Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
OpenAI · OpenAI Enterprise Privacy
The 30-day retention limit with automatic deletion is a specific, time-bounded data handling commitment that is material for organizations with data minimization obligations under GDPR or other regulations.
CA-P-011969 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
Cursor · Cursor Data Use & Privacy Overview
This provision clarifies that users who supply their own API keys cannot avoid Cursor's data pipeline, meaning the same data handling terms apply regardless of whether a personal or organizational API key is used.
CA-P-011153 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
YouTube Kids · YouTube Kids Privacy Notice
Watch history and search terms are used to recommend content and serve contextual ads, meaning the app builds a behavioral profile of your child's viewing habits even without collecting their name.
CA-P-008531 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Apple App Store · Apple Privacy Policy
The clause establishes Apple's data usage practices for advertising and marketing purposes while providing users with the procedural means to disable personalized ad targeting and marketing communications. This defines the operational scope of Apple's advertising platform and the available preference controls.
CA-P-002415 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
Apple · Apple App Store Review Guidelines
This provision establishes a disclosure mechanism that consumers can use to assess an app's data practices before downloading, covering identifiers, location data, usage data, contact information, and other categories as disclosed by the developer.
CA-P-011497 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Apple App Store · Apple Developer Agreement
The provision establishes a transparency mechanism that standardizes privacy disclosure across the App Store ecosystem, enabling comparative assessment of data practices and creating uniform reporting obligations for developers across app categories.
CA-P-007008 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Apple · Apple App Store Review Guidelines
This provision establishes a consent gate that users must pass through before cross-app and cross-website behavioral tracking for advertising can occur, and prohibits retaliatory restriction of app functionality for users who decline.
CA-P-011498 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
FanDuel · FanDuel Privacy Policy
The phrase 'or for any reason set forth in this Privacy Policy' is notably broad and links audio recording to FanDuel's full suite of data use purposes, including marketing and analytics, beyond the narrower use cases consumers typically expect when contacting customer support.
CA-P-007236 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Perplexity AI · Perplexity Data Processing Addendum
Audit rights are required under GDPR Article 28(3)(h) and are operationally significant for customers conducting vendor due diligence; the practical scope of the audit right, including whether it covers on-site inspection or documentation review only, determines its utility for compliance verification.
CA-P-012523 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
SoFi · SoFi Privacy Notice
The clause establishes a technical architecture where access to privacy option controls is contingent upon session authentication state, which affects how the service delivers privacy management functionality to different user categories.
CA-P-006486 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
SoFi · SoFi Privacy Notice
This routing mechanism creates two distinct technical pathways for privacy preference management, which compliance teams should verify produce equivalent opt-out outcomes and that both pathways propagate consent signals to the same set of data sharing partners.
CA-P-012331 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
Windsurf · Windsurf Terms of Service
Unlike Chat data training, opting out of Autocomplete data training does not result in loss of service access, providing users a meaningful choice. The agreement also explicitly commits to not using Autocomplete data to train generative models.
CA-P-011642 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Bumble · Bumble Privacy Policy
Automated profiling in a dating app context can significantly affect who you are able to connect with, and under GDPR users have specific rights related to automated decision-making that produces significant effects on them.
CA-P-008868 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Checkout.com · Checkout.com Privacy
Automated fraud decisions can result in transactions being declined or accounts being flagged without any human judgment involved, and individuals may not always know when they have been subject to such a decision or how to challenge it.
CA-P-010385 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Salesforce · Salesforce Privacy Statement
This provision operationally constrains Salesforce's ability to render determinative decisions about users through automated systems alone. The restriction applies specifically to decisions with legal consequences, requiring human review or alternative decision pathways for such determinations.
CA-P-001093 First tracked Apr 3, 2026 Last seen May 7, 2026 Compare across platforms →
Character.AI · Character.ai Community Guidelines
This provision discloses that human reviewers have access to user content and AI-generated outputs, which is relevant to user privacy expectations and may engage data protection obligations depending on what data is reviewed and retained.
CA-P-010617 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Sourcegraph Cody · Sourcegraph Privacy Policy
This provision authorizes collection of detailed behavioral data tied to a persistent user identifier, which may allow reconstruction of individual usage patterns over time even if the identifier is not directly linked to a name.
CA-P-011842 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Twitch · Twitch Privacy Notice
This automatic data collection happens passively without any active input from you, and it is used to build a behavioral profile that informs advertising targeting, which is a core revenue mechanism for Twitch.
CA-P-009598 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
RunPod · RunPod Privacy Policy
This provision authorizes passive collection of IP addresses, browsing activity within the platform, and device identifiers, which are categories of personal data subject to GDPR and CCPA protections and may require disclosure in cookie consent frameworks.
CA-P-013128 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
OpenRouter · OpenRouter Privacy Policy
This provision authorizes collection of a broad set of behavioral and device-level identifiers through automatic technologies, including data categories such as location data and browser history that may constitute personal data or sensitive data under applicable privacy frameworks.
CA-P-012761 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
Square · Square Privacy Notice
Automatic collection of behavioral data across third-party websites enables cross-site tracking and profiling, which is the foundation for targeted advertising and may engage stricter consent requirements in some jurisdictions.
CA-P-010457 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Anyscale · Anyscale Privacy Policy
This type of automatic data collection is used to build a profile of your behavior and device, which feeds into advertising and analytics operations. The policy states this data may be used to identify you as the same person across different Anyscale services.
CA-P-010118 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
Anthropic · Anthropic Privacy Policy
The policy states that advertising identifiers, probabilistic identifiers, and IP-derived location data are collected automatically, which are categories of data with direct relevance to targeted advertising and behavioral profiling capabilities, though the policy states Anthropic does not sell personal data.
CA-P-011309 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Unreal Engine · Epic Games Privacy Policy
This broad automatic collection covers a wide range of behavioral and technical data linked to your identity or device, and underpins Epic's ability to run analytics, personalize experiences, and serve advertising across all its services.
CA-P-007190 First tracked May 9, 2026 Last seen May 20, 2026 Compare across platforms →
Hugging Face · Hugging Face Privacy Policy
This provision discloses automatic collection of IP addresses and session location data, which under GDPR and other frameworks qualify as personal data; this collection occurs passively for all users regardless of account status.
CA-P-011659 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Inflection AI · Inflection AI Privacy Policy
Automatic collection of IP addresses, device identifiers, and browsing behavior creates a detailed profile of your usage even beyond the content of your conversations.
CA-P-008929 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Cloudflare · Cloudflare Privacy Policy
Your IP address and browsing behavior are collected passively across a vast range of internet destinations that use Cloudflare's infrastructure, which represents a significant breadth of data collection relative to a single service provider.
CA-P-007415 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
Pika · Pika Privacy Policy
Automatic data collection means Pika may build a profile of your usage patterns, device characteristics, and behavior on the platform even beyond what you actively submit, which can affect how your data is used for service improvement, analytics, or advertising.
CA-P-004313 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
Public.com · Public.com Privacy Policy
This automatic collection occurs whether or not you actively provide information, and the data gathered may be shared with advertising and analytics vendors, some of whom may use it for cross-site tracking purposes.
CA-P-008307 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Uber · Uber Privacy Notice
The collection and use of background check data for platform eligibility decisions implicates the Fair Credit Reporting Act (FCRA) requirements for adverse action notices and permissible purpose, and the periodic update mechanism means drivers may be subject to ongoing screening throughout their engagement with the platform.
CA-P-002030 First tracked Apr 4, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial