-
PayPal
· PayPal Privacy Statement
The policy states that PayPal discloses Personal Information collected after November 27, 2024 to Partners and Merchants for personalized shopping experiences in the United States by default, without requiring affirmative consent, unless applicable law requires consent. Users may opt out through the Data and Privacy setting in their PayPal account....
Why it matters: This provision establishes a default data sharing program for U.S. users under which Personal Information including products, preferences, sizes, and styles is disclosed to Partners and Merchants for personalized shopping without requiring opt-in consent. The opt-out mechanism and the November 27, 2024 cutoff date are operationally significant for both user-facing privacy controls and compliance assessments under U.S. privacy law....
-
PayPal
· PayPal Privacy Statement
The policy states that PayPal may use Personal Information to train AI models and deploy Automated Decision Making technology for risk analysis, fraud prevention, and service personalization. This includes using profiling techniques to evaluate economic situation, reliability, and behavior....
Why it matters: This provision authorizes PayPal to use the full scope of collected Personal Information, including transaction history, behavioral data, and inferred attributes, for AI model training and automated profiling. The policy states that automated assessments may result in refusal of new services, termination of existing services, or account restrictions....
-
PayPal
· PayPal Privacy Statement
The policy states that PayPal may collect biometric data including voice identification, photo identification, and face scans when users consent through the user experience, for account authentication purposes. Biometric data is retained for up to three years after account closure unless applicable law requires otherwise....
Why it matters: This provision establishes a consent-based biometric data collection framework tied to specific account actions, with a stated maximum retention period of three years post-account closure. The retention period and consent mechanism may require evaluation under state biometric privacy statutes that impose stricter requirements....
-
PayPal
· PayPal Privacy Statement
For EEA users, PayPal may update its list of third-party recipients quarterly, with a 30-day notice period before new transfers begin. Failure to object within 30 days of publication is deemed acceptance of the updated list; the only remedy for disagreement is account closure....
Why it matters: This provision establishes a deemed acceptance mechanism for EEA users whereby silence within 30 days of a quarterly third-party list update constitutes consent to new data disclosures. The adequacy of this mechanism under GDPR consent requirements, which generally require freely given, specific, informed, and unambiguous affirmative action, may require evaluation by legal teams....
-
PayPal
· PayPal Privacy Statement
The policy discloses that PayPal may provide Agentic AI Tools, operated directly or through partners, that access Personal Information including queries, preferences, interests, purchase history, and payment information to perform tasks and initiate actions autonomously on behalf of the user....
Why it matters: This provision discloses a category of AI-driven functionality that can autonomously initiate actions using payment and personal information. The policy states these tools are not designed for decisions with legal, medical, financial, or employment implications, but the access scope including payment information and the autonomous action capability are operationally significant disclosures....
-
Monitoring
These provisions have changed before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
NVIDIA NIM
· NVIDIA NIM Terms of Use
The agreement states that NVIDIA does not certify its Software for Critical Applications, disclaims liability for any claims or damages arising from such uses, and places sole responsibility on Customer to ensure safety, redundancy, and regulatory compliance for any systems built with the Software....
Why it matters: This provision allocates liability for Critical Application deployments entirely to Customer, which has significant operational and legal implications for enterprise customers deploying NVIDIA Software in safety-critical contexts such as autonomous vehicles, medical devices, or industrial control systems....
-
Webull
· Webull Customer Agreement
The terms assert that Webull retains proprietary ownership of all user accounts and may suspend or permanently terminate any account at any time without providing a reason. Users are prohibited from transferring or selling their accounts to third parties....
Why it matters: This provision establishes that account access is held at Webull's discretion rather than as a contractual entitlement of the user, which has direct operational implications for users with active brokerage positions, pending transactions, or linked cash management accounts. For broker-dealer accounts, FINRA rules may impose procedural requirements that interact with the breadth of this discretionary termination assertion....
-
Webull
· Webull Customer Agreement
The terms prohibit disclosure of user personal information except in six defined circumstances, the last of which (Section 4.6) permits disclosure whenever Webull unilaterally determines it to be necessary, without specifying the nature or category of such necessity....
Why it matters: Section 4.6 creates an open-ended disclosure authorization that is not bounded by a legal basis, regulatory requirement, or defined category of necessity. This provision may require evaluation under the CCPA's requirements for disclosing personal information and GDPR's lawful basis requirements for data processing and transfer....
-
Webull
· Webull Customer Agreement
The dispute resolution clause states that disputes should first be addressed through negotiation or arbitration, and if unresolved, through courts in the jurisdiction where Webull is registered; however, the clause does not specify an arbitration body, governing rules, seat, or whether arbitration is binding....
Why it matters: The ambiguity of this provision creates operational uncertainty for users seeking to resolve disputes: it references arbitration without specifying a forum, rules, or binding nature, and directs litigation to courts in Webull's registration jurisdiction without identifying that jurisdiction. For broker-dealer customers, FINRA Rule 12200 requires FINRA arbitration for eligible disputes, which may operate independently of or in addition to this clause....
-
SoFi
· SoFi Terms of Service
The agreement authorizes SoFi, its agents, and affiliates to contact users via auto-dialers, pre-recorded voice messages, artificial voice, SMS, and automated chatbots at any telephone number provided, with users bearing all associated carrier charges....
Why it matters: This provision establishes broad communications consent covering both marketing and account-related contact across all contact methods and all telephone numbers provided to SoFi or any of its affiliates. The Telephone Consumer Protection Act generally requires separate written consent for autodialed or pre-recorded marketing calls and texts, and whether this bundled agreement provision satisfies that requirement may depend on regulatory interpretation and enforcement context....
-
SoFi
· SoFi Terms of Service
The agreement requires users to file any claim or cause of action related to the SoFi Site, App, or these Terms within one year of the claim arising, regardless of any longer period that would otherwise apply under applicable statute or law....
Why it matters: This provision contractually shortens the filing period for user claims against SoFi to one year. Many state statutory limitations periods for consumer financial, fraud, or contract claims exceed one year, and courts in some jurisdictions have declined to enforce contractual limitations periods that override consumer protection statutes; enforceability depends on applicable jurisdiction and the specific claim type....
-
SoFi
· SoFi Terms of Service
SoFi may suspend or terminate any user's account and access to all SoFi products and services at any time, for any or no reason, without prior notice, at its sole and absolute discretion....
Why it matters: This provision grants SoFi unilateral authority to terminate access to any or all SoFi financial products and services, including banking, lending, and investment accounts, without advance notice. For users who rely on SoFi as a primary banking or financial services platform, abrupt termination without notice may create operational continuity concerns; the scope of this authority and any applicable regulatory limits would depend on the specific product type and governing financial services regulations....
-
SoFi
· SoFi Terms of Service
When a user connects an external financial account, SoFi may collect any and all information available in that account and use it for product marketing, sharing with affiliated companies, and eligibility targeting, subject to SoFi's Privacy Policies....
Why it matters: This provision establishes that linking an external bank account, loan, or credit card to SoFi authorizes collection of all available account data and its use for marketing and cross-affiliate product targeting. The scope of permissible use extends to sharing with SoFi affiliated companies, and the data is processed through a mandatory Plaid intermediary with its own separate privacy policy....
-
SoFi
· SoFi Terms of Service
When a user enrolls in Credit Score Monitoring, SoFi is authorized to obtain and retain full credit report data from a credit reporting agency on a recurring basis and use that data for targeted advertising, product eligibility targeting, and internal statistical analysis....
Why it matters: This provision establishes that enrollment in Credit Score Monitoring authorizes SoFi to use full credit report data, including detailed credit history obtained on a recurring basis, for advertising and marketing purposes beyond the monitoring function itself. This use of credit data for advertising purposes engages FCRA considerations regarding permissible purposes for obtaining and using consumer report information....
-
Binance.US
· Binance.US Terms of Use
The agreement requires that substantially all disputes between users and BAM be resolved through binding individual arbitration rather than court proceedings, and delegates questions about the arbitration clause's scope and applicability to an arbitrator rather than a judge....
Why it matters: This provision requires disputes to proceed through individual arbitration under the stated terms, and the delegation clause means that challenges to whether a dispute is arbitrable are also resolved by the arbitrator. This provision operates alongside the class action waiver, meaning users cannot aggregate claims with other users in a single proceeding....
-
Binance.US
· Binance.US Terms of Use
The agreement includes an express waiver of users' right to a jury trial and the right to participate in any class action proceeding against BAM....
Why it matters: This provision establishes that users cannot bring or join class action lawsuits against BAM and cannot demand a jury trial in any dispute proceeding. The enforceability of class action waivers in consumer financial services contracts is subject to jurisdictional variation....
-
Binance.US
· Binance.US Terms of Use
Following the Soft-Staking Launch Date, BAM automatically enrolls eligible token balances held in user accounts into Soft-Staking; existing users receive an opt-out period before automatic enrollment applies, while new users are enrolled upon accepting the terms....
Why it matters: This provision authorizes BAM to stake user-held digital assets on third-party networks without requiring affirmative per-asset consent from users beyond the initial terms acceptance or consent screen acknowledgment. During the staking and any applicable unstaking periods, enrolled assets are not available for transfer or sale....
-
Binance.US
· Binance.US Terms of Use
The agreement authorizes BAM to collect name, address, phone number, device IP, email, date of birth, taxpayer identification number, Social Security number, government ID scans, occupation and income data, expected trading amounts, source of wealth information, bank account details, and biometric information, with a stated commitment to request consent before collecting biometric data....
Why it matters: This provision discloses a broad set of personal data categories collected for identity verification and AML compliance purposes, including biometric information and financial account details. The stated consent mechanism for biometric data collection requires evaluation against applicable state biometric privacy statutes that impose specific written consent, retention schedule, and destruction requirements....
-
Binance.US
· Binance.US Terms of Use
The agreement states that users bear sole responsibility for any slashing penalties or asset seizures imposed by token protocols on staked assets in the standard staking program, to the extent the Staking Services Provider does not assume liability; BAM expressly disclaims liability for slashing losses. In contrast, for Soft-Staking, BAM separately commits to reimburse or indemnify users for any slashing losses....
Why it matters: This provision allocates the risk of protocol-imposed asset loss, including partial or total seizure of staked assets, to users in the standard staking program. The practical effect is that users who opt into standard staking for specific Eligible Tokens bear the financial risk of validator misconduct or protocol non-compliance by third-party Staking Services Providers....
-
Binance.US
· Binance.US Terms of Use
The agreement authorizes BAM to terminate, suspend, or restrict account access in its sole discretion for identity verification issues, reasonable suspicion of unauthorized account use, or suspected illegal or fraudulent activity. The terms expressly disclaim liability for direct or indirect losses resulting from such account actions....
Why it matters: This provision grants BAM broad unilateral authority to restrict or terminate account access without prior notice, including during pending identity verification review. The accompanying liability disclaimer excludes BAM from responsibility for financial losses, including lost trading opportunities, resulting from account suspension or restriction....
-
Apple
· Apple App Store Review Guidelines
Developers must use Apple's in-app purchase system for all digital content unlocking, subscriptions, game levels, currencies, and premium features; alternative unlocking mechanisms including license keys, QR codes, and cryptocurrency wallets are not permitted....
Why it matters: This provision requires all digital monetization of unlockable content to route through Apple's payment infrastructure, which carries commission obligations and restricts developers from implementing alternative payment flows within the app except through specific regional entitlements....
-
Apple
· Apple App Store Review Guidelines
Apps in the Kids Category are prohibited from transmitting personally identifiable information or device information to third parties, and third-party advertising and analytics are generally not permitted, with narrow exceptions requiring that analytics services do not collect the IDFA, identifiable information, location, or device data....
Why it matters: This provision establishes strict data handling obligations for developers targeting children, restricting third-party data flows and advertising integrations that are common in other app categories, and requires compliance with applicable children's privacy laws globally....
-
Apple
· Apple App Store Review Guidelines
Medical apps making accuracy claims for health measurements must disclose their data and methodology to support those claims; apps claiming to perform clinical measurements using only device sensors without validated methodology are not permitted, and apps with regulatory clearance must submit that documentation during review....
Why it matters: This provision establishes specific accuracy disclosure and methodology validation requirements for medical apps, and requires submission of FDA or equivalent international regulatory clearance documentation, creating a direct interaction between App Review and medical device regulatory status....
-
OpenAI
· OpenAI Business Terms
Section 15.1 and 15.3 require all disputes between Customer and OpenAI to be resolved through final and binding arbitration administered by NAM, including disputes that arose before the agreement was entered into. Court litigation is not available except for small claims and requests for injunctive relief....
Why it matters: This provision requires pre-dispute waiver of court adjudication for all claims arising out of or relating to the agreement or Services, and its stated retroactive scope covers disputes predating the agreement itself, which may face enforceability scrutiny in certain jurisdictions....
-
OpenAI
· OpenAI Business Terms
Section 15.6 prohibits Customer from participating as a class member or plaintiff in any class action, consolidated proceeding, or representative action, and requires each party to waive jury trial rights for any court proceedings....
Why it matters: This provision establishes that disputes must be pursued individually, prohibiting aggregation of claims through class or representative mechanisms, and includes a mutual jury trial waiver for any disputes that proceed in court....
-
OpenAI
· OpenAI Business Terms
Section 5.4 prohibits Customer from processing Protected Health Information through any OpenAI service unless a separate Healthcare Addendum and Business Associate Agreement has been signed, and further states that even with a Healthcare Addendum, certain OpenAI services are not designed for PHI processing and may not be used for that purpose....
Why it matters: This provision creates a direct HIPAA compliance obligation on Customer by prohibiting PHI processing through non-designated services, and requires execution of a separate Healthcare Addendum before any PHI workflows can be enabled, creating an operational prerequisite for healthcare sector deployments....
-
OpenAI
· OpenAI Business Terms
Sections 16.11 and 16.12 assign sole responsibility to Customer for export control and trade sanctions compliance, prohibit use in U.S. embargoed countries or by restricted parties, and restrict Service access to supported countries and territories, with violations subject to Service suspension....
Why it matters: These provisions assign compliance responsibility for trade controls entirely to Customer and restrict geographic access to Services, creating operational obligations for customers with international operations or End Users in or near sanctioned jurisdictions....
-
OpenAI
· OpenAI Service Terms
OpenAI's intellectual property indemnification for API and Enterprise customers is subject to six enumerated exclusions including customer knowledge of infringement, disabling of safety features, modification or combination with non-OpenAI products, lack of input rights, trademark-based claims, and Third Party Offering outputs....
Why it matters: This provision establishes that the IP indemnification offered to API and Enterprise customers contains six specific carve-outs that significantly condition the scope of coverage; customers who modify outputs, disable safety features, or use third-party offerings within their workflows may find that indemnification coverage does not apply to resulting claims....
-
OpenAI
· OpenAI Service Terms
ChatGPT Enterprise Administrators are authorized to access, share, and remove End User Content and to access logs of End User activity within the Enterprise workspace; the agreement places the obligation to obtain and maintain all necessary End User consents on the customer organization....
Why it matters: This provision establishes that the consent compliance burden for administrator access to End User Content and usage logs rests entirely with the enterprise customer, not OpenAI. Organizations deploying ChatGPT Enterprise must ensure their internal consent frameworks and employment policies authorize this level of administrative access and monitoring....
-
OpenAI
· OpenAI Service Terms
The terms prohibit using ChatGPT for Healthcare to analyze medical images, ECG waveforms, genomic sequences, or outputs from in vitro diagnostic devices, and require that clinical professionals exercise independent judgment without relying primarily or solely on the service's output; a Business Associate and Healthcare Addendum governs use of this product....
Why it matters: This provision establishes explicit scope restrictions on clinical use of ChatGPT for Healthcare, prohibiting specific diagnostic analytical functions and requiring independent professional judgment. The reference to a Business Associate and Healthcare Addendum indicates that HIPAA-covered entity obligations and business associate protections are addressed through a separate contractual instrument....
-
Perplexity AI
· Perplexity API Terms of Service
This provision authorizes Perplexity to terminate API access and deactivate API Keys for a Customer Application if Perplexity determines the application is competitive with Perplexity or likely to damage Perplexity's reputation, in addition to standard AUP and security violation triggers....
Why it matters: The competitive use and reputational harm triggers in this provision are discretionary determinations made by Perplexity without an objectively defined standard. This creates operational dependency risk for businesses that have integrated the Perplexity API into production applications, as access may be terminated without a specific rule violation....
-
Perplexity AI
· Perplexity API Terms of Service
This provision prohibits use of the Perplexity API to process Protected Health Information as defined under HIPAA unless a separate Business Associate Agreement has been executed between Customer and Perplexity....
Why it matters: This provision establishes an absolute restriction on PHI processing absent a Business Associate Agreement. Customers in healthcare-adjacent industries who inadvertently transmit PHI through the API without a BAA may face HIPAA liability independent of any Perplexity contractual remedy....
-
OpenAI
· OpenAI Usage Policies
The policy prohibits using OpenAI services for real-time remote biometric identification in public spaces, building facial recognition databases without data subject consent, and evaluating or classifying individuals based on biometric data, social behavior, or personal traits including social scoring and profiling....
Why it matters: This provision establishes a categorical prohibition on a class of AI applications that regulatory frameworks including the EU AI Act designate as prohibited practices, creating a policy-level alignment with regulatory requirements that API customers and developers must independently satisfy under applicable law....
-
OpenAI
· OpenAI Usage Policies
The policy prohibits using OpenAI services to automate high-stakes decisions in enumerated sensitive domains, including financial activities, employment, insurance, medical, legal, law enforcement, and national security, without human review....
Why it matters: This provision imposes a human-in-the-loop requirement for a broad set of consequential decision domains, which is operationally significant for enterprise and API customers building automated decision-making systems on top of OpenAI services, though the policy does not define what constitutes adequate 'human review.'...
-
OpenAI
· OpenAI Usage Policies
The policy prohibits all use of OpenAI services involving CSAM, minor grooming, age-inappropriate content exposure, and underaged roleplay, and states that OpenAI reports apparent CSAM and child endangerment to the National Center for Missing and Exploited Children....
Why it matters: This provision discloses an active reporting practice: OpenAI states it reports apparent CSAM and child endangerment to NCMEC, which is consistent with obligations under federal law for electronic service providers. The categorical prohibition extends to AI-generated CSAM regardless of whether any real minor is depicted....
-
OpenAI
· OpenAI Usage Policies
The policy prohibits using OpenAI services to aggregate, monitor, profile, or distribute individuals' private or sensitive information without authorization, and specifically prohibits emotion inference in workplace and educational settings (with a medical or safety exception) and criminal risk prediction based on personal traits or profiling....
Why it matters: This provision prohibits emotion inference in workplace and educational contexts and criminal risk prediction based on personal traits, both of which are among the prohibited AI practices enumerated in the EU AI Act, creating a policy-level alignment with that regulation that developers and enterprise customers must independently evaluate for legal compliance....
-
OpenAI
· OpenAI Usage Policies
The policy prohibits using OpenAI services for weapons development, procurement, or use, including both conventional weapons and chemical, biological, radiological, nuclear, or explosive (CBRNE) materials....
Why it matters: This provision establishes a categorical prohibition on using OpenAI services for weapons-related purposes including CBRNE, which is operationally significant for defense contractors, research institutions, and security firms evaluating the scope of permissible use of OpenAI tools....
-
Roblox
· Roblox Privacy and Cookie Policy
For users 13 and older, Roblox states it monitors, collects, uses, and stores audio captured through users' devices for voice chat enablement, safety enforcement, AI model training, and product improvement purposes....
Why it matters: This provision establishes that audio recordings are used for AI training and product improvement in addition to safety purposes, which engages GDPR lawful basis requirements, US state voice data statutes, and EU AI Act training data transparency obligations depending on user jurisdiction....
-
Roblox
· Roblox Privacy and Cookie Policy
Roblox states it may collect images including selfies to perform facial age estimation, asserting that such images are deleted once the age assurance process is complete....
Why it matters: This provision establishes a facial estimation mechanism for age assurance that involves biometric-adjacent data processing; applicable law in certain jurisdictions (including Illinois BIPA and GDPR's biometric data provisions) may impose consent, retention, and deletion obligations that require evaluation against the policy's stated deletion practice....
-
Roblox
· Roblox Privacy and Cookie Policy
For users under 13, Roblox states it collects username, password, date of birth, optional gender, and persistent identifiers (IP address and device identifiers) for internal operations, asserting this collection is consistent with COPPA's definition of non-personal information....
Why it matters: This provision establishes the operational boundaries for child data collection under COPPA and determines which platform features are accessible to users under 13, including the exclusion of personalized advertising until age 18....
-
Uber
· Uber Terms of Use
The agreement requires users to resolve all disputes with Uber through binding individual arbitration rather than through court proceedings, and both parties waive their right to a jury trial. This obligation applies to disputes arising before or after the date the terms are accepted, including personal injury and death claims....
Why it matters: This provision requires that disputes, including those involving personal injury or death, proceed through private arbitration rather than the court system, with an arbitrator's decision being final and binding. The provision also asserts that the FAA governs interpretation and enforcement, asserting preemption of state arbitration laws to the fullest extent permitted....
-
Uber
· Uber Terms of Use
The terms require users to waive their right to participate in class, collective, coordinated, consolidated, mass, or representative actions against Uber, limiting disputes to individual proceedings only. The waiver applies in both arbitration and court proceedings, with courts retaining exclusive authority to determine the enforceability of the waiver itself....
Why it matters: This provision precludes users from joining or initiating group litigation against Uber, including as a participant in a class action initiated by others, except as expressly permitted for classwide settlements. Courts, not arbitrators, have exclusive authority to resolve disputes about the enforceability of the class and mass action waivers....
-
Uber
· Uber Terms of Use
The terms assert that questions about whether a dispute must go to arbitration, including claims that the arbitration agreement itself is unenforceable or unconscionable, must be decided by an arbitrator rather than a court, with the specific exception that courts have exclusive authority over class and mass action waiver disputes....
Why it matters: This provision delegates threshold arbitrability determinations, including unconscionability challenges to the arbitration agreement itself, to the arbitrator rather than a court. The carve-out preserving court authority over class and mass action waiver disputes is operationally significant, as it creates a bifurcated authority structure between arbitrators and courts....