Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
medium Privacy rights
Mistral AI · Mistral AI Privacy Policy
Your personal data may be included in Mistral AI's AI training even if you have never used any Mistral AI product, because the company sources training data from public internet content and third-party datasets that may contain your information.
CA-P-010427 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Threads · Threads Privacy Policy
The structural linkage between Threads and Instagram means that data from both platforms is associated and that users cannot create a Threads presence that is separate from their Instagram identity.
CA-P-010858 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
OpenAI · OpenAI Enterprise Privacy
The distinction between enterprise and consumer product data governance is operationally significant: employees or contractors who use personal free ChatGPT accounts for work tasks would not benefit from the enterprise data protections, potentially exposing organizational data to training data practices that the enterprise tier explicitly excludes.
CA-P-011974 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
TikTok Ads · TikTok Advertising Terms
The TikTok pixel collects behavioral and event data from the advertising portal; the terms governing what data is collected, how long it is retained, and how it is used for ad targeting or optimization are not fully disclosed in the transmitted page and require review of TikTok's full data processing documentation.
CA-P-011191 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Anthropic · Anthropic Privacy Policy
The policy discloses that personal data obtained from publicly available internet sources and commercial datasets is used for model training, which means individuals who have not consented to or interacted with Anthropic's services may have their personal data included in training data; a separate Non-User Privacy Policy governs this practice.
CA-P-011310 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Hugging Face · Hugging Face Model Card Guidelines
Training data disclosure is directly relevant to intellectual property compliance, data provenance assessments, and bias risk evaluation, particularly as regulatory frameworks increasingly require transparency about AI training data sources.
CA-P-012041 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
Steam · Steam Privacy Policy
Full credit card details are processed by Valve before transmission to payment service providers, meaning Valve is an intermediary in the payment data flow rather than relying solely on direct processor collection.
CA-P-009904 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Visa · Visa Privacy Notice
Visa's network position means this data covers spending behavior across a very wide range of merchants and contexts, creating a detailed financial profile that goes beyond what any single retailer would see.
CA-P-002245 First tracked Apr 4, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Microsoft · Responsible AI
This provision states a commitment to AI explainability that is directly relevant to regulated industries such as financial services, healthcare, and employment, where algorithmic decisions may be subject to explanation requirements under applicable law.
CA-P-002075 First tracked Apr 4, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Microsoft · Microsoft Responsible AI Standard
This principle addresses explainability and disclosure in AI systems, which is directly relevant to regulatory requirements around automated decision-making and the right to explanation under frameworks such as GDPR.
CA-P-002087 First tracked Apr 4, 2026 Last seen May 22, 2026 Compare across platforms →
Segment · Segment Privacy Policy
The consent management implementation creates an operational layer through which Segment's data processing practices are disclosed to users and user consent preferences are collected, stored, and referenced for subsequent processing activities. This infrastructure supports the legal framework for processing and sharing user data according to stated policies.
CA-P-010089 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
Bank of America · Bank of America Privacy Notice
The scope of data collected is broad and includes information that, if improperly handled or disclosed, could facilitate identity theft or financial harm.
CA-P-007248 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Udemy · Udemy Privacy Policy
This provision establishes the distinct data governance framework applicable to enterprise and institutional customers, where the allocation of controller and processor responsibilities affects compliance obligations for both Udemy and the enterprise customer.
CA-P-012906 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
OpenAI · OpenAI Usage Policies
This provision covers both cybersecurity intrusion and privacy-violating data aggregation, addressing a broad range of potential misuse from hacking to building unauthorized surveillance tools, and the privacy aggregation component is particularly relevant for data brokers, researchers, and analytics firms.
CA-P-011730 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Character.AI · Character.ai Community Guidelines
This provision discloses a material architectural difference in how minors experience the platform, which has direct implications for child safety compliance under COPPA and analogous state laws.
CA-P-010612 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Bluesky · Bluesky Privacy Policy
Unlike platforms that offer end-to-end encrypted messaging, Bluesky explicitly confirms that direct messages can be accessed by the company, which means users should not treat DMs as confidential communications.
CA-P-004961 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Anyscale · Anyscale Privacy Policy
The clause establishes the operational framework for privacy policy amendments, specifying that modifications may occur unilaterally and that notification occurs through publication and potential additional messaging rather than requiring affirmative user consent.
CA-P-006710 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Gemini · Gemini Privacy Policy
Because Gemini can change its data practices at any time, the terms governing how your personal data is used may shift without direct notification beyond a website update.
CA-P-009311 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Mistral AI · Mistral Terms of Use
The Privacy Policy governs how Mistral AI collects, uses, stores, and shares your personal data across all of its services, making it one of the most consequential documents for all users.
CA-P-007781 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Midjourney · Midjourney Community Guidelines
This provision clarifies that privacy settings, Stealth Mode, and content deletion do not remove content from the scope of guideline enforcement, meaning Midjourney retains the ability to review and act on content regardless of its visibility status.
CA-P-011654 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Baseten · Baseten Privacy Policy
The policy states that usage data is collected automatically, meaning this data collection occurs regardless of whether a user actively provides information, and includes device identifiers and behavioral browsing data.
CA-P-011915 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cursor · Cursor Terms of Service
This provision distinguishes Usage Data from Content (code inputs and suggestions), authorizing Anysphere to collect and process interaction and log data for business purposes and to share it with third parties in aggregated or de-identified form.
CA-P-004347 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Snowflake · Snowflake Terms of Service
The terms authorize Snowflake to collect behavioral and interaction data from all platform users for internal product development purposes, which is a permitted use that operates without requiring separate consent for each instance of use.
CA-P-011315 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Cash App · Cash App Privacy Policy
The GLBA notice requirement creates a regulatory framework governing how Cash App must communicate its data handling practices to consumers. This disclosure obligation establishes the baseline transparency requirement for financial privacy under federal law and defines what information practices the entity is authorized to conduct.
CA-P-004584 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Privacy rights
Afterpay · Afterpay Privacy Policy
The GLBA Consumer Privacy Notice is the federally mandated disclosure that governs your right to opt out of certain sharing of your nonpublic personal information with non-affiliated third parties, which is a legally meaningful protection distinct from the general privacy notice.
CA-P-008628 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Afterpay · Afterpay Privacy Policy
The GLBA notice requirement creates a regulatory framework obligating the company to disclose its information practices transparently, establish procedures for consumer access to personal information, and describe the circumstances under which nonpublic personal information may be shared with affiliated and nonaffiliated third parties.
CA-P-005554 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
This provision establishes that user-generated conversation content, including feedback, constitutes training data for Google's AI models unless users actively opt out via Gemini Apps Activity controls. The opt-out is available but is not the default state described in the notice, requiring affirmative user action.
CA-P-012682 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
MyFitnessPal · MyFitnessPal Privacy Policy
Tracking technologies enable the collection of behavioral data that can be linked to your health app usage and used to build advertising profiles, extending data use beyond what you actively input into the app.
CA-P-009363 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Medium · Medium Privacy Policy
Cookies and tracking technologies enable Medium and its partners to build a profile of your browsing habits, which can be used for advertising and analytics purposes both on and off the Medium platform.
CA-P-009559 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Intuit · Intuit Privacy Statement
Tracking technologies collect behavioral data continuously across browsing sessions, and the involvement of third-party advertising partners means this data flows to external companies who may combine it with other data sources.
CA-P-008516 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial