Live feed · updated daily

Recent policy changes

361 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
838 Documents tracked
361 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
April 3, 2026
Plaid
Plaid End User Privacy Policy
medium
Plaid Account terms revised: removed monitoring service language, added identity verification and contact data request provisions.
Why it matters: The updated terms clarify and expand Plaid's authority to collect contact information (phone numbers, email addresses) and identity data during account creation and verification processes. This is operationally significant because it makes explicit what data Plaid may request and retain, affecting how third-party applications and Plaid itself can integrate identity verification into user onboarding workflows. The removal of references to standalone monitoring services may indicate a shift in Plaid's service model, though this is not explicitly stated.
April 2, 2026
Ledger
Ledger Privacy Policy
medium
Removed carve-outs for Ledger Recover and Multisig from privacy policy; service coverage status now ambiguous.
Why it matters: The removal of explicit service carve-outs creates legal and operational ambiguity about which Ledger products are governed by this privacy policy. Under GDPR and CCPA, consumers are entitled to clear, specific notice of what services and data are covered by any given privacy statement. If Recover and Multisig were previously governed by separate policies and are now intended to fall under the main policy, that expansion requires clear notification. If they remain separate, their removal from the policy without replacement disclosure violates transparency standards.
Cash App
Cash App Terms of Service
medium
Discontinues Remittance Service effective May 1, 2026; establishes auto-cancellation and refund timeline for pending transactions.
Why it matters: The updated terms eliminate an entire service line (Remittance Service) after May 1, 2026, affecting users who depend on Cash App for remittance transfers. The terms establish automatic cancellation and refund procedures for pending transactions, creating a defined transition window during which users must act to complete transfers. The California gift card threshold change modifies redemption mechanics but has minimal operational impact.
April 1, 2026
Microsoft Azure
Microsoft Privacy
medium
Restructured data retention disclosure, removing detailed criteria and examples; now directs to product documentation.
Why it matters: The privacy policy is the primary document users and regulators consult to understand how companies handle data. By moving retention details from the policy to scattered product documentation, Microsoft reduced transparency at the point of disclosure, making it harder for users and compliance teams to understand how long their data is kept. This shift also complicates vendor audits and Data Processing Agreement alignment.
Microsoft
Microsoft Privacy Statement (Legacy)
medium
Restructured data retention criteria; moved specific retention period documentation from privacy statement to individual product docs.
Why it matters: The updated terms consolidate retention rationale into five broad business purposes but move specific retention period specifications from the main privacy statement to product-level documentation. This restructuring means that users and compliance teams must now consult multiple product documents rather than a single consolidated retention criteria statement to understand how long Microsoft will keep their data. The change does not appear to alter Microsoft's underlying retention practices, but it affects how retention commitments are disclosed and discovered.
March 31, 2026
Figma
Figma Terms of Service
medium
Removes footer links to Subprocessors list and Candidate Privacy Notice; adds trademark policy links.
Why it matters: The Subprocessors list is a key transparency mechanism under GDPR Article 28 and equivalent data protection frameworks that allows data controllers to verify which third parties process their data. Removing the direct link from the Terms of Service reduces the accessibility of this information and may complicate compliance audits and vendor due diligence workflows, even if Figma's underlying obligation to disclose subprocessors remains unchanged.
March 27, 2026
Google Gemini
Gemini Apps Privacy Notice
medium
Adds disclosure of data use from Connected Apps and imported cross-platform AI chats for personalization and AI model training.
Why it matters: The updated notice explicitly discloses that Gemini uses data from connected Google apps and imported data from other AI platforms for personalization and AI model training. This clarifies the scope of data processing and training data use, which has direct relevance to GDPR transparency obligations, CCPA consumer disclosures, and emerging AI transparency requirements. Organizations that process regulated data through Gemini should confirm this disclosed practice aligns with their vendor contracts and customer privacy commitments.
March 25, 2026
Poshmark
Poshmark Privacy Policy
medium
Expanded privacy policy with detailed disclosures of personal data collection practices, including user-generated content, transaction data, and interaction history.
Why it matters: The expanded policy provides users with clearer visibility into what personal data Poshmark collects and processes, including user-generated content, transaction history, and behavioral data. For users subject to state privacy laws (particularly California), the explicit disclosure supports understanding of rights to access, delete, and opt out of certain data uses, though exercising those rights requires understanding the full updated policy language.
Poshmark
Poshmark Terms of Service
medium
Expanded Privacy Policy with new sections on data collection, usage, sharing, storage, legal basis for processing, and user rights; effective March 25, 2026.
Why it matters: The expanded Privacy Policy provides substantially more transparency about what personal data Poshmark collects, how it uses and shares that data, and what rights you have. This increased transparency helps you understand what information Poshmark retains about your account, purchases, listings, and interactions, and enables you to make informed decisions about whether to use the platform and what data to provide.
March 23, 2026
Google Gemini
Gemini Apps Privacy Notice
medium
Removed Connected Apps personalization disclosure from privacy notice, no longer explaining how data from linked Google apps personalizes Gemini experience
Why it matters: The removal of this disclosure eliminates a material transparency requirement from the privacy notice. Under privacy regulations including GDPR and CCPA, organizations must disclose material data practices in their privacy policies. The absence of disclosure language creates ambiguity about whether the Connected Apps personalization practice continues undisclosed, has been discontinued, or is now treated differently. This impacts users' ability to understand how their data is used and may affect compliance obligations for organizations relying on Gemini's disclosures to inform their own privacy practices.
Revolut
Revolut Terms of Service (Superseded URL)
medium
Removes Move Money Rules feature documentation from Terms of Service
Why it matters: The removal of Move Money Rules documentation from binding terms creates operational and regulatory ambiguity. Users can no longer reference the terms to understand how automatic fund movements work, what conditions trigger them, or what fees apply. If the feature remains available, the removal may violate disclosure obligations under consumer protection and payment services regulations. If the feature has been discontinued, the removal should be accompanied by explicit notice to affected users.
March 21, 2026
Bumble
Bumble Privacy Policy
medium
Removes UK from disclosed server locations; now lists only US and EU servers
Why it matters: Data location disclosures form the basis for regulatory compliance and customer trust. Removing UK from server locations signals a change in data infrastructure that affects where user data is processed, stored, and protected; this matters to UK users who may have data residency or jurisdiction preferences, and to organizations that need accurate vendor location information for their own compliance documentation.
March 19, 2026
Target
Target Terms and Conditions
medium
Added comprehensive Target Circle loyalty program terms including automatic updates without notice and continued-use consent provisions.
Why it matters: The updated terms establish an explicit unilateral modification framework for a major consumer loyalty program, enabling Target to change program features, rewards, data handling, and terms without advance notice. The provision that continued participation constitutes acceptance means members remain bound to updated terms simply by using the program, without affirmative reaffirmation. This operational structure concentrates authority to modify loyalty program governance in Target's hands and depends on members actively opting out if they object to changes rather than proactively consenting to each modification.
Twilio
Twilio Privacy Notice
medium
Reorganized Privacy Notice with expanded disclosure of data collection, processing relationships, and data controller accountability.
Why it matters: The updated Privacy Notice operationally establishes Twilio's explicit role as a data controller and maps the scope of data relationships it processes, which clarifies accountability for GDPR, CCPA, and equivalent compliance frameworks. Organizations using Twilio as a vendor must verify that their Data Protection Addenda and customer privacy disclosures remain aligned with Twilio's now-detailed controller role and multi-tier data subject framework.
Twilio
Twilio Terms of Service
medium
Removes Brazil from entity-specific contracting structure; adds Japan as separate Twilio jurisdiction; commits to not materially decrease service functionality.
Why it matters: The removal of Brazil from the entity-specific contracting structure creates uncertainty about dispute jurisdiction, applicable law, and data handling for Brazilian customers. The addition of Japan as a separate jurisdiction establishes clearer contractual clarity for Japanese customers. The commitment to preserve functionality protects customers against unilateral removal of core service capabilities, though the definition of 'materially decrease' remains subject to dispute interpretation.
Nintendo
Nintendo Privacy Policy
medium
Shifted child privacy certification from CARU to ESRB and simplified data retention language in privacy policy update.
Why it matters: The updated policy removes explicit transparency about what persistent identifiers Nintendo collects from child users and why, which may affect how the policy complies with COPPA's requirement for clear disclosure of information collection practices. The shift from CARU to ESRB changes which independent body audits and enforces Nintendo's compliance with its stated practices. Simplified retention language removes prior detail about how Nintendo handles data based on sensitivity levels, though the practical retention practices may remain unchanged.
Glassdoor
Glassdoor Privacy Policy
high
Removes data correction rights, third-party opt-out protections, and use-limitation requests; adds binding arbitration for disputes.
Why it matters: The removal of documented data correction, deletion, and opt-out rights narrows the contractual protections users have in the published privacy policy and may create compliance gaps under GDPR, FADP, and CCPA, which grant users statutory rights to access, correct, and delete personal data and to object to processing. The addition of binding arbitration establishes a mandatory dispute mechanism that limits judicial recourse. For organizations using Glassdoor as a data processor, these changes may require amendment of existing vendor data processing agreements to ensure user data subject rights are preserved through contract rather than relying on Glassdoor's published policy.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

March 15, 2026
Cash App
Cash App Privacy Policy
medium
Prohibited children under 13 from using service; removed parental authorization option and child-specific privacy guidance.
Why it matters: The updated terms establish a blanket prohibition on service access for children under 13, eliminating a previously documented pathway for parental authorization. This change operationally narrows Cash App's scope and may reduce COPPA compliance complexity, but it also creates ambiguity around detection procedures and data deletion timelines if child-attributed data is collected prior to age verification.
March 13, 2026
Microsoft
Microsoft Privacy Statement (Legacy)
medium
Removes EEA user rights language and adds consent-based auto-dialer marketing contact authorization using AI-generated voice.
Why it matters: The updated policy establishes explicit authorization for Microsoft to initiate automated marketing calls using AI-generated voice technology where user consent to phone marketing has been given. This creates operational implications for users who provide phone numbers and have opted into marketing contact: they may now receive calls from automated systems. Simultaneously, the removal of language describing EEA user rights narrows the explicit protections stated in the policy for that region, which may have regulatory implications if those rights represented statutory disclosures rather than contractual commitments.
March 12, 2026
Binance.US
Binance.US Privacy Policy
medium
Adds explicit fraud-detection data sharing authority to law enforcement and third parties; clarifies cookie and email-based targeted advertising on external platforms
Why it matters: The updated policy explicitly authorizes data sharing with law enforcement and third parties for fraud detection without requiring advance notice or consent in most cases, and clarifies that customer email addresses and identifiers may be used for targeted advertising across external platforms. These expanded disclosures affect how customer data may be used and shared beyond Binance.US's direct operations, which is material for users who expect their financial data to remain within the platform or not be used for external marketing purposes.
March 10, 2026
OpenAI
OpenAI Privacy Policy
high
Removed dedicated sections on data retention, user rights, security, and children protections; reorganized policy with jurisdiction-specific routing.
Why it matters: The removal of seven dedicated policy sections, including those addressing data retention, consumer rights, security, and child protections, reduces the transparency and accessibility of core privacy disclosures previously consolidated in standalone form. The reorganization and jurisdiction-specific fragmentation may create compliance documentation challenges and may obscure consumer remedies and protections that were previously clearly delineated.
March 8, 2026
Roblox
Roblox Privacy and Cookie Policy
medium
Clarified COPPA compliance language for child accounts; removed detailed data collection purpose categories.
Why it matters: The updated policy establishes a narrower definition of personal information collected from children under COPPA (email only) and removes detailed disclosure of how persistent identifiers are used for internal operations. This affects how parents understand child data handling and may influence how organizations process or represent Roblox's child account practices in their own compliance frameworks.
Roblox
Roblox Terms of Use
medium
Restructured Terms of Use with embedded AI policies, advertising updates, and regional compliance appendices; removed standalone change summary.
Why it matters: The restructured terms incorporate AI tool disclosures and advertising policies directly into binding user and creator agreements, rather than treating them as supplemental guidance. The addition of six region-specific appendices establishes different contractual terms based on user location, particularly in regulated jurisdictions like the EU and UK. The removal of the standalone change summary eliminates the previous transparency mechanism, requiring users to navigate a 1242-sentence document to understand what changed.
Binance.US
Binance.US Privacy Policy
medium
Removes explicit fraud-prevention data disclosures and narrows privacy appeal submission methods to email only.
Why it matters: The removal of explicit fraud-prevention data-sharing disclosure reduces the stated transparency of how customer information flows to government agencies and financial institutions, a practice that typically requires clear disclosure under state consumer privacy laws. The consolidation of privacy appeal submission to email only narrows the procedural accessibility of privacy rights requests and may affect response timelines for users who previously relied on webform submission.
March 6, 2026
Robinhood
Robinhood Privacy Policy
medium
Restructured privacy policy separates financial data disclosures by service entity and removes social media product from scope.
Why it matters: The updated policy reorganizes how Robinhood discloses its financial data practices by service entity and separates non-financial data handling to a distinct privacy statement. This change affects how users and compliance teams locate privacy information for specific Robinhood services and makes clear which policy statement governs different types of data collection. The removal of Robinhood Social from this policy's scope creates a practical question about where social media privacy practices are now documented.
Coinbase
Coinbase User Agreement
medium
Removed Direct Deposit feature documentation, including enrollment and virtual account procedures
Why it matters: The removal of Direct Deposit documentation from Coinbase's principal User Agreement eliminates contractual disclosure of a potentially significant financial feature. If the service remains operational, users no longer have access to official terms explaining enrollment, virtual account mechanics, or service scope. If the service has been discontinued, the removal without explicit notification creates ambiguity about the transition timeline and available alternatives.
Netflix
Netflix Privacy Statement
medium
Removed US state privacy disclosures from main statement; simplified data collection language around advertising inferences and voice inputs
Why it matters: The updated statement removes explicit references to key data practices and reorganizes how state privacy rights disclosures are accessed, which affects transparency regarding advertising inferences and voice input collection. The removal of household inference language and voice input mentions narrows what Netflix explicitly discloses about data practices, even if underlying practices continue. For state privacy law compliance, the removal of the direct 'Notice at Collection' reference from the main body may affect whether disclosures meet accessibility and prominence requirements under CCPA and similar laws.
Netflix
Netflix Terms of Use
medium
Restructured and condensed membership terms with clearer definitions; removed prior arbitration and dispute resolution language.
Why it matters: The removal of mandatory arbitration language from Netflix's Terms of Use represents a material change to the dispute resolution framework documented in the consumer contract. The prior terms explicitly required users to resolve disputes through arbitration rather than in court, and this language is no longer present in the updated excerpt. If this removal is complete and not offset by replacement language elsewhere in the full document, Netflix consumers would regain access to class action and court-based dispute resolution, which could affect the company's litigation posture and consumer complaint handling procedures. The change also affects how customers understand their contractual rights and remedies available to them.
Microsoft Azure
Microsoft Privacy
medium
Clarified data retention criteria including customer expectations, automated deletion controls, and data sensitivity; disclosed 30-day post-deletion retention window.
Why it matters: The updated policy clarifies that deletion is not instantaneous; your data persists for up to 30 days after you take deletion action. This matters because it affects how quickly your data is truly removed from Microsoft's systems and may impact your understanding of data breach risk, data residency, and compliance with privacy regulations that require timely erasure.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

March 5, 2026
Microsoft
Microsoft Privacy Statement (Legacy)
medium
Removed disclosure of AI-generated voice marketing call practices from privacy statement.
Why it matters: The removal of explicit disclosure language about a specific marketing contact practice (AI-generated voice auto-dialer calls) creates an absence where the policy previously acknowledged the possibility. For users accustomed to seeing this disclosure in Microsoft's terms, the removal signals a change in how the company describes its marketing practices. For compliance teams, the removal may trigger review of whether TCPA and FTC Act transparency obligations are still adequately addressed under the updated language, and whether vendor documentation needs to be refreshed.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

← Newer Page 12 of 13 Older →