Live feed · updated daily

Recent policy changes

361 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
838 Documents tracked
361 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
May 1, 2026
Ancestry
Ancestry Terms and Conditions
medium
Removed CCPA opt-out link from terms footer, reducing visibility of California data sale rights.
Why it matters: CCPA requires businesses to provide California residents with a clear and conspicuous method to opt out of personal information sales and sharing. Removing the opt-out link from the terms footer reduces the discoverability of this required right from a prominent location, potentially creating a CCPA compliance gap if equivalent access is not available elsewhere.
Upwork
Upwork Terms of Service
medium
Removed Data Privacy Framework compliance disclosures; retained contact mechanism for data transfer documents.
Why it matters: The removal of Data Privacy Framework language eliminates transparent commitments about how Upwork handles personal data transfers from regulated jurisdictions. For individual users and enterprises, this creates ambiguity about the legal mechanism protecting cross-border transfers and may require verification of the current transfer arrangement.
Roblox
Roblox Privacy and Cookie Policy
medium
Restricts personalized advertising to users 18 and older; users under 18 will see only nonpersonalized ads.
Why it matters: The updated terms establish a clear age-based boundary for ad personalization, restricting targeted advertising to adults 18 and older. This change affects how minors experience the platform and limits data use for marketing purposes, which has operational implications for advertisers relying on behavioral targeting and compliance implications for organizations subject to child privacy regulations like COPPA.
Coinbase
Coinbase User Agreement
medium
Added exception permitting asset transfers to third parties for Secured USDC cardholder agreements; restricts user withdrawals of designated USDC
Why it matters: The updated terms create a new category of asset transfers that operate outside the prior framework requiring user instruction or legal mandate. Users who opt into the Secured USDC feature agree to lose withdrawal rights and permit Coinbase to follow third-party instructions without their further approval. This materially changes the control and disposition rights for designated assets and introduces a new product-specific governance structure not previously addressed in the general asset custody provisions.
OpenAI
OpenAI Privacy Policy
medium
Adds explicit direct marketing disclosures and marketing partner data sharing; introduces user controls for third-party product promotion.
Why it matters: The updated terms establish explicit authorization for OpenAI to engage in direct marketing to users and to share data with non-service-provider marketing partners to support those efforts. This change operationalizes a new category of data recipient and marketing use case that was not previously disclosed with this level of specificity. The addition of user-control mechanisms suggests OpenAI intends to scale direct-marketing activities while maintaining an option for users to opt out, which affects how personal data flows through the company's marketing operations.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

April 30, 2026
Google Gemini
Gemini Apps Privacy Notice
medium
Updated privacy notice to clarify Memory feature consent requirements and expand personalization practices globally.
Why it matters: The updated terms authorize personalization based on chat history for all users globally, whereas the prior policy restricted this to users outside regulated jurisdictions. This represents a material expansion of the scope of data processing and personalization practices. Organizations that based their vendor assessments or compliance strategies on prior geographic limitations should reevaluate their data processing documentation.
April 29, 2026
Cohere
Cohere Privacy Policy
medium
Removes specifics on data retention timelines and deletion procedures previously disclosed in privacy policy
Why it matters: The updated policy removes specific, quantified commitments about data retention and deletion request handling. Where users previously could reference a 30-day retention period and one-month response timeline from the policy document itself, they now encounter only a reference to external 'retention practices' without in-policy specificity. This reduction in transparency may create friction with regulatory requirements that mandate clear disclosure of data retention practices and user deletion rights, and it affects how downstream organizations can represent Cohere's data handling to their own customers.
FanDuel
FanDuel Privacy Policy
medium
Removed Fantasy Picks platform from privacy policy scope; affected users should verify separate privacy terms for Picks accounts.
Why it matters: A privacy policy that explicitly lists which platforms and services it covers creates user expectation and legal protection. Removing a named service (Fantasy Picks) from that scope without clearly stating an alternative privacy framework may confuse users about their rights and may trigger regulatory scrutiny under state privacy laws (CCPA, VCCPA, CPA, CTDPA) and GDPR, which require transparent disclosure of data practices.
Nextdoor
Nextdoor Privacy Policy
medium
Removed footer navigation link to 'Do not Sell or Share My Personal Data' opt-out page
Why it matters: The removal of a prominent footer link to opt-out controls may reduce the discoverability of privacy rights that California and other state privacy laws require companies to maintain in a 'clear and conspicuous' manner. If opt-out controls are no longer accessible from the footer, users must locate them through alternative navigation, and regulatory bodies may question whether the new approach satisfies conspicuousness standards. This is particularly relevant for California residents and users in other states with similar privacy statutes.
Shein
Shein Terms and Conditions
medium
Removed account persistence choice from cookie consent interface; replaced with promotional offer.
Why it matters: The removal of explicit consent language regarding account persistence eliminates a documented checkpoint where users could control whether Shein remembers their login. Under GDPR and CCPA, consent for persistent authentication tracking must be freely given and informed; removing the choice mechanism may undermine this documentation.
April 28, 2026
GitHub
GitHub Privacy Statement
high
Adds explicit authorization for collecting AI outputs from user content and sharing personal data with affiliates for AI/ML model training and product improvement.
Why it matters: The updated terms establish explicit authority for GitHub to use AI outputs and personal data for AI/ML model training and improvement, and to share this data with affiliates including Microsoft for these purposes. This expands the stated scope of data processing beyond prior language and formalizes a use case (AI model training) that some users may not have anticipated when evaluating how their code and data would be used. Organizations that have made representations to their own customers about code use restrictions or data protection measures should evaluate whether this policy change affects those commitments.
GitHub
GitHub Terms of Service
medium
Added dedicated section on AI features, training data, and user controls in Terms of Service.
Why it matters: The updated Terms of Service now establish dedicated contractual governance for AI features and data practices. This formalization allows users, customers, and regulators to identify specific terms governing AI training data uses in a single location rather than inferring them from general service language. For organizations subject to data protection regulations (GDPR, CCPA, LGPD), the explicit terms establish what data uses are contractually authorized and what user controls exist, which affects how they must represent GitHub's practices in their own data governance and customer commitments.
Cash App
Cash App Terms of Service
medium
Foreign transaction fee increased to 3.25% and fee waiver now applies to card-present transactions only
Why it matters: The updated terms increase the cost of international transactions and narrow the circumstances under which users can avoid that fee. Users who previously received a full Foreign Transaction Fee waiver for online international purchases will now pay 3.25% on those transactions even if they meet spending or deposit thresholds, as the waiver is restricted to in-person card transactions only.
April 24, 2026
YouTube
YouTube Community Guidelines
medium
Adds likeness detection capability for civic leaders and journalists to content protection framework
Why it matters: This change indicates that YouTube is broadening its enforcement of policies against deepfakes and synthetic media to protect public figures beyond creators, which may result in faster removal or labeling of synthetic content involving civic leaders and journalists and affects how such content is moderated and appealed.
April 23, 2026
Booking.com
Booking.com Privacy Statement
medium
Separates California privacy disclosures and adds opt-out rights for data sales, behavioral ads, and sensitive information limits.
Why it matters: California law (CPRA) grants residents specific rights over their data that Booking.com did not previously disclose in its main privacy notice. By separating California disclosures and adding explicit opt-out mechanisms, the updated policy clarifies which data categories the company collects, how it may share them, and what control consumers have. This matters because California residents now have actionable mechanisms to opt out of practices they may not have known were occurring.
Glassdoor
Glassdoor Privacy Policy
medium
Adds data access, correction, and deletion rights for EU/UK/Swiss users; requires opt-in for sensitive data sharing and establishes complaint resolution procedures
Why it matters: The updated policy codifies individual rights to access, correct, and delete personal data that are required under the EU-U.S. Data Privacy Framework, giving EU, UK, and Swiss users explicit procedural pathways to exercise those rights. It also establishes that sensitive data sharing requires affirmative opt-in consent, strengthening control over how personal information is used and disclosed.
Roblox
Roblox Terms of Use
high
Removes major sections on user accounts, payments, dispute resolution, arbitration, and intellectual property from Terms of Use; new version effective April 30, 2026.
Why it matters: The removal of 1,448 sentences from Roblox's binding Terms of Use, particularly sections on dispute resolution, arbitration, user account protections, and intellectual property rights, eliminates explicit contractual language that historically defined user remedies, account security, payment guarantees, and creator rights. Without visibility into replacement language, users, developers, parents, and enterprise partners cannot assess what protections remain or whether their rights have been narrowed, making informed consent to continued use difficult.
April 22, 2026
Booking.com
Booking.com Privacy Statement
medium
Removes California-specific privacy protections and replaces with US-wide terms; adds credit card vendor data-sharing disclosures.
Why it matters: The removal of California-specific sensitive data protections narrows privacy rights previously available to California consumers and may require organizations using Booking.com to update their own privacy representations. The addition of credit card vendor disclosures introduces a new third-party data controller into the data processing chain, meaning personal data will be shared with an independent party not bound by Booking.com's own privacy commitments.
Disney+
Disney+ Privacy Policy
medium
Expanded privacy policy scope to include offline data collection in theme parks, stores, resorts, and cruise ships alongside online tracking.
Why it matters: The updated policy makes explicit that Disney collects personal information not only when you stream online, but also when you visit theme parks, stores, resorts, cruise ships, or call Disney guest centers. Understanding the full scope of collection is essential for consumers who visit multiple Disney properties or use Disney+ through third-party platforms, as the policy now clearly states that privacy settings configured on third-party sites will not apply to Disney+'s own collection.
OpenAI
OpenAI Privacy Policy
medium
Removes disclosure of cookie-based marketing partner data sharing and statement on sensitive data inference protections
Why it matters: The updated terms remove explicit transparency around how OpenAI shares data with marketing partners via cookies and remove a stated protection against sensitive data inference. These removals reduce explicit consumer-facing disclosure of specific data practices that were previously described. Whether these practices continue under alternative authorization or have ceased is now unclear from the policy text alone, which may affect how consumers and regulators assess data handling practices.
April 21, 2026
SoFi
SoFi Privacy Notice (Retired URL)
medium
Replaced blanket cookie consent with category-based Privacy Preference Center; shifts from implicit acceptance to explicit preference management
Why it matters: The updated terms establish a granular consent mechanism that moves away from implied consent by silence toward explicit, category-based preference management. This change affects how SoFi collects and uses tracking data by allowing users to disable non-essential cookies while maintaining transparency about the functional consequences of doing so. The shift aligns with regulatory expectations under GDPR and state privacy laws that require affirmative, informed consent for non-essential data processing.
Plaid
Plaid Terms of Use (Legal Index)
medium
Adds explicit developer responsibility for account activities and employee/contractor data access; introduces session replay and activity monitoring oversight
Why it matters: The updated policy shifts accountability to developers for all account activities and introduces monitoring mechanisms that may affect how organizations manage team access to sensitive financial data. This creates new compliance and operational requirements for anyone integrating Plaid's services and may require updates to data processing agreements, vendor contracts, and customer privacy disclosures.
Plaid
Plaid End User Privacy Policy
high
Expands developer accountability for account access and end user data; introduces session replay and activity monitoring; adds Authorized User management requirements.
Why it matters: The updated policy shifts accountability for data access directly to developers and introduces monitoring that was not previously disclosed, creating new compliance obligations and operational risks for any organization using Plaid to handle customer financial information. Developers can no longer delegate accountability for data handling; they must now formally manage and justify every person's access to customer data.
Meta
Meta Privacy Policy
medium
Removed reference directing US residents to Regional Privacy Notice for consumer privacy rights details.
Why it matters: The Privacy Policy previously made it easy for US residents to find information about their state-level privacy rights by directing them to the Regional Privacy Notice. Removing that direction reduces policy transparency and makes it harder for consumers to understand and exercise those rights without additional searching.
Meta
Meta Terms of Service
high
Dispute resolution now depends on where you live: consumers can sue in their home country, but Meta can only be sued in California courts.
Why it matters: The updated terms shift dispute resolution authority from a single California venue to a multi-jurisdictional model where consumer disputes proceed under local law in local courts. This change affects the practical cost and accessibility of dispute resolution for consumers outside California and may increase Meta's exposure to enforcement under consumer protection laws in jurisdictions where disputes can now be filed. The 30-day advance notice requirement creates a new procedural restraint on Meta's ability to unilaterally change terms without user awareness.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

April 20, 2026
Chime
Chime Privacy Policy
medium
Removes joint marketing data sharing with other financial companies and clarifies affiliate information-sharing practices.
Why it matters: The updated notice narrows the scope of data sharing that The Bancorp discloses to consumers, specifically removing statements about joint marketing with other financial companies and affiliate sharing of transaction and creditworthiness data. This change either reflects a reduction in actual data-sharing practices (which benefits consumer privacy) or represents a disclosure gap that may expose The Bancorp to regulatory scrutiny under GLBA and FTC Act requirements.
April 19, 2026
Poshmark
Poshmark Privacy Policy
medium
Expanded privacy policy with detailed disclosure of personal data collection, use, sharing, and consumer rights including region-specific information.
Why it matters: Poshmark's expanded privacy policy provides significantly more granular transparency about what personal data the company collects from you, how it uses that data, and what rights you have to control that data, particularly if you live in California or another state with privacy protections. The detailed disclosure of data categories (payment information, photos, videos, social media accounts, interaction history) allows you to understand Poshmark's data footprint and identify which privacy rights and opt-out options are available to you.
Poshmark
Poshmark Terms of Service
medium
Poshmark added 249 sentences to Terms of Service and modified 3 existing sentences, expanding document to 6,703 total sentences.
Why it matters: The magnitude of this change (249 added sentences, 3 modified) indicates substantive revision to Poshmark's terms, but the specific operational significance cannot be determined without reviewing the actual updated language. Users and organizations relying on these terms should obtain and review the complete document to understand any new policies, obligations, restrictions, or disclosures.
Paramount+
Paramount+ Terms of Use
high
Adds mandatory arbitration clause and class action waiver; establishes binding dispute resolution procedure
Why it matters: The addition of mandatory arbitration and class action waiver clauses fundamentally changes how consumers can resolve disputes with Paramount+, shifting from potential court proceedings to private arbitration and eliminating the possibility of joining group lawsuits. These are material changes to consumer legal rights and protections.
Ledger
Ledger Privacy Policy
high
Removed service exclusions and reduced privacy policy scope from 224 to 36 sentences, eliminating explicit carve-outs for Ledger Recover and Multisig services.
Why it matters: The removal of explicit service exclusions and cross-references to separate privacy policies creates regulatory compliance risk and user confusion about what data practices apply to each Ledger service. Under GDPR and CCPA, privacy policies must clearly disclose the scope of services covered; the absence of this disclosure may not satisfy those requirements.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

← Newer Page 10 of 13 Older →