Found in 296 of 352 platforms tracked (84% adoption) · 4187 provisions
This defines a broad category of data collection that encompasses essentially all substantive input a user provides to AI21 Labs' models.
This clause establishes a hard boundary on AWS Bedrock personnel access to customer Content, which is a significant security and confidentiality assurance for workloads running on Nitro System EC2 in…
Consent to session replay technology is obtained through continued use rather than an affirmative opt-in, meaning users who keep using the service are treated as having agreed to potential recording …
Detailed behavioral data including navigation patterns and mouse movements may be recorded by Acorns during platform interactions, though both the deployment and recording are qualified as non-certai…
This collection extends beyond Activision's own platforms to include browsing behavior on unrelated websites visited before and after using an Activision property, enabling cross-site tracking.
Registration triggers the collection of personally identifiable information, including a phone number in specific cases, establishing a direct link between the user's real identity and their account.
The consent is irrevocable, meaning users cannot later withdraw permission for monitoring and recording of their communications during Product use.
This extends Activision's data collection beyond the game itself to encompass private communications and broader device activity, including software unrelated to the game.
The scope of collection is exceptionally broad, encompassing not only files but also behavioral artifacts such as prompts and search terms that users may not consider 'content.'
An opt-out exercised for standard versions does not carry over to Beta Versions, meaning users who believe they have limited data collection may still be subject to it—including human review of their…
Users who handle Sensitive Personal Information through Adobe's platform without meeting one of the three stated exceptions are in breach of the Terms, which could affect regulated industries or spec…
Biometric data is among the most sensitive categories of personal information, and its collection by Adobe is explicitly acknowledged, with legal definitions governing its scope.
KYC data, which can include sensitive identity information, is actively shared with third-party verification and screening entities, and may also reach regulatory authorities, expanding the universe …
Affirm collects highly sensitive personal identifiers including Social Security numbers, creating significant privacy and identity-theft risk if this data were exposed.
Affirm collects highly sensitive financial credentials and account details, meaning a data incident could expose comprehensive financial information.
The breadth of processing activities — collection, use, disclosure, transfer, storage, retention, and other processing — combined with the wide range of triggering interactions establishes that virtu…
The clause establishes that access to a user's credit or consumer report data is predicated on the user's own consent and instructions, which frames the user as an active authorizing party rather tha…
Treating continued interaction as consent means users who keep using Afterpay's Services are bound by all Privacy Notice practices without requiring an affirmative opt-in action.
The prohibition covers sensitive data of any individual, not only the user's own data, expanding the scope of the restriction beyond self-disclosure to include third-party personal information.
The availability of centralized governance tools indicates that administrators can control access and data protection settings across their organization's Airtable environment.
The clause grants Amazon Associates broad rights over data collected from an associate's site and visitors, including the ability to disclose that data to others.
The scope of collection is defined by what the user provides, making users the source of the data Amazon receives and retains.
Data collection extends to physical spaces through passive technology, meaning users in Amazon stores may have their in-person behavior monitored and recorded.
Collection is automatic and does not require any affirmative act by the user, meaning data is gathered passively during ordinary use.
American Airlines limits direct collection of children's personal data but retains two explicit exceptions — legal compliance and safety and security — that permit such collection even from children.
American Airlines' consent obligation for sensitive data is conditional on two cumulative requirements — legal mandate and absence of any other lawful basis — meaning consent is not always sought bef…
Providing certain Account Information is a non-negotiable condition of accessing Ancestry's Services.
Facial geometry templates are among the most sensitive categories of personal data and are regulated as biometric data in several jurisdictions; their collection by Anthropic carries significant priv…
The claim establishes that Anthropic collects a category of data that carries heightened legal protections as biometric data in certain jurisdictions, affecting what rights users may have over that d…
Cross-site interest tracking combined with referral-fee facilitation means user behaviour data directly influences financial transactions between websites, extending the commercial use of that data.
Cross-device and cross-channel tracking by Google Analytics enables construction of a unified behavioural profile that extends beyond a single session or device.
This requirement ensures users are both asked for permission and actively notified at the moment any recording or logging of their activity occurs, combining consent with real-time transparency.
The clause establishes a stated design principle that personal intelligence is delivered without collection of personal data by Apple, setting the foundational privacy commitment of the system.
Telephone communications with Bank of America are subject to potential monitoring or recording, which affects consumer expectations of privacy on those calls.
The open-ended 'including but not limited to' language means the categories of personally identifiable information Baseten may collect are not exhaustively defined by the listed examples.
This clause ties continued use of the Service to consent to data collection and use practices, making use itself the mechanism of agreement.
This clause establishes that payment card data never passes through Baseten's own storage, shifting custody and associated risk to third-party processors.
Users' information will be shared with third-party partners and transferred across multiple countries, which may involve varying data protection standards.
Best Buy collects biometric fingerprint data, but collection is conditional on a legal requirement and is limited to the trade-in program fraud-detection context.
In-store shoppers at certain locations may have their biometric data, including facial recognition data, collected without necessarily initiating any specific interaction, as collection may occur via…
Although Best Buy collects biometric geometry data, the no-retention commitment limits the duration of exposure, and collection requires user permission.
The protection is limited by the qualifier 'knowingly,' meaning inadvertent collection from children under 13 is not explicitly prohibited by this clause.
The clause is consequential because it discloses that biometric-adjacent facial image data may be collected and processed by a third-party vendor, Socure, as part of Betterment's identity verificatio…
A dedicated privacy policy defines the scope of Betterment's data collection and use practices, establishing the framework under which customer information is handled.
Consent to broad data practices is established through the mere act of use or access in any manner, without requiring an affirmative opt-in step separate from that access.
Biometric data is among the most sensitive personal data categories; the clause limits its use to a single stated purpose—identity verification for security and compliance—at the onboarding stage.
The consent requirement creates a procedural obligation on Binance.US before biometric data collection occurs, giving users a formal opportunity to agree or decline.
The scope of collection encompasses substantive communication content—not merely metadata—including recordings of video calls and the contents of emails, representing a broad reach into employee comm…
Because posts are both collected by Bluesky and public, they are available to Bluesky and to anyone else, with no expectation of privacy.
The use of third-party verification services means user data may be shared with external parties as part of a legally triggered age-check process.
Because direct messages are unencrypted and accessible to Bluesky, users cannot assume their private communications are confidential from the platform.
The clause identifies the breadth of personal information categories Boston Dynamics may collect and use, spanning financial, behavioral, and biographical data.
The clause discloses that Boston Dynamics collects data generated by its products, including data derived from images and audio, which may involve sensitive environmental or personal information.
Linking a bank account triggers automatic collection of sensitive financial data, including account balance information.
The scope of transaction data collected is detailed and includes user-generated content such as annotations, creating a comprehensive record of financial activity.
Highly sensitive identity documents are collected as a compliance requirement, meaning users cannot opt out if they wish to use Brex's services.
Precise geolocation collection enables the core matching functionality of the service by establishing geographic proximity between users. The provision establishes that location-based features depend…
The clause authorizes the collection and processing of biometric data through facial recognition technology for identity verification purposes, while establishing an alternative verification pathway.…
This provision establishes a recommended practice regarding information disclosure rather than a binding restriction. It reflects the service's operational guidance on profile content management and …
The processor designation means Calendly does not control the purposes or means of processing that customer-directed data, which affects whose privacy obligations govern that data and where affected …
Data collection about users extends beyond Calm's own services to other websites and online services, and is conducted by third parties outside Calm's direct control.
Users interacting with Calm through multiple communication channels—including feedback and market research sessions—may have those interactions recorded.
This clause is consequential because it establishes that Cash App collects some of the most sensitive categories of personal data, including biometric identifiers and government-issued identification…
This clause is consequential because it establishes that Cash App's data collection is not limited to information users directly provide, but extends to data sourced from external third parties inclu…
This clause is consequential because it establishes the baseline set of personal and account identifiers Cash App collects from users, including network-level identifiers such as IP address.
This clause is consequential because it establishes that Cash App may collect precise geolocation data, which is among the most sensitive categories of location information and can reveal users' phys…
The 'knowingly' qualifier means the restriction applies to deliberate collection; Cerebras does not warrant against inadvertent collection from minors.
This links data provision to service access, meaning exercising deletion rights or withholding information may result in loss of service.
The enumerated categories include financial account numbers and login credentials, which are among the most sensitive categories of personal data.
Chase's data collection is not limited to information users directly provide; it extends to external commercial sources including credit bureaus, which may hold sensitive financial data.
Session replay technology captures detailed behavioral data about how a user navigates Chegg's interfaces, including inputs, which goes beyond standard analytics.
Chat interactions are not ephemeral; Chegg has the stated ability to record and retain both the content of chats and information users provide within them.
Cloudflare commits to both avoiding collection and remedying inadvertent collection of minors' personal information through deletion.
Users of the 1.1.1.1 resolver receive a specific privacy assurance—no personal information logging—and a short maximum retention window for most non-personal data.
This clause establishes that all SaaS Platform use is subject to logging and monitoring, meaning user activity is recorded and reviewed for defined compliance and security purposes.
Users or enterprises deploying Cohere models in private or third-party-managed environments retain data isolation from Cohere itself, meaning Cohere cannot collect, review, or use that data.
Customers using Cohere through third-party or private deployments have a structural data isolation from Cohere — their prompt and generation data never reaches Cohere's systems.
The categories collected include highly sensitive government identifiers and financial address documents, making this collection consequential for user privacy and data security.
Biometric data is among the most sensitive categories of personal information, and its collection for identity verification means Coinbase processes data that carries significant privacy implications.
The monitoring and recording right extends beyond calls to all communication media and covers not just the customer but anyone using the customer's Services, broadening the scope of who may be record…
The breadth of automatically collected identifiers means Copy.ai can build a detailed technical profile of a user without any active input from that user.
Biometric facial data is a particularly sensitive category of personal data, and its generation is performed by a third-party vendor rather than Coursera directly.
Coursera explicitly disclaim collecting financial data, meaning users' financial information rights and protections are governed by the third-party processor's policies, not Coursera's.
The distinction between controller and processor determines who bears primary legal responsibility for data processing decisions and who users must direct rights requests to.
The prohibition on knowingly collecting data from under-18 users, combined with a conditional deletion obligation, defines Cursor's stated approach to child data protection.
Personal data embedded in user Inputs is actively collected by Cursor and may be reproduced in Suggestions, meaning sensitive information could appear in generated outputs.
Customer data, including meeting content, may be transcribed and recorded by a third-party subprocessor in the United States.
Customers can review which organizations access their data, where those organizations are located, and the category of services they perform.
Transmitting personal data without first executing the data processing agreement would put the customer in breach of the Agreement, with potential regulatory exposure under applicable data protection…
Biometric data is among the most sensitive personal information; its collection for identity verification and government-mandated screening has significant implications for traveler privacy.
Third parties, not only Delta Airlines, are granted access to and storage of data on users' devices, and one stated purpose is personalized advertising.
Consent is identified as the legal basis for three specific categories of data use, meaning Delta Airlines' authority to process this data depends on the user having affirmatively consented.
Processing of the most sensitive categories of personal data is conditioned on the purpose for which it was originally provided or on express consent, limiting Delta Airlines' authority to repurpose …
The clause establishes that use of facial comparison technology is optional, meaning users retain the choice whether to submit to it at the named touchpoints.
Location data collection extends across digital and physical touchpoints, including passive methods such as IP address association and beacon technologies, meaning location may be collected without e…
Parental consent is a prerequisite to children's data collection, grounding a compliance obligation in both law and Disney+'s self-stated practices.
Use of the Services is framed as acknowledgment of the data collection and use practices described in the Privacy Notice, establishing the notice as the governing framework for those practices.
DoorDash explicitly recognizes that transactional data it holds may constitute sensitive health information, signaling that ordinary purchase records on the platform carry heightened privacy implicat…
DoorDash may collect precise location data continuously—including when the app is backgrounded—meaning location tracking is not limited to active, foreground use of the app.
Consent is triggered automatically by the act of communication, meaning users cannot communicate with DraftKings without simultaneously consenting to comprehensive surveillance and retention of that …
Using DraftKings' Services is conditioned on acceptance of its data practices — there is no mechanism to use the Services while objecting to those practices.
It establishes that Account creation necessarily involves personal information collection, binding users to the privacy notice's data practices from the outset.
Biometric data collection is among the most sensitive forms of personal data processing; the consent requirement is the critical legal condition gating this practice.
User data collection is not limited to DraftKings — multiple named third-party vendors independently collect user and visit data, and the list of such vendors is expressly non-exhaustive.
Users' stored content is not merely held passively; Dropbox actively accesses and scans it as part of service operation.
Users viewing shared content—not just account holders actively uploading or managing files—are subject to data collection, including individually identifying information such as email addresses.
The acknowledgment that some processed data is personal data is consequential because it triggers applicable data protection obligations with respect to that subset of data.
The clause limits the permissible use of personal information collected from children under 13 to internal operations, excluding other uses such as advertising or third-party sharing.
The clause makes continued use of the Service the mechanism of consent to all data practices described in the Privacy Policy, rather than requiring a separate affirmative consent act.
The clause establishes that child users are not subject to third-party behavioral tracking, limiting external data collection about their activities.
The clause discloses that third-party companies can use cookies placed through Duolingo to track users beyond Duolingo's own platform for advertising purposes.
This establishes that a user's gameplay may be captured and redistributed to third parties within EA's ecosystem, meaning in-game behavior is not necessarily private to the session.
This establishes that EA's data collection can extend to hardware-level device identification, enabling persistent identification of a device even if other identifiers are cleared.
Egnyte collects detailed behavioral browsing data that goes beyond basic account information, capturing navigation patterns before and during a visit to the Website.
Egnyte collects sensitive financial data, specifically payment card information or bank account numbers, as part of its data collection practices.
The breadth of processed content — Input, Output, and any additional information — means personal information embedded in any user interaction with the Services is within scope for processing.
ElevenLabs' training data collection extends beyond information users directly provide, drawing from publicly available third-party sources subject to applicable law.
ElevenLabs' traceability design means generated content is not anonymous; it can be linked back to the user who created it, enabling ElevenLabs to identify and act against abusive users.
Biometric data is among the most sensitive categories of personal data; its collection for verification purposes means some users may provide this data as part of normal Service use.
Biometric data is a sensitive category of personal information; its collection for verification purposes carries significant privacy implications for affected users.
ElevenLabs' training data is not limited to information provided directly by its users; it also draws from publicly available third-party sources.
Voice and text chat data is retained locally and can be transmitted to Epic Games for review upon a report of a potential violation, meaning communications are not ephemeral.
The authorization is broad, covering ongoing monitoring and compilation of multiple categories of sensitive personal and financial data from consumer reporting agencies and other sources.
The consent requirement means this category of visual data collection—inside users' homes—is conditional, establishing a user right to withhold authorization.
Collection is automatic and involves third parties, meaning users have no opportunity to affirmatively provide or withhold this usage data during normal interaction with Eufy's platforms.
Keystroke-level recording can capture sensitive input such as passwords, personal information, or search terms, representing a significant depth of behavioral surveillance beyond typical analytics.
Precise geolocation—distinct from general location—can pinpoint a consumer's exact physical position; its sale or disclosure enables third parties to obtain granular movement data.
Commercial and transactions data—including insurance claims and vehicle information—leaves Experian's possession through sale or disclosure to outside parties.
Geolocation data reveals physical movement and presence; its sale or disclosure to third parties for marketing extends its use well beyond the consumer's interaction with Experian.
These categories are among the most sensitive personal attributes a consumer possesses; their sale or disclosure by Experian transfers information that can be used to discriminate or target individua…
This category includes highly sensitive government-issued identifiers; their sale or disclosure to third parties increases the risk of identity-related harm to consumers.
This category of data constitutes complete account-access credentials; its collection and sale by Experian creates direct financial security exposure for consumers.
Online activity data can reveal detailed behavioral patterns; Experian's sale or disclosure of this category transfers those behavioral records to outside parties.
Government-issued identification numbers are primary vectors for identity theft; Experian's sale or disclosure of these numbers transfers that risk to the parties receiving the data.
Third parties—not just Faire—are collecting user behavior data, enabling interest-based advertising and analytics that extend beyond Faire's direct data practices.
Message content is not private from Faire; it may be retained and reviewed for compliance and security purposes.
Retailers grant Faire and third-party agents access to sensitive personal and business credit data as a condition of being evaluated for credit eligibility.
Because providing identity verification information is mandatory — not optional — users who decline cannot access the affected aspects of the Services.
Consent is triggered automatically by the act of access, meaning users do not need to take any affirmative opt-in step before FanDuel's data collection and use practices apply to them.
Users who contact FanDuel through any channel should expect that the full contents of those communications may be retained by FanDuel or a third party, with no stated limit on retention duration or p…
Precise GPS-level location tracking is among the most sensitive forms of data collection, and FanDuel uses it for multiple purposes including commercial advertising delivery.
The governing rules for Fastly's handling of personal data are set by a separate document — the Data Processing Terms — not by the main Agreement alone.
Collection of photos, videos, and recordings of users and their environments is a high-sensitivity category of personal data that can capture detailed visual and audio information about individuals.
Consent to data collection, use, and disclosure is triggered by any form of access to the Services, not only by affirmative agreement or account creation.
The protection is limited to knowing collection or solicitation; Figure AI does not represent that it has technical measures preventing such collection.
Explicit consent is a heightened legal standard under the GDPR; this clause commits Fitbit to obtaining it before processing the most sensitive categories of personal data.
Access to the Fitbit Service constitutes agreement to data collection and use, making it impossible to use the service without consenting to the Privacy Policy's data practices.
Collection of precise geolocation data is conditioned on the user granting access, meaning the user retains control over whether this sensitive category of data is collected.
This acknowledgment authorizes Fly.io to gather data about Customer's behavior both within the Services and from external third-party sources.
This clause establishes implied consent through conduct — the act of uploading sensitive data itself serves as the legal consent mechanism for US-based storage, without requiring a separate affirmati…
Precise real-time movement data is sensitive; the consent requirement means Garmin must obtain affirmative agreement before collecting it.
Users are consenting in advance to real-time or recorded monitoring of their interactions on the site, and that monitoring may be carried out by third-party service providers.
Session replay technology can reconstruct a user's on-screen activity in detail; its explicit use signals that Gemini captures behavioral interaction data beyond standard analytics.
The scope of collection extends to granular behavioral signals — including every keystroke and AI tool input — meaning Gemini captures not just what users submit but how they interact in real time.
Biometric data such as face geometry is among the most sensitive categories of personal information, and its collection from identity documents signals a high-stakes data collection practice.
Children aged 13 to 15 cannot have their personal information sold or shared by General Motors without first giving affirmative authorization, adding a protective gate for this age group.
General Motors captures granular, individually attributable driving behavior data, which creates a detailed behavioral profile of how a specific person operates a vehicle.
Precise geolocation is among the most sensitive categories of personal data, and General Motors may collect it across multiple triggering conditions, including general vehicle use.
The scope of collection is broad, encompassing substantive user-generated content including AI-interaction outputs and source code.
This clause extends GitHub's privacy compliance obligations beyond GitHub itself to any third party that collects data from the Service, making the Privacy Statement a binding standard for all data c…
It establishes that user-written code and chat inputs, together with surrounding context, are transmitted to an AI system, defining a high-severity data collection category that includes the substanc…
Activity data collected across services can be used to build a profile of user behaviour, informing recommendations and other personalised features.
Using the Service binds the user to the Google Privacy Policy, making that external document's terms enforceable conditions of use.
The prohibition extends to hashed data and to third-party facilitation, meaning any indirect transmission of recognizable PII to Google through the user's platform is also prohibited.
Signed-out users are not anonymous to YouTube Ads; collected data is persistently associated with their browser, application, or device via unique identifiers.
Location data collection is tied directly to ad targeting, meaning users' physical whereabouts inform the advertising they receive.
This clause places full compliance responsibility for all applicable data-collection laws and agreements on the user, not on Google.
The instruction identifies Unpaid Services as an environment where sensitive or personal data should not be entered, which is directly relevant to data protection for developers and any end users who…
Personal data flowing through Additional Products falls outside the contractual data protection framework established by these Terms, leaving that data without the same enumerated protections.
The permission extends Google's data collection beyond information the user directly provides, encompassing data held by merchants and payment issuers, which broadens the scope of personal informatio…
Consent to data processing is tied to the act of accessing or using the services, meaning no separate affirmative consent step is required beyond use.
It establishes the broad scope of data collection, encompassing both conversational inputs and rich media content shared during interactions.
It establishes that location data collection is not optional or conditional — it occurs every time a user uses Gemini Apps, with no opt-out described in this clause.
The Customer's agreement acknowledges a broad data use right for Google and its Affiliates, covering retention and use of identifiable data points for product improvement across Google's portfolio, n…
The clause establishes Google's operational authority to gather security-related device data and take protective actions (warnings, removals, blocks) without prior user consent for each instance. It …
Precise geolocation is among the most sensitive location data types; its collection is conditioned on user permissions, but its permissible use extends to distance-based features visible to others.
Biometric information is among the most sensitive categories of personal data; its processing for age verification means some users must submit it as a condition of confirming eligibility to use the …
Consent is established as the legal basis for non-essential tracking technologies for EEA/EU/UK users, meaning those technologies cannot lawfully be deployed without an affirmative user action.
User-uploaded content—including private messages and audio—is subject to active scanning and analysis by Grindr and third-party partners, not merely stored.
Collection is automatic and does not require any affirmative submission by the user—simply using the platform triggers collection of detailed behavioral and browsing data.
A wide range of ordinary user actions—including simply interacting with Grubhub—trigger the collection of personal identifiers.
Consent to Grubhub's full data practices—collection, storage, use, and disclosure—is obtained through the act of accessing or using the platform, rather than through a separate explicit opt-in.
This clause conditions Gusto's processing of sensitive personal information on obtaining prior opt-in consent, but only where applicable law requires it, meaning consent is not universally guaranteed.
Users are put on notice that health information—potentially carrying heightened legal protections depending on jurisdiction—may be collected as a condition of using the service.
The HIPAA designation, where it applies, triggers a specific legal framework governing how health information may be used and disclosed, offering users corresponding protections.
Users may be invited to disclose a range of sensitive demographic and identity attributes, creating a detailed personal profile that carries heightened privacy risk.
Health and wellness data, including mental and physical health status, is actively collected during use of the platform, creating a record of sensitive personal health information.
Customers bear the operational obligation to technically prevent unauthorized personal data from reaching Contentsquare, placing compliance responsibility on the customer.
This clause discloses that data capture is not limited to information the user intentionally submits, meaning unsubmitted drafts or partially typed entries may still be collected and retained by Heap.
The protection applies only to knowing collection, disclosure, or sale, meaning inadvertent collection without awareness of minority status is not explicitly prohibited by this clause.
Health data collection extends beyond direct disclosures to passive behavioral signals such as browsing and purchasing, broadening the scope of what Hims & Hers treats as health information.
Biometric information is among the most sensitive personal data categories; its collection and use by third-party service providers in addition to Hims & Hers directly expands the number of parties h…
Sexual orientation and sex life information are among the most sensitive personal data categories, and their explicit collection and analysis by a commercial platform carries significant privacy risk.
Face geometry data is among the most sensitive personal data types, and its collection through opt-in features means users should be aware that voluntary participation triggers biometric data collect…
The consent mechanism is triggered by the act of providing the data rather than by a separate affirmative consent step, which determines how Hinge grounds its legal basis for processing highly sensit…
Session replay captures granular behavioral data—keystrokes, mouse movements, page navigation—beyond standard analytics, creating a detailed reproduction of a user's session.
ALPR collection means Home Depot may capture and retain vehicle license plate data from individuals visiting its properties, linking physical presence to identifiable vehicle records.
The breadth of identifier categories—spanning physical, digital, governmental, and financial data—means Home Depot can build detailed profiles linking online and offline consumer identity.
Individuals' professional data may be collected and stored by HubSpot without any direct relationship with HubSpot, sourced from multiple independent channels.
HubSpot's designation as controller for this data means HubSpot bears legal responsibility for how that professional personal data is collected and processed before it is shared with customers.
Individuals may have Personal Data collected by HubSpot from sources they did not knowingly provide it to, including public social media profiles.
Identifying the Privacy Policy as the governing instrument for user data means users must consult that document to understand their data rights and Hulu's data obligations.
Use of any Service constitutes agreement to the full scope of data practices described in the Privacy Policy, without requiring any separate affirmative consent action.
Session replay technology and cookies can capture detailed behavioral data; the involvement of third parties means user data may flow outside Ideogram to other organizations.
Users who reside outside the United States have no opt-out: continued use of the Site or Service operates as consent to cross-border data transfer and U.S.-based processing.
Collection of demographic data is conditioned on both user consent and legal permissibility in the relevant market, meaning neither condition alone is sufficient.
Private or incognito browsing does not prevent Indeed from collecting site activity data, contrary to what users of those modes might assume.
Private browsing or incognito mode does not prevent Indeed from collecting site activity data, contrary to a common user assumption about those modes.
Opting in constitutes agreement to grant Indeed access to the full email inbox, not merely to specific messages, for the stated scanning purpose.
Two independent conditions must both be satisfied before Indeed collects demographic data: user consent and market-level legal permissibility.
Individuals who have never created an Indeed account may have their resume or profile data held by Indeed as a result of a purchase from a third party.
The absolute prohibition on storing full card numbers limits Indeed's exposure to payment card data and reduces the risk that a data breach would expose complete card information.
Users whose data is processed through Inflection AI's API or similar commercial offerings receive no protections under this Privacy Policy.
Session replay recording of keystrokes and interactions can capture sensitive input—such as search terms or form entries—creating a granular reproduction of a user's in-session behavior shared with t…
Prescription-related data—including birth date, prescription numbers, and refill counts—is sensitive health-adjacent information flowing from the pharmacy to Instacart without requiring a separate us…
Precise device location is among the most sensitive personal data types, enabling detailed tracking of a user's physical movements.
Collection of government ID data, including potentially a full card copy, represents a high-sensitivity data category that carries significant identity-theft and privacy risk.
Biometric data is uniquely sensitive and often irreplaceable; requiring prior notice and consent before collection gives individuals a meaningful opportunity to refuse before any collection occurs.
Data processed in the United States is subject to U.S. law rather than the user's home country's privacy laws, which may provide different or lesser protections.
Creators must submit sensitive government identification documents as a condition of accessing their earnings, which carries significant personal data and privacy implications.
Kick's non-involvement in age assurance data means that personal information submitted for that purpose is governed by K-ID's practices rather than Kick's, affecting which entity bears responsibility…
The data collected is extensive and behavioral, covering reading habits, content interactions, search activity, and device diagnostics, all transmitted to Amazon automatically through the software.
Klarna collects a broad range of sensitive personal and financial data specifically for fraud and AML purposes, which represents a significant scope of data collection tied to regulatory obligations.
This clause requires affirmative consent from individuals before their information may be collected through Klaviyo, directly limiting how users may acquire data via the platform.
This clause bars the full lifecycle of special category data handling — from collection through transmission — on Klaviyo's platform, covering the most sensitive personal data categories recognised u…
The qualifier 'knowingly' limits this protection to situations where Leonardo AI has actual knowledge that a user is a child, meaning inadvertent collection is not explicitly covered by this commitme…
Personal information embedded in user-uploaded content and its metadata is explicitly within Leonardo AI's data collection scope, meaning uploads may expose more personal data than users anticipate.
Lime collects sensitive financial account information from logistics providers.
Lime continuously collects location data from both the user's device and the vehicle itself during rides, creating a detailed record of user movements.
Lime collects a broad set of sensitive personal and financial identifiers as part of account creation, including government ID numbers and payment card details.
Access to certain Lime Services is conditional on providing sensitive identity document images, which Lime then holds.
This clause treats any use or access of the Services — however minimal — as legally sufficient to establish the user's consent to the full scope of data collection, use, and sharing practices describ…
LinkedIn collects identifying device data from people who have never interacted with its Services, meaning non-engagement does not prevent data collection for users outside the Designated Countries.
This requirement imposes a specific technical security obligation on advertisers whose linked sites collect sensitive data, making non-HTTPS collection a policy violation.
Cross-device linking enables LlamaIndex to build a more comprehensive profile of a user by combining data collected across different devices, expanding the scope of data associated with a single indi…
Recording of keystroke activity and detailed interaction behavior is highly granular surveillance of user activity, which may capture sensitive information entered by users on LlamaIndex's services.
Data collection by third-party ad partners occurs automatically upon visiting LlamaIndex's websites, meaning the reader does not need to take any affirmative action for this collection to occur.
Automatic collection via multiple technology types by both LlamaIndex and third parties means data is gathered without any active submission by the user and through a broad range of technical mechani…
The scope of collected Customer Content is broad, covering nearly any form of data or media a user actively submits, meaning substantive and potentially sensitive user-generated material is collected…
Personal or sensitive information shared in conversation Inputs is collected by Luma AI and may be reproduced in Outputs, which could be seen by other parties depending on how Outputs are used.
Precise location data is collected continuously, including during background app operation, for the full duration of a ride, representing persistent and granular tracking.
Phone call contents—not just metadata—may be recorded or monitored, though Lyft commits to prior notice before each such call.
Lyft collects sensitive financial identifiers that carry significant risk if exposed, including bank routing numbers and tax information.
The clause establishes that Lyft's data collection extends beyond what users actively submit, reaching device-level information and third-party sources, broadening the scope of data Lyft holds.
Location data can reveal sensitive details about a person's physical movements, routines, and frequented places.
Collection of off-platform activity means McDonald's gathers behavioral data about users beyond their direct interactions with McDonald's properties.
Data collection about users extends beyond Medium's own platform to other websites, and is performed by third parties over whom users have no direct relationship.
Biometric information is among the most sensitive categories of personal data; its collection by Mercury has significant implications for user privacy and data security.
This clause mandates a specific technical privacy safeguard — hashing — before any Contact Information leaves the advertiser's environment, reducing transmission of raw personal data to Meta.
This clause makes advertisers directly responsible for obtaining and being able to demonstrate lawful cookie consent in every applicable jurisdiction, including the EU, before Meta's tools collect da…
This prohibition places an affirmative duty on users not only for actual knowledge but also for information they reasonably should know relates to children under 13, expanding the scope of the restri…
The restriction extends beyond the named categories to any information deemed sensitive under applicable law, creating a dynamic prohibition that expands with evolving legal definitions.
Health information is sensitive personal data; requiring Meta's prior permission before it can be solicited through ads adds a gatekeeping layer that restricts how advertisers can collect it.
Private keys control access to cryptocurrency wallets; an explicit commitment not to collect them is a foundational security and custody assurance for users.
IP address processing is explicitly limited to temporary processing and only where required for specific Offerings, conditioning the scope of IP data handling on both necessity and user settings.
This clause simultaneously asserts a data retention function (remembering details) and a data protection commitment, making both the capability and the security posture explicit.
Content-level collection—as opposed to metadata—means Microsoft may hold the substance of private communications and personal files, representing one of the most expansive categories of personal data…
Location data—especially precise location—is among the most sensitive personal data categories, capable of revealing home address, daily routines, religious practice, medical visits, and associations.
Browsing history is among the most revealing categories of personal data, capable of exposing interests, beliefs, health concerns, and behaviors; its collection by Microsoft establishes a broad surve…
Information about Microsoft's personal data processing practices is located in a separate document — the Microsoft Privacy Statement — rather than in the Azure agreement itself.
Consent to data collection, use, and disclosure is embedded in acceptance of the Terms, meaning agreeing to use the Services simultaneously grants this data consent.
The scope of data collection is broad, encompassing not just typed prompts but voice-derived input, multimedia content, and documents, meaning substantial user-generated content may be collected.
This clause establishes that Midjourney collects a broad range of user-generated input, including multimodal content, which means significant amounts of potentially sensitive user material are subjec…
This establishes both a consent requirement before non-essential cookies are deployed and an ongoing user right to revoke that consent, creating a continuous user control mechanism.
This obligation sets a minimum security standard tied to Applicable Data Protection Law and requires ongoing maintenance, meaning Mistral AI cannot implement measures once and consider its obligation…
This requirement places the legal burden of establishing a valid basis for processing on the Customer, meaning Mistral AI's processing is contingent on Customer having fulfilled these obligations.
The restriction gives Customer enforceable control over where its data is geographically processed, which has direct implications for regulatory compliance and data sovereignty.
Use of the Service is treated as agreement to data collection and use practices described in the Privacy Policy, making continued use the mechanism of consent.
The listed categories are non-exhaustive, meaning Modal may require additional personally identifiable information beyond those named.
This clause identifies a specific, sensitive category of health data that MyFitnessPal may collect from connected devices, conditioned on user permission.
This clause discloses that MyFitnessPal collects sensitive health-adjacent data—including medication use—through voluntary user input, establishing the scope of data collected via these features.
Users of the ad-supported tier have a meaningfully larger set of personal data collected about them than users on other plans, including demographic and behavioral advertising data.
Netflix's interaction data collection includes audio recordings and transcripts of voice inputs, meaning users who engage with voice-related features have their spoken content captured and retained.
Netflix's data collection extends beyond behavioral observation to include derived conclusions about users and their households, compounding the scope of information Netflix holds about individuals.
Individuals who have never created a Nextdoor account and have not directly interacted with the platform may still have their personal information collected, based solely on the choices of registered…
Nextdoor may hold personal information about users sourced from third parties outside the platform, expanding the data profile Nextdoor can build on any individual.
Precise geolocation is among the most sensitive categories of personal data; access is conditioned on user permission, but once granted it may be used for address confirmation and broader service ope…
This establishes that even child users are subject to persistent identifier collection, with the scope expressly limited to internal operational purposes.
This establishes that Nintendo can capture audio and video communications between users, subject to consent and enforcement purposes—meaning user communications are not treated as fully private.
Noom collects data in categories widely recognized as sensitive, and does so not only when users volunteer the information but also through inference.
Noom both collects and actively analyzes sensitive health information, meaning this data is processed beyond mere storage.
Noom collects the combination of identifiers and authenticators that together enable account access, which is among the most sensitive category of personal data.
Message content can include sensitive personal disclosures; Noom's collection of this content means those communications are retained as personal data.
Email message content is among the most sensitive categories of personal data, and this clause establishes that Notion handles that content directly via the Gmail API.
Third parties — not just Notion — may collect user data through technologies placed on users' browsers, expanding the set of entities that have access to user information.
This establishes that OnlyFans may collect and share identifying personal data with third-party screening providers to conduct criminal background checks on U.S. users.
This establishes a clear demarcation of data custody, placing full control of Face Recognition Data with a third party rather than OnlyFans itself.
OpenAI's model development is fueled in part by publicly available internet data, meaning publicly posted information may be incorporated into its models.
Consent to data collection and use is established by the act of using the Site or Service, without requiring a separate affirmative consent step.
The biometric information designation under applicable laws typically triggers heightened legal protections and obligations; users are on notice that submissions may carry this legally significant cl…
OpenSea collects on-chain data linked to users without requiring any direct submission by the user, potentially associating public blockchain activity with user identities.
Oscar Health collects highly sensitive identifying information, including government-issued identifiers such as social security numbers, which carry significant identity-theft and privacy risk.
Consent is required not only for Oura's own use of user information but also for sharing with third parties for marketing purposes, which extends data exposure beyond Oura itself.
Consent is established as a hard prerequisite for sensitive personal data processing, meaning Oura may not process such data without it.
Biometric data is a sensitive category of Personal Information; collection is conditioned on the user's consent given within the user experience for specific account authentication purposes.
Biometric data is among the most sensitive categories of personal information; its collection at physical properties affects individuals who visit those locations.
This clause places affirmative legal compliance obligations on the Customer, not just on Perplexity AI, covering all privacy law requirements at the point of data provision.
Browsing history is among the most sensitive categories of behavioral data; its collection by Perplexity AI is consequential because it reveals users' online activity beyond the Perplexity platform i…
A representation and warranty creates an enforceable legal commitment; if any Personal Data was ever handled in violation of Privacy Laws, Customer is in breach of this warranty regardless of when th…
Browsing history is among the most sensitive categories of personal data, and this collection occurs at the browser level through a synced account, potentially covering activity across many websites.
Processing extends to both user inputs and AI-generated outputs, meaning a broad scope of interaction data is collected and handled by Perplexity AI.
Health data is among the most sensitive categories of personal information; this clause establishes that participation in health-related services triggers processing of that data.
This places the legal compliance burden for data subject consent and notice squarely on the Customer, meaning Pinecone's processing is only as lawful as the Customer's upstream consent practices.
Pinterest may combine data it receives from external advertisers and third-party services with your on-platform activity to target advertising, meaning your offsite behavior informs the ads you see.
This clause places individual consent and disclosure obligations squarely on advertisers at every data collection point tied to Pinterest ads, creating direct legal exposure for non-compliance.
The claim establishes that data collection is automatic, persistent over time, and shared across multiple parties—including advertising partners—expanding the scope of who holds combined user data.
Sensitive personal information collection is legally mandated for certain services, meaning users cannot opt out of this data collection if they wish to use those services.
Biometric data is among the most sensitive categories of personal information, and its collection by Public.com means users must provide such data as part of using the service.
Because the authorization is ongoing and recurring, Ramp's data collection through Integrations is not a one-time event but a continuous, standing permission.
Ramp collects highly sensitive government-issued identifiers and biographic data, which represents a significant category of Personal Information with serious privacy and security implications.
Users connecting third-party services to Ramp should be aware that Ramp may receive and process their Personal Information—including sensitive financial data—from those services.
When Ramp acts as a Controller, it determines the purposes and means of processing Personal Information, making this Privacy Policy the governing framework for those interactions.
The qualifier 'knowingly' limits the scope of this commitment, meaning inadvertent collection is not explicitly prohibited by this clause.
Users uploading training data should be aware that any content in that data, including potentially sensitive information, is collected by Replicate.
The scope of seller data collection is broad and includes government-level identity information such as valid identification and taxpayer address, which carries significant privacy implications.
The absence of a Protect Plan means no video is retained by Ring, limiting the user's ability to review past footage while preserving real-time viewing capability.
This defines the specific triggers under which Ring creates and retains video recordings, directly determining when footage of users and others is captured and stored.
Users' personal information, including identifiers that can be linked to them, is collected and analyzed by third parties—not just Ring—through automated means on Ring's platforms.
Riot Games' monitoring authority extends to the user's own device — not only its servers — and the purposes for monitoring are broadly described as a wide variety, leaving their scope undefined.
Background software on a user's device can trigger automated account-level consequences, including permanent suspension, without direct human review at the point of decision.
The breadth of sensitive health data Ro collects is consequential because such information is among the most personal and legally protected categories of personal data.
Sex life and sexual orientation are among the most sensitive categories of personal data, and their collection by a healthcare company has significant privacy implications.
Conditioning access to a specific product feature on enabling precise geolocation means users may have to share their exact physical location to use that feature.
This provision authorizes Robinhood to lend securities you own to third parties, which removes SIPC insurance protection on those securities while they are on loan and introduces counterparty risk as…
The identity data collected includes highly sensitive categories—social security numbers, biometric-capable photographs, and marital status—that carry significant privacy and identity-theft risk if e…
Chatbot conversations may contain sensitive personal, financial, or behavioral information; collection of this data creates a record that can be used for purposes beyond the immediate interaction.
Facial geometry data is biometric data; its extraction directly from user-submitted images creates a sensitive biometric record tied to the user's identity and face.
The collection of biometric data, including facial geometry, through consumer-facing features triggers state biometric privacy statutes including Illinois BIPA, Texas CUBI, and Washington's biometric…
Persistent identifiers collected at sign-up enable Roblox to track users across sessions for operational purposes, forming a foundational layer of ongoing data collection.
Persistent identifiers are collected at account creation and tied to stated internal operational purposes, meaning this data collection is ongoing and foundational to account use.
Use of audio features triggers Roblox's right to retain and process voice recordings, including for product training purposes beyond the immediate communication function.
Audio captured through a user's device is actively monitored and retained by Roblox, not merely transmitted, and is used for purposes beyond enabling the feature itself, including training.
This collection occurs automatically without affirmative user action, and includes persistent identifiers that can be used to track individuals across sessions or devices.
Users who rely on their browser's DNT setting as a privacy control will find that setting has no effect on Rumble's data collection practices.
The collected data includes highly sensitive categories—login credentials, photographs, and biographical information—that together can comprehensively identify and profile an individual.
Biometric data such as voice data and face scans is among the most sensitive personal data a service can collect, and its collection is explicitly confirmed here.
Salesforce acquires Personal Data about individuals from outside sources—not just from the individuals themselves—and uses it specifically for targeted advertising.
The commitment to the highest security and privacy practices sets a stated standard of care for how Salesforce Einstein approaches product safety and harm mitigation.
Data collection extends beyond Samsung's own platforms to third-party sites and apps, meaning users can be tracked even when not directly using Samsung services.
Collecting multiple unique device identifiers allows Samsung to persistently identify and track a device across contexts, even if some identifiers are reset.
Precise geolocation requires a separate consent step, but approximate location data via Wi-Fi and cell towers is transmitted without that additional consent when using certain Services.
Voice recordings are collected in two distinct contexts — active use of a voice feature and Customer Service interactions — meaning audio data may be retained from routine support contacts.
The warranty is ongoing, meaning the customer is continuously on the hook for ensuring legal bases for data processing exist throughout the term of the agreement, not just at signing.
The breadth of communications metadata collected—including engagement signals like opens, clicks, and unsubscribes—means Segment captures detailed behavioral information from electronic communication…
Connecting a third-party inbox grants Shopify access to email data, which is used to surface and display order information within the Shop app.
Shopify collects the actual content of email messages, not merely metadata, from connected inboxes and transferred emails.
Audio and video from inside a user's environment are actively collected by SimpliSafe, making this among the most privacy-sensitive categories of data the company gathers.
The clause establishes registration and membership as trigger points for Personal Data collection, defining when Skillshare may initiate that request.
Financial and identity-linked data is collected at the point of any membership, free trial, or purchase transaction, expanding the scope of personal data Skillshare holds.
Collection is automatic and requires no affirmative action by the user, meaning a broad set of technical identifiers is gathered simply by using the Services.
User activity may be recorded in video form and processed by external third-party providers, meaning detailed behavioral data is shared outside of Skillshare.
A categorical exclusion of Sensitive Personal Data collection limits the risk of exposure of the most legally protected categories of personal information.
Snapchat's ad-targeting inputs are not limited to data users provide directly; external parties also supply data that shapes what ads users see.
Advertisers are prohibited from using ads as a mechanism to gather sensitive or special category data, with the full scope of prohibited data defined by reference to external Rules.
Unlike the initial soft pull, proceeding with an application triggers a hard inquiry that may have a measurable negative effect on the reader's credit.
The use of tracking technologies means SoFi collects behavioral data beyond what users actively submit, across multiple stated purposes including marketing.
This clause puts users on notice that information collection, use, and sharing are triggered by any product or service use, with the scope of those practices governed by external policy documents.
The protection applies only where Sony PlayStation has actual knowledge of the user's age, meaning it does not extend to cases where the user's age is unknown to Sony PlayStation.
Automatic collection triggered each time a device or app is used means data may be gathered on an ongoing, session-by-session basis across all supported device types.
The qualifier 'intentionally' means that inadvertent collection of sensitive data is not excluded by this commitment, which limits the absolute scope of the protection.
The collection of prompt titles, prompt categories, and query-derived metadata means that metadata about a user's AI interactions is captured, even if the full content of inputs is not retained.
Customers meeting all three conditions—enterprise license, own LLM API key, and self-hosted deployment—receive a stronger data isolation guarantee because Sourcegraph Cody has no access to their inte…
The Data Processing Agreement is triggered by the act of processing Customer Personal Data on the customer's behalf, establishing a specific contractual framework for that processing activity.
Spotify collects biometric and identity document data—among the most sensitive categories of personal data—as part of age verification, making the scope and handling of such data highly consequential.
Precise geolocation data is a sensitive category of information that can reveal detailed patterns of movement and location; its collection, even if conditional, carries significant privacy implicatio…
Square's data collection is not limited to what users actively submit; it also includes passive collection during Service use and acquisition from third-party sources, broadening the scope of informa…
Square collects biometric data extracted from facial scans, which is among the most sensitive categories of personal information and is subject to heightened legal protections in many jurisdictions.
It draws a clear boundary on Squarespace's direct involvement with biometric data, placing that data exclusively in the vendor's hands.
Squarespace places the entire compliance burden for data protection, security, and privacy law—including major EU regulations—on the user, meaning users bear legal risk for any regulatory violations.
It establishes that biometric verification cannot proceed without affirmative user consent, creating a meaningful gate before sensitive biometric data is used.
This prohibition directly restricts mass collection of facial data, which is a primary mechanism enabling pervasive surveillance and identification of individuals without their knowledge.
Precise GPS coordinates reveal granular physical movements and location history, making this among the most sensitive categories of data Starbucks may collect.
Health information is among the most sensitive categories of personal data; its collection, even when user-initiated, creates records that could be used or disclosed in ways that affect the user.
The combination of government identifiers, financial account numbers, and login credentials represents a high-sensitivity data set whose exposure could enable identity theft or unauthorized account a…
The consent covers 'any other use,' meaning there is no defined limit on how recorded communications and data may be used beyond the examples listed.
Consent to recording and retention is automatic upon Platform use, covering all communications and data exchanged with Stash or anyone acting on its behalf.
Biometric data is among the most sensitive categories of personal information because it is immutable — a person cannot change their fingerprints or facial geometry if the data is compromised.
Nonpublic personal information is a legally defined category with specific federal protections; its collection by Stash places this data within a regulatory framework governing financial institutions.
Participation in these programs, combined with granting the required permissions, results in State Farm collecting and using precise location data, which is a sensitive category of personal informati…
The claim establishes both a specific collection purpose and a retention limit tied directly to that purpose, meaning the data may not be held beyond what is minimally necessary.
Routing payment data through a third party and not retaining it on StockX's servers limits StockX's direct exposure but also means a third party holds sensitive financial data.
The scope of identity data requested is extensive and sensitive, and it is shared directly with a third-party provider rather than retained solely by StockX.
A consent requirement before biometric data collection is a meaningful procedural protection, giving users a formal opportunity to refuse.
Biometric data is among the most sensitive personal data a company can collect; knowing it flows to a named third-party vendor clarifies who handles it.
Biometric data carries heightened legal protections in many jurisdictions; disclosure that the identity verification process may collect it signals a significant data collection practice.
Access to core functionality is conditioned on granting precise location permissions, meaning users who decline cannot use GPS tracking, routes, or segments.
Health data is a sensitive category of personal information; its collection, even when user-initiated, has implications for how that data may subsequently be used or shared.
This identifies the specific legal entity and jurisdiction accountable for Personal Data processed in regions outside the Americas, which determines which data protection regime governs and which ent…
Data entry into a checkout form triggers potential data collection by Stripe regardless of whether the transaction is completed, meaning partial form completion is not private.
The clause establishes that customer Personal Data falls within the definition of User Data, meaning all provisions governing User Data—including processing instructions and consent obligations—apply…
The clause establishes that data collection and processing is triggered broadly by any interaction or subscription, covering both free and paid services.
Voice recordings are a category of biometric data, and Suno's processing of them to create voice models means your voice may become the basis for generated audio content.
Any content a user records or uploads — including sensitive media like voice recordings — becomes data that Suno collects, which may include embedded metadata or associated information beyond the fil…
Everything a user submits as User Content, including AI interactions, is formally collected and stored by Supabase as part of normal Service operation.
Both sides of every AI tool interaction — the user's prompt and the AI's response — are collected by Supabase, meaning the full content of those exchanges is retained.
The clause establishes that Synthesia actively solicits biometric-capable media from users as a required step in Avatar creation.
T-Mobile collects highly sensitive categories of personal data whose exposure or misuse could enable identity theft or financial fraud.
T-Mobile's data collection extends well beyond what users directly provide, incorporating data from commercial resellers and sensitive institutional sources.
TaskRabbit collects full payment card credentials, including the security code, which are among the most sensitive categories of financial personal data.
Criminal history data is among the most sensitive categories of personal information, and its collection by TaskRabbit has significant implications for how that data may be used or shared.
TaskRabbit collects government-issued identification numbers and document images, which are among the most sensitive categories of personal data and commonly targeted in identity theft.
Metadata collection goes beyond message content and captures behavioral and technical identifiers that can be used to profile or identify users.
Cloud chat content—including private messages and media—resides on Telegram's servers, making it accessible to Telegram and subject to any server-side processing or legal demands.
A mobile number—a persistent, real-world identifier—is a mandatory condition of account creation, meaning anonymous account creation is not possible.
The scope of collection explicitly includes the substantive content of AI prompts, meaning the actual text and queries users enter — not just metadata — may be treated as personal information Thomson…
Biometric data is among the most sensitive personal data because it is tied to a person's physical identity and is typically immutable — its collection by Thomson Reuters carries significant privacy …
Personal information held by Thomson Reuters about a user may originate from data brokers and advertising partners — sources the user may never have directly interacted with or consented to share dat…
Deemed consent triggered by interaction — rather than explicit opt-in — means Chinese residents may not receive a separate, affirmative consent request before Thomson Reuters collects and processes t…
Sign-up creates an immediate and explicit data collection obligation covering personal identifiers and behavioral configuration data.
The collection scope encompasses not just what users post but also passive behaviors such as viewing, interaction patterns, and associated metadata, enabling detailed behavioral profiling.
Threads collects identifying information not only about the user but also about the third-party platform they use, including that platform's IP address.
Ticketmaster collects persistent and location-based data through multiple technical means, enabling tracking of user behavior, movement, and browsing origin across sessions.
Accessibility-related requests are recorded as data points, and users in certain markets may be required to provide additional information to validate a health or disability status.
This clause establishes a legal basis for collecting biometric and other sensitive data in two distinct circumstances, including where law merely permits—not mandates—such collection.
Users interacting with AI interfaces may share sensitive or personally revealing information through prompts and files, all of which TikTok explicitly collects, including the generated outputs.
The restriction to limited data collection for children under 13 reflects heightened legal protections for minors; the clause confirms TikTok operates a distinct data environment for this age group.
Biometric identifiers are among the most sensitive categories of personal data; their collection from user content means users may be sharing biometric data without actively providing it.
TikTok's data collection is not limited to on-platform activity; third-party partners supply TikTok with behavioral data from across the web, extending TikTok's profile of users beyond their TikTok a…
Collection of face and body-part location data from user content goes beyond basic metadata and may constitute or approach biometric data collection, raising significant privacy implications.
Content that a user decides not to share publicly may still be collected by TikTok, meaning discarded or unpublished drafts are not necessarily private from TikTok.
The commitment to process sensitive personal information only in accordance with applicable law ties TikTok's obligations to the varying and evolving requirements of state privacy statutes rather tha…
TikTok Ads builds user profiles using behavioral data collected outside its own platform, meaning a user's TikTok-facing data profile extends beyond what they do on TikTok itself.
This collection encompasses biometric-adjacent data—specifically the existence and location of facial and body features—extracted from content users post, raising significant privacy implications bey…
Content is collected before a user makes any publishing decision, meaning TikTok Ads obtains data from content the user may have chosen to discard, fundamentally undermining the assumption that only …
TikTok Ads constructs inferred demographic and interest profiles on users—going beyond data users explicitly provide—to drive content personalisation.
This behavioral tracking creates a granular record of a user's attention and engagement patterns across all content types on the platform, including advertisements specifically.
Keystroke pattern collection is a behavioural biometric that can be used to identify or fingerprint a user, going beyond passive device metadata.
Advertisers are bound by TikTok Ads' data collection standards, which constrains how they may gather data in connection with their advertising activity.
Face geometry data carries heightened legal protections in jurisdictions that classify it as biometric data, and participation in these features triggers that collection.
The act of providing sensitive data is itself treated as consent, meaning no separate consent mechanism is required beyond the user's voluntary submission.
Users' sensitive financial data is not retained by Together AI, limiting exposure in the event of a data breach or unauthorized access.
This is an ongoing warranty obligation, meaning a failure to maintain adequate consents or notices at any point during the Agreement constitutes a breach of warranty.
Twilio collects the substantive content of communications, not merely metadata, which represents a high level of data sensitivity.
This establishes Twilio's role as a data controller actively processing personal data across a broad range of operational activities, setting the scope of its data practices.
This establishes that data collection is automatic and passive, occurring without any affirmative action beyond accessing the service or opening an email.
This links data collection to continued service access, meaning users who exercise data deletion rights risk losing the ability to use the Twitch Services.
Biometric data, a sensitive category of personal information, is generated directly by Uber's own technology for identity and fraud control purposes.
Location data is collected continuously as long as the app is open, including when the user is not actively looking at or interacting with the app.
Uber gathers a wide range of sensitive personal and legal background data at onboarding, including criminal history where legally permitted.
Biometric data — a sensitive category of personal information — is collected through an automated facial verification process tied to account security and fraud prevention.
Users of AV Services have no opt-out from recording as a condition of using the service; consent is given automatically by use.
Precise location data is collected for the full duration of every ride or delivery, creating a continuous record of the user's movements during each trip.
Video recordings of users inside a vehicle are collected as a mandatory consequence of taking an autonomous vehicle ride, with no opt-out indicated.
Connecting a wallet triggers automatic data collection and logging by Uniswap, with the address used for both analytics and illicit-activity screening.
The absence of user accounts and personal data collection significantly limits the personal information Uniswap holds about users.
This clause ties consent to the act of using the Online Services, meaning a user who accesses the services is deemed to have consented to all data practices described in the Privacy Policy without an…
Location data is among the most sensitive categories of personal information; this clause permits UnitedHealthcare to obtain it from a user's device through the mobile application.
Users may not realize that using a third-party app built with Unity results in Unity directly handling their Personal Information under this Policy.
Users are contractually barred from submitting Sensitive Personal Information through any Offering, placing the compliance burden on the user rather than on Unity's data handling.
The collection from children's accounts is expressly limited in scope and conditioned on compliance with applicable youth privacy law, establishing a legal floor for data minimization.
Venmo actively collects location data precise enough to identify users' whereabouts, and the stated purpose is limited to fraud and risk—establishing the scope of that collection.
Face scans are biometric identifiers; their collection is conditioned on consent but, once given, Venmo stores and uses this sensitive biometric data for authentication and fraud purposes.
Venmo collects highly sensitive financial credentials, including online banking login information, which if exposed could enable unauthorized access to users' bank accounts.
The claim establishes that the content users actively produce while using AI features—including prompts and generated outputs—is collected as personal information.
This clause discloses that Verizon-installed system software—not a user-downloaded app—may collect location data and a list of apps from the device, raising device-level surveillance concerns.
The clause establishes that Verizon's data collection extends beyond what users directly provide, incorporating sensitive financial and demographic profiles sourced from third-party companies.
This clause reveals that Verizon-installed software can remain active and non-visible on a deactivated device whenever it connects to Wi-Fi, meaning users may not be aware these apps are running.
The clause establishes that Verizon collects device location data, which is among the most sensitive categories of personal information, as part of its network and device monitoring.
The clause reveals that Verizon's data collection extends to highly sensitive categories—including biometric identifiers and government-issued identification numbers—that carry elevated privacy and i…
It establishes that Visa has a dedicated U.S. policy document addressing Social Security Numbers and Sensitive Personal Information, indicating these categories receive distinct treatment.
These categories carry heightened legal sensitivity under California law, and their collection by Walgreens is explicitly acknowledged.
Facial scan data is among the most sensitive categories of biometric information; its collection by Walgreens is explicitly disclosed.
Precise location data reveals detailed information about your physical movements; its collection through multiple simultaneous technologies significantly broadens the scope of location tracking.
Automatic collection of real-time location, MAC address, and IP address represents collection of precise identifying and locational data without requiring any affirmative action by the user.
Consent is the legal basis Walgreens relies upon, and it is triggered broadly by any interaction across any channel — including in-store — rather than requiring an affirmative opt-in.
This clause establishes that continuous microphone access and listening occur as a baseline condition whenever the Walmart app is open, not only when a user actively invokes the assistant.
Geolocation data collection shifts from imprecise to precise based on user consent, meaning the granularity of location tracking is directly tied to whether consent is given.
Biometric data is uniquely sensitive because it is tied to physical identity and cannot be changed if compromised, making its collection a significant privacy consideration.
This clause establishes the breadth of personal information categories Walmart may collect, spanning highly sensitive data types such as biometrics and precise geolocation alongside standard identifi…
Biometric data collection for virtual try-on is gated on affirmative consent, meaning Walmart may not proceed without the user's explicit agreement.
Visitors to Walmart properties may have their vehicle and associated personal information automatically captured without any active interaction or awareness.
Consumers visiting Walmart properties may have their vehicle license plate data automatically collected without active notice, constituting passive surveillance tied to personal information.
Continuous microphone access is active for the entire duration the app is open, not only when a user deliberately activates a voice feature.
Users may reasonably believe Invisible mode provides privacy from Waze as well as from other users; the clause clarifies that Waze's own data collection is unaffected by that mode.
Data collection is not limited to active app use; Waze may gather location data as background activity, extending its reach beyond sessions the user consciously initiates.
The act of access or use alone is treated as full acknowledgment and agreement to all data practices described in the Policy, without requiring any separate affirmative consent step.
Compliance with anti-money laundering law creates a legally grounded basis for collecting sensitive identity information, which users may not be able to decline if they wish to open an account.
The clause discloses that physical visits to Weights & Biases facilities may result in collection of biometric data and video surveillance, which are among the most sensitive categories of personal d…
Transmitting Sensitive Data without prior written consent would breach a Customer warranty, potentially exposing the reader to liability for any resulting harm.
The clause establishes that a wide range of user-generated content — including communications and tool inputs and outputs — is actively collected, meaning conversational and operational data is withi…
The inclusion of scanned identification documents indicates Wix may collect sensitive government-issued identity data, which carries heightened privacy risk.
Personal information voluntarily embedded in inputs is collected by Writer and may reappear in generated outputs, creating potential exposure of that information.
It establishes two distinct technical protections: encryption during storage and transmission, and isolation at the infrastructure level.
The act of submitting personal information constitutes consent to a broad set of data-handling activities, including cross-border transfer, binding Canadian users to those practices from the moment o…
Wyze's AI development may be fueled by personal data acquired through commercial purchase from third parties, meaning individuals' data may reach Wyze without any direct relationship between those in…
Facial Data collection is automatic and extends to all individuals appearing in the camera's viewing area, not only the account holder, meaning third parties who have not interacted with Wyze are sub…
Wyze explicitly acknowledges that the Facial Data it creates could be considered biometric information, which may trigger heightened legal protections under applicable biometric privacy laws.
The clause confirms that children's personal information is collected in child-directed service areas, with the scope bounded by applicable law rather than a narrower internal standard.
Granting precise geolocation access extends the use of that data beyond service delivery to include advertising, which may not be apparent to users who enable location for navigation or local search …
Location collection is not limited to active, foreground use of the app — background operation of the app can also trigger ongoing location data collection and storage.
Certain categories of directly identifying personal information are not collected from children by the app, limiting direct identification data held by YouTube Kids.
Consent is triggered by the act of using the Website and extends to future versions of the Privacy Notice, meaning the scope of consent may expand over time without requiring a separate consent actio…
The collection of browsing history, search history, and device data represents a broad category of behavioral and technical information gathered during routine Website use.
Collection of both real-world identifiers (name, email) and technical identifiers (IP address, unique online identifiers) allows linkage of a user's identity to their online activity.
Zendesk collects a broad set of identifiers that can individually or collectively identify a person, including digital identifiers used in advertising.
Zendesk's tracking extends beyond a single session or site, enabling persistent cross-device and cross-site behavioral profiling.
Zendesk's data collection includes a category of sensitive personal data—such as health and demographic information—that carries heightened legal protections in many jurisdictions.
The customer bears the legal responsibility for ensuring consent and notice obligations are met; if the customer fails to do so, it may expose both the customer and Zendesk to regulatory or legal ris…
The scope of the Privacy Notice's protections and rights is limited; individuals whose data Zendesk processes as a Processor on behalf of Subscribers are not covered by this Notice.
Zendesk's collection extends beyond basic identifiers to detailed behavioral and device-level data, covering how individuals interact with Zendesk across its products, services, and communications.
Phone calls and chat interactions may be recorded and retained as personal data, meaning conversational content — not just form-submitted data — is collected by Zillow.
Precise geolocation such as GPS coordinates is significantly more sensitive than general location data and is only collected subject to dual conditions: device-level permission and user choice to sha…
Biometric data is among the most sensitive categories of personal data; its processing for multiple purposes by eBay and potentially for third-party compliance frameworks carries significant privacy …
The scope of data collected from sellers is substantially broader and more sensitive than that collected from buyers, encompassing financial and government identity documents.
The clause establishes a wide set of collection triggers, meaning nearly any interaction with eBay results in personal data collection.
No message sent through eBay's messaging platforms is private from eBay's automated scanning and analysis, including communications between individual users.
Collection is automatic and requires no affirmative act by the user, meaning interaction itself triggers data collection.
This clause establishes that multiple common user actions—including simply contacting Adobe for support—trigger the collection of identifying information.
Automated tracking technologies can collect behavioral and session data from users, which has implications for how much information Afterpay gathers beyond what users actively provide.
The scope limitation means information Afterpay collects about you through other means or contexts is not governed by this Privacy Notice.
American Airlines may passively collect a detailed technical profile — including precise geolocation and mobile advertising identifiers — simply from your use of its Interactive Services, without any…
Amplitude's use of cookies and web beacons enables passive, automatic collection of behavioral and device data without requiring active user input.
Amplitude may hold Personal Data about users that was not supplied directly by those users, meaning users may be unaware of the full scope of data Amplitude possesses.
Automatic collection of device and network identifiers means Anyscale gathers data about you passively, without any active submission on your part.
The clause establishes that Apple App Store collects a broad range of behavioral and technical data about users, spanning both intentional activity and background device data.
The clause establishes that aggregated trend collection—including about processed content—is conditional on the user's opt-in and is subject to privacy-preserving techniques.
The clause establishes that Apple Intelligence accesses personal on-device data spanning multiple apps, defining the breadth of local data use.
The clause defines and limits the categories of metadata Apple collects about PCC requests, bounding the scope of data collection.
The clause establishes a firm exclusion of request and result content from the metadata Apple collects, defining the boundary of collection.
Third parties, including advertising and analytics partners, are explicitly named as co-deployers of tracking technologies, meaning your activity may be tracked by parties beyond Atlassian itself.
Collection extends beyond core product activity to include interactions with connected third-party services, broadening the scope of data Atlassian gathers about you.
If you miss an electronic notification of a terms change, you may unknowingly accept new terms that reduce your rights or expand the bank's authority over your account.
Best Buy's data collection is not limited to what consumers directly provide; it extends to information sourced from external data brokers and third parties.
Users may have information collected about them from sources they never directly provided to Canva, expanding the scope of data Canva holds.
Personal Data about you can reach Cerebras even if you have never directly interacted with Cerebras, expanding the scope of data Cerebras may hold.
Personal information is gathered about you from sources beyond your direct interactions with Chime, meaning data you did not provide to Chime directly may still be held and used.
Users are subject to tracking not only by ClickUp but also by third-party advertising and analytics partners, meaning data collection extends beyond ClickUp itself.
Users of Cloudflare's Websites are subject to cookie-based and other tracking data collection, including for marketing purposes.
Session-replay recording means Coursera can reconstruct a detailed visual record of how individual users navigate and interact with its platform.
Users may not be aware that their spoken audio is captured and converted into a textual record that Coursera retains.
Codebase indexing is an opt-in action that results in code being transmitted to Cursor's servers, which affects where the user's code resides.
Automated collection of internet and device activity data occurs without requiring any active submission from the user, meaning data is gathered simply by visiting the Sites.
Users of Datadog Products should be aware that personal information embedded in technical data streams such as logs, traces, and metrics is actively collected by Datadog.
Data entered in an incomplete transaction is captured, meaning users who abandon a booking do not automatically prevent Delta Airlines from retaining what they entered.
Discord's profile of a user may be enriched by data gathered from outside sources beyond what the user directly provides, expanding the scope of information Discord holds.
This collection extends beyond account registration data to encompass behavioral and device-level information, broadening the scope of personal data DocuSign holds about users.
Full disclosure of Duo Security's data processing practices is located in a separate document, meaning the Terms of Service alone do not contain the complete picture.
This establishes the specific categories of personal data EA collects at account creation, informing users of exactly what identifiable information enters EA's systems.
This establishes that voluntary submission of information to the Services triggers Personal Data collection for every category of user.
Data collection is triggered automatically across multiple touchpoints—Services, advertisements, and emails—without requiring any affirmative action beyond mere interaction.
While full payment card data is not held by Figma, associated payment metadata is retained, which has its own privacy implications.
While raw payment data is not held by Figma, associated payment metadata may still be collected and stored.
IP-address-based location data can reveal a user's approximate geographic location, which is a category of personal data with privacy implications.
Location data is among the most sensitive categories of personal data; its collection, even for feature support, means Garmin holds information about where users are.
Device synchronisation automatically transmits technical and network data to Garmin, which may occur without the user actively choosing to share that specific data.
Users' credentials, including passwords, are retained by Garmin as part of account operation, making the security of that stored data consequential.
It establishes that behavioral interaction data is collected under pseudonymous identifiers, meaning users are not identified by name but their interaction patterns are still recorded as a defined da…
It establishes that GitHub actively collects user-generated feedback signals, including voluntary and support-context communications, as a named data category.
It establishes that Suggestions are a defined data or output category derived directly from user prompts, which is relevant to understanding how user input is processed and what is returned.
Collection is automatic and involves third parties, meaning data flows beyond Glean itself without any active submission by the user.
The scope of collection is broad, encompassing identifiers that can be used to track individual users across sessions and devices.
This provision establishes that continued use of Google Play after the 30-day notice period constitutes acceptance of updated terms, and that new terms apply retroactively to previously purchased Con…
Continuing to use Google Play after a terms change counts as acceptance, meaning new terms apply retroactively to all previously purchased content, not just future purchases.
This clause means Google retains the ability to modify software on your device without your explicit consent in the moment, overriding user-level settings in cases Google determines are security-crit…
Combining first-party data with third-party sources can significantly expand the profile Greenhouse holds on an individual beyond what the user directly disclosed.
Any form submission on Greenhouse's site results in the user providing personal data to Greenhouse, regardless of the form's purpose.
California residents applying for jobs at Greenhouse are subject to specific personal information collection and use practices described in this notice.
Users generate a detailed behavioral and technical profile simply by using the Services, without any active submission of information.
Conversations with customer service representatives may be retained and used internally, meaning the content of support interactions is not ephemeral.
Harvey AI collects granular behavioral and identity data about how users engage with the Services, which can reveal patterns of professional activity and research behavior.
Instacart's collection of granular browsing and cart activity creates a detailed behavioral record of users' shopping habits and interests.
Users' detailed on-screen behavior—including clicks, scrolls, and form entries—may be captured and reviewed by Intuit or its named third-party vendors, raising questions about what sensitive data is …
Users may not be aware that Klarna is gathering personal and financial information about them from sources beyond their direct interactions with Klarna.
Pixel tracking silently captures behavioral engagement data each time a user interacts with an email, without requiring any affirmative action beyond opening the message.
LangChain can build or enrich a profile of you using data sourced entirely outside your direct interaction with LangChain, for marketing purposes.
Location data collection from multiple sources, including passive inference from IP addresses and third-party partners, means location information may be gathered even without a user's active input.
Calendar data includes sensitive details about who you meet, when, and where; LinkedIn uses this data not only to benefit you but also to generate suggestions for others.
Tracking occurs not only on LinkedIn's own platform but also off-platform and across multiple devices, expanding the scope of data collection beyond what users may expect.
Loom's automatic collection of granular behavioral data means detailed records of in-service activity are generated without any affirmative step by the user.
Collection happens automatically without any affirmative act by the user beyond accessing the service, meaning users may not be aware of the scope of data being gathered.
The Privacy Policy is the primary document governing how Max handles user information, making it the central reference for understanding Max's data practices.
Data combination allows McDonald's to build a more comprehensive profile of a user than any single source alone would permit.
This clause defines the scope of personal data Medium collects from direct user input, which encompasses a wide range of identifying and substantive information.
This establishes that Medium actively deploys tracking technologies beyond simple form submissions, meaning data collection occurs through passive browsing activity.
Users' raw payment card data is not held by Midjourney, which limits exposure of that data in the event of a breach or unauthorized access.
This clause establishes a hard prior-consent requirement for non-essential cookies and a continuous right to withdraw, giving users ongoing control over this category of data collection.
It establishes a specific data collection limitation tied to the use of a Mojang account.
The scope of logging is broad, covering nearly all in-product activity, meaning Miro holds a detailed behavioral record of each user's session.
The reference to a named data processing addendum signals that commercial customers are subject to specific data-processing terms, though those terms are not stated here.
Collection occurs on every visit without requiring any affirmative action from the user beyond visiting the Service.
This clause defines the stated purposes for which telemetry data is collected, establishing the boundaries of NVIDIA NIM's declared data use.
Collection occurs passively upon visiting the Sites, meaning visitors may not be aware that device-level identifiers and IP addresses are being gathered, potentially by third parties.
Nextdoor conditions account creation on the disclosure of personally identifying information, including a physical address, which is more sensitive than many services require.
This establishes that Nintendo captures detailed behavioural and social data generated through normal use of its services.
The collection is automatic and covers multiple persistent and semi-persistent identifiers that can be used to track users across sessions and devices.
Okta's use of targeting and advertising cookies means user activity is being used for commercial marketing purposes, not solely for service functionality.
The terms authorize OpenAI to modify the agreement unilaterally, with continued use treated as acceptance, which means users should monitor for updates, particularly regarding data use and arbitratio…
Collection is automatic and occurs upon any interaction with the Service, meaning users do not need to actively submit information for OpenSea to obtain it.
The automatic and passive nature of this collection means visitors do not need to take any affirmative action for Palantir to gather a wide set of identifying and behavioral data.
The clause does not itself disclose data handling practices; it relocates that information to a separate document, meaning the reader must consult an external policy to understand Paramount+'s actual…
The clause does not itself describe data handling practices; the operative details are located in a separate document that users must consult independently.
Creating a PayPal account is not a prerequisite for PayPal to collect a person's Personal Information; data collection applies to any use of covered services.
Contact information collected at account creation is linked to identity verification, establishing a direct tie between the user's identity and their account data.
IP address collection for personalization means a network identifier linked to a user's approximate location is used to shape bot responses.
Sensitive financial and personal data is handled by a third-party billing provider, not solely by Poe, which affects where that data resides and who controls it.
Interacting with ads on Poe triggers collection of device- and identity-linked data points that can be used for ad measurement purposes.
This collection is automatic and requires no affirmative action from the user, meaning data is gathered on every online access regardless of user awareness or consent.
Collection is automatic and continuous across all interactions with the Sites, meaning users cannot opt out of this data collection simply by limiting what they voluntarily submit.
This provision defines the scope of data collection activities by specifying the digital touchpoints where personal data is gathered. It establishes the institutional basis for data collection across…
The scope of the commitment is bounded by statutory definitions; only categories that qualify as sensitive personal information under those specific laws are excluded from collection.
Data collection procedures are operationally necessary for margin account management, including monitoring leverage positions, assessing creditworthiness, and meeting regulatory reporting obligations…
This provision authorizes use of securities held in margin accounts for third-party lending purposes, including short selling, which means customers' holdings may be used in ways that could affect ma…
This clause means the terms governing your Robinhood account can be updated without requiring your explicit re-consent, and that using the platform after a notice is issued generally binds you to the…
Automatic logging by multiple parties means data collection occurs without any affirmative action by the user, and the collection spans identity, device characteristics, and behavioral history.
Collection is automatic and device-level, meaning personal information may be gathered without active input from the user.
Scale AI's reservation of this right means no transmission through the Site can be treated as private or unmonitored.
The category of data collected includes government-issued identifiers such as national ID numbers and driver's license numbers, which are sensitive credentials beyond standard contact information.
Body measurement data is a sensitive personal category; its collection by a retailer goes beyond standard purchase or contact information and enables detailed physical profiling.
Customers contacting support have no option to communicate without being recorded; the recording is retained beyond the interaction.
Enabling a third-party integration creates a data-sharing pathway from the third party to Slack that users may not anticipate.
The explicit no-impact guarantee distinguishes the rate-check inquiry from a hard pull, setting a firm limit on the credit consequence of exploring SoFi's rates.
Automatic logging through multiple tracking technologies means user activity may be captured across web, email, and advertising contexts without any affirmative action by the user.
This collection occurs automatically without any affirmative action by the user, meaning technical metadata is gathered simply by accessing the Services.
This collection is triggered by voluntary user action and is scoped to expressions of interest in Stability AI or its offerings, meaning it is not limited to formal sign-up or purchase actions.
The breadth of identifier categories collected — including address book contacts and IP address — means Starbucks may hold data that can identify not only the user but potentially their contacts.
Suno's automatic collection of this data means users have no option to opt out of this logging while using the service, and the data collected can identify or locate a user.
The clause identifies the specific categories of personal data Tabnine collects from users, establishing the scope of personally identifiable information the company holds.
Extending the Policy to offline collection confirms that end users retain policy-based protections regardless of the channel through which Unity collects their data.
The scope clause defines which services and websites are bound by Unity's stated information practices, determining where Unity's data obligations apply.
Incorporation by reference makes the TOMs legally binding within the DPA without reproducing them in full, meaning the DPA's obligations include the TOMs' data security requirements.
Extending the Policy to offline collection means Unity's data obligations and the individual's rights apply beyond digital interactions.
Voice data, which users may not expect to be retained or reviewed, can be transmitted to Epic when a violation report is triggered, enabling human or automated review of voice interactions.
Users who rely on DNT signals to limit tracking will receive no effect from that setting when using Venmo.
The clause establishes three distinct categories of collection, meaning Verizon gathers data both when users actively submit it and passively through usage and interaction tracking.
It identifies the Privacy Center as the authoritative source for understanding Visa's data handling practices.
It establishes that online tracking data practices are governed by a separate dedicated notice, meaning readers must consult an additional document to understand Visa's full data collection practices.
Collection occurs across three distinct trigger points—installation, access, and use—meaning data is gathered even outside active messaging activity.
This clause establishes a defined and limited scope of Slack data access, meaning the broad contents of a customer's Slack workspace are not accessed by Devin.
The collection spans sensitive categories including health and safety details and full payment card data, meaning event registration carries a broader personal data footprint than contact-only collec…
It establishes that Writer has a stated commitment to multi-layered security protections over user data.
Device-level data is collected automatically during ordinary use, meaning a child's interaction with the app generates data collection without any affirmative submission by the child.
Voice data is collected and deleted immediately after processing, which limits the duration of retention but confirms that voice information is actively captured during audio feature use.
Collection is automatic and passive, meaning it occurs without the user taking any active step to submit information.
This is a standard adhesion contract: you cannot negotiate individual terms, and acceptance is implied by purchase, which means the terms of the CoC apply to every passenger even if they were not rev…
The agreement authorizes Anthropic to use the Customer's name and logo for marketing purposes by default; customers who do not wish to be publicly identified as API users must actively submit an opt-…
The clause establishes that on-device processing is the preferred approach, which when achieved prevents any data transmission off the device.
The reference to a named cookie policy signals that all users are subject to cookie-related terms, though those terms are not stated here.
The clause does not itself describe how personal data is handled but establishes that the Privacy Policy is the authoritative source for that information, meaning users must consult a separate docume…
The ability to opt out of marketing at any time is a practical consumer protection, but users should also be aware that transactional and operational communications are typically not subject to the s…
This provision means that important financial and legal documents, including trade confirmations and regulatory disclosures, will be delivered only electronically unless the customer specifically req…
TurboTax's commitment is qualified by 'help safeguard' rather than an absolute guarantee, which limits the strength of the data protection promise.
Monitor emails you the same day a platform you choose changes these clauses.
A data collection clause is a provision in a platform's terms of service or privacy policy governing data collection-related rights, obligations, or restrictions.
ConductAtlas tracks 296 platforms with data collection clauses - roughly 84% of platforms in the archive. 1084 are classified as high severity.
Severity reflects the magnitude of rights waived, availability of opt-out, breadth of users affected, financial or legal exposure created, and the degree of discretion retained by the platform.