Live feed · updated daily
Recent policy changes
361 policy changes
detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.
April 19, 2026
Replaced marketing homepage with binding website privacy notice requiring express consent to data collection and retention.
Why it matters: The change converts zelle.com from a marketing destination into a legally binding privacy notice that requires your consent to data collection merely by visiting. This means Zelle is now asserting broad authority to collect and use your personal information on the basis of your presence on the site, and the notice warns that you should not visit if you disagree.
GitHub substantially revised Terms of Service with 54 modified sentences, 40 removed, and 4 added; review specific changes to understand revised service terms.
Why it matters: The revision scale indicates material changes to GitHub's service terms. The removal of 40 sentences and modification of 54 others suggests changes to core provisions governing acceptable use, intellectual property handling, liability, dispute resolution, or data processing. Users and organizations with GitHub in their vendor stack should identify the specific provisions that changed to assess operational and contractual implications.
Added Mexico and Brazil entities to Terms of Service; removed guarantee against material service functionality reduction; clarified online order placement options.
Why it matters: The addition of Mexico and Brazil service entities creates distinct legal contracting relationships with regional companies, potentially affecting dispute venue, applicable law, and regulatory compliance for customers in those jurisdictions. The removal of the functionality protection clause broadens Twilio's contractual authority to modify service features without the prior constraint that changes be non-material to overall functionality, shifting risk to customers who may have relied on that commitment for service stability planning.
Expands privacy notice with 516 added sentences covering data collection, AI decision-making, cookie usage, and traveler rights
Why it matters: The expanded privacy notice provides substantially more detail about what data Booking.com collects from travelers, how it uses that data (including for AI-driven decisions), who it shares data with, and what rights travelers have. For travelers considering booking through Booking.com, the additional transparency allows more informed decisions about data privacy before committing to a reservation.
Removes UK from stated server locations; now lists only US and EU servers
Why it matters: Transparency about server locations is a key privacy disclosure that affects where your data is stored and what data protection laws apply. Removing UK from the list changes what the policy tells you about data handling and may indicate a shift in infrastructure that affects your rights under UK and EU data protection law.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Adds explicit disclaimers that Noom is not medical care, requires age 18+, clarifies features may be inaccurate, and reserves unilateral account suspension rights
Why it matters: The updated terms make explicit that Noom is not a substitute for medical care and that its coaching and food features may be inaccurate, which is critical for users who might rely on it for health decisions. The new language also reserves Noom's right to terminate your account at any time without stated cause or process, expanding the company's unilateral control over your access.
Shifts child privacy certification to CARU, clarifies persistent ID collection for children, and expands parental visibility of authorized third-party app access.
Why it matters: Nintendo now explicitly discloses that it collects and permits service providers to collect persistent identifiers from child users for specific operational purposes, and parents can see exactly which apps are authorized to access their child's account, providing clearer visibility into data practices affecting children. The shift from ESRB to CARU oversight represents a change in the third-party body conducting independent audits and enforcement of the company's child privacy compliance.
Adds AI-powered phone marketing disclosures and reorganizes data retention criteria; removes specific retention examples.
Why it matters: Microsoft disclosed a new marketing contact method (AI-generated voice calls) that consumers may not expect, requiring them to verify their consent preferences. Simultaneously, the company made its data retention commitments less specific and more operationally broad, which reduces consumer clarity about how long their data is kept and may complicate vendor compliance verification.
Removed one-month response commitment for privacy requests and explicit disclosure of child safety consortia data sharing
Why it matters: The removal of response timelines for privacy rights requests eliminates a compliance commitment that operationalized GDPR and UK DPA obligations, creating ambiguity about what timeline now applies when users exercise data subject rights. The removal of explicit child safety consortium disclosure eliminates transparency about a data processing practice, which may affect users' ability to understand what data is shared and for what purpose, and may create compliance questions under transparency-focused regulations like GDPR Article 14.
Reframes Plaid Account role from third-party app accelerator to direct consumer service provider; adds Plaid Web-App monitoring platform.
Why it matters: The updated terms establish that Plaid is now a direct service provider with its own account and monitoring platform, not just an intermediary for third-party apps. This means Plaid's use of your financial and identity data has expanded beyond facilitating third-party connections to include providing its own alerts and monitoring services, and organizations using Plaid need to verify their data processing agreements and customer disclosures reflect this expanded role.
Restructured account terms to clarify Plaid's direct service role and introduced new account monitoring service with expanded payment data sharing scope.
Why it matters: The restructured terms expand Plaid's explicitly authorized scope to share your financial data for payment purposes and introduce a new direct service offering. This shift from Plaid as a connection intermediary to Plaid as a direct service provider with its own monitoring system means Plaid's role and data-handling authority is now broader and more direct than previously stated in the account terms.
Updated privacy notice now authorizes data sharing for joint marketing with financial companies and permits nonaffiliate marketing.
Why it matters: The updated notice establishes new authority for Chime to share customer data for joint marketing with other financial companies, which expands the scope of permitted data sharing beyond the prior disclosed categories. This change materially affects who has access to customer financial information and for what purposes, which is operationally significant under GLBA disclosure requirements and affects consumers' ability to exercise data-sharing objections.
Updated children's policy to permit parental authorization of accounts for users under 13, replacing prior blanket prohibition.
Why it matters: The updated terms establish that children under 13 may now use Cash App with parental authorization, replacing a prior blanket prohibition. This change expands Cash App's addressable market to include minors while creating specific COPPA compliance obligations around parental consent, data use restrictions, and security that organizations relying on Cash App services should understand and incorporate into their own compliance frameworks.
Adds explicit fraud-prevention data disclosure to law enforcement and third parties; clarifies email/identifier use for cross-platform targeted advertising; introduces privacy rights webform.
Why it matters: The updated policy establishes explicit authority to disclose user information to law enforcement and financial crime investigators, which operationalizes compliance with anti-money laundering and financial crime statutes but creates new transparency obligations under state privacy laws. The clarification regarding email-based cross-platform advertising expands Binance.US's stated use of identifiers beyond its own platforms, which may affect how users understand data use and which audiences are subject to targeted advertising.
Adds Connecticut-specific virtual currency risk disclosures including warnings about irreversibility, lack of government insurance, and fraud schemes.
Why it matters: The updated language establishes explicit risk disclosures that Connecticut regulations and similar state regimes likely require. These disclosures address irreversibility of transactions, absence of government protection, fraud risk, and market volatility, ensuring users understand fundamental characteristics of cryptocurrency before transacting. This change affects how Coinbase communicates the nature of its service and the risks users assume.
Expanded data collection disclosures to include voice inputs and ad preference inferences; added US state privacy notice section.
Why it matters: The updated statement brings Netflix's privacy disclosures into formal alignment with US state privacy law frameworks by adding explicit notice of voice recording collection and advertising preference inferences, and by establishing a modular disclosure structure for state-specific privacy rights. This change operationalizes Netflix's compliance infrastructure for emerging privacy statutes and clarifies data practices that were previously referenced in general terms.
Added mandatory arbitration requirement with time-limited opt-out option; users must resolve disputes through arbitration unless they exercise opt-out right
Why it matters: The updated terms establish a mandatory arbitration framework for dispute resolution, which fundamentally changes how users can assert legal rights against Netflix. Under the revised language, users cannot pursue litigation or participate in class actions through court unless they affirmatively opt out within the window specified in Section 6; this has practical implications for the cost, scope, and outcome of any dispute with Netflix.
Expanded data retention justifications to include business operations, safety, product development, and dispute resolution.
Why it matters: The updated terms establish broader grounds for retaining personal data, expanding from transaction and legal necessity to include business operations and product development. This change affects how long data may be retained and the purposes Microsoft may rely on to justify that retention, shifting retention decisions away from unified policy guidance into product-specific documentation that users must actively consult.
Replaced service warranty with broad as-is disclaimer; expanded terms scope to all users; clarified Privacy Policy applicability.
Why it matters: The updated terms establish that Google makes no contractual commitment to service quality or reliability except where specific services include their own warranties. This change affects how users can seek remedies for service failures and narrows the contractual protections that previously existed under the reasonable care warranty. For organizations relying on Google services, this warranty disclaimer may affect their own vendor risk management and customer-facing representations about service reliability.
April 18, 2026
Removes disclosure of 6-month Steam Wallet fund expiration requirement for Japanese subscribers
Why it matters: The updated agreement eliminates explicit contractual notice that Steam Wallet funds will expire after six months for Japanese users, removing a transparency mechanism that previously informed users of a time-dependent financial obligation. Japanese law typically requires clear disclosure of stored value expiration terms, so the removal of this contractual language may create compliance risk unless Steam has implemented alternative disclosure mechanisms outside the agreement text.
Removed third-party sign-in service disclosures; clarified AI chatbot as internal content-directing tool rather than optional feature.
Why it matters: The removal of published disclosures about third-party sign-in data handling eliminates transparency about a material data flow. Users can no longer reference the privacy policy to understand what information Apple or Google shares with Acorns or how Acorns uses that data. Regulators may scrutinize whether omission of these disclosures constitutes material unfairness or deception. Organizations relying on Acorns' transparency to satisfy their own privacy notice obligations will need to address the gap.
Removed explicit exclusion of Ollie mobile app from privacy notice scope and removed 'affiliates' from covered entities.
Why it matters: The removal of explicit language stating the Privacy Notice does not apply to Ollie App eliminates transparency about scope boundaries. Users previously had clear notice that Ollie was governed by separate privacy terms; that notice is now absent, creating ambiguity about whether Ollie's data handling is covered by the updated notice or remains subject to undisclosed separate terms. Additionally, removing 'affiliates' from the definition of covered entities narrows the perceived scope of the Privacy Notice, which may affect how users and regulators understand what parts of Coursera's business operations are subject to the stated privacy protections.
Introduces 'Extra Members' outside household access, adds 18+ age requirement for account creation, removes account personalization language
Why it matters: The updated terms establish explicit account creation age requirements (18+) and formalize support for out-of-household Extra Member accounts. These changes affect who can create Netflix accounts and how subscription sharing is legally structured, with potential compliance implications under COPPA and age-verification frameworks in regulated jurisdictions.
Clarified data activity management controls; expanded ad and analytics service references; broadened cross-site and cross-app data linking descriptions.
Why it matters: The updated policy clarifies that Google links your activity across multiple websites and apps through cookies and other technologies as part of its integrated ad and analytics services, not just within individual analytics dashboards. This expanded and more transparent description of cross-site and cross-app tracking is relevant to users concerned about the scope of their digital footprint and to organizations that must disclose Google's data practices to their own customers.
Stay ahead of the changes
You're seeing a fraction of what's changing
ConductAtlas monitors every tracked platform and captures every policy update.
Updated daily. New changes added as detected.