Provision Registry

12505 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
medium Data retention
Steam · Steam Privacy Policy
This provision establishes the operational framework governing data lifecycle management within Valve's systems, specifying both the retention trigger (purposes fulfilled) and the disposal mechanism (deletion or anonymization). The clause delineates Valve's obligations regarding when and how personal data transitions from active processing to removal or anonymization.
CA-P-006586 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Chegg · Chegg Privacy Policy
This provision establishes the operational parameters for data lifecycle management within Chegg's systems. It clarifies that retention duration is tied to specific business and legal purposes rather than indefinite storage, and identifies the conditions under which deletion or anonymization procedures are triggered.
CA-P-001831 First tracked Apr 3, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Duo Security · Duo Privacy
The provision establishes operational criteria for data lifecycle management rather than fixed retention periods. This approach permits extended retention based on institutional assessment of necessity and risk factors, rather than automatic deletion at specified intervals.
CA-P-004677 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Hinge · Hinge Privacy Policy
The clause creates a defined data retention schedule that balances service operations and legal compliance with member deletion requests, specifying a post-deletion retention period for safety investigations rather than indefinite data preservation.
CA-P-001241 First tracked Apr 3, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
OnlyFans · OnlyFans Privacy Policy
The provision creates dual retention standards: a primary baseline tied to operational necessity and legal requirements, and an extended retention authorization upon occurrence of specified conditions. This structure establishes the operational parameters governing data lifecycle management and compliance duration.
CA-P-006088 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Grubhub · Grubhub Privacy Policy
The additional retention period beyond account closure is not defined by a specific timeframe, meaning your data may be retained for an indeterminate period after you close your account, which limits the practical effect of account deletion.
CA-P-005743 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Lyft · Lyft Privacy Policy
An open-ended retention standard without specific timeframes for each data category makes it difficult for users to know how long sensitive information like location history and trip data is retained, which affects their ability to exercise deletion rights meaningfully.
CA-P-008047 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
TaskRabbit · TaskRabbit Privacy Policy
The retention provision does not specify defined retention periods for any category of personal information, relying instead on general necessity language, which may require evaluation against GDPR data minimization and storage limitation principles requiring specific, documented retention schedules.
CA-P-005174 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Coinbase · Coinbase Privacy Policy
Because Coinbase is subject to financial regulatory recordkeeping requirements under the Bank Secrecy Act and related rules, certain data including transaction records and identity documents may be retained for five years or more after account closure, limiting the practical effect of deletion requests.
CA-P-011714 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
OpenAI · OpenAI Privacy Policy
The clause authorizes data retention across multiple operational categories (service provision, legal obligations, dispute resolution, contract enforcement) without specifying fixed retention timelines, establishing a principle-based rather than time-bound retention framework.
CA-P-000090 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Eufy · Eufy Privacy Policy
Without specific retention periods stated for sensitive data categories like video footage and biometric data, users cannot know how long their most sensitive information is kept, and regulators may view this as inconsistent with data minimization principles.
CA-P-009532 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Shopify · Shopify Privacy Policy
This provision establishes the retention timeline and deletion procedures for personal data held by Shopify. It defines the operational framework under which data lifecycle management occurs, specifying both the retention triggers and the deletion or anonymization obligations that conclude the retention period.
CA-P-002225 First tracked Apr 4, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Webull · Webull Privacy Policy
This clause defines the operational boundaries for how long Webull stores user data, establishing that retention periods are governed by necessity of purpose and legal compliance rather than indefinite storage. The provision creates a structured framework requiring ongoing assessment of retention appropriateness based on specified criteria.
CA-P-000496 First tracked Apr 3, 2026 Last seen Apr 28, 2026 Compare across platforms →
medium Data retention
Venmo · Venmo Privacy Policy
The clause operationalizes data retention by anchoring it to functional necessity rather than fixed time periods, which means retention duration varies based on the specific purposes for which data was collected and applicable regulatory requirements.
CA-P-002802 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Privacy rights
EA · EA Privacy and Cookie Policy
The absence of defined retention periods means users cannot predict when their data will be deleted, and the broad 'operational or other legitimate reasons' exception could support extended retention well beyond what users might expect.
CA-P-009052 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Craigslist · Craigslist Privacy Policy
The absence of a defined retention period means your personal data, including contact details, location history, and device identifiers, could be held indefinitely as long as Craigslist determines a functional reason exists.
CA-P-008253 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Leonardo AI · Leonardo AI Privacy Policy
The retention policy defines the operational lifecycle of user data within Leonardo AI's systems and establishes the conditions under which data disposal or anonymization occurs. This framework addresses both service continuity requirements and data minimization obligations under privacy regulations.
CA-P-004197 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Privacy rights
TurboTax · TurboTax Privacy Statement
The absence of specific retention periods for sensitive financial data like SSNs and tax returns means your data may remain in Intuit's systems for extended periods, increasing the window of exposure to breach or secondary use.
CA-P-010238 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Robinhood · Robinhood Privacy Policy
This provision establishes the retention framework governing how long Robinhood maintains personal data in its systems. The operational significance lies in the connection between retention duration and specific institutional purposes—legal compliance, dispute resolution, and contract enforcement—rather than retention by default.
CA-P-002208 First tracked Apr 4, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Privacy rights
Xfinity · Comcast Privacy Policy
Open-ended retention standards without specific time limits for sensitive data categories like browsing history, viewing data, or biometrics may not satisfy state laws that require defined retention schedules, and longer retention increases data breach risk.
CA-P-001720 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Mixpanel · Mixpanel Privacy Statement
Retention periods are not defined with specific timeframes in this provision, meaning the duration for which personal data may be held is discretionary within the bounds of stated business necessity and applicable law.
CA-P-011467 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Cursor · Cursor Privacy Policy
The policy discloses that certain interactions not visible in a user's history may be retained for safety and system monitoring purposes, meaning the absence of data in a user's visible history does not confirm that data has been deleted.
CA-P-011606 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Upwork · Upwork Privacy Policy
The provision defines the operational framework for data lifecycle management post-closure, establishing that retention duration depends on identification of legitimate business purposes rather than a fixed timeline, and creates obligations for either deletion, anonymization, or secure isolation as alternatives.
CA-P-006528 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Webull · Webull Privacy Policy
This provision establishes Webull's operational framework for data lifecycle management post-account closure. The retention criteria create a standard whereby personal information persists in systems based on institutional requirements rather than automatic deletion upon account termination.
CA-P-002739 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Privacy rights
Yelp · Yelp Privacy Policy
Account closure does not result in immediate deletion of personal data; Yelp retains data indefinitely for broadly stated legal and business purposes, which means personal information persists even after a user has ended their relationship with the platform.
CA-P-009023 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Coinbase · Coinbase Privacy Policy
This clause specifies the operational framework for data lifecycle management post-account-termination and establishes the conditions triggering deletion obligations. It delineates Coinbase's responsibilities to remove personal information contingent on account status and affirmative user deletion requests or legal requirements.
CA-P-000417 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
WhatsApp · WhatsApp Privacy Policy
The provision operationalizes distinct data deletion protocols based on the method of account termination, establishing that the in-app deletion process triggers immediate removal of specified data categories while alternative removal methods result in continued server storage. This distinction creates procedural requirements for users seeking expedited data removal.
CA-P-000954 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Luma AI · Luma AI Privacy Policy
The clause establishes that data deletion requests do not trigger immediate removal of all personal information retained by the entity. Post-deletion retention is conditioned on legal obligations, regulatory compliance requirements, and operational backup procedures, which may extend the duration of data storage beyond the account deletion date.
CA-P-006375 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Roblox · Roblox Privacy Policy
This provision establishes a two-year post-deletion retention period for persistent identifiers, which creates a materially longer data lifecycle than account deletion alone would suggest. Under GDPR, retention beyond what is necessary for the original purpose requires a documented lawful basis and proportionality justification; under CCPA and similar state laws, users' deletion rights may be subject to exceptions for security and fraud prevention purposes.
CA-P-009159 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Netflix · Netflix Privacy Statement
This clause establishes Netflix's operational framework for data persistence post-cancellation, clarifying that service termination does not automatically trigger deletion of personal information. The provision creates a retention regime tied to legal compliance, dispute resolution, and fraud prevention rather than to active subscription status.
CA-P-003913 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial