Provision Registry

7353 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Medium × Clear all
medium Data retention
Binance.US · Binance.US Privacy Policy
This provision establishes the temporal scope and operational basis for data retention. By anchoring retention to legal compliance obligations and dispute resolution, the clause creates an indefinite retention framework where retention duration is determined by regulatory requirements and contractual enforcement needs rather than a fixed time period.
CA-P-000542 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Squarespace · Squarespace Privacy Policy
The clause creates a need-based retention standard rather than fixed retention periods, authorizing Squarespace to maintain data for operational and compliance purposes while establishing obligations to remove or isolate data when business justification ends. This affects the duration and scope of data processing the company conducts.
CA-P-006878 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
EA · EA Privacy and Cookie Policy
The absence of defined retention periods means users cannot predict when their data will be deleted, and the broad 'operational or other legitimate reasons' exception could support extended retention well beyond what users might expect.
CA-P-009052 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Home Depot · Home Depot Privacy Policy
This provision establishes Home Depot's operational framework for data lifecycle management, defining both the retention period (tied to stated purposes and legal obligations) and the company's obligation to dispose of data upon purpose completion. The clause creates a time-limited retention model rather than indefinite data storage.
CA-P-006761 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Leonardo AI · Leonardo AI Privacy Policy
The retention policy defines the operational lifecycle of user data within Leonardo AI's systems and establishes the conditions under which data disposal or anonymization occurs. This framework addresses both service continuity requirements and data minimization obligations under privacy regulations.
CA-P-004197 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Privacy rights
Cursor · Cursor Privacy Policy
The policy discloses that certain interactions not visible in a user's history may be retained for safety and system monitoring purposes, meaning the absence of data in a user's visible history does not confirm that data has been deleted.
CA-P-011606 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Steam · Steam Privacy Policy
This provision establishes the operational framework governing data lifecycle management within Valve's systems, specifying both the retention trigger (purposes fulfilled) and the disposal mechanism (deletion or anonymization). The clause delineates Valve's obligations regarding when and how personal data transitions from active processing to removal or anonymization.
CA-P-006586 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Headspace · Headspace Privacy Policy
The retention policy creates a tiered framework that ties data persistence to operational relationship status and legal requirements rather than a fixed retention schedule. This structure permits extended retention periods when legal obligations or litigation risk factors are present, giving the entity discretion in applying retention timeframes within the bounds stated.
CA-P-001140 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Robinhood · Robinhood Privacy Policy
This provision establishes the retention framework governing how long Robinhood maintains personal data in its systems. The operational significance lies in the connection between retention duration and specific institutional purposes—legal compliance, dispute resolution, and contract enforcement—rather than retention by default.
CA-P-002208 First tracked Apr 4, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Data retention
Shopify · Shopify Privacy Policy
This provision establishes the retention timeline and deletion procedures for personal data held by Shopify. It defines the operational framework under which data lifecycle management occurs, specifying both the retention triggers and the deletion or anonymization obligations that conclude the retention period.
CA-P-002225 First tracked Apr 4, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data retention
Bumble · Bumble Privacy Policy
The clause operationalizes data retention constraints by tying data lifecycle management to dual criteria: functional necessity and legal compliance ceilings. This establishes a procedural framework for when Bumble must delete or depersonalize user data rather than maintaining indefinite archives.
CA-P-001200 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
MyFitnessPal · MyFitnessPal Privacy Policy
This provision establishes the operational framework governing data lifecycle management, defining both the retention period (necessity-based) and the deletion mechanism (upon request with specified exceptions). The clause creates a conditional retention model tied to service provision and legal compliance requirements.
CA-P-006168 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Kick · Kick Privacy Policy
The clause defines the retention standard as tied to legitimate business necessity rather than establishing fixed retention periods, which means data retention duration depends on the classified purpose of collection and applicable regulatory obligations.
CA-P-005953 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Gemini · Gemini Privacy Policy
Understanding how long your data is retained is important, particularly given the sensitivity of the financial and identity data Gemini collects and the regulatory requirements that mandate retention of financial records.
CA-P-000556 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Samsung · Samsung Privacy Policy
This provision establishes the operational framework governing Samsung's data retention lifecycle and specifies the conditions under which personal information will be removed or anonymized from active systems. The clause ties retention periods to functional necessity and legal requirements rather than indefinite storage.
CA-P-005052 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Privacy rights
TurboTax · TurboTax Privacy Statement
The absence of specific retention periods for sensitive financial data like SSNs and tax returns means your data may remain in Intuit's systems for extended periods, increasing the window of exposure to breach or secondary use.
CA-P-010238 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
RunPod · RunPod Privacy Policy
This provision establishes RunPod's data retention framework by authorizing retention based on functional necessity rather than specifying fixed deletion timelines. The operational significance lies in the institution's discretion to maintain data across multiple retention scenarios determined by internal assessment criteria.
CA-P-005946 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Tabnine · Tabnine Privacy Policy
The provision creates a dual retention framework: a service-necessity standard for ongoing operations, and a broader set of institutional purposes (legal compliance, dispute resolution, fraud prevention, agreement enforcement, legitimate interests) that may extend retention beyond active service provision. This structure allows data retention across multiple operational and legal contexts.
CA-P-004225 First tracked Apr 30, 2026 Last seen Apr 30, 2026 Compare across platforms →
medium Data retention
Rumble · Rumble Privacy Policy
The clause creates a standard data retention framework tied to operational necessity while preserving Rumble's ability to maintain data longer when legally required, establishing the institutional basis for how long personal data remains in active use or storage systems.
CA-P-004492 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data retention
Figma · Figma Privacy Policy
The clause establishes retention criteria based on functional necessity rather than fixed time periods, meaning data persistence is tied to stated operational and legal purposes rather than automatic deletion schedules. This framework allocates responsibility for determining retention duration based on the purposes identified at collection.
CA-P-001112 First tracked Apr 3, 2026 Last seen May 7, 2026 Compare across platforms →
medium Privacy rights
Mixpanel · Mixpanel Privacy Statement
Retention periods are not defined with specific timeframes in this provision, meaning the duration for which personal data may be held is discretionary within the bounds of stated business necessity and applicable law.
CA-P-011467 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Character.AI · Character.ai Privacy Policy
This provision establishes the operational framework governing how long Character.AI maintains user data in its systems. It conditions retention duration on both the original collection purpose and user-initiated choices, creating variable retention periods rather than fixed deletion timelines.
CA-P-000790 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Upwork · Upwork Privacy Policy
The provision defines the operational framework for data lifecycle management post-closure, establishing that retention duration depends on identification of legitimate business purposes rather than a fixed timeline, and creates obligations for either deletion, anonymization, or secure isolation as alternatives.
CA-P-006528 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Yelp · Yelp Privacy Policy
Account closure does not result in immediate deletion of personal data; Yelp retains data indefinitely for broadly stated legal and business purposes, which means personal information persists even after a user has ended their relationship with the platform.
CA-P-009023 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
Webull · Webull Privacy Policy
This provision establishes Webull's operational framework for data lifecycle management post-account closure. The retention criteria create a standard whereby personal information persists in systems based on institutional requirements rather than automatic deletion upon account termination.
CA-P-002739 First tracked Apr 18, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data retention
Coinbase · Coinbase Privacy Policy
This clause specifies the operational framework for data lifecycle management post-account-termination and establishes the conditions triggering deletion obligations. It delineates Coinbase's responsibilities to remove personal information contingent on account status and affirmative user deletion requests or legal requirements.
CA-P-000417 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Privacy rights
Roblox · Roblox Privacy Policy
This provision establishes a two-year post-deletion retention period for persistent identifiers, which creates a materially longer data lifecycle than account deletion alone would suggest. Under GDPR, retention beyond what is necessary for the original purpose requires a documented lawful basis and proportionality justification; under CCPA and similar state laws, users' deletion rights may be subject to exceptions for security and fraud prevention purposes.
CA-P-009159 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data retention
WhatsApp · WhatsApp Privacy Policy
The provision operationalizes distinct data deletion protocols based on the method of account termination, establishing that the in-app deletion process triggers immediate removal of specified data categories while alternative removal methods result in continued server storage. This distinction creates procedural requirements for users seeking expedited data removal.
CA-P-000954 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data retention
Luma AI · Luma AI Privacy Policy
The clause establishes that data deletion requests do not trigger immediate removal of all personal information retained by the entity. Post-deletion retention is conditioned on legal obligations, regulatory compliance requirements, and operational backup procedures, which may extend the duration of data storage beyond the account deletion date.
CA-P-006375 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Data retention
Netflix · Netflix Privacy Statement
This clause establishes Netflix's operational framework for data persistence post-cancellation, clarifying that service termination does not automatically trigger deletion of personal information. The provision creates a retention regime tied to legal compliance, dispute resolution, and fraud prevention rather than to active subscription status.
CA-P-003913 First tracked Apr 28, 2026 Last seen Apr 28, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial