Found in 267 of 352 platforms tracked (76% adoption) · 1909 provisions
The unconditional scope of account responsibility means customers bear liability for unauthorized or third-party actions taken under their account, with no exception for actions they did not approve.
A Business can be granted sweeping control over a user's profile and Content—including deletion and retention—covering both past and future uploads, meaning users have limited autonomy over their own…
The one-account limit means any attempt to open additional accounts is a breach of the terms, which could have consequences for account standing.
Users cannot exit the Afterpay relationship or close their Account while a balance remains, meaning the contractual relationship and its obligations persist until the debt is cleared.
Users bear full responsibility for account activity even if unauthorized parties accessed the account, which can have significant financial and legal consequences.
A user who creates a personal-seeming account with a work email may find their account — and its contents — accessible to their employer's administrator without separate consent.
Using a work email address may cause a user's account—and its contents and activity—to become visible to and controllable by their employer's administrator without any separate consent step described…
The requirement directly restricts who can access model weights and under what conditions, establishing a structural safeguard against unauthorized or unilateral access to core AI assets.
Users who register with employer or organizational email addresses may lose effective control and privacy over their account, as a third-party administrator may gain oversight and control.
This establishes that Asana, not the Managed User, defers to the Customer on data control matters, meaning the Managed User's rights over their data are governed by the Customer, not directly by Asan…
The customer bears full contractual responsibility for user conduct, meaning any user violation of the Agreement or misuse of Customer Data is attributable to the customer, not the individual user.
The age floor and accuracy requirement establish baseline eligibility conditions; failing either could constitute a breach of the Terms from the moment of registration.
The minimum age requirement establishes a hard eligibility threshold that excludes users under 13 from lawful use of the Services.
The clause is consequential because it makes the provision of personal information a non-negotiable condition of access to Betterment's services.
Enrollment is automatic and applies to all existing users once the Opt-Out Period has passed, meaning users who did not act during that window have no further opportunity to avoid enrollment.
Users bear responsibility for account activity they did not authorize, meaning unauthorized access or misuse by a third party using valid credentials still falls on the account holder.
Liability for unauthorized account use falls on the account holder when that unauthorized use results from the account holder's own failure to maintain security — extending potential exposure to thir…
A user's account and all Content within it can transfer to organizational control without further action by the user if they miss the 14-day response window.
An authorized user's personal information may be subject to terms they have not directly agreed to and cannot independently enforce against Brex.
The minimum age requirement sets a legal threshold for registering and using Bumble, with the applicable age varying by jurisdiction for users in countries where the contracting age of majority excee…
Users in an Administered Account do not have exclusive control over their own account, content, or designs; an Admin Entity's admin holds concurrent power over all of these.
Users on a Team account do not have exclusive control over their own uploaded content or created Designs; Team Owners and Administrators hold the power to access, delete, or transfer ownership of tha…
An individual user's act of signing up with a work email can create binding legal obligations for their employer or organization without that entity's independent assent.
Users operating under an Administered Account have significantly reduced control over their own account, content, and privacy preferences, all of which can be altered or eliminated by an admin.
Cash App can liquidate a user's bitcoin holdings without further user action to cover a failed transfer, exposing users to a forced sale at whatever price bitcoin holds at that time.
Cash App's recovery authority extends across multiple funding sources simultaneously, including credit cards and external linked accounts, meaning Cash App can reach funds beyond the core Cash App Ba…
Users enrolled in for-credit programs may be unable to exercise a standard account-deletion right, limiting their control over their personal data while enrolled.
This provision establishes the operational consequence of payment method failure at renewal—account deletion becomes an authorized remedy rather than requiring notice, cure period, or advance warning…
An Authorized User's account and access to Platform Services are subject to control by their organization's administrators, not solely by the user themselves.
Strict access controls on internal employees directly limit the insider-threat surface for production systems and customer data.
The restriction directly limits who may access a subscription, making unauthorized sharing a potential breach of the terms.
Employees who use work email addresses for DocuSign accounts may have those accounts located and acted upon by their employer organization, limiting the employee's exclusive control over the account.
Users on a Dropbox Team account do not have exclusive control over their stored information; organizational administrators hold broad powers over that content.
Team account users do not have exclusive control over their accounts; an administrator may access and control the account, which has implications for the privacy of content stored there.
The clause grants teachers the ability to fully access and act within a student's account, including logging in as that student, which represents a significant level of account control by a third par…
This establishes that children's personal information is collected and used by EA, but only on certain services and only with parental consent, defining the conditions under which EA processes minors…
This places the risk of unauthorized account activity squarely on the customer, including actions taken by others who obtain the customer's credentials.
Access to the Professional Voice Cloning tool is gated behind a technological verification requirement, meaning it is not freely available to all users.
Liability for unauthorized account use extends to a broad set of Eufy-affiliated parties and is not capped in this provision, potentially exposing users to significant financial risk.
Users bear sole responsibility for credential security, and any breach of this obligation — including sharing or using others' credentials — is a violation of the Terms.
Collecting sensitive personal data through Eventbrite's platform is prohibited by default, which limits how organizers and users can use the platform for data gathering.
Users have no recourse outside Eventbrite's own judgment when account ownership is contested; the decision cannot be appealed.
Users accessing Figma through an organization have their information subject to disclosure to that organization and to rights the organization holds over that information.
Because credentials are non-transferable, any sharing—even within a team—constitutes a violation of the Terms, exposing the Customer to enforcement action.
The clause grants the service provider unilateral termination authority without requirement for advance notice, stated justification, or procedural review. This establishes the operational framework …
The prohibition establishes a minimum age gate for account creation tied to jurisdiction-specific law, with parental consent as the only permitted exception.
The prohibition establishes a hard age threshold for account eligibility and places an affirmative restriction on Fly.io's data collection and content direction practices toward that age group.
Users whose accounts are supplied by an institution have reduced direct control over their Personal Data, as the institution—not GitHub—holds the primary Data Controller role for most of that data.
Mandating Indeed Login for new users means new users cannot access Glassdoor services without creating or using an Indeed account, linking their Glassdoor access to a separate platform.
Users who link accounts lose the ability to sever that connection, making any data sharing or integration that results from the connection permanent.
The inability to disconnect linked accounts is a permanent and irrevocable restriction on account control, which has significant implications for how a user's data and identity are managed across con…
Legacy login access has a defined expiration date, after which existing users relying on that authentication method will need to use an alternative.
Automatic synchronization means changes to a user's Profile on one platform are reflected on the other, removing user control over maintaining separate profiles across the two services.
Account access and data retention rights are extended to third-party administrators and resellers, meaning parties other than the user or Google may hold copies of account information.
The minimum age requirement establishes a hard eligibility threshold that bars anyone under 16 from using Google Pay.
Removal of a Payment Instrument renders it unusable with the Service, meaning users lose access to that instrument for Google Pay transactions on the affected device.
A prolonged failure to connect to any Google product or service — not just Google Pay — can trigger removal of a payment instrument, even if the user intends to continue using Google Pay.
Inactivity for 12 consecutive months on a single device can trigger automatic removal of a payment instrument, rendering it unusable on that device.
The age requirement operates as a hard eligibility gate, barring anyone under 18 from using the Google Pay app regardless of other circumstances.
Users may lose access to their account and its associated data at an administrator's direction.
Users may not have independent control over their own data or privacy settings if an administrator imposes restrictions.
It establishes a direct link between the Keep Activity setting and the use of chat and media data to train generative AI models, making the user's setting choice consequential for AI training.
A terms violation of any kind, regardless of severity, can result in immediate loss of access to all purchased content and account data with no financial remedy, which is a significant potential cons…
This provision establishes that the Content license granted upon purchase is subject to unilateral revocation by Google under defined circumstances, and that the sole remedy available to affected use…
Users who register with a work or institutional email address may have their account information disclosed to their organization's administrators, affecting their expectation of individual privacy.
Because termination can occur for any or no reason, users risk losing the entire accumulated value in their account with no guaranteed recourse.
Employers bear full financial and legal exposure for any unauthorized activity on their account, with no allocation of that risk to Gusto.
Access to sensitive license-plate and location data is nominally restricted, but the authorization standard—'Authorized Purpose'—is defined by Home Depot, leaving the scope of access within its discr…
This sets a minimum eligibility threshold for account creation, which may affect the enforceability of the agreement with users below age 13.
Sharing a subscription with people outside the household violates the Agreement unless the user's specific service tier expressly allows it.
Because responsibility for credential security rests with the user, Ideogram is not liable for account compromises resulting from the user's failure to secure their credentials.
Any use of the Site by a person under 18 is characterized as unauthorized and unlicensed, which may carry legal consequences for both the minor and any adult who facilitated access.
Full responsibility for all account activity means users bear liability for any actions taken through their account, including by third parties who may gain access.
The irreversibility of the account merge means a decision to delete one account has unavoidable consequences for access to the other service.
Linked users are granted potential access to the full contents of the employer's account, including candidate personal data, as a consequence of the employer's own invitation.
The irreversibility of the account merge means that deleting an Indeed account has permanent consequences for access to a separate service, Glassdoor, with no option to restore that access.
Individual users in business accounts do not have sole control over their own account data; an employer or administrator holds authority over personal information including sensitive payroll details.
Children's accounts are technically restricted at the feature level to prevent personal information from being posted or disclosed through the platform.
Because the Customer bears sole responsibility for authorization and authentication, LangChain can place liability for unauthorized access on the Customer rather than itself.
The claim establishes that a third-party Admin Entity—not the individual user—may hold operational control over the user's account and all Content within it.
The claim establishes that inactivity of 12 months or more can trigger permanent, irrecoverable deletion of both the account and all user-generated Content.
Leonardo AI retains the power to unilaterally modify or eliminate an Administered Account, which could affect access to content, settings, and the account itself.
Account sharing or transfer is expressly prohibited, meaning any such action would constitute a breach of the agreement.
A member using an employer-funded paid Service does not have exclusive control over that account; the paying party holds recognised access and reporting rights over it.
By disclaiming user ownership of both the account and stored data, LlamaIndex retains full control over both, limiting users' ability to assert proprietary claims over their account or data held on L…
Users who sign up or log in with a work email domain may not realize that their personal account content and history become accessible to their employer's administrator.
This restriction places the user in sole control of and responsibility for their API key, and any unauthorized sharing would constitute a breach of the Terms.
Work account users have no personal privacy expectation in the data they create through those accounts, as Microsoft explicitly vests access and processing rights in the employing organization rather…
This access restriction means Copilot-generated content is not universally accessible, making permission controls a meaningful gate on that content.
Account closure is a permanent and consequential action that eliminates access to the account and any Services tied to it.
Immediate termination of access means there is no grace period during which a user could retrieve data, content, or settings associated with the account.
It establishes a universal account requirement that applies across all versions of the game.
It establishes that account deletion automatically terminates any active Realms subscription.
It establishes that account deletion is permanent and results in irreversible loss of both account access and previously purchased game ownership.
This clause makes continued access to Minecraft's Services conditional on completing account migration for affected users.
Individual users lose practical control over their account and its contents once an employer entity assumes control, including the ability to access or remove information the user created.
The prohibition covers a broad range of transfer mechanisms — not just sale but sharing and licensing — meaning any form of access grant beyond the Customer's own entity is barred.
The Customer cannot shift liability for account or infrastructure activity to Mistral AI or to End Users; sole responsibility rests with the Customer.
The prohibition covers multiple forms of credential sharing and commercialisation, any of which can constitute a breach of the terms.
The restriction means any multi-person use of a single account violates the terms, which can be grounds for enforcement action.
Authorized users' accounts and Platform Services access are subject to control by their organization's administrators, not solely by the users themselves.
The clause places the burden of account security on the account holder and other users, meaning Netflix does not accept responsibility for access that results from their failure to secure credentials…
By making users responsible for all account activity, Okta shifts liability for unauthorized use to the user, regardless of how that unauthorized use occurred.
This allocation of control means Okta does not determine individual users' access; accountability for provisioning lies with the Okta customer organization.
This establishes a minimum age threshold as a condition of use, meaning anyone under 18 is categorically ineligible to hold a fan account.
The clause creates an exhaustive list of permissible access purposes, meaning employee access outside those three purposes is not authorized.
This clause means users bear full responsibility for any misuse of their account, even where a third party gains access, because sharing or allowing access is itself prohibited.
The restriction narrows the universe of personnel who can access customer API business data, which defines the scope of internal exposure.
This clause means an individual's account can be placed under organisational control without the user's prior consent, which may affect the user's access and privacy.
Users joining a business or enterprise account lose exclusive control over their account and Content, which becomes accessible to third-party administrators.
This clause establishes OpenAI's unilateral right to discontinue service access without preconditions. From an operational standpoint, it means the availability of the Services depends on OpenAI's de…
Users bear full responsibility for all account activity, including actions taken by unauthorized parties who gained access through shared credentials.
Users have no guaranteed continuity of account access, no right to prior notice, and no stated entitlement to a refund, leaving accounts vulnerable to removal under any circumstance.
The prohibition directly restricts who may access an account, meaning any sharing beyond household members constitutes a breach of the terms.
This dual age requirement means the effective minimum age varies by country, as local data-consent laws may set a threshold higher than 13.
This requirement gates access to core creator and purchasing functions behind an age threshold or explicit adult authorization, excluding minors acting independently.
Users must actively change their privacy setting from the default Public state; without action, their profile is publicly visible and discoverable by other Members.
A single deletion action triggers irreversible loss of data across every account sharing that email, which may include accounts the user did not intend to delete.
Placing confidentiality responsibility on the user means that unauthorized access resulting from a user's failure to protect their credentials may be attributed to the user rather than Pinecone.
Users who have been banned are permanently barred from re-registering unless Pinterest affirmatively and discretionarily grants written permission, giving Pinterest unilateral control over re-access.
Because Company bears responsibility for all credential holders and any person using those credentials, unauthorized or negligent use by any such person exposes Company to liability under the Agreeme…
This provision means that payments made by a third party who accesses a device to which the card is added are treated as authorised by the cardholder, which affects liability for those transactions.
These three prohibitions collectively restrict account duplication, commercial use of personal accounts, and re-registration after a prior closure, defining the outer limits of permissible personal a…
Anyone under 18 is ineligible to open a Revolut account, making age a hard precondition for access.
All material control over a Group Pocket — including member funds and access — is concentrated exclusively in the owner, leaving other members dependent on the owner's actions.
These two prohibitions together prevent circumvention of account closure and cap each person at a single personal account.
The mandatory nature of this verification means users cannot opt out, and the measure is framed as a safeguard against unauthorized account access.
Any sharing or transfer of account access — including merely offering to do so — is prohibited and may expose the account to enforcement action.
This establishes minimum eligibility conditions for account creation and use of the Riot Services, directly restricting who may legally enter the agreement.
The automatic nature of these restrictions means under-13 users cannot opt into features like personalized advertising regardless of preference; the settings are applied without requiring any user ac…
Children's account data is subject to a general restriction on use and sharing, with an additional consent requirement where mandated by law, limiting Roblox's ability to process that data broadly.
The privacy restriction is automatic and not user-initiated, meaning under-13 users do not need to act to receive these protections, but also cannot opt out of the feature restrictions.
Users under 13 face mandatory feature restrictions tied explicitly to the protection of their Personal Information, limiting platform access as a privacy safeguard.
Users on Enterprise or team accounts do not retain exclusive control over their own accounts, as administrators have explicit access and control rights.
Access to the Services for children under 13 is entirely conditioned on a legal guardian taking affirmative action to create a compliant Child Account.
Users whose accounts were provisioned by a Customer may not have exclusive control over their own account information; the provisioning Customer's Admin shares that control.
Sole responsibility means the customer cannot shift liability to Segment for unauthorized, improper, or third-party use that occurs under the customer's account.
This age requirement bars minors from creating accounts and makes any account created by a person under 18 non-compliant with the Terms.
This clause restricts access to a paid or registered membership to a single individual, preventing household or group sharing of a single subscription.
Users' information is not solely under their own control; a range of Customer-side actors may access or alter it.
Because User conduct is legally attributed to Customer, any User violation of the Agreement exposes Customer directly to liability or consequences under the Agreement.
A user's deletion request does not fully remove all data from administrator visibility; organizational administrators can retain access to certain data elements, limiting the practical effect of a de…
Users bear full responsibility for third-party actions on their account, meaning Square can hold users accountable for misuse or unauthorized activity by anyone they have granted access.
Users accessing services through a corporate domain have reduced privacy expectations, as their Inputs and Outputs may be visible to and controlled by their employer's administrator.
The strict personal nature of Accounts and Subscriptions means users cannot monetize, gift, or transfer their Steam libraries or account access to third parties.
The prohibition on sharing credentials, combined with personal responsibility for account security, means users bear the consequences of any unauthorized access resulting from their own disclosure.
The clause permits a Platform to lock a User out of controlling who has access to their own Stripe Account, removing a fundamental account-security lever from the User.
Account closure is automatic and tied to inactivity across all cards, meaning a single dormant account with multiple cards requires activity on at least one card to avoid closure.
The Customer bears the obligation to verify age and consent before authorising Custom Avatar creation, making compliance failures the Customer's contractual responsibility.
Customers bear financial liability for charges accumulated before reporting and cannot eliminate that liability simply by suspending service.
This prohibition establishes an absolute age floor for platform access and account creation, with no exceptions stated.
Compliance with the Advertiser Account Policy is a condition placed on advertisers, meaning failure to comply may affect their ability to advertise.
Because responsibility is sole, the account holder cannot shift blame to TikTok Ads or other parties for any account activity, even activity initiated by Permitted Users rather than the holder direct…
Account closure is automatic upon two years of inactivity, meaning users do not receive a discretionary decision — the closure is mandatory once the inactivity threshold is met.
Access is cut off automatically upon ineligibility without any action by Tinder, meaning there is no grace period or notice required before authorization ends.
Account reassignment to a reseller cannot be used as a mechanism to escape contractual obligations that were originally agreed to.
Sole responsibility means you cannot attribute liability for account activity to Twilio or any other party, regardless of who actually performed the actions.
Because Uniswap has no custody, control, or ability to retrieve or transfer wallet contents, users have no recourse through Uniswap if wallet contents are lost or inaccessible.
Cabined Accounts, which apply to children, face specific functional restrictions that limit both social interaction and financial transactions within the platform.
The act of choosing to use the aggregation service is framed as an express authorization for Wealthfront to access the full scope of Outside Account Information accessible via the provided credential…
The reader's continued access to their account is subject to Webull's absolute discretion, with no stated conditions or limitations on when that power may be exercised.
Account access can be ended by Webull at its sole discretion if the user violates the prohibition on transferring or selling the account.
This establishes a minimum eligibility threshold that conditionally bars younger users from independently accessing WhatsApp's Services, with the threshold varying by jurisdiction.
Account creation is conditioned on providing a mobile phone number, making anonymous or phone-number-free registration unavailable.
Users on enterprise or business accounts do not have exclusive control over their accounts or User Content — administrators have access and control rights that extend to that content.
Users accessing Writer through an employer or other organization may have reduced privacy expectations, as their account activity may be visible to and controllable by an administrator.
By placing security responsibility on the user, Xfinity may disclaim liability for unauthorized access that results from the user's failure to secure their account or devices.
Participants in meetings or webinars have no control over whether the account owner views or shares recordings and transcripts of those sessions.
The prohibition means each individual must have their own account and rights, and any sharing without written pre-approval from Zoom constitutes a breach of the agreement.
Participants in a recorded meeting who send messages to Everyone may have those messages and their identity visible to the account owner, not just the meeting host.
Any participant joining a meeting or webinar on someone else's Zoom account, or messaging a user on that account, is subject to personal data access by the account owner and their designees.
Encryption of Zoom Email does not prevent account owners or designated administrators from accessing email content, removing an assumption of privacy that users might otherwise rely on.
Zoom Chat messages between users on an account are not private from the account owner, who can access both metadata and full message content depending on their settings.
The use of 2-factor authentication represents a specific security measure applied to user accounts, which is relevant to assessing the baseline protection 23andMe provides for account access.
The agreement permits Anthropic to suspend access based on its reasonable belief of a violation or vendor disruption, with no liability to the Customer for resulting business losses, including lost p…
The asymmetric termination notice structure means that while both parties can terminate for convenience, Anthropic can terminate immediately without the 30-day notice period if it determines that pro…
Teens hold the ability to initiate the cessation of parental activity sharing, which affects the scope of parental oversight available through Character.AI.
The invitation mechanism places the parent's email address — and thus their access — entirely within the teen's control to initiate.
Removal of parental email access cannot be completed by the teen alone; it requires affirmative parental confirmation, preserving a parental check on the removal process.
Access to parental oversight tools is contingent on an affirmative parental action; without it, no parental visibility is granted.
This provision authorizes permanent account and data deletion as a consequence of payment method failure at renewal, without Anysphere incurring any liability, which creates a significant data loss r…
This provision authorizes Anysphere to modify or discontinue paid features without notice and without liability, which means users relying on specific paid functionalities have limited contractual re…
Customer vetting at sign up means not all applicants are automatically granted access; ElevenLabs applies a screening step before a customer can use the platform.
If your business or application depends on Fireworks AI's API, an unexpected account termination with no notice and no liability commitment could disrupt your operations with no contractual recourse.
Readers without a Google Account cannot access the discount regardless of other eligibility.
The one-account limit restricts users from creating multiple accounts, which could otherwise be used to circumvent enforcement actions or usage limits.
It puts existing Mojang account holders on notice that their account type will be discontinued and replaced with a Microsoft account requirement.
Age restrictions may vary by Service, meaning a user who meets baseline age requirements could still be restricted from particular Services.
The provision creates an enforcement mechanism whereby OpenAI retains unilateral authority to assess policy compliance and impose account termination as a remedial measure. The clause grants OpenAI d…
This clause establishes OpenAI's unilateral authority to restrict service access without advance notice requirement or stated grounds review process. The provision defines the company's operational d…
This establishes that TurboTax applies access-restriction technology intended to prevent unauthorized parties from accessing a user's account.
This clause establishes that Windsurf applies a least-privilege access model to its production infrastructure, limiting the population of individuals who can directly interact with customer data envi…
It establishes that automated agent actions are subject to identity validation, permission checking, and activity logging before reaching connected systems.
Account closure can result in the permanent loss of access to all content, settings, and data associated with the account.
The asymmetric notice requirement creates different operational timelines for service discontinuation: Anthropic must provide advance notice before terminating for convenience, while the customer may…
The cap of 7 profiles defines the maximum number of distinct user identities permitted under a single account.
Monitor emails you the same day a platform you choose changes these clauses.
A account control clause is a provision in a platform's terms of service or privacy policy governing account control-related rights, obligations, or restrictions.
ConductAtlas tracks 267 platforms with account control clauses - roughly 76% of platforms in the archive. 771 are classified as high severity.
Severity reflects the magnitude of rights waived, availability of opt-out, breadth of users affected, financial or legal exposure created, and the degree of discretion retained by the platform.