Provision Registry

2201 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Medium × Clear all
medium Privacy rights
Smartsheet · Smartsheet Privacy Policy
AI training on customer-submitted data is a growing area of regulatory scrutiny, and the scope of what data may be used and under what legal basis is not fully specified in the notice, creating ambiguity for enterprise customers evaluating data governance risk.
CA-P-008058 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Zoom · Zoom Privacy Statement
This provision establishes a stated restriction on using meeting content for AI model training, which is directly relevant to enterprise and institutional customers with confidentiality or data use obligations. The distinction between 'customer content' covered by this restriction and other data categories used for AI improvement is a material interpretive boundary that compliance teams should assess against their contractual requirements.
CA-P-012533 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Spotify · Spotify Privacy Policy
The collection of AI interaction prompts and transcripts means that the content of your conversations with Spotify's AI features is stored as personal data, which may be used for service improvement, personalization, or other stated purposes and is subject to the policy's data sharing and retention terms.
CA-P-011546 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Miro · Miro Privacy Policy
The existence of a separate AI Terms Addendum means that users of Miro's AI features are subject to additional data processing terms that must be reviewed in conjunction with the privacy policy to assess the full scope of AI-related data handling.
CA-P-012985 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Snowflake · Snowflake Privacy Notice
The existence of a referenced AI governance framework is relevant to customers using Snowflake's AI or machine learning features, as it may define how AI outputs, data used for model training, and related obligations are governed.
CA-P-011439 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cerebras · Cerebras Privacy Policy
Users submitting potentially sensitive business, technical, or personal information to Cerebras AI services may rely on this commitment as a data minimization assurance, though the policy does not describe the technical controls or audit mechanisms that implement it.
CA-P-009365 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TikTok · TikTok Privacy Policy
AI interaction inputs may contain highly personal, sensitive, or proprietary information; the policy states this data is also used to train and improve machine learning models and algorithms, and to scan and analyze AI interactions and associated metadata for enforcement purposes.
CA-P-000305 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
Anthropic · Anthropic API Terms
The opt-out mechanism does not fully prevent your conversations from being used to train AI models, because two significant carve-outs apply regardless of your settings choice.
CA-P-009793 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Luma AI · Luma AI Privacy Policy
Users uploading personal images, videos, or sensitive text may not expect that content to contribute to AI model development, and no specific opt-out for this use is described in the policy.
CA-P-004290 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Ideogram · Ideogram Privacy Policy
Users may not expect that their creative prompts and generated images become training data for an AI system, and there is no clearly described opt-out mechanism for this specific use within the policy.
CA-P-010005 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cohere · Cohere Privacy Policy
This provision determines whether the prompts, documents, and queries you submit to Cohere's AI services are retained and used to further develop Cohere's models, which has implications for confidentiality of submitted content and data minimization obligations.
CA-P-011021 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cursor · Cursor Terms of Service
This provision establishes that the default position is no use of user content for AI training, which is a contractually explicit opt-in framework rather than a passive opt-out arrangement.
CA-P-007791 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Anthropic · Anthropic Privacy Policy
This means the opt-out is not absolute: any conversation that triggers a safety review can be retained and used for model training even if you have explicitly chosen not to contribute your data, and users have no visibility into when or why a conversation is flagged.
CA-P-007407 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
The terms authorize Google to use conversation content for AI model training and product improvement, which means information submitted in conversations may inform future AI outputs and training datasets. The policy's advisory against submitting confidential information confirms the operational scope of this use.
CA-P-003712 First tracked Apr 28, 2026 Last seen May 20, 2026 Compare across platforms →
Leonardo AI · Leonardo AI Privacy Policy
Users of generative AI platforms have a reasonable expectation that their creative inputs are used to produce outputs for them, not necessarily to train the underlying AI systems. This provision extends the use of user data beyond the immediate service transaction.
CA-P-004194 First tracked Apr 30, 2026 Last seen May 20, 2026 Compare across platforms →
OpenAI · Privacy Policy (ROW)
This provision determines whether the content of your interactions, including text prompts, uploaded files, and feedback, may be incorporated into future AI model development, which has implications for confidentiality of the information you share.
CA-P-011108 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Windsurf · Windsurf Security & Data Handling
The document states that data may be routed to third-party AI inference providers regardless of which model the user has explicitly chosen, which means users may not have full visibility into which providers receive their code or conversation data.
CA-P-011257 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
Unreal Engine · Epic Games Privacy Policy
This provision discloses that personally identifying user inputs are processed by AI-powered features, but the policy as excerpted does not address whether those inputs are used for model training, retained beyond immediate use, or processed by third-party AI infrastructure providers. This gap in disclosure is operationally significant for GDPR compliance (Articles 13 and 14 transparency requirements) and for enterprise and developer users of Epic's tools who may submit proprietary or sensitive information.
CA-P-007192 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Supabase · Supabase Privacy Policy
This provision establishes that AI support tool interaction data, including both user prompts and system-generated responses, is retained as part of the Service's data collection. This creates a data category that may require separate assessment under GDPR, CCPA, and emerging AI governance frameworks, particularly if users inadvertently include sensitive personal information in prompts.
CA-P-012937 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
Dun & Bradstreet · D&B Privacy Policy
AI-generated scores and ratings produced by D&B may influence credit decisions, business risk assessments, and professional due diligence about individuals, making the governance of these systems material to both individuals and the organizations that rely on D&B data.
CA-P-007990 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Cursor · Cursor Privacy Policy
The security review exception means that Inputs flagged for Terms of Service enforcement purposes may be analyzed by Anysphere, which is a conditional pathway that applies even without the user's explicit consent to training use.
CA-P-011599 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Cursor · Cursor Privacy Policy
This clause defines the operational scope of model training practices by establishing default non-use of user-generated content for training purposes and creating exceptions only for security analysis, user-initiated feedback, or affirmative consent. The provision creates an opt-in framework rather than opt-out, which affects data handling procedures and third-party data sharing policies.
CA-P-005192 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Privacy rights
Yelp · Yelp Privacy Policy
This clause means your publicly posted reviews and photos, as well as private AI chat inputs and outputs, can be used to improve Yelp's commercial AI products without additional compensation or separate consent beyond using the service.
CA-P-009021 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Instacart · Instacart Terms of Service
This clause operationalizes Instacart's compliance obligations under alcohol sales regulations by placing verification responsibility on the delivery stage and establishing the merchant's authority to reject orders that fail age verification procedures.
CA-P-007884 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Twitch · Twitch Privacy Notice
As an Amazon subsidiary, Twitch's data collection exists within a large corporate ecosystem; the relationship means data sharing within the Amazon affiliate group may occur and users should understand that Twitch's data practices connect to a wider set of Amazon services.
CA-P-002780 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
Sourcegraph Cody · Sourcegraph Privacy Policy
This provision authorizes automated access to user files and connected codebases for advertising purposes, which is operationally distinct from standard developer tool privacy practices and may be relevant for users storing sensitive or proprietary code.
CA-P-011840 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Uniswap · Uniswap Privacy Policy
The use of Google Analytics means your browsing and usage data from Uniswap Labs products is also transmitted to Google, and your contact information may be used for promotional communications from Uniswap Labs and third-party partners.
CA-P-008148 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Chime · Chime Privacy Policy
This provision establishes the operative scope of opt-out rights available under federal privacy law, defining which sharing practices fall within permissible categories that consumers may limit. The acknowledgment of state law variations creates a framework where Chime's actual restriction obligations may exceed the federal baseline described here, depending on applicable state regimes.
CA-P-006625 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Stash · Stash Privacy Policy
This carve-out is broad: if Stash's anonymization process is incomplete or reversible, data that the company treats as outside the policy's protections could still be linked back to you, and you would have no privacy rights over it under this policy.
CA-P-007857 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI API Data Usage Policies
This provision establishes the primary data use boundary for enterprise and API customers, directly affecting purpose limitation and data minimization compliance under GDPR and equivalent frameworks. The default exclusion from model training is a material operational distinction from consumer-tier ChatGPT accounts, where different terms may apply.
CA-P-012351 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial