Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
medium Privacy rights
Tabnine · Tabnine Privacy Policy
The absence of specific retention periods for categories such as code snippet data, telemetry, and account information means users and enterprise customers cannot determine from the policy alone when their data will be deleted. GDPR's data minimization and storage limitation principles require that retention periods be defined and justified.
CA-P-007303 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Lime · Lime Privacy Policy
Without a specified maximum retention period, your location history, trip records, and account data may be retained indefinitely, which has implications for both privacy risk and your rights to have data deleted.
CA-P-008701 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Smartsheet · Smartsheet Privacy Policy
Open-ended retention criteria mean personal data may be kept for extended periods, and users cannot easily predict when their data will be deleted without submitting a specific deletion request.
CA-P-005137 First tracked May 7, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
BeReal · BeReal Privacy Policy
The absence of specific retention timelines for categories of data such as dual-camera imagery and location data makes it difficult for users to know exactly how long their most sensitive information is held.
CA-P-006344 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
ADP · ADP Privacy Statement
Without specific retention timelines for each data category, it is difficult for individuals or employers to predict when their data will be deleted, which affects the practical ability to enforce deletion rights.
CA-P-005457 First tracked May 7, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Chegg · Chegg Privacy Policy
The absence of specific retention periods means Chegg may hold your personal data indefinitely under broad justifications, limiting users' ability to predict when their data will be deleted.
CA-P-008562 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Dropbox · Dropbox Privacy Policy
Deleting your account does not immediately erase all of your data; Dropbox retains information for legal compliance, dispute resolution, and contract enforcement purposes for unspecified additional periods.
CA-P-008462 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Perplexity AI · Perplexity AI Privacy Policy
The absence of specified retention periods for distinct data categories, including query content, voice audio, and conversation history, creates uncertainty for compliance assessments and may engage GDPR storage limitation requirements, which mandate that personal data not be retained longer than necessary for the specified purpose.
CA-P-012344 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
GitHub · GitHub Privacy Statement
The policy does not specify retention periods for individual data categories, stating instead that retention is based on necessity and legal obligation; this means users cannot determine from this document alone how long specific types of data will be held.
CA-P-003601 First tracked Apr 27, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Inflection AI · Inflection AI Privacy Policy
Open-ended retention language tied to broad purposes like service improvement and AI training means personal data, including conversation history, could be retained for extended and indeterminate periods.
CA-P-004150 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Grammarly · Grammarly Privacy Policy
The policy does not specify fixed retention periods for different data categories, meaning personal data and submitted content could be retained for extended periods unless you actively request deletion.
CA-P-004134 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Jasper AI · Jasper Privacy Policy
This provision establishes a purpose-based retention standard without specifying defined retention timelines for different categories of personal data, which may present disclosure adequacy considerations under GDPR's data minimization and storage limitation principles.
CA-P-010661 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
DocuSign · DocuSign Privacy Statement
Open-ended retention language means your data, including document content, may be retained for extended periods beyond the immediate transaction, and the specific retention periods are not detailed in the public notice.
CA-P-008915 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Synthesia · Synthesia Privacy Policy
Open-ended retention language tied to business necessity can mean data is kept for extended periods; users who close their accounts should confirm deletion of sensitive data including avatar likeness and voice recordings.
CA-P-009280 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Walmart · Walmart Privacy Policy
The absence of specific retention timelines in the general notice means consumers cannot easily determine how long their purchase history, location data, or biometric identifiers will be retained, which is relevant to the practical effectiveness of deletion rights.
CA-P-011365 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Copy.ai · Copy.ai Privacy Policy
Without defined retention periods for specific data categories, users and enterprise customers cannot easily assess how long their submitted content, usage data, or account information will be stored.
CA-P-004320 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Perplexity AI · Perplexity Privacy Policy
This provision does not specify retention periods for individual data categories, including conversation history and voice data, which creates compliance uncertainty under GDPR's data minimization and storage limitation principles and under state privacy laws requiring disclosure of retention practices.
CA-P-006929 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Squarespace · Squarespace Privacy Policy
The litigation hold carve-out means Squarespace may retain your data beyond the period you would expect or request deletion, and the retention periods are not specified with defined timeframes.
CA-P-010307 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cloudflare · Cloudflare Privacy Policy
The absence of specific retention periods in the public policy makes it difficult for users to know how long their IP addresses, usage logs, and account data are stored, which is relevant to understanding the scope of potential data exposure.
CA-P-003016 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
ClickUp · ClickUp Privacy Policy
Open-ended retention language means your data could be kept indefinitely without a clear endpoint, which affects both your privacy expectations and your ability to request deletion.
CA-P-008115 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
HubSpot · HubSpot Privacy Policy
This provision establishes a principles-based rather than fixed-period retention framework, which may require evaluation under GDPR data minimization and storage limitation principles where specific retention schedules are expected by supervisory authorities.
CA-P-002981 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Fly.io · Fly.io Privacy Policy
Open-ended retention language means your personal data may be held indefinitely unless you actively request deletion, and the criteria for determining retention length are not defined with precision.
CA-P-005364 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
MyFitnessPal · MyFitnessPal Privacy Policy
The retention period is not precisely defined, which means your health and fitness data could be held for an extended and uncertain duration even after you stop using or delete your account.
CA-P-009362 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Miro · Miro Privacy Policy
If Miro retains your data for extended periods after account closure or inactivity, your information may remain in Miro systems longer than you would expect. Users who close accounts should consider submitting a deletion request to ensure timely removal.
CA-P-007872 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Riot Games · Riot Games Privacy Notice
Indefinite or open-ended retention tied to broad purposes like 'enforce our agreements' or 'resolve disputes' means data may be retained for longer than users might expect, and specific deletion timelines are not guaranteed.
CA-P-005356 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Monday.com · Monday.com Privacy Policy
The absence of specific retention periods means personal data may be retained for an indeterminate period after you stop using the service, until you actively request deletion or your account is closed.
CA-P-008746 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Fiverr · Fiverr Privacy Policy
Retention periods are not specified with precision, meaning Fiverr may retain your personal data for extended periods after you stop using the service, including for unspecified legal obligation and dispute resolution purposes.
CA-P-007435 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Weights & Biases · Weights & Biases Privacy Policy
Retention periods determine how long your personal data exists in CoreWeave's systems, affecting both your privacy and the company's obligation to delete data upon request.
CA-P-004029 First tracked Apr 30, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Grindr · Grindr Privacy Policy
Open-ended retention periods for sensitive data including health information, sexual orientation, and location mean your most private information could be held indefinitely, increasing the risk of breach or misuse over time.
CA-P-009388 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Zoom · Zoom Privacy Statement
The absence of specific retention period commitments for most data categories in the statement means users and enterprises cannot determine from this document alone how long meeting recordings, transcripts, or usage data are retained. This is relevant for compliance teams conducting data minimization assessments.
CA-P-006537 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial