Provision Registry

7353 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Medium × Clear all
medium Data retention
Revolut · Revolut Privacy Policy
The provision operationalizes Revolut's data retention obligations under anti-money laundering and financial services regulations, which typically mandate multi-year record preservation. The extended retention period reflects compliance requirements rather than discretionary data practices, establishing a regulatory framework for how long customer records are maintained.
CA-P-004845 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Meta Ads · Meta Privacy Policy
This provision establishes Meta's operational framework for data retention and deletion, specifying that retention determinations are individualized rather than standardized, and clarifying the scope of deletion obligations when account termination is requested. The distinction between user-posted content subject to deletion and third-party-shared information that remains in Meta's systems creates separate data management pathways.
CA-P-000187 First tracked Apr 3, 2026 Last seen Apr 27, 2026 Compare across platforms →
medium Data retention
Dropbox · Dropbox Privacy Policy
The clause defines the operational retention timeline for user data and establishes a deletion initiation process rather than immediate deletion upon account termination. The 30-day window creates a defined transition period between account closure and data removal completion.
CA-P-001040 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
OpenAI · OpenAI Privacy Policy
The clause authorizes data retention across multiple operational categories (service provision, legal obligations, dispute resolution, contract enforcement) without specifying fixed retention timelines, establishing a principle-based rather than time-bound retention framework.
CA-P-000090 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Tabnine · Tabnine Privacy Policy
The provision creates a dual retention framework: a service-necessity standard for ongoing operations, and a broader set of institutional purposes (legal compliance, dispute resolution, fraud prevention, agreement enforcement, legitimate interests) that may extend retention beyond active service provision. This structure allows data retention across multiple operational and legal contexts.
CA-P-004225 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Data retention
Walmart · Walmart Privacy Policy
This provision establishes the operational framework governing how long Walmart maintains personal data in its systems. The clause ties retention duration to specific business and legal functions rather than establishing a fixed timeline, which means retention periods may vary across different data categories.
CA-P-005044 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Steam · Steam Privacy Policy
This provision establishes the operational framework governing data lifecycle management within Valve's systems, specifying both the retention trigger (purposes fulfilled) and the disposal mechanism (deletion or anonymization). The clause delineates Valve's obligations regarding when and how personal data transitions from active processing to removal or anonymization.
CA-P-006586 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Venmo · Venmo Privacy Policy
The clause operationalizes data retention by anchoring it to functional necessity rather than fixed time periods, which means retention duration varies based on the specific purposes for which data was collected and applicable regulatory requirements.
CA-P-002802 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data retention
Bumble · Bumble Privacy Policy
The clause operationalizes data retention constraints by tying data lifecycle management to dual criteria: functional necessity and legal compliance ceilings. This establishes a procedural framework for when Bumble must delete or depersonalize user data rather than maintaining indefinite archives.
CA-P-001200 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Udemy · Udemy Privacy Policy
The provision establishes a flexible retention framework that ties data persistence to operational and legal necessity rather than fixed time periods. This structure authorizes retention decisions based on multiple justifications, each with potentially different duration implications.
CA-P-006796 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Headspace · Headspace Privacy Policy
The retention policy creates a tiered framework that ties data persistence to operational relationship status and legal requirements rather than a fixed retention schedule. This structure permits extended retention periods when legal obligations or litigation risk factors are present, giving the entity discretion in applying retention timeframes within the bounds stated.
CA-P-001140 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Character.AI · Character.ai Privacy Policy
This provision establishes the operational framework governing how long Character.AI maintains user data in its systems. It conditions retention duration on both the original collection purpose and user-initiated choices, creating variable retention periods rather than fixed deletion timelines.
CA-P-000790 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Privacy rights
Unity · Unity Privacy Policy
The absence of specific, published retention periods for key data types such as advertising identifiers and behavioral data makes it difficult for users to know when their information will be deleted, and regulators in some jurisdictions require more granular retention schedules.
CA-P-005895 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Monday.com · Monday.com Privacy Policy
This provision establishes the operational framework governing the company's data lifecycle management, defining both the retention triggers (service provision and stated purposes) and the mandatory procedures for data disposition (deletion, anonymization, or isolation). The clause creates a procedural obligation to eventually eliminate retained data rather than maintain indefinite archives.
CA-P-005659 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Webull · Webull Privacy Policy
This clause defines the operational boundaries for how long Webull stores user data, establishing that retention periods are governed by necessity of purpose and legal compliance rather than indefinite storage. The provision creates a structured framework requiring ongoing assessment of retention appropriateness based on specified criteria.
CA-P-000496 First tracked Apr 3, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Binance.US · Binance.US Privacy Policy
This provision establishes the temporal scope and operational basis for data retention. By anchoring retention to legal compliance obligations and dispute resolution, the clause creates an indefinite retention framework where retention duration is determined by regulatory requirements and contractual enforcement needs rather than a fixed time period.
CA-P-000542 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Medium · Medium Privacy Policy
This clause defines the operational framework for data retention duration and grounds for post-termination retention. It establishes that retention extends beyond active account status for specified institutional purposes, rather than limiting retention to the active service period alone.
CA-P-006299 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Cursor · Cursor Privacy Policy
The policy discloses that certain interactions not visible in a user's history may be retained for safety and system monitoring purposes, meaning the absence of data in a user's visible history does not confirm that data has been deleted.
CA-P-011606 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Kick · Kick Privacy Policy
The clause defines the retention standard as tied to legitimate business necessity rather than establishing fixed retention periods, which means data retention duration depends on the classified purpose of collection and applicable regulatory obligations.
CA-P-005953 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Ledger · Ledger Privacy Policy
This provision establishes the operational framework for data retention duration, permitting extended retention periods when justified by legal compliance requirements or contractual enforcement needs, rather than restricting retention to a fixed timeframe.
CA-P-003655 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
AWS · AWS Privacy Notice
This provision establishes the data retention framework governing how long AWS maintains personal information in its systems. The retention period is tied to service delivery necessity, stated purposes, legal mandates, and specific communications to users rather than a fixed timeframe.
CA-P-005587 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Privacy rights
Replicate · Replicate Privacy Policy
The retention period is not specified in concrete terms, meaning your data could be kept for an indefinite period under the broadly stated 'legitimate interests' justification, and residual backup copies may persist even after a deletion request.
CA-P-004182 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Eufy · Eufy Privacy Policy
Without specific retention periods stated for sensitive data categories like video footage and biometric data, users cannot know how long their most sensitive information is kept, and regulators may view this as inconsistent with data minimization principles.
CA-P-009532 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Lyft · Lyft Privacy Policy
An open-ended retention standard without specific timeframes for each data category makes it difficult for users to know how long sensitive information like location history and trip data is retained, which affects their ability to exercise deletion rights meaningfully.
CA-P-008047 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TaskRabbit · TaskRabbit Privacy Policy
The retention provision does not specify defined retention periods for any category of personal information, relying instead on general necessity language, which may require evaluation against GDPR data minimization and storage limitation principles requiring specific, documented retention schedules.
CA-P-005174 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Midjourney · Midjourney Privacy Policy
The policy does not specify fixed retention periods for most data categories, instead using purpose-based retention language; the carve-out allowing extended retention to improve service functionality could cover a broad range of operational activities.
CA-P-000674 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Netflix · Netflix Privacy Statement
The policy does not state specific retention durations for most data categories, instead reserving discretion to determine retention based on business and legal purposes; this may be relevant to users exercising deletion rights under GDPR, CCPA, or other applicable law.
CA-P-000350 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Coinbase · Coinbase Privacy Policy
Because Coinbase is subject to financial regulatory recordkeeping requirements under the Bank Secrecy Act and related rules, certain data including transaction records and identity documents may be retained for five years or more after account closure, limiting the practical effect of deletion requests.
CA-P-011714 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TransUnion · TransUnion Privacy Policy
There is no fixed maximum retention period for most personal data at TransUnion, and anonymized data derived from your information may be kept and used forever, even if you later request deletion of your identifiable data.
CA-P-009413 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Grubhub · Grubhub Privacy Policy
The additional retention period beyond account closure is not defined by a specific timeframe, meaning your data may be retained for an indeterminate period after you close your account, which limits the practical effect of account deletion.
CA-P-005743 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial