Found in 241 of 352 platforms tracked (68% adoption) · 1256 provisions
The obligation is qualified by 'strive to provide,' which is a best-efforts standard rather than a guarantee, and the commitment is calibrated to data sensitivity rather than uniform across all data.
This provision binds AI21 Labs to non-discriminatory treatment in pricing and service delivery, subject to CCPA-defined exceptions.
This commitment ensures consumers can exercise their CPRA rights without fear of retaliatory or differential treatment by AWS.
AWS conditions access to its Offerings for minors on parental or guardian involvement, establishing a gatekeeping requirement for underage users.
The existence and nature of security measures directly affects the risk of unauthorized access to or disclosure of users' personal information.
American Airlines has stated an enforceable consequence — denial of boarding — for refusing to provide legally required information, directly linking data provision to physical travel access.
Claude's agentic outputs can have tangible real-world consequences beyond the Anthropic platform, and those consequences are conditioned on permissions the user grants, placing meaningful weight on t…
The claim establishes that Claude's actions are contingent on user-granted permissions and can produce effects beyond Anthropic's own platform, which means consequences may extend to external systems…
This requirement directly addresses insider-threat risk: even Apple's own operational staff must not have a technical path to circumvent PCC privacy protections, making the privacy guarantee structur…
This requirement sets an enforceable architectural standard: no critical PCC component may be placed beyond the reach of constraint or analysis, which underpins the verifiability of the system's guar…
Non-targetability is a core privacy property; the routing mechanism is presented as a structural safeguard against attackers singling out specific users.
This non-targetability property raises the cost and visibility of attacks: an adversary cannot surgically target an individual user's data without triggering a system-wide attack, which is harder to …
The absence of privileged data-exposing interfaces is a structural privacy control, meaning there is no designed-in mechanism by which elevated access could be used to retrieve user data.
The clause is consequential because it removes user control over a defined category of communications that Betterment classifies as administrative.
The clause is consequential because it removes the user's ability to decline specific categories of communications as a condition of holding an account.
Users who lack the qualifying products hold balances that carry no FDIC pass-through insurance protection, meaning those funds are not protected in the same way as insured bank deposits.
Without FSCS coverage, funds held in a Checkout.com account are not protected up to the statutory compensation limit if Checkout.com were to fail.
This clause shifts legal compliance responsibility for end-user personal data to the customer, meaning Cohere does not assume that obligation for data customers choose to upload.
Daily authenticated scanning of both first-party and third-party/open-source packages, combined with SAST and DAST, provides broad and frequent coverage of potential vulnerability sources.
Explicitly prioritizing Severity-0 vulnerabilities above other rollouts means the most critical threats, including zero-day exploits, are structurally moved to the front of the remediation queue.
The materiality threshold means that no penetration test can be closed as passing while material vulnerabilities remain unresolved, creating a mandatory remediation gate.
Requiring security scanning before production promotion creates a gatekeeping step that prevents unscanned code or images from reaching the live environment.
Access to certain Service functionalities is conditionally linked to the provision of personal information, meaning withholding data carries a practical cost to usability.
By placing legal compliance responsibility on the user, Eufy limits its own obligation to ensure lawful use of its surveillance-capable products, and users bear the risk of non-compliance.
This commitment ties Google's AI practices to internationally recognized legal and human rights standards, establishing a normative baseline for its AI governance.
Placing sole responsibility on the developer means Google AI Studio bears no responsibility for service actions, which is consequential when service actions cause harm or unintended outcomes.
The clause gives the Customer an enforceable right to independently verify Google Ads' data protection compliance, rather than relying solely on Google Ads' self-reporting.
Google DeepMind explicitly identifies model weight exfiltration as a pathway to removing most safeguards, establishing the protection of model weights as foundational to the integrity of all other sa…
By characterizing collective action as vital, Google DeepMind positions individual security improvements as insufficient and frames industry-wide coordination as a necessary condition for meaningful …
By asserting that all critical capabilities—without exception—warrant this process, Google DeepMind establishes a universal scope for its mitigation obligations, leaving no critical capability catego…
By singling out the machine learning R&D domain for particularly high security levels, the Framework identifies this domain as requiring elevated treatment relative to other capability areas.
The use of 'may exceed' rather than 'will exceed' means this is a possibility, not a commitment, and the baseline remains the operative floor established by the Framework.
This establishes a mandatory governance gate that must be cleared before general availability deployment, meaning no model can be broadly released without an affirmative approval from a designated co…
Identifying this as the mandatory first step establishes that safeguard iteration is a prerequisite to subsequent stages in Google DeepMind's deployment mitigation process.
This position establishes that Google DeepMind views its own security mitigations as insufficient to deliver full social benefit in isolation, making industry-wide adoption a prerequisite for meaning…
The commitment to develop a safety case that is 'assessable' and must show minimisation to an 'acceptable level' creates a defined, evaluable standard rather than a discretionary or informal review.
SSL encryption is a baseline security measure for protecting financial and personal data in transit; its use signals a minimum standard of transmission security for online orders.
This is a breaking change from prior behavior: repos created after August 2024 no longer receive automatic transformers library detection, so omitting the explicit field will result in the library no…
The assumption of risk is not limited to disclosed or foreseeable risks—it extends to any risk associated with Unattended Delivery, including those not enumerated in the Terms.
The clause contractually forecloses employment status, which determines eligibility for employment protections, benefits, and legal remedies under labor law.
Meta's risk assessment is conditioned on a causal link between technological advancement and catastrophic harm — mitigation steps are triggered only where that link is identified.
The metric Meta uses to set risk thresholds is the degree to which its models facilitate threat scenarios, meaning model behavior directly determines where risk limits are set.
This clause imposes a floor on the quality of Neon's security protections for the duration of an Order, preventing Neon from weakening security while the Customer is bound to that Order.
It establishes that the model cleared a defined, comprehensive safety process—including a named framework and targeted red-teaming in high-risk domains—prior to deployment.
Partnering with governments specifically to combat disinformation globally signals that OpenAI's anti-disinformation efforts operate at a governmental and international scale, not solely through inte…
Establishing security risk management as a covered area confirms OpenAI has committed to structured security governance within its frontier AI framework.
This clause establishes that the Preparedness Framework is the primary instrument governing OpenAI's risk management approach for its most serious AI risks, giving it structural precedence within Ope…
The clause explicitly warns against emergency reliance, signaling that bots are not designed or guaranteed to perform reliably in life-critical situations.
The governing legal framework determines what privacy rights and protections apply; users who hold or applied for a brokerage account may not be able to rely on state privacy law protections.
Replit places the compliance burden for COPPA notice and consent obligations on publishers, which defines where legal responsibility sits for child-directed content.
The right to act without notice or demand and to reach across multiple accounts—including joint accounts—means Revolut can recover debts immediately and from funds a customer may not expect to be aff…
The safeguarding method determines how customer funds are protected in the event of Revolut's insolvency, and defines the nature of that protection as distinct from FSCS deposit insurance.
Service access or functionality may be conditioned on providing personal information, meaning withholding information carries a practical consequence for the user's experience.
RunPod places the legal and operational burden of data security, backup, and encryption compliance on users, meaning RunPod does not assume responsibility for data loss or security failures attributa…
Exercising a data deletion right may result in loss of Service access, creating a practical trade-off between privacy rights and continued use.
Users are deemed to have consented to international data transfers to jurisdictions that may afford fewer privacy protections, simply by using the Service or submitting information.
Emergency response is not available at all times; it is restricted to specific conditions, meaning gaps in coverage exist outside those conditions.
Customers who bring their own LLM relationship may lose the benefit of Sourcegraph Cody's stated data commitments, including those on training and retention, creating a gap in their assumed protectio…
Square places the legal burden of obtaining customer consent or permission directly on the seller, not on Square itself, which means sellers bear compliance risk if customer permissions are inadequat…
The broad consent covers all provided contact channels and any purpose, including debt collection, with no stated frequency or time restrictions.
Failing to notify T-Mobile in writing within 60 days may extinguish the customer's ability to dispute that bill or charge.
The clause places sole responsibility for user notice — a key privacy compliance obligation — on the Business Partner rather than on Tabnine, which means end users may receive no direct notice from T…
A one-year limitation period is shorter than many statutory limitation periods, meaning users may lose their legal claims more quickly than they would under default law.
This requirement creates a procedural prerequisite to litigation, which could delay or add steps before a user can pursue formal legal remedies.
This means user data collected by Twitch can be transferred to an entirely different entity in a corporate transaction, potentially subjecting it to different privacy practices.
Pharmacy-related information operates under a separate, federally mandated legal framework, meaning the protections and rights described in this Privacy Policy do not apply to it.
WhatsApp explicitly acknowledges that the privacy of your communications depends in part on the behavior of other users, whom WhatsApp does not control with respect to capturing and resharing content.
By assigning sole legal compliance responsibility to the user, Wyze disclaims any shared or parallel obligation to ensure the user's camera use complies with local privacy or surveillance law.
The existence of management, observation, and debug capabilities on PCC nodes is consequential because such capabilities could in principle expose user data; the privacy-aware qualifier indicates the…
Users who rely on Do Not Track signals to limit data collection will receive no effect from that mechanism when using Cerebras services.
The security commitment is bounded by federal law compliance, meaning protections are defined by regulatory minimums rather than any higher standard.
The reliability limitation on non-English outputs may affect the suitability of Cohere's model for multilingual or non-English use cases.
Users who supply their own API key may assume their requests go directly to the model provider, but this clause establishes that Cursor's backend remains an intermediary for all requests.
Scoping penetration tests to major releases, new services, and security-sensitive features means new and high-risk functionality is actively probed before or around deployment.
Compliance offerings and certifications indicate that Databricks has met externally validated security and privacy standards, which may be required by regulated-industry customers.
Automated and continuous coverage of systems, libraries, and code reduces the window in which undetected vulnerabilities could be exploited.
This clause creates a reciprocal benchmarking right for Databricks that explicitly overrides any contractual restrictions the user may have placed on benchmarking of their own products or services.
The recommendation signals that Garmin acknowledges potential health risks associated with exercise and positions the responsibility for medical clearance with the user.
It establishes that the governance and assurance framework does not vary by use case, meaning no use case receives a weaker or different standard of oversight.
The recommendation is specifically tied to non-transformers models, meaning creators of such models are on notice that omitting library_name is contrary to Hugging Face's guidance.
The pipeline tag has functional consequences beyond labeling: it directly controls the interactive widget shown on the model page and the APIs invoked, meaning an incorrect or missing tag affects mod…
Relying on automatic detection is actively discouraged, meaning repo creators who omit the explicit library_name field are not following Hugging Face's stated guidance.
The clause establishes a time-bound obligation on Ledger, giving users a defined window within which to expect a response to legitimate requests.
Meta's catastrophic risk assessment is an active, structured process that involves external expertise, not solely internal review.
Risk evaluation under Meta's framework is not one-sided; potential benefits are explicitly factored in alongside catastrophic risk, which shapes how risk thresholds and mitigations are determined.
The existence of a dedicated oversight body signals that ethics and governance responsibilities are institutionally assigned rather than ad hoc.
The clause establishes the complete enumerated framework of values that defines Microsoft's responsible AI commitment, providing the basis for evaluating its AI governance positions.
The clause positions Microsoft's own standard as a model and identifies the minimum principles that such a standard should address.
Advertisers whose ads have been disapproved or whose accounts have been subject to action are pointed to a specific process for seeking review, establishing that a review pathway exists.
It establishes a binding legal obligation under GDPR for organizations handling personal data to maintain appropriate security.
A 256k-token context ceiling directly bounds how much input and conversational history the model can consider in a single request.
The obligation is aspirational ('striving') rather than a firm commitment, and the standard is 'commercially acceptable' rather than any higher benchmark.
It establishes that separate evaluation is triggered only by OpenAI's own judgment about material risk impact, meaning independent evaluation is not automatic or universal.
Collaboration with industry leaders and policymakers signals that OpenAI's harm-reduction efforts extend beyond its own internal controls into coordinated external governance efforts.
Framing risk management as a continuous daily activity implies an ongoing and iterative process rather than a fixed or periodic review, which characterizes the nature of OpenAI's stated risk governan…
The annual frequency cap and cost allocation to the Customer constrain the Customer's practical ability to verify OpenAI's data processing practices.
It discloses that GPT-5.5 Pro is not always independently safety-evaluated, relying instead on results from GPT-5.5 as a proxy.
It establishes that OpenAI incorporated pre-release input from a defined group of partners, indicating the release was preceded by structured external feedback.
Users outside the select markets where Paramount+ operates cannot access the service, limiting its geographic reach.
Users in the relevant markets cannot access Paramount+ content directly through Paramount+ and are directed to a separate platform, SkyShowtime, instead.
Users outside the select markets where Paramount+ is available cannot access the service, establishing a geographic restriction on availability.
Users in the referenced markets must access Paramount+ content through a separate platform, SkyShowtime, rather than directly through Paramount+.
An opt-out from marketing does not constitute a full communications opt-out; users will continue to receive administrative messages regardless of their preference settings.
The clause indicates that compliance documentation exists and is accessible, which is relevant to readers who need to verify Salesforce's regulatory standing.
The standard is 'commercially reasonable' and measures are 'intended to' protect — not guaranteed to — which defines the scope of Windsurf's security commitment.
The presence of an Accessibility section signals that Airtable addresses accessibility in some form within its policy documentation.
The clause establishes Microsoft's overarching commitment governing its entire AI development and release lifecycle.
The availability of a PGP encryption option means reporters can protect sensitive vulnerability information during transmission to Progressive.
Progressive designates a specific reporting channel for suspected phishing emails, providing a mechanism for users to flag potential fraud.
The use of 'attempt' means the 10-business-day timeframe is a stated goal rather than a guaranteed commitment, limiting Progressive's obligation.
Money movement services are legally provided by a separately licensed entity, meaning regulatory obligations and liability for those services sit with Intuit Payments Inc. rather than TurboTax direct…
It establishes that access to open banking through Visa is geographically restricted, and users outside supported regions receive a different privacy framework.
Monitor emails you the same day a platform you choose changes these clauses.
A other clause is a provision in a platform's terms of service or privacy policy governing other-related rights, obligations, or restrictions.
ConductAtlas tracks 241 platforms with other clauses - roughly 68% of platforms in the archive. 214 are classified as high severity.
Severity reflects the magnitude of rights waived, availability of opt-out, breadth of users affected, financial or legal exposure created, and the degree of discretion retained by the platform.