprints, IP addresses, and usage patterns to identify anomalous activity. Processing of this data by two separate U.S.-based vendors across all non-government products creates data sharing obligations under GDPR and may be relevant to user transparency and profiling disclosures....
-
Anthropic
· Anthropic Sub-Processors
The document lists Brave Search and TurboPuffer, both in the United States, as subprocessors for web search functionality. Brave Search applies to all Claude products including Claude for Government; TurboPuffer applies to all products except Claude for Government....
Why it matters: Web search subprocessors process user queries that may contain personal information or sensitive content. Brave Search's inclusion across all products, including Claude for Government, while TurboPuffer is excluded from Claude for Government, creates a distinction in web search infrastructure between government and non-government product lines....
-
Minecraft
· Minecraft Privacy Statement
The page footer references separate documents titled 'Privacy and Cookies,' 'Consumer Health Privacy,' and 'Terms of use' as the locations where operative privacy and data terms are disclosed, rather than presenting those terms on this page....
Why it matters: The operative privacy terms governing Minecraft user data are not contained on this page but are distributed across multiple externally linked documents, which compliance teams would need to obtain and review separately to assess data collection, sharing, and user rights provisions....
-
Minecraft
· Minecraft Privacy Statement
The page footer includes a distinct 'Consumer Health Privacy' link separate from the general 'Privacy and Cookies' link, indicating the existence of a separate notice addressing consumer health data....
Why it matters: The presence of a separate Consumer Health Privacy notice may indicate that Minecraft or its parent Microsoft collects or processes health-related data subject to jurisdiction-specific statutes such as the Washington My Health MY Data Act or similar state laws, though the content of that notice is not available in the provided text....
-
Minecraft
· Minecraft Privacy Statement
The footer includes a 'Your Privacy Choices' link attributed to Microsoft, indicating the presence of a privacy rights exercise mechanism consistent with U.S. state privacy law requirements....
Why it matters: The 'Your Privacy Choices' link is associated with opt-out rights under CCPA and CPRA, specifically the right to opt out of the sale or sharing of personal information; its placement in the Minecraft footer indicates that these rights are available to applicable users through the Microsoft privacy framework....
-
Minecraft
· Minecraft Privacy Statement
The page footer attributes copyright to Mojang AB and trademark to Microsoft Corporation, indicating a dual-entity governance structure for the Minecraft platform that may affect which entity acts as data controller under applicable privacy frameworks....
Why it matters: The joint attribution of Mojang AB and Microsoft Corporation in the footer is relevant to determining controller identity under GDPR and equivalent frameworks, which affects which entity bears primary data protection obligations and which privacy documentation governs user data....
-
Threads
· Threads Privacy Policy
This provision states that Meta's ability to verify and process data deletion requests submitted directly by third-party federated service users is described as limited, and that Meta may be unable to process such requests. The policy states that deletion signals transmitted automatically via the interoperable protocol from third-party services will receive reasonable efforts to honor....
Why it matters: This provision establishes a qualified data deletion pathway for third-party federated service users, conditioning fulfillment on Meta's ability to verify the request and committing only to reasonable efforts for protocol-based deletion signals. This may require evaluation under GDPR's right to erasure and CCPA's deletion rights framework, particularly regarding the adequacy of the deletion mechanism for non-Threads users whose data has been collected by Threads....
-
Threads
· Threads Privacy Policy
This provision states that username, name, profile picture, and bio are always public on Threads regardless of whether the user has set their profile to private or public, and are accessible to anyone on or off Meta Products. Post content visibility is configurable via private or public profile settings, but the four enumerated profile fields are not subject to audience restriction....
Why it matters: This provision establishes that four categories of user data (username, name, profile picture, bio) are permanently public and not subject to the audience controls available for other content. Compliance teams assessing user data minimization or privacy-by-default configurations should note that these fields cannot be restricted regardless of profile setting....
-
Threads
· Threads Privacy Policy
This provision states that Threads uses account information from the Instagram, Facebook, or other linked account used to sign up in order to generate connection recommendations on Threads, and that this use is bidirectional, meaning Threads activity may also inform recommendations on the linked account....
Why it matters: This provision authorizes cross-product data use between Threads and other linked Meta accounts for the purpose of connection recommendations. Compliance teams assessing Meta's cross-product data integration practices should note that this provision explicitly extends the data use relationship bidirectionally between Threads and linked accounts....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
When a supplemental term such as the AI Terms of Use, Data Processing Agreement, or Security Exhibit conflicts with the base Terms of Service, the supplemental term governs on that subject matter. Each supplemental term activates only when its stated condition is met....
Why it matters: This provision establishes the contractual priority structure across all Sourcegraph legal documents, which determines which obligations and limitations apply to a given customer in cases of conflict. Legal teams must assess which supplemental terms are triggered by their specific agreement conditions to understand the complete applicable framework....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Privacy Policy applies to all users of any Sourcegraph product or service and governs personal data that Sourcegraph collects and uses in its capacity as a Data Controller....
Why it matters: This provision establishes that Sourcegraph acts as a Data Controller for personal data collected through its products, which under GDPR imposes direct legal obligations on Sourcegraph regarding lawful basis for processing, data subject rights, and accountability independent of the agreement's own terms....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
A dedicated set of supplemental terms applies to employees and contractors of the U.S. Government who use Sourcegraph products and services....
Why it matters: This provision identifies a distinct legal framework applicable to U.S. Government users, which is operationally relevant for federal procurement compliance and may address Federal Acquisition Regulation requirements, data handling restrictions applicable to federal systems, and government-specific use limitations....
-
Sourcegraph Cody
· Sourcegraph Terms of Service
The Acceptable Use Policy applies to all users of any Sourcegraph product or service without exception....
Why it matters: This provision establishes that the Acceptable Use Policy is a universally applicable supplemental term, meaning its restrictions and requirements govern all user interactions with Sourcegraph products regardless of account type, agreement date, or order form contents....
-
Character.AI
· Character.AI Safety Center
The Parental Insights tool allows teen users to invite parents or guardians to receive a weekly activity report disclosing time spent on the platform and the top Characters interacted with. Both the initiation of sharing and the removal of parental access are controlled by the teen user, with parents receiving a confirmation email before removal takes effect....
Why it matters: This provision establishes a teen-controlled parental visibility mechanism, in which the minor user determines whether, with whom, and when activity data is shared with a parent or guardian. The design, in which the teen initiates and terminates parental access, may warrant evaluation under COPPA and analogous minor-protection frameworks that address the adequacy of parental consent and oversight mechanisms....
-
Runway
· Runway Usage Policy
The policy states that Runway may suspend a user's account for any violation of the usage policy, with an appeal process available via email to suspension@runwayml.com....
Why it matters: This provision reserves broad discretionary suspension authority without specifying a graduated enforcement process, notice period, or defined timeline for appeal resolution, which creates operational continuity exposure for enterprise and business users relying on platform access....
-
Runway
· Runway Usage Policy
The policy prohibits generating content that may violate intellectual property rights and separately prohibits attempting to create content in the style of a known living artist....
Why it matters: The prohibition on content in the style of a known living artist represents a notable policy position in the generative AI context, engaging unsettled questions under copyright law and personality rights doctrines that are the subject of active litigation and regulatory attention as of the document's publication date....
-
Runway
· Runway Usage Policy
The policy prohibits using Runway's tools to impersonate individuals or entities, misrepresent affiliation, defraud, scam, or deliberately mislead others....
Why it matters: This provision addresses AI-generated deepfake and synthetic media use cases that engage FTC Act Section 5 prohibitions on deceptive practices and, for election-related contexts, emerging federal and state AI transparency and disclosure requirements....
-
Runway
· Runway Usage Policy
The policy establishes additional prohibitions specific to Runway's Characters and Game Worlds products, including prohibitions on characters modeled on minors' likeness or voice, content targeting users under 18, and AI characters designed to simulate professional medical, legal, financial, or therapeutic advice....
Why it matters: The prohibition on characters targeting users under 18 engages COPPA obligations and platform-level duty-of-care frameworks applicable to AI products used by or designed to attract minors. The prohibition on AI characters simulating professional advice engages FTC guidance on AI-generated professional recommendations and state-level professional licensing frameworks....
-
Coinbase
· Coinbase Fee Schedule
Coinbase includes a spread in the price quoted to users for simple buy, sell, and convert orders, and the document states Coinbase may retain any excess spread generated from those transactions....
Why it matters: This provision establishes that the effective price paid or received by consumers for trades includes an undisclosed margin above or below the market rate, and that Coinbase retains any excess above the amount required to execute the transaction. The spread is visible on the order preview screen but is not expressed as a fixed percentage, meaning the cost to the consumer may vary across similar transactions....
-
Coinbase
· Coinbase Fee Schedule
This provision discloses that when Coinbase batches multiple users' transactions together for network submission, the total estimated network fees charged to those users may collectively exceed the actual network fee that Coinbase pays, with Coinbase retaining the difference....
Why it matters: This provision establishes that the network fee charged to an individual user is based on an estimate of standalone transaction costs, and that efficiency gains realized by batching are not passed through to users. The resulting difference between aggregate user charges and Coinbase's actual cost is retained by Coinbase....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges an additional service fee on DEX trades beyond the standard trading fee, may retain any excess service fee, and explicitly excludes this fee from the Coinbase One subscription's zero-fee trading benefit....
Why it matters: This provision establishes a fee category for DEX trades that operates independently of the Coinbase One subscription benefit structure, meaning subscribers who pay for zero-fee trading are nonetheless subject to a separate service fee on all DEX transactions. The document also states that DEX aggregators routing trades may retain any price improvement over the quoted price as a fee....
-
Coinbase
· Coinbase Fee Schedule
If Coinbase liquidates a user's Bitcoin collateral under a loan agreement, it charges a flat fee of 2% of the total transaction value at the time of liquidation....
Why it matters: This provision establishes a liquidation fee triggered by collateral sale events under Coinbase lending arrangements, creating a fixed cost that applies at the point when a borrower's collateral position is being reduced, potentially compounding financial exposure during adverse market conditions....
-
Coinbase
· Coinbase Fee Schedule
Coinbase charges a network fee for all recovery attempts of unsupported cryptocurrency sent to a Coinbase account, plus an additional 5% fee on the portion of the estimated recovery value exceeding $100, with a disclaimer that estimated value may differ from actual market value....
Why it matters: This provision establishes a fee structure for asset recovery services where the 5% fee is calculated on an estimated value that the document itself acknowledges may differ from actual market value, creating a situation where the fee basis may not align with the consumer's ultimate realized value....
-
Coinbase
· Coinbase Fee Schedule
The document states that all fees and charges disclosed in the schedule are subject to change without specifying a notice period, notice method, or effective date requirement for fee changes....
Why it matters: This provision reserves Coinbase's right to modify any fee or charge in this schedule without specifying a notice period, notice mechanism, or advance-notice obligation to users, which may interact with applicable consumer financial protection and money transmission regulations that impose notice requirements for material changes to fee terms....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits users from representing AI-generated content as having been created solely by a human when the intent is to deceive....
Why it matters: This provision establishes a disclosure obligation tied to AI content provenance, which intersects with emerging EU AI Act transparency requirements for AI-generated content and state-level synthetic media disclosure statutes in the United States....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to generate or distribute content that facilitates spam, phishing, malware, infrastructure disruption, or circumvention of Google's abuse protections and safety filters, including prompt manipulation designed to bypass policy restrictions....
Why it matters: This provision directly addresses adversarial use of generative AI for security attacks and model manipulation, including jailbreaking attempts, and places user-side responsibility for not circumventing Google's safety infrastructure....
-
Google Gemini
· Google Generative AI Prohibited Use Policy
The policy prohibits using generative AI to facilitate fraud, impersonation of individuals without explicit disclosure, misleading claims of expertise in sensitive areas, and false information about governmental or democratic processes or harmful health practices, where the intent is deception....
Why it matters: This provision covers a range of AI-facilitated deception categories with relevance to election integrity, public health information, and financial fraud, placing the conduct prohibition on the user and conditioning it on deceptive intent....
-
Airbnb
· Airbnb Privacy Policy
Airbnb's privacy governance is distributed across a main Privacy Policy and multiple supplemental documents; users are instructed to identify and review the supplements applicable to their geography and services....
Why it matters: This provision establishes that operative data rights and obligations are not contained in a single document but are distributed across geographic and service-specific supplements, requiring users and compliance teams to identify and review multiple documents to understand the full scope of applicable terms....
-
Airbnb
· Airbnb Privacy Policy
Airbnb maintains a separate privacy notice specifically addressing DAC7-related data processing, which governs personal information collected about individuals (including hosts) for EU platform economy tax reporting purposes, potentially including individuals who are not direct Airbnb account holders....
Why it matters: The DAC7 Privacy Notice indicates that Airbnb processes personal data for EU tax authority reporting obligations that may apply to individuals regardless of whether they have a direct contractual relationship with Airbnb, creating a distinct processing purpose and notice obligation separate from the main user privacy policy....