Provision Registry

7353 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Medium × Clear all
medium Data retention
Airbnb · Airbnb Privacy Policy
This provision establishes the operational scope and duration of data retention by defining retention triggers (contract performance and legal compliance) and creates a mechanism for users to initiate account deletion while preserving Airbnb's obligation to maintain records for regulatory and legal purposes.
CA-P-006870 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Duolingo · Duolingo Privacy Policy
This provision defines the operational framework for data lifecycle management, establishing both the retention trigger (service provision and stated purposes) and the termination mechanism (deletion or anonymization upon cessation of need). The clause ties retention duration to functional necessity rather than a fixed time period.
CA-P-002768 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data retention
Chegg · Chegg Privacy Policy
This provision establishes the operational parameters for data lifecycle management within Chegg's systems. It clarifies that retention duration is tied to specific business and legal purposes rather than indefinite storage, and identifies the conditions under which deletion or anonymization procedures are triggered.
CA-P-001831 First tracked Apr 3, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Kick · Kick Privacy Policy
The clause defines the retention standard as tied to legitimate business necessity rather than establishing fixed retention periods, which means data retention duration depends on the classified purpose of collection and applicable regulatory obligations.
CA-P-005953 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
OnlyFans · OnlyFans Privacy Policy
The provision creates dual retention standards: a primary baseline tied to operational necessity and legal requirements, and an extended retention authorization upon occurrence of specified conditions. This structure establishes the operational parameters governing data lifecycle management and compliance duration.
CA-P-006088 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Peloton · Peloton Privacy Policy
The provision establishes a document structure where state-specific privacy obligations, including data retention requirements, are consolidated in a separate notice rather than integrated into the primary privacy policy.
CA-P-001179 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Fiverr · Fiverr Privacy Policy
The retention framework creates an operational structure where data persistence extends beyond active service delivery to encompass post-termination periods, establishing legitimate business purposes as a retention basis alongside legal compliance requirements.
CA-P-000867 First tracked Apr 3, 2026 Last seen Apr 27, 2026 Compare across platforms →
medium Data retention
MyFitnessPal · MyFitnessPal Privacy Policy
This provision establishes the operational framework governing data lifecycle management, defining both the retention period (necessity-based) and the deletion mechanism (upon request with specified exceptions). The clause creates a conditional retention model tied to service provision and legal compliance requirements.
CA-P-006168 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Redfin · Redfin Privacy Policy
The clause establishes a multi-category retention framework that extends data retention beyond active service periods, conditioned on operational and legal justifications rather than fixed time limits. This creates ongoing data stewardship obligations tied to specified institutional purposes.
CA-P-001258 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Checkout.com · Checkout.com Privacy
The provision operationalizes Checkout.com's compliance obligations under data protection and financial services regulations, which typically mandate multi-year retention of transaction records for audit, dispute resolution, and regulatory reporting. The indefinite retention of anonymized analytical data enables the entity to maintain historical performance metrics and trend analysis without ongoing retention justifications.
CA-P-006973 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Glean · Glean Privacy Policy
The clause establishes the operational framework for data retention periods across different processing contexts. It distinguishes between Glean's independent data controller retention practices and its processor obligations, which are governed by customer instructions rather than unilateral Glean policy.
CA-P-004387 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Data retention
Grindr · Grindr Privacy Policy
The retention framework operationalizes Grindr's data stewardship practices by defining temporal boundaries for different data categories and establishing that post-deletion retention serves specific institutional functions (internal reporting, metrics, statistics) rather than ongoing service delivery.
CA-P-001416 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Groq · Groq Privacy Policy
This provision establishes the operational framework governing how long personal information remains in Groq's systems. The multi-factor retention standard creates flexibility in retention periods across different data categories based on assessed risk and regulatory context rather than a uniform deletion timeline.
CA-P-004220 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Data retention
Hinge · Hinge Privacy Policy
The clause creates a defined data retention schedule that balances service operations and legal compliance with member deletion requests, specifying a post-deletion retention period for safety investigations rather than indefinite data preservation.
CA-P-001241 First tracked Apr 3, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Fitbit · Fitbit Privacy Policy
This provision establishes the operational basis for data retention across different data categories, distinguishing between account infrastructure data (required for service continuity) and user-generated activity data (retained pending user-initiated deletion). The structure creates different retention lifecycles based on functional necessity.
CA-P-001454 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Stability AI · Stability AI Privacy Policy
The clause defines the operational retention framework for personal data processing, establishing both a necessity standard and a hard temporal limit that aligns with privacy-by-design principles while carving out exceptions for legal compliance obligations.
CA-P-001626 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Privacy rights
EA · EA Privacy and Cookie Policy
The absence of defined retention periods means users cannot predict when their data will be deleted, and the broad 'operational or other legitimate reasons' exception could support extended retention well beyond what users might expect.
CA-P-009052 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cursor · Cursor Privacy Policy
The policy discloses that certain interactions not visible in a user's history may be retained for safety and system monitoring purposes, meaning the absence of data in a user's visible history does not confirm that data has been deleted.
CA-P-011606 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TurboTax · TurboTax Privacy Statement
The absence of specific retention periods for sensitive financial data like SSNs and tax returns means your data may remain in Intuit's systems for extended periods, increasing the window of exposure to breach or secondary use.
CA-P-010238 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Binance.US · Binance.US Privacy Policy
This provision establishes the temporal scope and operational basis for data retention. By anchoring retention to legal compliance obligations and dispute resolution, the clause creates an indefinite retention framework where retention duration is determined by regulatory requirements and contractual enforcement needs rather than a fixed time period.
CA-P-000542 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Ledger · Ledger Privacy Policy
This provision establishes the operational framework for data retention duration, permitting extended retention periods when justified by legal compliance requirements or contractual enforcement needs, rather than restricting retention to a fixed timeframe.
CA-P-003655 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
OpenAI · Privacy Policy (ROW)
The clause operationalizes data lifecycle management by anchoring retention to multiple justified purposes rather than a fixed timeline. This structure permits extended retention where legal or operational justification exists while establishing that retention is not indefinite.
CA-P-000046 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Gemini · Gemini Privacy Policy
Understanding how long your data is retained is important, particularly given the sensitivity of the financial and identity data Gemini collects and the regulatory requirements that mandate retention of financial records.
CA-P-000556 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Venmo · Venmo Privacy Policy
The clause operationalizes data retention by anchoring it to functional necessity rather than fixed time periods, which means retention duration varies based on the specific purposes for which data was collected and applicable regulatory requirements.
CA-P-002802 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data retention
DocuSign · DocuSign Privacy Statement
The clause defines the operational parameters for data lifecycle management by tying retention duration to stated business and legal purposes rather than establishing a fixed time period, which affects the scope and duration of DocuSign's data stewardship obligations.
CA-P-001056 First tracked Apr 3, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
DoorDash · DoorDash Privacy Policy
The clause creates an operational standard for data lifecycle management by tying retention duration to specific, enumerated purposes rather than indefinite retention. It establishes that data destruction or de-identification is the default outcome when retention purposes are satisfied, subject to legal hold or litigation defense requirements.
CA-P-005480 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Walmart · Walmart Privacy Policy
This provision establishes the operational framework governing how long Walmart maintains personal data in its systems. The clause ties retention duration to specific business and legal functions rather than establishing a fixed timeline, which means retention periods may vary across different data categories.
CA-P-005044 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
ZipRecruiter · ZipRecruiter Privacy Policy
Without clearly specified retention periods, it is difficult for users to know how long their job search history, resume data, and profile information will remain in ZipRecruiter's systems and accessible to employers.
CA-P-005498 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Bumble · Bumble Privacy Policy
The clause operationalizes data retention constraints by tying data lifecycle management to dual criteria: functional necessity and legal compliance ceilings. This establishes a procedural framework for when Bumble must delete or depersonalize user data rather than maintaining indefinite archives.
CA-P-001200 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
AWS · AWS Privacy Notice
This provision establishes the data retention framework governing how long AWS maintains personal information in its systems. The retention period is tied to service delivery necessity, stated purposes, legal mandates, and specific communications to users rather than a fixed timeframe.
CA-P-005587 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial