Provision Registry

288 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Data retention × Medium × Clear all
medium Data retention
Cursor · Cursor Data Use & Privacy Overview
The provision creates a conditional data handling framework where Privacy Mode activation triggers modified data retention policies with external model providers while preserving Cursor's ability to retain code data for feature development. This distinction establishes different operational parameters for data handling depending on user configuration.
CA-P-010698 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Windsurf · Windsurf Terms of Service
The provision creates a conditional data governance framework where Pro Users can elect restrictive data practices for standard operations, but the restrictions are suspended when using designated model variants or opt-in features that functionally require data persistence. This structure ties data retention authorization directly to the specific model selection and feature activation.
CA-P-010266 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
Windsurf · Windsurf Terms of Service
The clause establishes a discretionary data handling framework for Pro Users, permitting them to implement stricter data retention and usage controls than the default service terms, with explicit carve-outs for models designated as non-ZDR where content storage is permitted for service delivery.
CA-P-004079 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Minecraft · Minecraft Privacy Statement
The clause creates a variable retention framework rather than fixed deletion timelines, which means data lifecycle management is contingent on operational necessity and legal requirements rather than predetermined schedules. This structure requires the entity to determine retention duration based on contextual factors for different data categories.
CA-P-004710 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Reddit · Reddit Privacy Policy
The provision creates a two-stage deletion process: account visibility termination is immediate, but content persistence depends on prior user action. This distinction establishes Reddit's data retention authority during the deletion process and permits indefinite retention of anonymized or legally-mandated information, affecting the scope and timeline of data removal.
CA-P-000713 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Amazon Marketplace · Amazon Privacy Notice
The retention standard establishes that data retention is tied to service provision, legal compliance obligations, and disclosed purposes rather than automatic deletion upon account closure or service discontinuation. This creates an ongoing data retention framework with multiple operational justifications.
CA-P-002302 First tracked Apr 9, 2026 Last seen Apr 9, 2026 Compare across platforms →
Anthropic · Anthropic Privacy Policy
The provision establishes a deletion mechanism with two operational components: a general data deletion request process subject to exceptions, and an immediate conversation-level deletion with a defined 30-day backend purge timeline. The 30-day backend retention period represents the operative timeframe between user-initiated deletion and complete removal from backend infrastructure.
CA-P-000104 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
Anthropic · Anthropic Privacy Policy
The provision establishes a data deletion mechanism with two operational pathways: user-initiated deletion requests for personal data (subject to exceptions) and automatic deletion of conversation records following a 30-day backend retention period. This structure creates distinct timelines for different data categories.
CA-P-004653 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Robinhood · Robinhood Customer Agreement
This clause establishes the operational framework under which RHS monetizes securities lending activity. By retaining all compensation from lending activities, RHS creates a revenue stream from account assets while margin account holders bear the counterparty risk associated with securities being loaned.
CA-P-007602 First tracked May 9, 2026 Last seen May 11, 2026 Compare across platforms →
Uniswap · Uniswap Terms of Service
The clause establishes the operational framework for data handling within the Support Chatbot feature, defining the permissible uses of conversation data and establishing that users bear responsibility for avoiding submission of sensitive information to an automated support channel. The accuracy disclaimer allocates responsibility for validating chatbot-generated content to the user rather than the service provider.
CA-P-004630 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Google Gemini · Gemini Apps Privacy Notice
The clause creates a two-phase deletion process: immediate deletion of primary activity data coupled with permissible short-term retention of ancillary data for technical system purposes. This structure defines the operational scope and timeline for data removal rather than immediate complete erasure.
CA-P-002313 First tracked Apr 9, 2026 Last seen Apr 9, 2026 Compare across platforms →
medium Data retention
Character.AI · Character.ai Privacy Policy
The provision establishes the operational mechanism by which Character.AI obtains user identity information through federated authentication, rather than requiring users to create separate credentials. This creates a data flow pathway from third-party platforms to Character.AI's systems during the login process.
CA-P-000791 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Google Gemini · Gemini Apps Privacy Notice
The clause establishes a standard data retention practice for reviewed conversations, defining the temporal scope of data persistence in the service infrastructure. This retention period governs how long Google maintains access to conversation records for operational, quality, and compliance purposes.
CA-P-003711 First tracked Apr 28, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Windsurf · Windsurf Security & Data Handling
The provision operationalizes different data handling standards based on subscription tier, with enterprise and team arrangements automatically excluding data retention while individual users must affirmatively elect this configuration.
CA-P-010663 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Eufy · Eufy Privacy Policy
This clause operationalizes data subject rights under privacy regulations by establishing a defined request mechanism and contact point. The provision creates a procedural structure through which users can initiate data access, modification, or deletion processes managed by Eufy's privacy function.
CA-P-006288 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Reddit · Reddit Privacy Policy
The clause establishes a self-service mechanism for account termination and specifies the operational effect of deletion on profile visibility and content attribution, clarifying the scope of what account removal accomplishes within the platform's system.
CA-P-000709 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Kick · Kick Privacy Policy
This clause operationalizes data subject rights by creating a defined process through which users can exercise control over retained personal information. The provision establishes Kick's obligation to implement deletions across both its own systems and those of contracted service providers.
CA-P-005952 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Duolingo · Duolingo Privacy Policy
This clause operationalizes data subject rights that vary by jurisdiction, establishing a procedural mechanism for users to exercise legally-recognized rights where applicable. It designates privacy@duolingo.com as the contact point for processing such requests.
CA-P-005770 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
MyFitnessPal · MyFitnessPal Privacy Policy
The provision establishes that MyFitnessPal recognizes jurisdiction-dependent data subject rights and makes these rights available to users where applicable by law. The clause creates an operational framework acknowledging differential legal obligations across jurisdictions.
CA-P-006171 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Oura · Oura Privacy Policy
The clause creates a consent-based processing framework where the company conditions sensitive data processing on affirmative user action, either through explicit consent or through functional use of designated application features.
CA-P-004913 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Atlassian · Atlassian Privacy Policy
The clause establishes procedural mechanisms through which data subjects can exercise statutory privacy rights under applicable data protection frameworks. It specifies the portal submission process as the operational pathway for accessing and controlling personal information records.
CA-P-006100 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Strava · Strava Privacy Policy
The provision operationalizes a multi-document privacy framework for US users, requiring reference to state-specific notices and health data policies in addition to the base policy. This structure indicates Strava maintains differentiated privacy terms based on jurisdictional requirements.
CA-P-004930 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Grammarly · Grammarly Privacy Policy
The clause establishes Grammarly's procedural obligations to honor user data rights requests and identifies the mechanisms through which users can exercise those rights, with response timelines tied to regulatory requirements.
CA-P-004132 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
Netflix · Netflix Privacy Statement
The clause establishes procedural mechanisms through which users can exercise data subject rights under privacy regulations, requiring Netflix to maintain processes for receiving and responding to such requests.
CA-P-002625 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
OpenAI · OpenAI Privacy Policy
This clause establishes OpenAI's operational framework for responding to privacy rights requests that vary by jurisdiction. The provision designates a centralized mechanism (Privacy Portal) through which users initiate formal requests for personal data handling, ensuring requests are processed through documented procedures.
CA-P-003159 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
Fireworks AI · Fireworks AI Privacy Policy
The clause establishes a self-service mechanism for data subject exercise of access, portability, and deletion rights. It conditions the scope of these rights on jurisdictional requirements, meaning the availability and extent of these rights depend on applicable privacy regulations in the user's location.
CA-P-005149 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Noom · Noom Privacy Policy
The provision establishes that user data rights are conditional on applicable law by location, meaning the scope and availability of these rights vary by jurisdiction rather than applying uniformly to all users.
CA-P-003847 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
Coursera · Coursera Privacy Notice
The provision establishes procedural mechanisms through which users can exercise data subject rights recognized under certain legal regimes. These requests operate as formal channels for users to exercise control over personal information retention and use, with Coursera required to respond according to applicable legal obligations.
CA-P-002858 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
GitHub · GitHub Privacy Statement
The provision establishes procedural obligations for GitHub to process data subject requests and operationalizes statutory rights that vary by jurisdiction. The response timeline requirement creates a defined operational standard for handling such requests.
CA-P-003598 First tracked Apr 27, 2026 Last seen Apr 27, 2026 Compare across platforms →
Airbnb · Airbnb Privacy Policy
The provision operationalizes data subject rights that arise under various privacy regulations by designating account settings and direct contact as the primary mechanisms for users to request exercise of these rights. This establishes Airbnb's responsibility to respond to such requests and creates a procedural framework for handling data access, correction, and deletion requests.
CA-P-011494 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial