Provision Registry

2201 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Medium × Clear all
medium Privacy rights
Grammarly · Grammarly Privacy Policy
The policy does not specify fixed retention periods for different data categories, meaning personal data and submitted content could be retained for extended periods unless you actively request deletion.
CA-P-004134 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Fiverr · Fiverr Privacy Policy
Retention periods are not specified with precision, meaning Fiverr may retain your personal data for extended periods after you stop using the service, including for unspecified legal obligation and dispute resolution purposes.
CA-P-007435 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Copy.ai · Copy.ai Privacy Policy
Without defined retention periods for specific data categories, users and enterprise customers cannot easily assess how long their submitted content, usage data, or account information will be stored.
CA-P-004320 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Stability AI · Stability AI Privacy Policy
The retention standard is tied to broadly stated purposes rather than specific time periods, which means the duration of data retention may vary and is not fixed to a defined schedule visible to users.
CA-P-003730 First tracked Apr 28, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Riot Games · Riot Games Privacy Notice
Indefinite or open-ended retention tied to broad purposes like 'enforce our agreements' or 'resolve disputes' means data may be retained for longer than users might expect, and specific deletion timelines are not guaranteed.
CA-P-005356 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Jasper AI · Jasper Privacy Policy
This provision establishes a purpose-based retention standard without specifying defined retention timelines for different categories of personal data, which may present disclosure adequacy considerations under GDPR's data minimization and storage limitation principles.
CA-P-010661 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Monday.com · Monday.com Privacy Policy
The absence of specific retention periods means personal data may be retained for an indeterminate period after you stop using the service, until you actively request deletion or your account is closed.
CA-P-008746 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Walmart · Walmart Privacy Policy
The absence of specific retention timelines in the general notice means consumers cannot easily determine how long their purchase history, location data, or biometric identifiers will be retained, which is relevant to the practical effectiveness of deletion rights.
CA-P-011365 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Perplexity AI · Perplexity Privacy Policy
This provision does not specify retention periods for individual data categories, including conversation history and voice data, which creates compliance uncertainty under GDPR's data minimization and storage limitation principles and under state privacy laws requiring disclosure of retention practices.
CA-P-006929 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Verizon · Verizon Privacy Policy
Open-ended retention periods tied to broadly defined purposes such as 'legal obligations' and 'enforcing agreements' may result in personal data being retained for extended periods without a clear maximum duration disclosed to consumers.
CA-P-003776 First tracked Apr 28, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
DocuSign · DocuSign Privacy Statement
Open-ended retention language means your data, including document content, may be retained for extended periods beyond the immediate transaction, and the specific retention periods are not detailed in the public notice.
CA-P-008915 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
ClickUp · ClickUp Privacy Policy
Open-ended retention language means your data could be kept indefinitely without a clear endpoint, which affects both your privacy expectations and your ability to request deletion.
CA-P-008115 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cloudflare · Cloudflare Privacy Policy
The absence of specific retention periods in the public policy makes it difficult for users to know how long their IP addresses, usage logs, and account data are stored, which is relevant to understanding the scope of potential data exposure.
CA-P-003016 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Intuit · Intuit Privacy Statement
Open-ended retention language tied to legal obligations and dispute resolution means sensitive financial data, including tax records and government identifiers, could be retained for extended periods without a specific deletion deadline.
CA-P-008515 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Udemy · Udemy Privacy Policy
This provision establishes the temporal scope of Udemy's data processing activities and determines how long personal data including learning activity, payment records, and communications content remains subject to Udemy's use and sharing permissions.
CA-P-010208 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Perplexity AI · Perplexity AI Privacy Policy
The absence of specified retention periods for distinct data categories, including query content, voice audio, and conversation history, creates uncertainty for compliance assessments and may engage GDPR storage limitation requirements, which mandate that personal data not be retained longer than necessary for the specified purpose.
CA-P-012344 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Squarespace · Squarespace Privacy Policy
The litigation hold carve-out means Squarespace may retain your data beyond the period you would expect or request deletion, and the retention periods are not specified with defined timeframes.
CA-P-010307 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
T-Mobile · T-Mobile Privacy Policy
Open-ended retention language tied to 'business needs' and 'legal obligations' without specific retention periods means consumers have limited visibility into how long sensitive data such as location records, call logs, and financial information is actually stored.
CA-P-010245 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
GitHub · GitHub Privacy Statement
The policy does not specify retention periods for individual data categories, stating instead that retention is based on necessity and legal obligation; this means users cannot determine from this document alone how long specific types of data will be held.
CA-P-003601 First tracked Apr 27, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
OpenAI · Privacy Policy (ROW)
The absence of fixed retention timelines means users cannot rely on a defined period after which their data will be deleted, and the scope of legitimate retention grounds is broad.
CA-P-011111 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Klarna · Klarna Privacy Policy
Your financial and personal data may be held by Klarna for an extended and unspecified period after you stop using the service, and the policy does not commit to specific maximum retention periods for most data categories.
CA-P-003483 First tracked Apr 27, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Duo Security · Duo Privacy
The absence of defined retention periods for specific data types like authentication logs means Cisco may retain this data for an extended and indeterminate period, which is relevant to privacy rights and data minimization requirements.
CA-P-007442 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
OpenRouter · OpenRouter Privacy Policy
The policy does not specify defined maximum retention periods for specific data categories, meaning personal data including account information, transaction records, and browsing data may be retained indefinitely for broad business purposes.
CA-P-011902 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Dropbox · Dropbox Privacy Policy
Deleting your account does not immediately erase all of your data; Dropbox retains information for legal compliance, dispute resolution, and contract enforcement purposes for unspecified additional periods.
CA-P-008462 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Grindr · Grindr Privacy Policy
Open-ended retention periods for sensitive data including health information, sexual orientation, and location mean your most private information could be held indefinitely, increasing the risk of breach or misuse over time.
CA-P-009388 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Baseten · Baseten Privacy Policy
The policy does not specify fixed retention periods for different categories of personal data, instead using purpose-based and legal-obligation criteria, which means users cannot determine from this document alone how long specific data types will be retained.
CA-P-011922 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
GOAT · GOAT Privacy Policy
Open-ended retention periods mean your data could be held indefinitely under broad business justifications, with limited ability for users in most jurisdictions to compel deletion beyond what specific privacy rights provide.
CA-P-008266 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Discord · Discord Privacy Policy
The policy does not specify fixed retention periods for most data categories, relying instead on a reasonableness standard; data may persist after account closure for legal and enforcement purposes, meaning deletion of your account does not guarantee immediate or complete erasure of all personal data.
CA-P-009004 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Tabnine · Tabnine Privacy Policy
The absence of specific retention periods for categories such as code snippet data, telemetry, and account information means users and enterprise customers cannot determine from the policy alone when their data will be deleted. GDPR's data minimization and storage limitation principles require that retention periods be defined and justified.
CA-P-007303 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Public.com · Public.com Privacy Policy
The absence of specific retention periods for sensitive financial and identity data means Public may retain your SSN, trading history, and financial account information for an indeterminate period after you close your account.
CA-P-008308 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial