Provision Registry

12505 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
low Privacy rights
Notion · Notion Privacy Policy
The retention provision uses open-ended language ('as long as we reasonably need it') without specifying retention periods for different data categories, which creates uncertainty about how long specific types of data such as usage logs, deleted content, or account information are held.
CA-P-011198 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Audible · Audible Privacy Notice
This provision establishes an open-ended retention standard tied to service purposes and legal requirements rather than fixed timeframes. Under GDPR, the absence of specific retention periods for each data category may present compliance exposure, as the regulation requires personal data to be kept in a form that permits identification no longer than necessary for the stated purpose.
CA-P-003702 First tracked Apr 28, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Duolingo · Duolingo Privacy Policy
The policy does not specify fixed retention periods for different categories of data, which under GDPR requires that retention periods or criteria be communicated to users; the absence of specific timeframes creates ambiguity about how long learning and behavioral data is retained.
CA-P-005772 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
AWS · AWS Privacy Notice
This provision establishes a purpose-based and legally required retention framework without specifying concrete retention periods for any category of personal data. The absence of defined retention timelines may complicate data subject deletion requests and may require evaluation under GDPR's storage limitation principle, which requires that data not be kept longer than necessary.
CA-P-013079 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
low Data retention
Snapchat · Snapchat Privacy Policy
The provision operationalizes Snapchat's data lifecycle management by defining automatic deletion schedules for ephemeral content while carving out exceptions for legally-required or operationally-necessary retention. This structure allocates data stewardship responsibilities between the platform and users.
CA-P-011512 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
low Privacy rights
OpenSea · OpenSea Privacy Policy
This provision establishes the framework under which OpenSea holds user data after account closure or inactivity, with retention periods tied to legal obligations and business purposes rather than fixed timeframes, which affects the practical scope of deletion requests.
CA-P-008287 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Shopify · Shopify Privacy Policy
The policy does not specify fixed retention periods for different categories of personal data, stating instead that retention continues as long as necessary for service provision or legal compliance, which means the practical duration of data retention for specific data types is not disclosed to users.
CA-P-011123 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
OpenAI · OpenAI Privacy Policy
The policy does not specify fixed retention periods for individual data categories, which means the duration for which conversation content, uploaded files, and account data may be retained is not precisely defined for users.
CA-P-002667 First tracked Apr 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Ideogram · Ideogram Privacy Policy
The absence of specific retention periods makes it difficult for users to know how long their prompts, images, and account data are stored, and creates compliance ambiguity under GDPR's data minimization and storage limitation principles.
CA-P-004448 First tracked May 2, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
AI21 Labs · AI21 Labs Privacy Policy
Without specific retention periods stated in the policy, users cannot easily determine how long their prompt data, account information, or behavioral data will be stored, which limits their ability to manage their own data lifecycle.
CA-P-008139 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Canva · Canva Privacy Policy
The policy does not specify defined retention periods for particular data categories, which is relevant to GDPR's data minimization and storage limitation principles and may be a point of inquiry for compliance teams or data subject rights requests.
CA-P-008235 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Databricks · Databricks Privacy Notice
Open-ended retention language means your data could be kept indefinitely for broad purposes including legal defense, which may conflict with data minimization principles under GDPR and similar frameworks.
CA-P-006114 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Writer · Writer Privacy Policy
The policy does not specify exact retention periods for each data category, meaning users cannot easily determine how long their content and account data will be held.
CA-P-005916 First tracked May 8, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Affirm · Affirm Privacy Policy
An open-ended retention standard without specific timelines means your financial and behavioral data may be retained indefinitely unless you affirmatively request deletion.
CA-P-008406 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Betterment · Betterment Privacy Policy
The absence of specific retention periods for most data categories means Betterment retains broad discretion over how long it holds your sensitive financial information, including after you close your account.
CA-P-009208 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Leonardo AI · Leonardo AI Privacy Policy
This provision establishes a purpose-based retention framework without specifying fixed retention periods for different data categories, which may affect compliance with GDPR storage limitation requirements and user ability to predict how long their data is held.
CA-P-007584 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Vercel AI · Vercel AI SDK Privacy
Without specific retention timeframes, it is difficult to know how long your data will be held, and the open-ended criteria could mean data is retained for extended periods beyond what users might reasonably expect.
CA-P-008981 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Acorns · Acorns Privacy Policy
The retention standard stated in this provision is broadly defined by reference to service necessity, legal obligations, dispute resolution, and agreement enforcement, without specifying maximum retention periods for particular data categories, which may create compliance ambiguity under regulations that impose specific retention period requirements or data minimization obligations.
CA-P-004623 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Datadog · Datadog Privacy Policy
The policy does not specify fixed retention periods for individual data categories, instead relying on purpose-based retention criteria; this approach is consistent with GDPR storage limitation principles but may limit users' ability to predict when their data will be deleted.
CA-P-004907 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Best Buy · Best Buy Privacy Policy
The policy does not specify fixed retention periods for individual data categories, instead relying on a purpose-based standard, which may make it difficult for consumers to know how long their data is held and may require evaluation under state laws that mandate retention period disclosures.
CA-P-005566 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Data retention
Atlassian · Atlassian Privacy Policy
The clause defines the retention standard as tied to business necessity and legal compliance rather than specifying fixed retention periods, meaning data persistence duration depends on the company's assessment of ongoing legitimate needs.
CA-P-006102 First tracked May 8, 2026 Last seen May 11, 2026 Compare across platforms →
low Privacy rights
Starbucks · Starbucks Privacy Policy
The absence of specific retention periods for most data categories means consumers have limited visibility into how long their purchase history, location data, and behavioral profiles are kept, which affects the practical scope of deletion rights.
CA-P-004536 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
low Privacy rights
Brex · Brex Privacy Policy
Open-ended retention tied to legal and regulatory obligations is common in financial services, but it means your data may be held for extended periods beyond your active use of Brex products.
CA-P-009181 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Samsung · Samsung Privacy Policy
Without defined retention periods for specific data types, personal data including browsing history, location, and health metrics may be retained for extended and undefined periods, which limits consumer ability to predict when their data will be deleted.
CA-P-007960 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Chime · Chime Privacy Policy
A deletion request may not result in complete removal of your data if Chime determines it has legal or business reasons to retain certain records, which is a standard but important limitation on the right to deletion.
CA-P-009951 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Sony PlayStation · PlayStation Privacy Policy
The absence of specific data retention periods in the main policy text means users may not know how long their behavioral, communications, or account data is retained, which is relevant to both privacy risk and the exercise of deletion rights.
CA-P-008459 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
low Data retention
Walmart · Walmart Privacy Policy
Data retention and security policies establish the operational framework governing how long personal data remains in Walmart's systems and what technical and administrative controls apply to that data during the retention period.
CA-P-007940 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
low Privacy rights
Rumble · Rumble Privacy Policy
How long your data is kept and where it is stored affects your ability to exercise deletion rights and the risk that your information could be exposed in a data breach.
CA-P-007200 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Anyscale · Anyscale Privacy Policy
The absence of specific retention periods for most data categories means your personal information may be retained indefinitely for broadly stated business purposes, which may be difficult to challenge or verify.
CA-P-010121 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
low Privacy rights
Twitch · Twitch Privacy Notice
Without specific retention periods disclosed, users cannot know how long their data, including sensitive information like billing details and chat history, is held by Twitch.
CA-P-009602 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial