Live feed · updated daily

Recent policy changes

420 policy changes detected across 352 platforms. Most platforms don't announce policy changes — these updates were detected automatically.

Stay ahead of the changes

Start monitoring platform changes

Free: research letter. Monitor: same-day alerts on the platforms you choose.

352 Entities monitored
844 Documents tracked
420 Changes detected
Showing the most important changes (medium + high severity). Show all changes including minor updates
July 13, 2026
Zillow
Zillow Terms of Use
medium
Adds consent requirements for calls, texts, and automated communications including advertising, with opt-out mechanism for SMS.
Why it matters: The updated terms formalize Zillow's authority to conduct automated and telemarketing communications across multiple channels, which may trigger Telephone Consumer Protection Act compliance obligations for Zillow and potentially for downstream business partners. The addition of call recording language establishes a new monitoring and internal use practice that users consent to as a condition of using the platform.
July 12, 2026
Robinhood
Robinhood Customer Agreement (PDF)
medium
Adds fiduciary verification requirements and trustee liability provisions for trust accounts; Robinhood may now rely on trustee instructions without verifying compliance with trust instruments.
Why it matters: The updated terms substantially reallocate fiduciary risk by establishing explicit personal liability for trustees while authorizing Robinhood to rely on trustee instructions and representations without independent verification of authority or trust validity. This creates practical exposure for trustees whose instructions fall outside their authority under applicable trust law, and establishes Robinhood's right to freeze accounts or demand documentation without prior notice. The change affects how trustees and beneficiaries interact with Robinhood and may require legal review if trust instruments do not explicitly allocate this liability.
Bank of America
Bank of America Deposit Agreement
high
Adds prominent arbitration and class action waiver disclosure; substantially revises deposit agreement with 401 structural changes affecting dispute resolution and account operations.
Why it matters: The updated agreement explicitly establishes mandatory arbitration and class action waiver provisions that fundamentally alter how disputes between deposit account holders and Bank of America are resolved. These provisions require disputes to proceed through individual arbitration rather than court litigation and eliminate the ability to participate in class actions, which operationally affects the remedies available to customers and the economics of pursuing disputes.
July 11, 2026
Box
Box Terms of Service
medium
Adds automatic billing for API and AI Unit overage charges, with suspension rights if balances unpaid.
Why it matters: The updated terms establish explicit, automated billing procedures and service suspension mechanisms for overage consumption of API Calls and AI Units. Previously, overage language was discretionary and general; the new section creates specific billing procedures, usage reporting rights, and technical control authority that may be automatically enforced without explicit customer authorization for each overage event. Organizations integrating Box APIs or relying on continuous Box availability in production systems should evaluate whether these new suspension rights conflict with existing customer commitments or operational requirements.
Medium
Medium Terms of Service
medium
Adds unilateral service termination clause; Medium may discontinue Services or features at sole discretion.
Why it matters: The updated terms explicitly establish Medium's unilateral right to discontinue the Services or any features at its discretion. This provision materially affects platform continuity for users who depend on Medium for publishing, distribution, or audience access. The absence of specified notice periods or transition procedures creates operational uncertainty for content creators and publishers regarding how discontinuation would be handled.
July 10, 2026
Shopify
Shopify Privacy Policy
medium
Revised cross-border data transfer framework from adequacy-based to Binding Corporate Rules and Standard Contractual Clauses for EEA/UK/Swiss users.
Why it matters: The updated policy establishes a new legal framework for protecting personal data when it moves across borders. Rather than relying on European Commission decisions that data protection in certain countries is adequate, Shopify now uses Binding Corporate Rules (internal company commitments approved by regulators) and Standard Contractual Clauses (contractual commitments with third parties). This shift reflects ongoing changes in international data transfer law, particularly EU court scrutiny of transfer mechanisms. The change does not materially alter the data flows themselves, but it affects how Shopify documents compliance with GDPR and UK data protection requirements.
July 9, 2026
StockX
StockX Privacy Policy
medium
Expands data sharing and selling to Live Sellers, Listings Marketplace sellers, and data brokers; explicitly authorizes selling personal information.
Why it matters: The updated terms explicitly authorize sharing and selling personal information to data brokers and new seller categories, expanding the recipients of user data beyond what was previously disclosed. Under CCPA, this shift to explicit 'sale' language may trigger new consumer opt-out rights and disclosure obligations. For EU and UK users, data sales to brokers require clear legal basis under GDPR, and the policy should clarify consent mechanisms or alternative lawful grounds.
Waze
Waze Privacy Policy
medium
Removed 16+ age requirement; added expanded Personal Information definition; eliminated contact book collection and social network integration documentation
Why it matters: The removal of the 16+ age gate without explicit replacement of parental consent or age verification language creates potential regulatory exposure under COPPA and GDPR Article 8 if minors are now permitted to use the service. The expansion of Personal Information definition and removal of specific feature disclosures (contact book collection, social network integration) change what data categories the policy acknowledges collecting and how transparent the disclosures are, affecting compliance with GDPR Article 13 transparency obligations and user understanding of data practices.
Waze
Waze Terms of Use
medium
Restructured Terms of Use to reference multiple binding policies (Content Moderation, Community Terms, Copyright) and clarified advertising model and age requirements
Why it matters: The updated terms materially expand the scope of binding obligations by incorporating multiple external policies (Content Moderation, Community Terms, Copyright) into a single binding agreement structure. This creates practical and legal complexity: users must now navigate four separate documents to understand their full rights and obligations, enforcement may depend on interpretation of how these policies rank relative to one another, and the removal of explicit data retention language from the Terms shifts governance of this critical issue to the Privacy Policy alone, creating potential transparency gaps under applicable data protection law.
Upwork
Upwork Terms of Service
medium
Adds Upwork Now Beta Addendum governing AI-driven freelancer sourcing, requires minimum account balance for client outreach, clarifies due dates as informational only.
Why it matters: The Upwork Now Beta Addendum establishes the operational terms for a new pilot hiring feature that introduces AI-driven freelancer matching, new account requirements, and clarifies contract formation and due-date mechanics. For clients, this changes how they source freelancers (automated invitations may supplement manual search) and imposes a minimum account balance requirement to send offers. For freelancers, this creates visibility into how they may be invited to jobs and clarifies that offers may be withdrawn and that contract formation requires explicit acceptance. The addendum also reserves Upwork's right to modify or remove beta features without notice, which affects the stability of workflows built around this feature during the pilot period.
Meta
Llama API Terms of Service
medium
Removes 700M user cap on Meta Model API access; expands availability to large-scale developers.
Why it matters: The removal of the 700 million user threshold and EU multimodal restriction materially expands who can legally access Meta's AI models under the updated terms, directly affecting platform eligibility and go-to-market timelines for developers previously blocked by scale. However, the removal of fine-tuning documentation creates operational uncertainty about whether that capability remains available, requiring clarification before integration decisions can be finalized.
Stay ahead of the changes

You're seeing a fraction of what's changing

ConductAtlas monitors every tracked platform and captures every policy update.

July 8, 2026
Geico
Geico Terms of Use
medium
Removes explicit liability disclaimers for website performance, viruses, and technical failures; restructures terms around acceptance framework
Why it matters: The removal of explicit liability disclaimers changes how Geico states its legal responsibility for website performance, technical failures, and related harms. Previously, the terms asserted that Geico would not be responsible for a defined list of categories (viruses, service interruptions, transmission delays, etc.). The updated terms no longer contain these specific assertions, which may affect dispute resolution expectations and the contractual foundation for liability claims related to website use.
Fireworks AI
Fireworks AI Terms of Service
high
Added mandatory individual arbitration and class action/jury trial waiver for all disputes.
Why it matters: The updated terms establish mandatory arbitration and eliminate class action and jury trial rights for all disputes, including claims that arose before users agreed to the revised terms. This fundamentally alters how disputes are resolved; users can no longer pursue claims in court or as part of a collective action, and must instead proceed through individual arbitration.
Uniswap
Uniswap Terms of Service
medium
Adds explicit sanctions screening and legal compliance representations to user signature requirements.
Why it matters: The updated terms establish explicit contractual representations regarding sanctions and legal compliance that are binding conditions of platform use. This change operationally means that users in OFAC-sanctioned countries or those subject to sanctions are contractually prohibited from using Uniswap, and users worldwide now make a legal certification of lawful use. The change reflects increasing regulatory scrutiny of cryptocurrency platforms regarding sanctions compliance.
BeReal
BeReal Privacy Policy
medium
Adds email collection requirement, discloses AI-inferred gender targeting, and introduces UX interaction recording for 0.001% of users.
Why it matters: The updated policy expands the types of personal data collected and disclosed: email becomes mandatory, AI-inferred gender classification is now explicitly listed as a targeting data category, and a new user interface recording practice is introduced for a randomized sample. These changes represent both increased transparency about existing or new data practices and, in the case of interface recording and AI-inferred classification, new processing activities that users previously may not have been aware of. Organizations relying on BeReal for services or partnerships may need to reassess their own compliance obligations if they account for these newly disclosed data categories in their own processing activities.
July 7, 2026
OpenRouter
OpenRouter Terms of Service
medium
Clarifies automatic chat logging and broadens content licensing scope for opted-in users
Why it matters: The updated terms clarify and formalize OpenRouter's rights to log, store, modify, and commercially reuse user content, including selling anonymized versions. The automatic activation of chat logging when prompt logging is enabled means users may unknowingly expand the scope of logged interactions, creating potential privacy and data governance considerations for both individual users and organizations integrating OpenRouter into their operations.
Grammarly
Grammarly Privacy Policy
medium
Adds voice data and screen content collection disclosures; clarifies privacy policy does not apply to organizational account content.
Why it matters: The updated policy expands transparency regarding voice and screen data collection, and clarifies that organizations providing Grammarly to employees or students are now responsible for privacy governance of organizational user data rather than relying on Grammarly's policy. This affects how organizations document vendor privacy practices, design privacy notices for internal users, and structure data processing agreements with Grammarly.
Coinbase
Coinbase User Agreement
medium
Added California-specific disclosures including fee caps, complaint procedures, and crypto irreversibility notices.
Why it matters: The updated agreement establishes explicit fee caps and advance notice obligations for California residents, creating transparent pricing expectations and procedural protections previously absent from Coinbase's public terms. This change operationalizes California's regulatory expectations around digital asset disclosures and money transmitter licensing, affecting how Coinbase communicates fees and material changes to its California customer base.
July 6, 2026
Windsurf
Windsurf Security & Data Handling
high
Shifts model training default from opt-in to opt-out for all users; paid plans can opt out on Data Controls page.
Why it matters: This change reverses Windsurf's baseline data handling presumption for model training. Previously, users started with non-use and had to actively opt in; now they start with automatic use and must actively opt out. For organizations serving regulated customers or having committed to stricter data practices, the shift from opt-in to opt-out may trigger privacy policy updates and potential compliance review under GDPR, CCPA, and sector-specific frameworks. The explicit consent requirement for Enterprise customers indicates that consent-based processing is operationally available, which may create expectations that other tiers warrant similar controls.
July 5, 2026
Perplexity AI
Perplexity Privacy Policy
medium
Expanded privacy disclosures across Comet browser, Email Assistant, and core services with clarified data processor roles and explicit statement that email content does not train AI models.
Why it matters: The updated privacy notice substantially expands transparency about data collection practices across Perplexity's service ecosystem, particularly for Comet browser and Email Assistant, while establishing clear contractual boundaries between consumer and enterprise data handling. The explicit statement that email content does not train AI models addresses a material practice question that many users likely have when considering Email Assistant adoption. The clarified processor role for enterprise customers affects how organizations must structure their own compliance obligations around Perplexity service use.
Perplexity AI
Perplexity AI Privacy Policy
medium
Restructured privacy notice with expanded data collection categories and explicit legal bases; added email analysis and local browser tracking disclosures.
Why it matters: The updated Privacy Notice establishes more granular and explicit disclosure of Perplexity's data collection and use practices across specific product areas, moving from categorical language to contextualized examples with stated legal bases. This operational shift makes it clearer what data Perplexity collects through specific features (Comet browser, Email Assistant), where that data is stored (locally on device in some cases), and on what legal basis it is processed (consent, legitimate interest, contract performance). For users in privacy-regulated jurisdictions, understanding these specific practices and their asserted legal bases is material to evaluating whether the company's data handling aligns with applicable transparency requirements and user expectations.
July 3, 2026
StockX
StockX Terms of Use
medium
Expanded liability for automated agents and bots accessing accounts; users now responsible for all actions by electronic agents operating on their behalf.
Why it matters: The updated terms explicitly state that you are responsible for all actions taken by automated agents, bots, and APIs accessing your account on your behalf. This creates direct liability exposure for anyone using automation or buy-for-me services. The removal of regional term overrides consolidates enforcement under a single global framework, eliminating previously available carve-outs in the UK, EU, Japan, and South Korea, which may affect dispute resolution, liability limitations, or data processing protections that were previously region-specific.
Coursera
Coursera Terms of Use
medium
Adds content-access threshold as refund denial ground: Coursera now may deny refunds if significant portion of course was accessed before refund request submitted.
Why it matters: The updated terms establish a new operational basis for refund eligibility tied to course content access. Learners who begin engaging with course materials before requesting refunds may find themselves ineligible, regardless of other circumstances, which affects the practical timeline and conditions under which refunds are available. Organizations that allocate Coursera courses to employees or learners should account for this new access-based threshold when setting expectations around refund availability.
Indeed
Indeed Terms of Service
medium
Adds AI application drafting feature with job seeker review responsibility; removes voluntary bot-verification process.
Why it matters: The updated terms establish a new AI-assisted application feature that may affect the quality and customization of job applications submitted by job seekers. The explicit disclosure that job seekers must review and approve AI-drafted content clarifies responsibility for accuracy and appropriateness, which is operationally significant because job application quality directly affects hiring outcomes. The removal of the bot-verification disclosure indicates that program is no longer available as an option for certain job seekers.
July 2, 2026
Comcast
Comcast Terms of Service
medium
Added prohibition on AI Agents accessing Comcast services without express permission, including data mining, scraping, and automated interactions.
Why it matters: The updated terms establish a contractual obligation requiring express permission before deploying AI Agents on Comcast services, which affects any user, developer, or business using automation tools, bots, APIs, or scraping workflows to interact with Comcast infrastructure. The definition is broad enough to cover common automation practices, making this operationally significant for organizations relying on automated integrations.
HubSpot
HubSpot Privacy Policy
medium
Adds explicit disclosure of email engagement tracking; removes prior data removal process language
Why it matters: The updated policy formalizes email engagement tracking as an explicit data collection practice, which affects how HubSpot customers' email campaigns are monitored and how email recipient data is processed. Simultaneously, the removal of the data removal process language eliminates a stated user pathway for requesting data deletion, which may create ambiguity about compliance with GDPR erasure rights and CCPA/CPRA deletion rights unless HubSpot has provided an alternative mechanism.
HubSpot
HubSpot Terms of Service
medium
Updated AI governance language to disclose AI as foundational to platform; added explicit opt-out mechanism for AI model training.
Why it matters: The updated terms establish explicit disclosure and authorization for AI model training on customer data, a material shift from prior language that addressed data use only in general terms. This formalization of AI practices may require organizations using HubSpot to update their own privacy notices, data processing agreements, and internal AI governance policies, particularly in jurisdictions with emerging AI-specific regulatory frameworks such as the EU AI Act.
July 1, 2026
Unity
Unity Terms of Service
medium
Requires prior authorization to train AI models on Unity data; restricts automated access through scrapers, bots, and AI agents.
Why it matters: The updated terms establish binding restrictions on a common and growing use case: training AI models on platform data. By requiring prior authorization, Unity now gates a development practice that was previously unaddressed in its terms, meaning organizations that plan to use Unity data for AI training must now explicitly request permission before proceeding. This also reflects a broader industry trend of platforms establishing control over AI training on their data and services, which affects how development teams integrate with third-party platforms.
Windsurf
Windsurf Terms of Service
medium
Rebrands service to Cognition Platform and clarifies new company ownership; prior terms govern for 30 days from posting.
Why it matters: The updated terms establish a formal transition structure for a corporate rebranding and ownership change. Users have 30 days to review and decide whether to accept the new Cognition Platform terms; after that period, continued use constitutes binding acceptance. Organizations that depend on the service should confirm that the shift from Exafunction to Cognition does not materially alter data processing terms, service level agreements, or compliance obligations.
DraftKings
DraftKings Terms of Use
medium
Adds VPN prohibition, authorizes cross-platform fund transfers, and clarifies terms apply to daily fantasy contests only, not other DraftKings services.
Why it matters: The updated terms operationally restrict how users can access the platform (VPN prohibition), change age eligibility requirements for two states (adding Illinois, removing Virginia grandfather), and establish that DraftKings can move user funds across its multiple business lines without explicit per-transaction authorization. These changes affect account access enforcement, user eligibility, and fund custody practices.
Stay ahead of the changes

Don't manually check every platform

Get alerts when policies change, before it affects you.

Updated daily. New changes added as detected.

← Newer Page 3 of 14 Older →